T3 Code audit: issues, volume 1

pingdotgg/t3code. All authors. Drafts included. Default branch main. 570 issue assessments and 925 PR assessments. Initial inventory: 570 open issues and 924 open PRs. Current assessed open inventory: 570 issues and 924 PRs. Final reconciliation: 2026-09-01T11:57:41.491617+00:00.

Source baseline: e86604d3372acccd9f6a33a2c4ae46f4e2685541. A fix in this commit is not necessarily in a stable release.

Issues, volume 1

181 items. Each GitHub number links to its item. Recommendations and GitHub metadata are shown separately.

Issue #274. Not able to commit changes when using GPG-autosigned commits

Request. Commit actions cannot complete signing that requires a passphrase or a user-presence prompt.

Audit finding. The Git action still executes git commit as a background process and has no signing-prompt exchange with the client. The discussion adds SSH hardware-key signing that works through the agent but not the commit button. Shell-environment changes do not prove that either interactive signing case is handled.

Recommendation. Keep open: work remains. Add a supported interactive signing path and test the commit button with both passphrase and hardware-key signing.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Kotsucoder. Updated 2026-04-12T01:25:29Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5740.

Limits. No passphrase or hardware-key signing reproduction was run.

Issue #635. Worktree creation fails when path's are too long

Request. Windows worktree creation fails when the generated base directory pushes paths past the Git path limit.

Audit finding. Worktree paths still add the repository and branch names under the T3 worktree directory. Current Git execution does not set core.longpaths, and the longer worktree-add timeout only changes the time limit. The Windows long-path proposal remains open.

Recommendation. Keep open: work remains. Review the Windows core.longpaths proposal with a checkout path longer than 260 characters.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author pingu2k4. Updated 2026-03-09T10:16:11Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #6327, #5614.

Limits. Windows checkout was not reproduced.

Issue #695. T3 Code is significantly slower than Codex for the same coding task (20+ min vs ~3m24s)

Request. T3 takes much longer than the provider's own client to complete comparable tasks.

Audit finding. Main now defaults to buffered output, appends legacy streaming deltas in SQLite, and parses large Codex frames without repeated concatenation. The discussion reports several different cases, including full-access runs and both Codex and Claude, so no single cause is established. These changes justify a new matched timing test, not closure of the broad performance report.

Recommendation. Keep open: retest. Repeat matched provider-client and T3 runs, recording provider completion time separately from UI delivery time.

Confidence medium. Release: Main only.

Observed GitHub metadata. GitHub state OPEN. Author MatejSkarka. Updated 2026-08-26T19:15:00Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #9032, #8605, #5681. Merged PRs that cover all or part: #9032, #8605.

Limits. No matched benchmark was rerun against the pinned main commit.

Issue #728. macOS: apps launched from integrated terminal can't request TCC permissions (mic, camera)

Request. macOS child apps cannot request microphone or camera permission when launched from the integrated terminal.

Audit finding. The dev launcher still changes the app and helper plists without signing the changed bundle. The production macOS build still has no microphone or camera usage-description keys and disables identity discovery for unsigned builds. The open microphone PR does not establish that camera access and both build paths are handled.

Recommendation. Keep open: work remains. Add and verify the required permission descriptions and signing behavior for both development and packaged macOS builds.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author mikaelweiss. Updated 2026-03-13T00:45:03Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5321.

Issue #861. Desktop app appears too small on high-DPI displays on Windows/Linux

Request. Windows and Linux users want usable high-DPI scaling with a persistent manual override.

Audit finding. Main now has an Interface font size setting and reliable main-window zoom commands, which address the missing manual adjustment described in the discussion. It still resets zoom to level zero and has no per-display baseline or monitor-change recalculation. The auto-scaling proposal was closed without merge, so the original multi-monitor request remains.

Recommendation. Keep open: partial fix. Decide and implement a per-display scaling rule that preserves manual zoom.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author SuperComboGamer. Updated 2026-08-04T16:01:21Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5691, #406, #7957. Merged PRs that cover all or part: #5691.

Issue #871. Assistant message projections collide across threads when message IDs are reused

Request. Reused assistant message IDs can overwrite another thread's projected message.

Audit finding. Both upsert paths still conflict on message_id alone and replace thread_id, while the table still has a global message_id primary key. The recent streaming optimization retained that identity model. Provider-specific ID fixes do not establish isolation for the deterministic two-thread input in this report.

Recommendation. Keep open: work remains. Scope message persistence and fallback identities by thread, then add the two-thread collision test.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author nassimna. Updated 2026-03-11T00:22:42Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #882, #4560.

Issue #881. No processing indicator when resuming an interrupted thread

Request. Resuming an interrupted Codex thread can produce replies without a visible working indicator.

Audit finding. Turn startup now preserves starting state through provider-ready events, and ChatView counts local dispatch and connecting state as work. The latest activity-row change also keeps agent activity visible between actions. These changes cover plausible causes, but neither the sleep/resume reproduction nor the later composer-only failure has been verified on the current build.

Recommendation. Keep open: retest. Retest interrupt and macOS sleep/resume while checking both the composer and sidebar indicators.

Confidence medium. Release: In nightly source.

Observed GitHub metadata. GitHub state OPEN. Author Rafcin. Updated 2026-07-09T06:03:01Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #886, #4101, #8984. Merged PRs that cover all or part: #4101, #8984.

Limits. No current sleep/resume or interrupted-follow-up reproduction.

Issue #932. BUG: Missing edited files in the turns panel

Request. The turn file list stops at the first Codex edits and later edits appear in the next turn.

Audit finding. The August 28 comment identifies the same early diff snapshot and follow-up-prompt workaround as the active detailed report. The reactor still captures a ready checkpoint from the first placeholder and skips a second capture at turn completion. Keep the detailed reproduction and current Windows report together under the active issue.

Recommendation. Close: duplicate. Close this as a duplicate of issue 1434 and preserve the August 28 Windows reproduction there.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author juanpablob. Updated 2026-08-28T20:23:07Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #1434.

Independent closure check. Both full discussions describe the same early turn diff snapshot and later edits appearing only after a follow-up prompt. The August 28 Windows reproduction from 932 is already copied verbatim into active issue 1434, which also has the fuller 18-file reproduction and an explicit cross-link. Pinned checkpoint code still captures a real snapshot from the first placeholder and then skips completion capture, so only duplicate closure is valid.

Issue #961. Persisted state corruption can leave T3 Code unusable with no clear recovery path

Request. Corrupt persisted state can block startup and lacks a clear, safe recovery path.

Audit finding. Merged changes now skip undecodable provider runtime rows and turn SQLite open failures into typed errors. Codex also has a recoverable-resume fallback, but these narrow paths do not provide recovery for a corrupt database, malformed state files, or client storage. The broad reliability issue therefore remains open despite the stable fixes.

Recommendation. Keep open: partial fix. Define a user-visible recovery path that preserves bad state for diagnosis before replacing it.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author copypasteitworks. Updated 2026-04-01T06:38:29Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3951, #3428, #964, #1231, #4374. Merged PRs that cover all or part: #3951, #3428.

Issue #1020. monorepo projects do not resolve nested app favicons

Request. Monorepo projects need automatic discovery of favicons below nested application roots.

Audit finding. The resolver still searches a fixed root-relative candidate list and does not enumerate apps or site directories. Merged icon-picker work lets users select a nested icon explicitly, as the discussion notes, but automatic discovery remains missing. The nested-resolution proposal is still open.

Recommendation. Keep open: partial fix. Keep automatic nested-icon discovery open and point users to the shipped icon picker meanwhile.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author ponbac. Updated 2026-08-29T17:14:55Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4424, #5775, #7823. Merged PRs that cover all or part: #5775, #7823.

Issue #1084. [Bug]: Malformed local SKILL.md causes unreadable thread failure and poor diagnostics

Request. A malformed Codex skill produces a short-lived, hard-to-read diagnostic in the thread.

Audit finding. Codex stderr is now classified and forwarded as runtime messages, and the thread banner supports explicit dismissal. The banner still clamps the message to three lines and has no full-text copy action, while malformed-skill recovery or skipping is not established. This improves the diagnostic path but does not meet the full readable, retained-error request.

Recommendation. Keep open: partial fix. Add a persistent expandable error detail with copy support and test malformed skill startup.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author sebherrerabe. Updated 2026-03-14T16:49:41Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #1202, #3747, #6123. Merged PRs that cover all or part: #1615, #6123.

Limits. No malformed-skill run on the current Codex CLI was performed.

Issue #1399. Sidebar context menus are inaccessible to screen reader and keyboard-only users

Request. Keyboard and screen-reader users cannot reach all sidebar project actions.

Audit finding. The August retest confirms thread context menus work on Windows, but project actions remain the missing part. The current searchable project picker still nests its action button inside each ComboboxItem and stops pointer events without an equivalent keyboard action. The sidebar redesign therefore does not close the project-action defect.

Recommendation. Keep open: partial fix. Make project actions a separate keyboard-reachable control and verify them with NVDA.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author haroonkareem22. Updated 2026-08-06T12:51:59Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5521, #7916.

Issue #1434. [Bug]: Diff view captures only the first few edits from a turn and shifts the rest to the next turn

Request. Codex turn diffs capture early edits and assign later edits to a following turn.

Audit finding. Runtime ingestion emits a missing checkpoint on the first turn.diff.updated event. The checkpoint reactor immediately replaces it with a ready filesystem snapshot, and turn completion skips a turn that already has a non-missing checkpoint. August 28 reports confirm the same symptom in current releases, and the earlier proposed fix was closed without merging.

Recommendation. Keep open: work remains. Make turn completion own the final checkpoint and test sequential edits after the first diff event.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author a-chugunov. Updated 2026-08-28T20:51:00Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #932, #1442.

Issue #1482. AppImage fails on Ubuntu 24.04+ (requires manual apt install and use of --no-sandbox)

Request. The Linux AppImage needs FUSE 2 and a sandbox workaround on current Ubuntu releases.

Audit finding. The Linux release target is still AppImage, and the desktop still enables the Chromium sandbox. The proposed static-runtime change is open and addresses the FUSE dependency, not the separate AppArmor sandbox failure. The discussion confirms the same launch problem on Ubuntu 26.04.

Recommendation. Keep open: work remains. Keep the issue open until the packaged AppImage launches on a clean supported Ubuntu install.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author ryanshipswell. Updated 2026-05-07T16:59:28Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7765, #4465.

Issue #1714. [Bug]: Externally created Git worktrees are treated as "Local"

Request. A worktree created by an agent during a thread does not update the thread workspace or editor target.

Audit finding. Provider startup still uses the thread and project workspace binding, while branch-drift handling only follows an already bound worktree. Creating another worktree through an agent command does not update that binding. The August comment confirms that the footer continues to display the original checkout after the agent moves work.

Recommendation. Keep open: work remains. Add an explicit agent-to-thread worktree binding operation that updates the workspace and editor target together.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author paulomanrique. Updated 2026-08-06T07:48:47Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3753.

Issue #1978. [Bug]: Windows "Open in Zed" opens Zed Nightly instead of stable Zed

Request. Opening Zed on Windows can select Zed Nightly when stable Zed is also installed.

Audit finding. The editor contract still lists zed before zeditor. The server returns the first available command without checking whether its resolved executable belongs to stable or Nightly. The focused stable-Zed proposal was closed without merge.

Recommendation. Keep open: work remains. Resolve the Windows Zed executable variant before choosing the launch command.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author srothgan. Updated 2026-04-16T13:58:13Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #2066.

Issue #2017. [Bug]: Checkpoint fail in git repos

Request. Checkpoint capture fails on each turn even though the project is a Git repository.

Audit finding. The report and comments provide no full Git failure, and one reporter suspects a large monorepo. Current capture still stages the workspace into a temporary index, so size, permissions, hooks, and repository layout cannot be distinguished from this evidence. The newer structured errors do not establish a fix for the reported failure.

Recommendation. Keep open: evidence needed. Request the full checkpoint error, repository size, and current app version from an affected run.

Confidence medium. Release: Release not verified.

Observed GitHub metadata. GitHub state OPEN. Author parzival1l. Updated 2026-05-08T19:15:42Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3646, #2441.

Limits. The report lacks the underlying Git error and a reproducible repository.

Issue #2127. [Bug]: Diff panel and Revert functionality not working

Request. Windows threads show no completed diffs and never allow revert.

Audit finding. Both reporters see no completed turns, but neither supplies checkpoint logs, a repository layout, or a recent version. The current reactor only records checkpoints after its Git-workspace guard passes, and capture errors have a separate activity path. This is not enough to choose between detection failure and checkpoint execution failure.

Recommendation. Keep open: evidence needed. Request one current Windows trace covering a completed turn and its checkpoint failure or skip.

Confidence medium. Release: Release not verified.

Observed GitHub metadata. GitHub state OPEN. Author tlh38. Updated 2026-07-20T15:48:43Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #2017, #2441.

Limits. No current-version reproduction or complete checkpoint log is available.

Issue #2141. [Bug]: Cant scroll terminal in mobile web

Request. Mobile browsers cannot scroll terminal history with a drag inside the terminal.

Audit finding. The terminal now uses Ghostty, but its canvas pointer handlers still start text selection or send mouse reports. Scrolling uses wheel events or the narrow scrollbar, with no touch-drag scroll path. The discussion confirms that dragging the scrollbar in landscape works and does not meet the requested gesture.

Recommendation. Keep open: work remains. Add touch-drag scrollback to the web terminal without changing mouse selection or terminal mouse reporting.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author jonocodes. Updated 2026-08-03T18:15:28Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #6096.

Issue #2148. [Bug]: Creating a thread in an empty git repository (no commits) crashes with "select a thread"

Request. Sending the first message in a repository without commits can fail worktree creation and remove the draft thread.

Audit finding. resolveSendEnvMode still checks only isGitRepo, not whether HEAD has a commit. Server bootstrap still calls createWorktree and deletes a newly created thread after failure. The landed unborn-HEAD status fix does not add a local-mode fallback to this send path.

Recommendation. Keep open: work remains. Add a no-commit fallback before preparing the first worktree.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author alecramos-sudo. Updated 2026-07-20T15:55:50Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #6208, #5944.

Issue #2187. [Bug]: Git integration treats 1Password shell-plugin gh auth as unauthenticated

Request. GitHub integration does not support authentication supplied only by a shell alias or a custom shell Git configuration.

Audit finding. GitHubCli invokes gh directly, so a 1Password alias is never evaluated. Desktop imports a fixed environment list that also omits the GIT_CONFIG_GLOBAL variable raised in the discussion. The generic login guidance does not explain either configuration gap.

Recommendation. Keep open: work remains. Define supported shell-plugin authentication and show a specific diagnostic when direct gh lacks the shell-provided credentials.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author harshPPatel. Updated 2026-05-22T14:28:13Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5840, #7618.

Issue #2336. [Bug]: Thread becomes permanently unusable if claudeAgent CLI session is killed before writing its first turn (dangling resume_cursor_json at turnCount=0)

Request. A Claude thread can persist an uncreated native session ID and then fail every resume attempt.

Audit finding. startSession still returns a generated resume cursor before any turn is written, and ProviderService persists it. ensureThreadId also accepts a failing result message as a durable session ID, so the missing-session error can preserve the same bad cursor. The discussion confirms this on v0.0.35 after a graceful first-turn shutdown, not only a crash.

Recommendation. Keep open: work remains. Review #5433 with both first-turn failure and recovery of an existing context-bearing session.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author shardmods. Updated 2026-08-28T09:01:49Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5433, #7155.

Issue #2343. [Bug]: [Critical]: T3Code forgets complete session history

Request. Threads can retain a visible transcript while their provider starts without the earlier context.

Audit finding. The discussion contains separate Claude, Codex, and OpenCode reports, including database evidence of repeated OpenCode sessions. Main now persists and reuses the OpenCode session ID, preserves history across directory changes, and propagates probe errors instead of silently creating an empty session. That fixes the documented OpenCode mechanism but does not establish the cause of the Claude or Codex reports.

Recommendation. Keep open: partial fix. Retest the remaining Claude and Codex cases while recording provider session continuity.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author degrootruben. Updated 2026-08-04T00:07:21Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3604, #3617, #3860. Merged PRs that cover all or part: #3617.

Limits. No current Claude or Codex reproduction establishes the remaining cause.

Issue #2441. [Bug]: Diffs/checkpoints not shown when workspace cwd is a subdirectory of a git repo

Request. Projects opened below a Git repository root miss checkpoints and can receive empty diffs.

Audit finding. The legacy helper still tests only for a .git entry directly inside cwd, and the checkpoint reactor still uses it. The newer VCS detector uses rev-parse, so successful Git status does not fix that earlier guard. The August 27 WSL reproduction also reports an empty working-tree preview through a separate guard, so fixing only checkpoint detection would leave part of the report unverified.

Recommendation. Keep open: work remains. Replace the checkpoint guard with VCS detection and verify both turn and working-tree diffs from a nested WSL project.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author imabdulazeez. Updated 2026-08-27T12:37:15Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #2443, #4022, #5616.

Issue #2477. [Bug]: Codex subagent completion output can interleave with main-agent output

Request. Overlapping Codex parent and child output can produce interleaved live text.

Audit finding. Registered native children now have separate event routing that drops their assistant deltas from the parent path. However, receiver-only children still have a registration gap, and ingestion reuses the active assistant segment for a canonical turn. The original report has no full delta trace, so current source cannot prove that its live-render interleaving is fixed.

Recommendation. Keep open: retest. Replay an overlapping parent-child delta trace and check both live text and persisted messages.

Confidence medium. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author lastobelus. Updated 2026-05-03T02:41:34Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5219, #5953. Merged PRs that cover all or part: #5219.

Limits. The original overlapping delta sequence and renderer state were not attached.

Issue #2519. [Bug]: Implement Plan Button Does not Appear after plan has be generated successfully

Request. Claude can finish a plan without showing the Implement action.

Audit finding. The adapter only captures a proposed plan when ExitPlanMode includes a non-empty plan string. The web follow-up action requires a captured proposed plan after the turn settles, so a prose plan or a tool call without inline plan text still has no Implement action. Moving plan mode to Legacy settings did not repair this enabled path, and both directly linked attempts were closed without merging.

Recommendation. Keep open: work remains. Capture Claude's completed plan when ExitPlanMode has no inline plan text.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Muzammil-Bit. Updated 2026-08-05T16:23:56Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #2597, #7263, #5664.

Issue #2523. [Bug]: Windows SSH environment error due to missing 'sh'

Request. Adding a native Windows SSH environment fails because remote startup requires sh.

Audit finding. The shared SSH launcher still runs sh -l -s on the remote host. Pairing, stop, and log commands also require sh, and the generated runner uses POSIX shell syntax. Native Windows SSH with a PowerShell default shell is not handled by the current path.

Recommendation. Keep open: work remains. Add a native Windows SSH launch path or reject unsupported targets with a clear message before setup.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author carlospedreira. Updated 2026-05-05T10:49:20Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Issue #2537. [Bug]: Frequent cmd.exe / conhost flashes on Windows from provider probe & VCS process kill paths

Request. Windows background probes and process cleanup open visible console windows.

Audit finding. The system-executable shell wrappers were removed by merged PR 2950, and VcsProcess now delegates to ProcessRunner. The dependency catalog still pins the process spawner to Effect beta.103, before the upstream window-hiding and taskkill fix reported in the discussion. OpenCode cleanup and maintenance still call child.kill, so the broad console-flash report is not fixed.

Recommendation. Keep open: partial fix. Update or patch the Effect process spawner and verify both normal child launches and process-tree cleanup on Windows.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author samvdst. Updated 2026-08-11T19:56:37Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #2950, #6284. Merged PRs that cover all or part: #2950.

Limits. No Windows runtime or Process Monitor reproduction was run.

Issue #2614. [Bug]: Orphaned t3 serve processes remain after closing app sessions, causing port leaks and high memory usage

Request. Managed SSH environments can leave remote server process trees running after disconnect or app exit.

Audit finding. The follow-up identifies the old Windows-desktop-to-Linux SSH launcher and corrects the expected shutdown trigger to Disconnect or Quit. Current SSH code records a managed PID, reuses a ready server, and runs remote cleanup from the tunnel finalizer. Tunnel ownership also changed after the reported build, but the report has no controlled current-build disconnect or quit capture.

Recommendation. Keep open: retest. Capture the remote process tree before and after Disconnect and Quit on the latest stable desktop.

Confidence medium. Release: Release not verified.

Observed GitHub metadata. GitHub state OPEN. Author fionns-openclaw. Updated 2026-08-04T18:04:08Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4347.

Limits. No current-build process-tree reproduction proves cleanup of the reported orphan chain.

Issue #2627. [Bug]: Cannot revert to prompt after provider error

Request. A failed prompt without a normal assistant message has no revert or delete action.

Audit finding. The web revert map still scans from each user message to a following assistant message and requires its checkpoint summary. A failure before an assistant message exists cannot enter that map, even if the turn has a checkpoint. Later prompts do not repair the association, and the related network-error report identifies the same missing path.

Recommendation. Keep open: work remains. Map revert availability through the failed turn checkpoint without requiring a rendered assistant message.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author gregbartell. Updated 2026-05-10T14:02:48Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7982.

Issue #2644. Chat shows 'working...' indefinitely after opencode CLI already finished responding

Request. OpenCode finishes a reply, but T3 remains in Working and can retain that state after restart.

Audit finding. The current adapter keeps an event-stream reader in the session scope, handles idle status, and recovers prompt-admission events that arrive out of order. The merged lifecycle work changes the old disconnect and completion paths, but the discussion covers several versions and does not establish that all stuck-state causes are fixed. Saved abort state and pending approvals still have separate open defects.

Recommendation. Keep open: retest. Retest a short OpenCode turn on the current release and capture the native event trace if Working remains.

Confidence medium. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author fadilsflow. Updated 2026-08-01T11:55:54Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8480, #8895, #7113, #8619. Merged PRs that cover all or part: #8480.

Limits. No current-build trace identifies the remaining cause across the older reports.

Issue #2709. Provider maintenance subprocesses don't inherit macOS system proxy settings

Request. Provider updates launched from the macOS Dock do not inherit system proxy settings.

Audit finding. DesktopShellEnvironment imports selected login-shell variables but does not read macOS system proxy configuration. The maintenance runner launches the update command with inherited process environment only. The comment gives a launchctl proxy-variable workaround, not automatic system-proxy support.

Recommendation. Keep open: work remains. Add system-proxy resolution for maintenance subprocesses, with focused tests for Dock-launched updates.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author mole828. Updated 2026-07-30T17:18:34Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Issue #2736. [Bug]: Cursor/OpenCode skill discovery returns zero skills despite skills existing on disk (Claude/Codex discover them fine)

Request. Cursor and OpenCode should expose installed user and project skills and commands in the composer.

Audit finding. OpenCode skills now enter the provider snapshot through the merged skill-discovery and HTTP catalog changes. Cursor still supplies neither skills nor slash commands, while OpenCode discovery still uses the server startup directory and does not load native custom commands. The latest Cursor reproduction and the project-local skill report therefore remain in scope.

Recommendation. Keep open: partial fix. Finish the missing Cursor and OpenCode skill and command discovery paths for the active project.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author AspectHeat. Updated 2026-08-31T21:08:36Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3154, #8480, #8770, #8778, #8792, #8043. Merged PRs that cover all or part: #3154, #8480.

Issue #2778. [Bug]: Session hung forever after spawning subagents

Request. OpenCode subagents can leave the parent turn running indefinitely.

Audit finding. Merged child-session handling explicitly permits external_directory in full-access mode and routes child permission requests through the parent thread. That addresses the original hidden-permission reproduction. The newer discussion records a different hang with empty permission and question queues after a connection failure, so child approval support and improved Stop handling do not prove this issue fully fixed.

Recommendation. Keep open: partial fix. Reproduce the no-permission parent-and-child busy hang after a network interruption.

Confidence high. Release: Main only.

Observed GitHub metadata. GitHub state OPEN. Author gustavodaltoe. Updated 2026-08-26T04:57:31Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5952, #8480, #9005. Merged PRs that cover all or part: #8480, #9005.

Limits. The no-permission network-failure hang was not reproduced during this read-only audit.

Issue #2789. [Bug]: session.revert fails with 400 'Expected object, got undefined' when rolling back all assistant turns

Request. OpenCode rollback omits the required message ID when all assistant turns are removed.

Audit finding. The adapter still computes assistantMessages.length minus numTurns minus one and uses null for a negative index. It then omits messageID in session.revert, exactly matching the reported empty-body failure. Recent OpenCode child-session fixes do not change this rollback block.

Recommendation. Keep open: work remains. Choose a valid first-message rollback target and test reverting all available OpenCode turns.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author aravindcm49. Updated 2026-06-27T03:30:31Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #2829.

Issue #2803. [Bug]: Cannot attach or paste images in remote web session on mobile Chrome

Request. Android Chrome needs a visible picker to attach images in a remote web chat.

Audit finding. The current web composer has an Attach files button beside Send with no mobile-width hiding rule. Its native file input accepts selected files through addComposerAttachments, and image classification keeps PNG and HEIC selections on the image path. This supplies the mobile-friendly picker explicitly requested, without relying on Android clipboard image support, and the change is included in the verified stable release.

Recommendation. Close: fixed. Close as fixed by the web attachment picker and ask users on old servers to update.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author joshua-lehmann. Updated 2026-07-09T05:37:56Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8236, #8048. Merged PRs that cover all or part: #8236.

Independent closure check. The body explicitly accepts either clipboard support or a mobile-friendly picker. Current ChatComposer renders a native multiple-file input and an Attach files button in the compact action group without a mobile hiding class. Selected PNG/JPEG/HEIC files follow the image attachment path and no clipboard API is required. The picker requires the current server attachment capability, so the recommendation must tell old-server users to update. Merged 8236 is in stable 0.0.37. No Android browser runtime check was performed.

Limits. Source and existing tests were inspected; no live Android Chrome session was run.

Issue #2804. [Bug]: Copy action for assistant responses is not discoverable or usable on mobile web

Request. Android mobile web users cannot find a reliable copy action for complete assistant responses.

Audit finding. The assistant copy control exists, but its footer still starts at opacity zero and becomes visible only on hover or focus. That preserves the touch discovery problem even though desktop copying works. Native Android copy work does not change this mobile-browser path.

Recommendation. Keep open: work remains. Make the assistant copy footer visible for touch input and check it in Android Chrome.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author joshua-lehmann. Updated 2026-05-25T19:20:46Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #1455.

Issue #2823. [Bug]: Cursor integration triggers an infinite loop of permissions alerts

Request. Cursor integration repeatedly opens Xcode MCP permission dialogs for newly spawned processes.

Audit finding. Disabled Cursor instances now skip probing, but an enabled Cursor health check still starts a fresh ACP session in the server working directory. That path has no Xcode or user-MCP isolation, so the relevant process-creation mechanism remains. The exact indefinite dialog loop has not been confirmed on current Cursor and Xcode versions.

Recommendation. Keep open: retest. Reproduce with current Cursor and Xcode while tracing which provider probes create each new MCP process.

Confidence medium. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author armanarutiunov. Updated 2026-05-27T12:24:42Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #6533, #7933, #8175. Merged PRs that cover all or part: #8175.

Limits. No macOS or Xcode runtime reproduction was run.

Issue #2830. [Bug]: Tailscale HTTPS - Show the "Serve is not enabled on your tailnet." error in GUI.

Request. Enabling Tailscale HTTPS hides the Serve-disabled error and restarts the desktop app anyway.

Audit finding. The desktop setting handler persists the requested value and requests a relaunch without running Tailscale Serve first. The server runs Serve during startup and logs a warning on failure instead of returning it to the Settings action. Structured Tailscale errors therefore do not provide the requested GUI error or prevent that restart.

Recommendation. Keep open: work remains. Return the Serve setup failure to Settings before persisting the enabled state or relaunching.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author mmmattG. Updated 2026-05-27T20:55:42Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4698, #4919, #4028.

Issue #2866. Bug: Cannot delete project with only archived threads , client/server state mismatch

Request. Removing a project with only archived threads fails after the client reloads its shell snapshot.

Audit finding. The server still treats every non-deleted thread as blocking project removal, including archived threads. The legacy sidebar still chooses its force-delete prompt from client-visible membership, so an archived-only project can take the unforced path. The discussion confirms the same failure on stable 0.0.36, and the direct fix is still open.

Recommendation. Keep open: work remains. Review and finish the archived-thread-aware removal fix.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author coygeek. Updated 2026-08-30T08:40:47Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8798, #4632.

Issue #2867. [Bug]: Packaged builds set server cwd to $HOME; ClaudeProvider auxiliary spawns leak it past project bindings

Request. Packaged desktop probes inherit the server home directory instead of a neutral or project directory.

Audit finding. #2124 added a cwd parameter, but ClaudeDriver still supplies ServerConfig.cwd, and packaged desktop still sets that directory to the user home. runClaudeCommand still omits cwd. The comment's separate environment concern is also present in mergeProviderInstanceEnvironment, which copies raw process.env without removing Electron and AppImage variables.

Recommendation. Keep open: work remains. Define and apply an explicit directory and environment policy for provider auxiliary processes.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author renatogcarvalho. Updated 2026-08-30T15:11:35Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #2124, #8818, #8835, #8908.

Limits. No packaged-wrapper or AppImage runtime reproduction was run.

Issue #3033. [Bug]: the *Claude provider surfaces the *selected* model, not the served* model. silent Fable 5 → Opus guardrail fallback is invisible

Request. Claude model fallback is hidden, so the selected model can differ from the model that served the turn.

Audit finding. The parent turn is still labeled from modelSelection, while model_refusal_fallback is explicitly discarded. Actual model updates from assistant snapshots are used for subagents, not parent-turn attribution. The open fallback-notice patch would add a warning, but it does not add per-turn served-model metadata.

Recommendation. Keep open: work remains. Review #8853 against the requested visible fallback notice and keep served-model attribution separate if needed.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author snipemanmike. Updated 2026-08-15T11:55:47Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8853, #7583.

Issue #3067. [Bug]: server-started terminals in devcontainers can miss forwarded SSH_AUTH_SOCK`

Request. Terminals started by a boot-time devcontainer server miss an SSH agent socket injected later by VS Code.

Audit finding. TerminalManager still takes its base environment from the running server and passes that environment to PTY spawn. There is no discovery of a later VS Code forwarded socket or refresh from the attached editor environment. Desktop login-shell hydration does not update this Linux server process, and the proposed devcontainer repair was closed without merge.

Recommendation. Keep open: work remains. Refresh the supported forwarded SSH agent socket before starting a devcontainer terminal.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author boblangley. Updated 2026-06-13T04:57:51Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3068, #5740.

Issue #3089. [Bug]: MCP plugin processes (bun server.ts) are never killed when closing conversations

Request. Closing Claude conversations leaves Telegram MCP Bun processes running and consuming resources.

Audit finding. A later report reproduces on 0.0.33 and traces orphaned Bun children to writes on undrained pipes after the app quits. Main closes the Claude SDK query, but has no separate ownership or forced cleanup of the plugin child tree shown in that trace. Settling-provider cleanup does not establish a fix for those already orphaned descendants.

Recommendation. Keep open: work remains. Add owned-process cleanup that covers the Telegram wrapper and its Bun child on session close and app quit.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author zordor. Updated 2026-08-19T06:35:49Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5774.

Limits. The Bun plugin process tree has not been reproduced on pinned main.

Issue #3094. [Bug]: Connecting to a remote OpenCode server through URL running on Linux from a Windows machine does not work

Request. A Windows T3 server sends its local project path to a remote Linux OpenCode server and prevents discovery.

Audit finding. The SDK client still includes directory for every server URL. Both external-server health checks and catalog discovery pass the local directory, so the Windows-to-Linux path mismatch remains. The proposed remote-directory fix is still open.

Recommendation. Keep open: work remains. Review PR #6228 for the remote-directory path.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author buzzy. Updated 2026-06-15T23:13:34Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #6228.

Issue #3131. Sidebar can miss unread Completed status for newly finished threads

Request. A newly observed completed background thread can appear read before the user opens it.

Audit finding. The old activity-timestamp seeding is gone, but hasUnseenCompletion still returns false when no visit timestamp exists. The new sidebar explicitly treats never-visited threads as read, with no distinction between bootstrap history and newly arriving completed threads. Stamping visits at completion time fixes clock skew for viewed threads, not this first-observation case.

Recommendation. Keep open: work remains. Distinguish initial history from newly observed completed threads when initializing read state.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author paulbettner. Updated 2026-07-20T16:51:29Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3139, #3235, #4695.

Issue #3141. [Bug]: preview annotation element picker does not work inside iframes

Request. The desktop preview annotation tools cannot select or draw over iframe content.

Audit finding. The picker still installs pointer handlers only on its own window, and its overlay allows pointer events through to the page. Pointer events inside an iframe do not reach those handlers, and there is no child-frame picker or frame-coordinate conversion. The two referenced proposals were closed without merging.

Recommendation. Keep open: work remains. Add frame-aware selection and a drawing layer that receives pointer input above iframes.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author tarik02. Updated 2026-06-18T11:11:52Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3160, #3237.

Issue #3142. [Bug]: Inline code typed on dead-key keyboard layouts renders literally (non-ASCII grave instead of U+0060)

Request. Inline-code delimiters typed on dead-key layouts can be stored as non-ASCII grave characters.

Audit finding. The composer handles a selected-text backtick surround only when the composition event already contains ASCII backtick. Other insertCompositionText input still passes through, and no scoped conversion of the reported look-alike codepoints exists. The report proves the renderer behavior but explicitly leaves the input origin unverified, so a blanket text replacement would be unsafe.

Recommendation. Keep open: evidence needed. Capture beforeinput and composition event codepoints for one affected keyboard layout.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author thelooter. Updated 2026-06-18T11:16:33Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3158, #3236.

Limits. No event capture proves whether the OS, input method, or composer introduces the look-alike delimiter.

Issue #3513. [Bug]: Failed startup session probe bricks the app , fatal, sticky error in root beforeLoad with no recovery

Request. A failed startup session probe leaves the desktop app on a sticky root error screen.

Audit finding. The session probe still runs before the guarded credential exchange. RootRouteErrorView still calls reset for Try again and has no focus or online retry, unavailable gate, or sign-out action. The retry proposal remains open, and it does not cover the separate session-store write failure or all diagnostic requests.

Recommendation. Keep open: work remains. Implement a recoverable startup-unavailable state that retries the session probe without deleting local credentials.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author aanishs. Updated 2026-07-20T18:30:23Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3520.

Issue #3525. [Bug]: Background git fetch fills up entire disk when fetch exceeds the 5s timeout (regression of #1965)

Request. Repeated timed-out background Git fetches leave temporary pack files and can fill the disk.

Audit finding. Current fetchRemoteForStatus still has a five-second timeout and no temporary-pack cleanup. Backoff reduces frequency, but the later reproduction explicitly reports continued growth after backoff existed. The proposed cleanup work was not merged, so this must not be closed on the basis of slower polling.

Recommendation. Keep open: work remains. Add owned temporary-pack cleanup and a fetch policy that can complete a large catch-up fetch.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Jardo-51. Updated 2026-08-13T03:22:49Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3646, #4296, #4338, #3537.

Limits. Disk growth was not reproduced in this read-only audit.

Issue #3530. [Bug]: Claude (Max OAuth) verifies OK but every generation 401s , only inside T3; CLI + Agent SDK both work standalone

Request. Claude Max authentication appears valid in Settings but generation fails with 401 errors only through T3.

Audit finding. The capability probe reads initialization data without making an API request, so its success does not verify generation credentials. Main uses the configured native binary on macOS and shares the Claude environment builder between probing and sessions, which does not support the comment that npm installation is required. Neither the report nor its recent follow-up identifies the failing query option, environment setting, or network difference.

Recommendation. Keep open: evidence needed. Collect a sanitized same-binary CLI/SDK/T3 comparison on the current release with exact CLI and SDK versions and effective query options.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author zordor. Updated 2026-08-28T09:16:49Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4017, #7690, #7878.

Limits. No failing request trace or demonstrated T3-specific option/environment difference is available.

Issue #3571. OpenCode adapter requires provider/model, but OpenCode Go runtime rejects opencode-go/<model> and expects bare model id

Request. OpenCode Go selections can contain a repeated provider prefix and fail model lookup.

Audit finding. The catalog still builds slugs from provider.id plus model.id, even when model.id already contains that prefix. The runtime parser removes only the first path segment, so a repeated prefix remains in modelID. The earlier CLI parser fix preserves slash-containing metadata but does not normalize these runtime IDs.

Recommendation. Keep open: work remains. Review PR #7247 against the current HTTP catalog path.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author jossadev-prog. Updated 2026-07-29T13:59:49Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7247, #5072, #8480.

Issue #3584. [Bug]: Chevron collapsed icon for tool calls is misleading

Request. Collapsed tool entries use a downward chevron instead of a right-facing chevron.

Audit finding. Turn-fold rows now use right and down chevrons, but individual expandable tool entries still render ChevronDownIcon when collapsed and rotate it 180 degrees when expanded. The reported tool-entry behavior remains in the shared web and desktop timeline.

Recommendation. Keep open: work remains. Use right and down chevrons for the individual tool-entry toggle.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author jakeleventhal. Updated 2026-06-27T19:22:55Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3853.

Issue #3646. [Bug]: Checkpoint capture on large monorepos retries a guaranteed 30s git-add timeout every turn , permanent CPU burn + tmp_pack disk litter

Request. Checkpoint capture repeatedly times out while staging large files and leaves temporary Git packs behind.

Audit finding. captureCheckpoint still runs git add -A against the workspace without a timeout override, so VcsProcess supplies 30 seconds. Its finalizer removes only the temporary index, and later turns attempt capture again. The newer Linux reproduction includes a large unignored core dump, so this is not limited to monorepos.

Recommendation. Keep open: work remains. Add checkpoint failure backoff with cleanup limited to temporary packs owned by the failed capture.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author mikeohuo. Updated 2026-08-11T15:11:58Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4517, #8301.

Issue #3664. [Bug]: Adding private personal github repository doesnt work due to git clone issue

Request. Private-repository cloning does not use the matching source-control CLI credential helper.

Audit finding. The clone service still executes bare git clone without a host-scoped credential-helper override. The maintainer and reporter agree that source-control authentication lives in the CLI, and the reporter proposes using that CLI only for this clone. A merged destination fix addresses the folder-selection problem mentioned in the thread, but not authentication.

Recommendation. Keep open: partial fix. Decide whether HTTPS clones should use the authenticated provider CLI as an invocation-scoped credential helper.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author Sy-D. Updated 2026-08-10T11:21:49Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5989. Merged PRs that cover all or part: #5989.

Issue #3694. [Bug]: GitHub PR creation fails on Windows v0.0.28 with generic createChangeRequest error despite manual gh pr create working

Request. Windows PR creation fails with a generic gh error even when the equivalent terminal command works.

Audit finding. The latest comment narrows the request to usable failure diagnostics and identifies a deliberate redaction tradeoff. VcsProcess classifies a few known failure categories but still discards arbitrary stderr, so GitHubCli cannot expose the actual PR-creation reason. No evidence identifies or fixes the original nonzero exit.

Recommendation. Keep open: decision needed. Choose bounded redacted gh diagnostics or local debug logging before attempting to fix the unknown creation failure.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author codemustflow. Updated 2026-08-11T23:42:01Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4380, #7382.

Limits. The original gh stderr is unavailable, so the cause of PR creation failure remains unknown.

Issue #3700. [Bug]: CAPTCHA aren't passing in the browser

Request. Privy CAPTCHA authentication fails in the desktop preview browser.

Audit finding. The discussion supplies a public email-auth reproduction and confirms that another embedded browser passes it. Current preview sessions still change the native User-Agent, but this alone does not prove the cause of Privy rejection. The landed OAuth popup fix does not establish CAPTCHA compatibility.

Recommendation. Keep open: evidence needed. Capture current console and network errors for the supplied Privy email-auth flow.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author VitorLostada. Updated 2026-07-20T16:18:15Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5002, #7110, #8435.

Limits. No current Privy CAPTCHA run or vendor rejection reason is available.

Issue #3709. WSL backend hangs at "Connecting to WSL…" (silent exit) when login-shell node is < 22.16

Request. The WSL backend can fail silently when the login shell selects an unsupported Node version.

Audit finding. The stable release includes a WSL preflight engine check and the entrypoint fallback for Node versions without import.meta.main. These remove the silent-start path described in the first half of the issue. The shared SSH/WSL shell helper still gates each version-manager fallback on node being absent, so an installed but unsupported Node still prevents selection of another installed version.

Recommendation. Keep open: partial fix. Finish the version-manager fallback change so each candidate must satisfy the engine range.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author arturskruze. Updated 2026-08-05T11:10:24Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3621, #7141, #3710. Merged PRs that cover all or part: #3621, #7141.

Issue #3712. [Bug]: preview_resize times out and leaves viewport state internally inconsistent

Request. Preview resizing times out and can leave requested dimensions different from the rendered page.

Audit finding. The PiP viewport fix added measured-viewport checks and guarded rollback of failed changes, and it is in stable v0.0.37. The operation still waits on the same full client and server timeout, and the discussion confirms later failures in fill, preset, and freeform modes, including a visible tab. The hidden-tab resize fix remains open.

Recommendation. Keep open: partial fix. Finish the resize fix and verify requested size, DOM size, rollback, and screenshot scale on a visible and a hidden Linux tab.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author gregbartell. Updated 2026-08-27T13:43:30Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8469, #8257. Merged PRs that cover all or part: #4661.

Issue #3713. [Bug]: preview_snapshot can fail or time out on loaded pages and leave tab automation unusable

Request. A failed or stalled preview snapshot can block later automation on the same tab.

Audit finding. Snapshots still request the complete accessibility tree and call capturePage without a desktop deadline. Every action holds one per-tab semaphore, so a stalled capture can block evaluate and input after the broker has timed out. Recent comments reproduce separate visible, hidden, and Windows failure cases. The recovery proposals are not merged.

Recommendation. Keep open: work remains. Bound and cancel desktop snapshot work, then verify that evaluate still works after a forced capture timeout.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author gregbartell. Updated 2026-08-30T03:03:39Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #6355, #8257, #8486, #8981, #7408, #7302.

Issue #3714. [Bug]: preview_click reports generic execution errors for missing targets

Request. A click on a missing element loses the target-specific error before it reaches the agent.

Audit finding. The desktop manager already throws PreviewAutomationTargetNotFoundError for zero matches. The web host only preserves its own error types and the not-editable special case, so target-not-found becomes a generic PreviewAutomationOperationError. Hidden, disabled, and ambiguous targets also need distinct handling. The diagnostics PR is still open.

Recommendation. Keep open: work remains. Preserve locator failure types through desktop IPC, the web host, and the MCP response.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author gregbartell. Updated 2026-07-05T18:54:58Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7301, #4685.

Issue #3715. [Bug]: preview_press does not reliably target the preview page

Request. Preview keyboard automation can miss the target page or send keys to the human composer.

Audit finding. The press path still focuses the guest WebContents, sends CDP input, and restores only the previously focused WebContents. It has no guard that proves focus stayed on the target before each event, and no restoration of the human DOM input. The latest comment reports unintended composer submission by Enter. Local and remote reports make this broader than host selection alone.

Recommendation. Keep open: work remains. Fix preview keyboard isolation and verify that Enter cannot submit a focused composer in another thread.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author gregbartell. Updated 2026-09-01T07:39:46Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5792, #8494, #8981.

Limits. Source and reports establish the risk, but this audit did not run a disposable input-isolation test.

Issue #3716. [Bug]: preview_evaluate fails with returnByValue: false

Request. preview_evaluate accepts returnByValue:false but cannot return CDP remote objects.

Audit finding. The tool still forwards returnByValue:false to CDP, while evaluateWithDebugger returns only result.value. Remote object results have an objectId instead of that value, so the later JSON encoding path cannot supply the promised result. The by-value-only fix remains open.

Recommendation. Keep open: work remains. Merge a reviewed fix that rejects or removes unsupported remote-object evaluation.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author gregbartell. Updated 2026-07-05T18:58:19Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7098.

Issue #3717. [Bug]: preview_click returns success in hidden tabs but does not dispatch the click

Request. Hidden preview tabs can report a successful click without dispatching it to the page.

Audit finding. The malformed null MCP result mentioned in the comment was fixed and is in stable v0.0.37. That response-format fix does not prove a click occurred. Current click code sends CDP mouse events without checking that the preview is visible or confirming delivery, and the hidden-preview rejection fix remains open.

Recommendation. Keep open: partial fix. Make hidden clicks either dispatch reliably or return an explicit unsupported-state error.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author gregbartell. Updated 2026-08-07T08:29:56Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8495, #5966, #8981, #6355. Merged PRs that cover all or part: #5966.

Issue #3718. [Bug]: preview_open(show: true) can load a tab without showing it to the user

Request. preview_open can return a loaded tab that the user cannot see despite requesting it be shown.

Audit finding. Current open code requests a thread mini-player, waits at most 500 ms for presentation, and then returns status even if visibility remains false. The latest Linux nightly report also says the manual Browser action fails to display the page, so this is not just a stale tool parameter. Existing background-browser work has not established a fix for that report.

Recommendation. Keep open: work remains. Reproduce the latest Linux case and make show requests report a presentation failure when no visible browser opens.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author gregbartell. Updated 2026-08-31T19:08:53Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3713, #6261, #8981.

Limits. The latest Linux window and compositor failure has not been reproduced in this source-only audit.

Issue #3736. [Bug]: Remote environment pairing cannot complete behind Cloudflare Access OAuth

Request. Remote pairing cannot pass an external access proxy while keeping T3 authentication enabled.

Audit finding. Remote endpoint construction still removes query parameters, and remote authentication supplies only T3 bearer or DPoP credentials. There is no saved proxy credential or browser-login flow for Cloudflare Access, including the Pangolin service-header case added in discussion. The current direct-pairing path therefore does not cover this request.

Recommendation. Keep open: work remains. Define and implement external access-proxy authentication for saved remote environments.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author tastelessjolt. Updated 2026-08-30T10:51:46Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Issue #3744. [Bug]: Plan mode performs real write / side-effecting actions (file edits, git commits, MCP tool calls) before the plan is approved

Request. Claude plan mode permits file and external-service writes before approval and can implement an old plan snapshot.

Audit finding. Claude sets the SDK plan permission mode for each planning turn. However, the T3 permission callback only blocks ExitPlanMode and otherwise allows tools under full-access without checking the current interaction mode. That leaves the reported permission gap in the callback, while the latest-plan handoff symptom still needs a focused reproduction.

Recommendation. Keep open: work remains. Enforce read-only tools for Claude planning and test the handoff after multiple plan refinements.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author proxet-p35. Updated 2026-07-23T23:10:18Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #2829.

Limits. No current SDK plan-mode write reproduction was run. The stale-plan handoff symptom was not reproduced.

Issue #3747. [Bug]: Model error messages render as broken raw JSON in the UI

Request. Structured provider errors appear as raw JSON in a clipped thread error banner.

Audit finding. The banner still renders the error string directly inside a three-line clamp, with the same string in a tooltip. The transport sanitizer only hides connection errors and does not extract a nested provider message. A later banner-dismissal fix does not resolve JSON formatting or provide a full readable error view.

Recommendation. Keep open: work remains. Extract structured provider messages and provide an expandable, copyable error detail view.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author arianXdev. Updated 2026-07-11T17:45:58Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #1084, #3830, #6123.

Issue #3884. [Bug]: Diff highlighting workers sustain ~600% CPU on Linux

Request. Diff syntax-highlighting workers can keep several CPU cores busy after rendering work should stop.

Audit finding. DiffWorkerPoolProvider still creates up to six workers with the same highlighter configuration as the report. No landed change in that provider replaces the engine or adds a time bound for pathological highlighting. The WASM highlighter proposal remains open, and the exact triggering diff is still missing.

Recommendation. Keep open: work remains. Capture a minimal diff that keeps a highlighting worker busy and use it to verify the engine fix.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author jetersen. Updated 2026-07-22T13:20:17Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8360, #8356.

Limits. The issue does not identify the exact diff or grammar that spins.

Issue #3962. [Bug]: Collapsing a project with many visible threads blocks the UI for seconds

Request. Collapsing a legacy sidebar project with many visible threads can block the renderer.

Audit finding. The affected grouped sidebar remains available as LegacySidebar, and every attached thread list still uses autoAnimate without a bulk-removal limit. Making the flat sidebar the default does not remove this supported path. The measured fix in the discussion was on an unmerged branch, not main.

Recommendation. Keep open: work remains. Apply the bounded bulk-collapse animation change to LegacySidebar and repeat the 100-thread measurement.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author AKuederle. Updated 2026-07-20T15:49:44Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4345, #4693, #5672.

Issue #4022. [Bug]: Diff panel Working tree/Branch scopes silently empty for every in-place project , getDiffPreview workspace-root guard compares against $HOME in packaged desktop builds

Request. Diff preview rejects registered projects outside the server startup directory and silently retries the wrong directory.

Audit finding. ReviewService still permits only config.cwd and the T3 worktree root, not registered project roots. The packaged desktop still uses the home directory as backend cwd, and DiffPanel still retries at that cwd after the guard fails. This is not fixed by later diff styling or Git invocation changes, and the duplicate reports add WSL evidence.

Recommendation. Keep open: work remains. Validate against registered project and thread roots, then remove the unrelated-directory retry.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author mikeohuo. Updated 2026-08-27T23:10:21Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #2441, #5616, #4288, #4733.

Issue #4028. [Bug]: Tailscale HTTPS cannot be enabled when using the WSL-only backend

Request. Tailscale HTTPS settings do not configure the active WSL-only backend.

Audit finding. The WSL bootstrap still forces tailscaleServeEnabled to false, while the desktop toggle only persists its value and requests a relaunch when that value changes. No path here reconciles the native Windows daemon against the active WSL listener. The discussion adds a WSL-only tailscaled case that also needs an explicit supported owner and useful failure diagnostics.

Recommendation. Keep open: work remains. Define which Tailscale daemon WSL-only mode manages and reconcile its desired HTTPS state on every start.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author jeremy-. Updated 2026-08-02T15:07:31Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #2830.

Issue #4074. [Bug]: Heavy CPU Usage on linux

Request. Streaming Markdown reparses the growing message and raises CPU use in long replies.

Audit finding. ChatMarkdown still passes the full text to ReactMarkdown for each update. Its component map still depends on text and isStreaming, so those updates replace the render functions as well. Recent work-log reuse does not change this parse path, and the render-coalescing proposal is still open.

Recommendation. Keep open: work remains. Bound streaming Markdown work while preserving tables, references, lists, and fenced blocks.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author mudit-loya. Updated 2026-08-17T10:41:46Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4349, #8006.

Issue #4103. [Bug]: No environment is available.

Request. Desktop cannot add a project because it has no available environment.

Audit finding. The body omits the app version and startup logs, and the comments only confirm the symptom on Windows and macOS. Current project entry points still depend on a discovered environment, while catalog decode and backend startup can fail before one is usable. No evidence identifies which prerequisite failed in this report, so it cannot be closed from an adjacent connection fix.

Recommendation. Keep open: evidence needed. Request the current app version and a redacted desktop startup trace from one failing launch.

Confidence low. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author neonvarun. Updated 2026-07-27T15:01:52Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4750, #6097.

Limits. No version, startup error, or current reproduction was supplied.

Issue #4106. [Bug]: Worktree threads can miss existing pull requests

Request. Worktree PR discovery must remain reliable when Git fetch is disabled or provider lookup fails.

Audit finding. Merged status work adds branch-aware caching and keeps the last known PR through some lookup failures. However, the broadcaster still skips subsequent remote refreshes when the automatic interval is zero, so subscribed worktrees do not keep polling PR metadata in that mode. The report also requires explicit pending or failed lookup state, which a nullable PR result does not provide.

Recommendation. Keep open: partial fix. Separate lightweight PR metadata refresh from the automatic Git-fetch setting.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author tonoizer. Updated 2026-07-20T15:56:18Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4281, #4108. Merged PRs that cover all or part: #4281.

Issue #4109. [Bug]: Grok provider: skills/slash commands empty; ACP crash on skills-reload (BigInt RequestId)

Request. Grok skills and slash commands are missing, and older builds crash on a string ACP request ID.

Audit finding. Merged PR 8358 adds grok inspect skill discovery and reasoning controls, so the empty skills catalog is addressed. The current RPC dependency accepts string request IDs, unlike the reported BigInt conversion path. GrokProvider still does not publish the general ACP slash-command catalog, and the separate live context meter requested in discussion is still missing.

Recommendation. Keep open: partial fix. Keep the issue focused on remaining Grok slash-command catalog support and track the composer meter in issue 8382.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author Dishah3241. Updated 2026-08-27T20:23:32Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8358, #8382, #5405. Merged PRs that cover all or part: #8358.

Limits. No live reproduction of the older skills-reload crash was run.

Issue #4123. Why promise no opt-out telemetry while telemetry has been on the whole time? Without even a button to turn it off.

Request. The report requests opt-in telemetry, an in-app consent control, and clear data-collection documentation.

Audit finding. AnalyticsService still defaults T3CODE_TELEMETRY_ENABLED to true and gates delivery with that environment setting. The requested consent flow and in-app telemetry control are not implemented by the later telemetry service refactors. This needs a maintainer privacy-policy decision, not closure as a technical fix.

Recommendation. Keep open: decision needed. Decide the telemetry consent policy and record the required product and documentation changes.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author salixhost. Updated 2026-08-19T18:40:33Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Issue #4144. SSH reconnects can accumulate stale local-forward processes

Request. Repeated SSH reconnects can leave stale local forwards for the same remote environment.

Audit finding. Managed tunnel children now disable SSH connection multiplexing, which improves process ownership. The manager still rejects an existing tunnel after a two-second readiness window with one-second probes and runs the remote-stop finalizer even for external server entries. The report asks for stronger generation and reconnect stress guarantees that the landed isolation change does not establish.

Recommendation. Keep open: partial fix. Verify repeated and concurrent reconnects with delayed readiness while fixing generation cleanup and external-server finalization.

Confidence medium. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author NotReliable. Updated 2026-07-20T15:56:19Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4347, #4145, #7733, #5749. Merged PRs that cover all or part: #4347.

Limits. The reported accumulated-process count was not reproduced on current main.

Issue #4149. Claude driver: explicit model slug bypasses ANTHROPIC_DEFAULT_* mapping; worktree mode not honored (sessions run in live checkout)

Request. OpenRouter model mapping is misleading, and the report also questions local-checkout defaults and new-worktree startup.

Audit finding. The guide still recommends ANTHROPIC_DEFAULT_* role mappings while resolveClaudeApiModelId sends explicit model IDs, so the reported mapping mismatch remains. The workspace resolver prefers worktreePath and a current test covers switching a Claude session into a worktree, but that does not reproduce the reported first-send path. Local checkout is still the configured default, which is a separate product choice.

Recommendation. Keep open: work remains. Split the report into the model-mapping documentation bug, checkout-default decision, and first-send worktree reproduction.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author brakergandalf. Updated 2026-08-03T11:21:58Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #2292, #7839, #8964.

Limits. The first-send new-worktree failure was not reproduced, and the report combines two defects with one default-setting request.

Issue #4178. [Bug]: Orchestration read model and per-thread client/VCS state grow unbounded over uptime

Request. Command state and per-thread caches keep growing as a server and its clients stay open.

Audit finding. The current projector still finds and copies thread arrays, and thread.deleted only stamps deletedAt instead of removing the entry. Bounded snapshot and replay reads reduce a different source of memory use, but do not make command-state work independent of retained thread count. The discussion explicitly separates the stale-replay OOM from this long-uptime problem.

Recommendation. Keep open: work remains. Bound resident command and per-thread cache state without deleting durable archived history.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author RusiruSadathana. Updated 2026-07-22T02:42:58Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4176, #5147, #5148.

Issue #4211. [Bug]: OpenCode provider update can leave the global Windows CLI without a working command

Request. A Windows OpenCode update removed working global command shims without restoring the previous executable.

Audit finding. The update runner still installs in place and checks the provider only after the package-manager command finishes, with no backup or rollback. The merged npm install-script fix does not validate malformed Windows binaries or restore missing shims. The issue does not establish which updater replaced this package, and the later pnpm comment does not match the original npm evidence.

Recommendation. Keep open: evidence needed. Request the Windows updater command and full updater output from the failed installation.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author ignaciomontenegroc. Updated 2026-08-27T06:50:42Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5646, #6436, #8363.

Limits. No updater output ties the malformed Windows package to a specific T3 update command.

Issue #4224. Nightly fails to launch on macOS 26.5.1 , RBSRequestErrorDomain Code=5 / POSIX 163 (Launchd job spawn failed)

Request. A signed macOS Nightly bundle fails at OS launch with POSIX error 163.

Audit finding. The macOS build still supplies associated-domain entitlements and a provisioning profile when signing is configured. Changes that stop automatic passkey prompts run after launch and do not address launchd rejecting the bundle. The report identifies an older signed artifact, but no current artifact or macOS launch result proves whether its profile-validation failure persists.

Recommendation. Keep open: evidence needed. Verify the current signed release on the affected macOS version and capture the launchd entitlement-validation failure.

Confidence medium. Release: Release not verified.

Observed GitHub metadata. GitHub state OPEN. Author robert-glh. Updated 2026-07-21T08:53:15Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Limits. No macOS launch reproduction or inspection of the currently published signed bundle.

Issue #4225. [Bug]: Prompting a not logged-in Claude makes the message invisible in the GUI

Request. A first prompt sent while Claude is signed out disappears, then is used after authentication recovers.

Audit finding. Current ChatView maps every server message into the timeline and retains unmatched optimistic messages, so this render path has no authentication-specific hiding rule. The adapter still fails to classify the signed-out synthetic assistant result correctly, and the related auth patch is open. Those findings do not prove the reported first-message visibility and replay sequence is fixed.

Recommendation. Keep open: retest. Repeat logout, send, login, and send on the current release while tracking the first message ID in stored history and the timeline.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Babissimo. Updated 2026-07-21T08:53:16Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8869, #7878, #7690, #8226.

Limits. The report gives no T3 or CLI version and no event sequence linking the hidden prompt to a stored message.

Issue #4231. [Bug]: Web client init dies after /.well-known/t3/environment on Chrome 150 , environment stuck "Offline" (works on Chromium 148 / Safari)

Request. Chrome 150 stops initializing a self-hosted web client after environment discovery.

Audit finding. The report does not contain the fatal browser exception, and its Clerk message also appears in a browser that works. Main still mounts Clerk for configured self-hosted builds, but ManagedRelayAuthProvider returns the application children without waiting for Clerk to load. The claimed Chrome-specific startup cause is not proved by the source or the later connection fixes.

Recommendation. Keep open: retest. Capture the first failing startup exception and network trace in current Chrome against the latest server.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author yasser-hazzaa. Updated 2026-07-21T12:13:38Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8141, #7756.

Limits. No fatal Chrome exception or current-build reproduction is available.

Issue #4253. [Bug]: Preserve native spellcheck behavior in the composer

Request. Native spelling correction can clear remaining markers and desktop suggestions can be missing.

Audit finding. The Electron menu still trusts dictionarySuggestions and displays No suggestions when that list is empty. There is no macOS checker fallback in this path. The composer also has no insertReplacementText-specific preservation path, so neither documented acceptance case has a demonstrated landed fix.

Recommendation. Keep open: work remains. Preserve native correction updates and add a macOS suggestion fallback before testing both cases.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author badcuban. Updated 2026-07-22T07:06:02Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4254, #7742.

Issue #4261. [Bug]: Projects and Chat Threads Disappear After Updating Nightly Build

Request. Projects and threads appear missing after a Windows desktop nightly update against a remote Ubuntu environment.

Audit finding. The current SSH launcher separates its connection bookkeeping from the normal remote T3 home and does not choose a fresh database for each package version. The report contains no before/after environment identity or database counts to distinguish a wrong server/home from a missing projection or data loss. Removing the remote T3 directory as a workaround destroys evidence and cannot demonstrate an update fix.

Recommendation. Keep open: evidence needed. Collect before/after remote environment IDs, server home paths, versions, and read-only database counts without deleting state.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author coderdevang. Updated 2026-07-22T10:15:49Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4374.

Limits. No exact updater transition, environment identity comparison, or preserved pre-failure database is available.

Issue #4333. [Bug]: Sidebar V2 header packs Search and project filter too tightly

Request. The sidebar Search and project-filter rows are too similar and too close together.

Audit finding. The header still places the Search/new-thread row directly above the project-filter/add-project row inside a gap-1 group. The searchable-combobox change improves project selection, but does not establish the requested visual separation between these two jobs. This remains a layout decision that needs a deliberate design change.

Recommendation. Keep open: decision needed. Choose and implement distinct spacing or grouping for the two header rows.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author levelorbit. Updated 2026-07-23T06:10:37Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4300, #5931.

Issue #4374. [Bug]: Cannot downgrade nightly to stable; channel switch does nothing and manual downgrade hides existing chats

Request. Switching nightly to stable can fail to install and a manual downgrade can hide existing history.

Audit finding. The update-channel change now temporarily enables allowDowngrade during its fresh update check, which directly improves the first reported failure. Nothing in that fix proves older stable code can read a newer nightly database and projections. The manual downgrade/history case therefore still needs a version-pair reproduction and an explicit compatibility policy.

Recommendation. Keep open: partial fix. Test a nightly-to-stable round trip against a copied database and define the supported downgrade behavior.

Confidence medium. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author j-flaherty. Updated 2026-08-27T23:10:27Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #6269, #4261, #3840, #8896. Merged PRs that cover all or part: #6269.

Limits. No current downgrade installation or old-reader compatibility test was run.

Issue #4380. Git command errors discard stderr, making failures opaque to callers

Request. Git command failures hide the stderr needed to identify the cause.

Audit finding. executeGit still builds GitCommandError from a static fallback plus stdout and stderr lengths. The moved-tag reproduction in the discussion confirms why fixing one command is not a general diagnostic fix. The bounded-error proposals remain open or were closed without merging.

Recommendation. Keep open: work remains. Review a bounded Git failure reason or redacted stderr excerpt at the executeGit boundary.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author nsxdavid. Updated 2026-08-26T13:34:32Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8645, #5620, #4513, #5489, #5740.

Issue #4398. [Bug]: Packaged web assets are served uncompressed and without cache headers, causing slow remote/mobile startup

Request. Packaged static web assets lack compression and useful cache headers on remote startup.

Audit finding. The packaged static route still reads each file and returns raw bytes with only contentType. Its index.html fallback has no revalidation policy either. Snapshot gzip and WebSocket compression do not apply to this asset response, and the asset-specific proposal remains open.

Recommendation. Keep open: work remains. Add negotiated precompressed assets and separate cache policies for hashed assets and HTML.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author r3xsean. Updated 2026-07-23T21:51:31Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4516, #4788, #4798.

Issue #4403. [Bug]: Unconditional PowerShell profile discovery delays Windows desktop startup

Request. Windows desktop startup loads a PowerShell profile even when the baseline environment already has Node.

Audit finding. Merged startup work runs profile and no-profile probes concurrently, which removes the old serial delay. It still starts the profile probe unconditionally and does not restore the requested skip when Node is already available. The conditional-probe proposal remains open.

Recommendation. Keep open: partial fix. Skip profile discovery when the no-profile environment satisfies runtime requirements and share one probe deadline.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author lmmontoya-ai. Updated 2026-07-23T22:10:16Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5878, #6301. Merged PRs that cover all or part: #5878.

Issue #4462. [Bug]: --tailscale-serve leaves headless backend classified as local-only

Request. A loopback server exposed with Tailscale Serve still disables remote pairing controls.

Audit finding. EnvironmentAuthPolicy still derives remote reachability only from config.host. It does not include tailscaleServeEnabled, so a loopback headless server still reports loopback-browser even when Tailscale Serve exposes it. The linked change remains open and is not a landed fix.

Recommendation. Keep open: work remains. Review and land the Tailscale Serve reachability fix with headless pairing coverage.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Kabilan108. Updated 2026-07-24T17:19:09Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4509.

Issue #4465. [Bug]: AppImage fails to launch on Ubuntu 26.04 , missing libfuse2, EPIPE crash, and instance-lock conflict

Request. The Ubuntu AppImage has FUSE setup failures, broken-pipe crashes, and confusing second-launch behavior.

Audit finding. The broken-pipe part is fixed: main.ts installs stdout and stderr EPIPE handlers before startup, and that commit is in v0.0.37. Linux still ships an AppImage, so this does not remove the FUSE prerequisite or prove clean Ubuntu launch behavior. The static-runtime proposal remains open.

Recommendation. Keep open: partial fix. Retest the remaining FUSE and second-launch behavior on a clean Ubuntu 26.04 system.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author sdhector. Updated 2026-07-24T17:59:11Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #1482, #4213, #7765. Merged PRs that cover all or part: #4213.

Limits. The clean-install and second-instance paths were not run during this read-only audit.

Issue #4495. [Bug]: Claude provider turn fails with "turn/setPermissionMode failed" when permission mode is Auto

Request. Claude turns fail during the permission-mode control request when Auto is selected on the reported Windows setup.

Audit finding. Main still maps Auto to the CLI auto mode and wraps a rejected control call as turn/setPermissionMode failed. #5431 only changed the Auto help text, not compatibility or error handling. The report explicitly lacks the underlying cause, and its later comment involves an old resumed thread, so an unsupported CLI mode cannot yet be distinguished from startup or resume failure.

Recommendation. Keep open: evidence needed. Get the underlying control-request error and current CLI version from a fresh Windows thread tested with Auto and Full access.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author abdellahjebar. Updated 2026-08-25T02:37:14Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5431, #5943, #2336, #7155.

Limits. The underlying SDK/CLI error was not captured, and the original CLI version predates current releases.

Issue #4513. [Bug]: Bulk thread delete aborts on "git worktree remove failed" when the worktree is already gone, and the error hides git's stderr

Request. Bulk thread deletion stops on worktree failures and hides the Git cause.

Audit finding. The merged fix makes removal of an already absent worktree succeed, and the batch discounts only threads actually deleted. The batch still returns on its first remaining failure, while removeWorktree deliberately exposes only a static message and stderr length. Those two explicit acceptance requirements remain open.

Recommendation. Keep open: partial fix. Keep the issue for batch continuation and useful failure diagnostics after the missing-worktree fix.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author Gablas. Updated 2026-07-25T12:37:17Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8076, #4615, #4380, #5614. Merged PRs that cover all or part: #8076.

Issue #4519. [Bug]: Opened a folder I'd previously used Claude Code inside, tried typing /resume - nothing happens - cannot resume

Request. Users cannot import and resume an existing standalone Claude Code session through the composer.

Audit finding. The pinned source has no native-session import operation and no built-in resume command. #8066 adds recent Claude and Codex thread import, but it merged into the onboarding feature branch and its commit is not an ancestor of pinned main, stable, or nightly. Its parent #5362 remains open, and the import scope is limited to recent threads rather than every old session.

Recommendation. Keep open: work remains. Review #5362 for a discoverable existing-project import path and older-session coverage before closing this request.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author dhilditch. Updated 2026-07-27T10:31:30Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8066, #5362, #5499.

Limits. The feature-branch import was not evaluated as a shipped main feature.

Issue #4543. [Bug]: Windows app never opened at first install (I uninstalled and churned instantly)

Request. The Windows desktop can start background processes without showing a window.

Audit finding. The comments show a missing optional pwsh probe, not a fatal stack, and one user reports that a longer startup budget helped. Current backend readiness continues probing while the child is alive, and Windows shell probes run concurrently after later fixes. Those changes support a new launch test, but do not prove every no-window failure in this broad report is fixed.

Recommendation. Keep open: retest. Retest a cold Windows launch and attach the first fatal error if no window appears.

Confidence medium. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author kendonB. Updated 2026-08-05T19:02:27Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5526, #5878, #5236. Merged PRs that cover all or part: #5526, #5878.

Limits. No exact original build or fatal launch error is supplied.

Issue #4560. [Bug]: Nightly , conversation/agent context from one Project leaks into another when running parallel tasks across multiple Projects

Request. Parallel threads in different projects can reportedly use the wrong workspace or conversation context.

Audit finding. The report does not identify a provider, exact nightly build, worktree mode, or mismatched session IDs. Current session startup reads the binding by threadId and derives cwd and resume state from that binding, which does not demonstrate the claimed cross-project race. The discussion adds no direct reproduction evidence.

Recommendation. Keep open: evidence needed. Collect one mismatched thread with its provider, build, expected project, effective cwd, and session ID.

Confidence medium. Release: Release not verified.

Observed GitHub metadata. GitHub state OPEN. Author PeterNiu7403. Updated 2026-08-01T01:57:46Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #871.

Limits. Provider, build, workspace mode, and a concrete session mismatch are missing.

Issue #4589. [Bug]: An environment's threads silently stop updating until the client is restarted

Request. An environment stops receiving thread updates while its RPC connection remains healthy.

Audit finding. subscribeDynamic still drains a transport-failed subscription and waits for a session change, while makeInput remains outside that failure handler. A healthy lease can therefore keep unary commands working without restarting the failed shell stream, matching the detailed discussion. Server-side settling removes a separate client precheck but does not repair this stream. Config-source termination now closes a session, but a shell/thread stream can still fail alone while the session remains usable.

Recommendation. Keep open: work remains. Review durable subscription recovery, including transport failure and input-construction failure on a surviving session.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author colonelpanic8. Updated 2026-08-24T22:33:13Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4602, #8192, #8193, #8194, #5742, #8600.

Latest main change. Config-source termination now closes a session, but a shell/thread stream can still fail alone while the session remains usable. Keep the issue open and verify general subscription recovery on the reported shell/thread path.

Issue #4596. [Bug]: Reopening a thread with a large event backlog freezes the UI while it visibly re-replays (quadratic replay)

Request. Stale thread subscriptions replay too many individual events and freeze the client.

Audit finding. The merged replay cap fixes the unbounded global scan by sending a snapshot when the gap exceeds 1000 events. Gaps of 1000 or less still emit individual events, and the issue itself measures a 77-second stall at 1000 deltas. Live tool-update coalescing does not batch this catch-up path, so the remaining replay publication cost still needs work.

Recommendation. Keep open: partial fix. Batch bounded catch-up events before publishing client state.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author colonelpanic8. Updated 2026-07-30T14:41:42Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5147, #5344, #8309, #8368. Merged PRs that cover all or part: #5147.

Issue #4640. [Bug]: Files panel silently truncates large workspaces at 25,000 entries

Request. The Files panel omits files after the workspace index reaches 25,000 entries.

Audit finding. WorkspaceSearchIndex.list still limits and slices the result at 25,000 entries. FileBrowserPanel uses the returned entries as the entire tree and does not display the truncated flag. The live file-search additions did not replace this tree with directory-by-directory enumeration.

Recommendation. Keep open: work remains. Use lazy directory enumeration for the Files tree and expose any remaining list truncation.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author SnaiCrys. Updated 2026-07-27T13:34:16Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #6492, #5501.

Issue #4644. [Bug]: Preview annotation comments do not support RTL text direction

Request. Preview annotation comments inherit the page direction instead of using the comment text direction.

Audit finding. The annotation host and toolbar still have no explicit direction, and the textarea has no dir=auto. The closed shadow root does not prevent inherited CSS direction, so LTR pages still give RTL comments the wrong direction and RTL pages can mirror the controls. General chat bidi work does not change this desktop preload UI.

Recommendation. Keep open: work remains. Set a stable direction on the annotation controls and content-based direction on the comment field.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author nassimna. Updated 2026-07-27T14:13:26Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #1771.

Issue #4650. [Bug]: context meter ratchets up and never reflects /compact , task_progress writes cumulative tokens into usedTokens via Math.max

Request. Claude background-task cumulative tokens overwrite the parent context meter and can hide compaction.

Audit finding. normalizeClaudeTaskProgressTokenUsage still writes max(cumulative task tokens, last used tokens) into activeTokens. Compact boundaries still emit no replacement when post_tokens is missing or zero. The newer turn-completion usage change removed the expensive context query, but neither fixes the task-progress overwrite nor the missing compact-boundary reading.

Recommendation. Keep open: work remains. Remove subagent cumulative totals from active context and handle compact boundaries without post_tokens.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author iKon85. Updated 2026-08-28T20:48:39Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8453, #7249, #5942, #8594, #8610.

Issue #4673. [Bug]: Queued prompts seem to interact badly with questions

Request. A queued prompt and the notes entered for a Claude question can become mixed or displaced.

Audit finding. Question text now follows a separate onPromptChange branch into the pending question answer, and returns before writing the regular composer prompt. Submission and stash behavior also have explicit pending-input branches. That separation is promising, but the issue does not identify whether the queue was the local stash or an already-submitted provider follow-up, so the exact ordering failure is not proved fixed.

Recommendation. Keep open: retest. Reproduce with one named queued prompt and one distinct question note, recording whether the prompt is stashed or already submitted.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Nopik. Updated 2026-07-27T19:55:41Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5507, #4787, #6646.

Limits. The report lacks build, queue type, prompt/answer order, and provider event evidence.

Issue #4693. [Bug]: @formkit/auto-animate position polling burns ~24% CPU permanently on an idle app

Request. Sidebar auto-animate polling keeps the renderer busy while the app is idle.

Audit finding. Both current and legacy sidebars still call autoAnimate on list containers. The current sidebar does not retain the controller or disable the polling when idle, and the dependency remains at 0.9.0. Server idle-CPU fixes do not remove this renderer timer and layout work.

Recommendation. Keep open: work remains. Remove or replace persistent position polling on sidebar thread lists.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Jardo-51. Updated 2026-07-28T00:14:31Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3962, #8187.

Issue #4697. [Bug]: No installed editors found

Request. Slow Windows editor discovery can replace installed editors with an empty list.

Audit finding. The server now caches successful discovery for one minute, which reduces repeated scans. It still discovers editors serially and converts a five-second timeout to an authoritative empty array, without preserving partial results. The later Windows comments reproduce that exact timeout, so cache improvements alone do not close the report.

Recommendation. Keep open: partial fix. Preserve known editors and report incomplete discovery separately from an empty result.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author Salloxy. Updated 2026-08-19T08:33:28Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5050, #6221, #5561, #5572. Merged PRs that cover all or part: #5561, #5572.

Issue #4713. Thread session stuck in running after turn interrupt , stop button becomes a no-op

Request. Stop can leave a terminal or absent provider turn projected as running, blocking further work.

Audit finding. Claude Stop now closes the SDK query and settles its tracked tasks, and interrupt failures now trigger server-side session recovery. The generic reactor still only reconciles when interruptTurn fails, so a successful abort with no terminal event is not repaired by that branch. The discussion explicitly retains OpenCode and Cursor live-Stop cases plus queued running/null-turn states, which prevents closure from the Claude fix alone.

Recommendation. Keep open: partial fix. Verify and repair terminal session reconciliation after successful Stop for each provider, including queued and missing active turns.

Confidence high. Release: Main only.

Observed GitHub metadata. GitHub state OPEN. Author davidjd7. Updated 2026-08-28T07:16:57Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5891, #7412, #9005, #8619, #7349, #7589. Merged PRs that cover all or part: #5891, #7412, #9005.

Limits. The multi-provider live-Stop and queued-turn acceptance matrix was not run.

Issue #4723. [Bug]: Deleting a thread's worktree while its session is "running" permanently wedges the thread (archive blocked, reaper never clears it)

Request. A thread can remain running and unarchivable after its worktree disappears.

Audit finding. The reaper still skips any thread with an activeTurnId, and the archive action still rejects that running state. The merged worktree-recreation change runs before a new turn starts, not when an already active session loses its cwd. It helps later starts but does not clear the stale active turn described here.

Recommendation. Keep open: partial fix. Detect loss of an active provider workspace and stop the stale session through the normal event path.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author alexito4. Updated 2026-08-15T15:47:19Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7839, #5524, #6197. Merged PRs that cover all or part: #7839.

Limits. Loss of a running worktree was not reproduced.

Issue #4728. [Bug]: Claude agent response only rendered the first sentence up to a specific tool call.

Request. T3 displays only an early Claude sentence even though the native session contains a later report after tool use.

Audit finding. Main handles streamed text around tools and has a fallback for assistant snapshots. However, snapshot backfill matches each snapshot against the whole turn block order by position, so a later snapshot without deltas can reuse a completed earlier block. The supplied diagnostics concern missing thread subscriptions and unrelated commands, not the SDK message sequence needed to connect that source gap to this incident.

Recommendation. Keep open: evidence needed. Capture the raw stream and assistant snapshots for one incomplete turn and compare them with stored assistant messages.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author burakcbdn. Updated 2026-07-28T11:02:30Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4930, #6389, #8880.

Limits. No native SDK event sequence or projection excerpt identifies where the later text disappeared.

Issue #4729. [Bug]: Custom Codex providers show a false unverified-auth warning after successful requests

Request. Working custom Codex providers still show an unverified-auth warning.

Audit finding. accountProbeStatus still returns ready with auth unknown when OpenAI authentication is not required and no account is returned. The shared provider-card helper still displays the exact unverified-auth text from the report. A successful turn does not change that probe result.

Recommendation. Keep open: work remains. Add an external-auth status and matching provider-card text without treating missing credentials as verified.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author jayeshp19. Updated 2026-07-28T11:12:20Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Issue #4749. [Bug]: Failed to authenticate. API Error: 401 API key is invalid.

Request. Claude requests return an invalid-API-key error even though desktop Settings reports authentication.

Audit finding. Claude still receives the provider instance environment, including inherited variables, and Settings can mark an initialized capabilities object authenticated without proving a chat API request succeeds. That leaves multiple possible causes for this Windows report, including the wrong instance credential source or stale status. The open authentication-status work does not itself establish a fix for an invalid API key during a turn.

Recommendation. Keep open: evidence needed. Request redacted Claude auth-status and token-source diagnostics from the exact configured instance and current app build.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author co50. Updated 2026-07-28T13:50:09Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7691, #8275, #4151.

Limits. The report has no CLI version, configured credential source, or matching-instance auth diagnostics.

Issue #4750. connection-catalog.json is written non-atomically every ~3s, and a corrupt document bricks the app permanently

Request. A corrupt connection catalog prevents desktop startup from recovering its projects and environments.

Audit finding. The current writer already uses a temporary file and rename, and blame places that code before this report, so the claimed in-place writer is not current source behavior. Corrupt document decoding still fails out of get without quarantine or a fallback catalog, and the writer has no explicit fsync. The recovery change remains open, including a later comment that confirms the same corruption symptom.

Recommendation. Keep open: work remains. Land catalog corruption recovery and verify recovery from an all-NUL document without losing saved metadata.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Samy104. Updated 2026-08-25T14:40:48Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5902, #8341, #8753.

Issue #4754. [Bug]: Cannot initialize conversation

Request. Starting a Claude desktop conversation can leave the main area black with a runtime-stream error.

Audit finding. The attached image says Claude runtime stream failed, which identifies the provider but not the failing subprocess operation. Main still reports that generic adapter error for several stream causes. No full cause chain or repeatable sequence links this report to the narrower first-send or renderer fixes.

Recommendation. Keep open: evidence needed. Request the Claude stream error cause and CLI version from a fresh reproduction.

Confidence low. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Sy-D. Updated 2026-07-28T14:15:13Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Limits. The screenshot was inspected, but the video and underlying error cause are unavailable.

Issue #4766. [Bug]: Stopped Claude thread silently loses native context when switching compatible provider instances

Request. Switching a stopped Claude thread between compatible provider instances can silently discard native continuation context.

Audit finding. Without an active adapter, the reactor still derives currentInstanceId from the already projected model selection and starts the desired instance without a cursor. ProviderService only recovers the stored cursor when its providerInstanceId exactly matches the target, so a compatible A-to-B switch still starts blank. Existing active-session switch handling does not cover this stopped-session boundary.

Recommendation. Keep open: work remains. Review #6148 with a stopped A session, a compatible B selection, and an assertion that A context is preserved or the switch is rejected.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author reed-yang. Updated 2026-07-28T18:33:25Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #6148, #4944, #2365, #3797.

Issue #4795. [Bug] T3 Code silently drops OpenCode skill permission requests , approval never shown, turn aborts

Request. OpenCode permissions outside bash, read, and edit have no actionable approval controls and can leave a stopped thread unsettled.

Audit finding. The adapter still maps skill, grep, task, and other permission names to unknown. Ingestion records an approval without a recognized request kind, and the web approval selector excludes it. Child-request routing and auto-accept-edits changes do not provide the missing fallback or clear saved unresolved requests.

Recommendation. Keep open: work remains. Add a generic actionable approval kind for every OpenCode permission name.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Jandev9. Updated 2026-08-31T00:28:11Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7113, #8441, #7484.

Issue #4801. [Bug]: OpenCode w/ Opus 5 fails due to unsupported thinking.type.enabled

Request. An OpenCode model rejects the thinking configuration used by T3 even though standalone OpenCode works.

Audit finding. T3 currently sends an OpenCode model, agent, and variant rather than constructing the Anthropic thinking payload itself. Variant defaults still select high or medium where available, while the merged HTTP catalog change now reads the provider runtime metadata. No source change proves that the reported adaptive-thinking mismatch is fixed.

Recommendation. Keep open: retest. Retest the affected model with current OpenCode and record the selected variant and sanitized upstream error.

Confidence medium. Release: Release not verified.

Observed GitHub metadata. GitHub state OPEN. Author KastanDay. Updated 2026-07-29T00:00:19Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8480.

Limits. No current OpenCode reproduction or sanitized request payload identifies which variant produces the rejection.

Issue #4804. [Bug]: Case-distinct POSIX Markdown file link opens the wrong workspace file

Request. Markdown links to case-distinct POSIX sibling paths open the wrong workspace file.

Audit finding. workspaceRelativePath still lowercases both the target and workspace before the containment test. This makes distinct Linux paths look like the same workspace and sends the wrong relative path to the viewer. Later file-link changes did not remove this comparison, and the focused fix is still open.

Recommendation. Keep open: work remains. Use case-sensitive comparison for POSIX paths while preserving Windows path behavior.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author AksharP5. Updated 2026-07-29T00:50:03Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4805.

Issue #4812. [Bug]: Nightly auto-update on macOS stalls at "Downloading (0%)" behind a TLS-inspecting proxy (Netskope)

Request. Desktop update downloads stall behind a TLS-inspecting proxy without an actionable error.

Audit finding. The download path still enables differential downloads on native arm64 and directly awaits the updater. It has no app-level no-progress timeout or retry as a full download, and the UI still receives the wrapper error message. The report explicitly leaves the proxy and differential-download root cause unproved.

Recommendation. Keep open: work remains. Reproduce the stalled asset request behind the proxy and add a bounded recovery path.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author hashmil. Updated 2026-07-29T05:11:34Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Limits. The exact TLS or range-request failure has not been isolated.

Issue #4818. [Bug]: SQLError Failed to execute OrchestrationCommandReceiptRepository.upsert.query

Request. An accepted orchestration command fails while its command receipt is persisted.

Audit finding. The receipt upsert still uses the shared error mapper that repeats the operation and hides the underlying cause. The discussion correctly says that a SQLite lock and a schema failure cannot be distinguished from this screenshot. The open diagnostic proposal would expose the reason, but it is not a fix for the unknown persistence failure.

Recommendation. Keep open: evidence needed. Capture the underlying receipt-upsert cause on a current build before selecting a database fix.

Confidence high. Release: Release not verified.

Observed GitHub metadata. GitHub state OPEN. Author Sy-D. Updated 2026-07-29T14:01:08Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4837, #5099.

Limits. No underlying SQL or schema error and no deterministic reproduction are available.

Issue #4841. [Bug]: Desktop window always reopens on the primary monitor, forgetting the display it was last used on

Request. A maximized desktop window reopens on the primary monitor instead of its last display.

Audit finding. Window persistence still saves getNormalBounds for a maximized window and records only bounds plus the maximized flag. Startup chooses a display from those normal bounds, with no saved display identity or last maximized display rectangle. The report describes this exact remaining path.

Recommendation. Keep open: work remains. Persist the last occupied display for maximized windows and restore the window there.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author leftytennis. Updated 2026-07-29T14:11:52Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Issue #4851. [Bug]: Cannot delete orphaned project after environment is gone

Request. A project cached from a retired environment cannot be removed through the current client or a replacement machine.

Audit finding. The CLI already resolves an existing project ID before filesystem normalization and forwards --force, and the web project settings send force for locally known child threads. Those operations still address the owning environment and its records; a replacement machine cannot resolve the retired environment record. No client-local project dismissal exists for the remaining offline case.

Recommendation. Keep open: partial fix. Add a client-local dismissal path for projects whose owning environment is permanently unavailable.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author nelsonsbrian. Updated 2026-07-29T15:59:42Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4852, #8924.

Issue #4852. [Bug]: Threads remain permanently Working when environment is unavailable

Request. Cached threads keep showing Working and cannot be cleaned up after their environment disappears.

Audit finding. Thread deletion, archive, and settlement still dispatch commands to the owning environment. The latest server-side settlement change removes client-side blocking checks, but it cannot run on a machine that is offline and adds no local dismissal. The cached Working state and missing offline cleanup path therefore remain unresolved.

Recommendation. Keep open: work remains. Add local dismissal and offline presentation without claiming to stop work on the unavailable host.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author nelsonsbrian. Updated 2026-08-26T07:04:30Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4851, #8924, #8935, #8600.

Issue #4877. [Bug]: The command menu shows keyboard shortcuts on mobile devices

Request. The web command menu shows desktop keyboard hints on touch-only mobile devices.

Audit finding. The legacy sidebar still renders its command-palette shortcut whenever a binding exists. The shared CommandShortcut component also renders its kbd element without an input-capability guard. The open mobile-shortcut proposal has not changed main.

Recommendation. Keep open: work remains. Hide command hints for touch-only input in the sidebar and shared command results.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author RobbyV2. Updated 2026-07-30T22:38:51Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8586.

Issue #4880. [Bug]: the name of forks are the same title as the upstream repo

Request. Forks inherit the upstream repository name and project labels disagree across the app.

Audit finding. Repository identity still prefers upstream over origin, so a renamed fork with an upstream remote receives the upstream identity. Project grouping can then combine or label it with that identity. The August 29 comment adds a saved project name that is not honored by the picker, so turning grouping off is only a workaround.

Recommendation. Keep open: work remains. Make fork identity use the intended clone remote and apply the saved project-group label consistently.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Project516. Updated 2026-08-29T19:53:08Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7686.

Issue #4889. [Bug]: Android manual pairing rejects formatted codes and can report a false timeout

Request. Android manual pairing rejects the formatted code shown by its own input and can hide an immediate failure behind a timeout.

Audit finding. buildPairingUrl still only trims the code while the screen suggests a hyphenated format. The raw code is therefore different from the presented code when it reaches token exchange. The normalization fix remains open, and the separate false-timeout symptom has no confirmed current cause.

Recommendation. Keep open: work remains. Review manual-code normalization and verify that an invalid code preserves the token-exchange error.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author LLBlumire. Updated 2026-07-30T00:02:04Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7123.

Limits. The false timeout was not reproduced or traced to a current error branch.

Issue #4894. [Bug]: t3 service install fails on WSL2 , loginctl enable-linger is called with no username and cannot resolve a session

Request. Service installation fails when loginctl cannot resolve or authorize the current user.

Audit finding. The activation plan still calls loginctl enable-linger without a username or a check for an already-enabled linger setting. The comments add an Arch case where lingering is already enabled but no polkit authority is available. Passing a username fixes the WSL session lookup, but does not cover that second case.

Recommendation. Keep open: work remains. Check current linger state before requesting a change and use the resolved username when a change is needed.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author CamiloGaete. Updated 2026-08-28T03:13:20Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5012, #8476.

Issue #4913. [Bug]: systemd user unit from t3 service install sets no PATH, so providers in [local path omitted] are invisible to the service

Request. A headless Linux service reportedly cannot find providers installed in user PATH directories.

Audit finding. The unit still has no PATH override, but the server runs fixPath at startup and merges login-shell entries into its process environment. The discussion points out that /proc environ shows the original environment and does not prove the effective lookup PATH is missing those entries. A provider spawn failure or failed PATH hydration is needed before choosing a unit-level change that could remove systemd-managed entries.

Recommendation. Keep open: evidence needed. Collect a provider lookup failure and the server PATH-hydration warning from the affected service.

Confidence medium. Release: Release not verified.

Observed GitHub metadata. GitHub state OPEN. Author coreldh. Updated 2026-08-05T22:57:36Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5013.

Limits. No trace proves which provider lookup failed after startup PATH repair.

Issue #4915. [Bug]: T3 Connect reports "relay offline" when the server binds a non-loopback host

Request. T3 Connect cannot reach a server that listens only on a non-loopback address.

Audit finding. The server honors the configured listen host but still reconciles the managed link with a 127.0.0.1 origin. Cloud link setup passes that hostname into the managed endpoint origin, so binding only a LAN address leaves the advertised loopback origin unreachable. No inspected startup change derives that origin from the actual bind address.

Recommendation. Keep open: work remains. Use a reachable effective bind address when constructing the managed tunnel origin.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author nwj48trwsy-dot. Updated 2026-07-30T03:51:50Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7530.

Limits. No managed tunnel was started. The separate service-update anecdote lacks enough data to assess here.

Issue #4924. [Bug]: macOS agent terminals fail with 'posix_spawnp failed' - node-pty spawn-helper ships without exec bit

Request. A macOS npm install has a non-executable node-pty spawn-helper and cannot start terminals.

Audit finding. Current NodePtyAdapter already finds the installed platform helper and tries chmod 0755 before its first spawn. That mitigation predates this report, and resolution or chmod failures are deliberately swallowed, so its presence cannot prove the reported install works. The missing-execute-bit report is distinct from Linux native-build failures and the resource-monitor executable issue.

Recommendation. Keep open: evidence needed. Capture the resolved helper path and chmod failure from an affected current npm install.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author hashmil. Updated 2026-07-30T05:13:31Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7736, #5280.

Limits. No affected macOS npm installation was available to inspect resolution or permission errors.

Issue #4927. [Bug]: Claude "full access" fails to start when bypassPermissions is disabled by policy

Request. Claude full access starts with a forbidden permission mode when managed settings disable bypass permissions.

Audit finding. The adapter still maps full-access directly to bypassPermissions and sets allowDangerouslySkipPermissions=true without checking resolved policy. It also stores that mode for later setPermissionMode calls. The linked server fallback is still open, and the requested disabled picker option is not supplied by this mapping.

Recommendation. Keep open: work remains. Review #7246 with managed-policy rejection and the web, desktop, and mobile permission pickers.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author preetpatel. Updated 2026-07-30T05:44:16Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7246, #7577.

Limits. Managed enterprise policy was not exercised locally.

Issue #4928. [Bug]: Claude shows "could not verify authentication status" on managed Bedrock installs

Request. A working managed Bedrock installation is marked unverified when the SDK capability probe returns no result.

Audit finding. #3931 added the Bedrock label and a 25-second probe budget, and that commit is in v0.0.37. It only helps when account capabilities return successfully. Main still returns warning/unknown when capabilities are absent, without the requested auth-status fallback, so the reported managed-install case remains open.

Recommendation. Keep open: work remains. Add a scoped auth-status fallback for a failed or empty capability probe, with managed Bedrock coverage.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author preetpatel. Updated 2026-08-11T19:57:17Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3931, #7363, #7690, #8818.

Limits. No managed Bedrock credentials or enterprise policy were exercised.

Issue #4930. [Bug]: Successful Claude /compact replays a preserved historical error as a new assistant message

Request. A resumed Claude compact operation can append a historical assistant error again as a new message.

Audit finding. handleAssistantMessage still processes a repeated native UUID and can allocate synthetic assistant items after resume. The existing resume test deliberately leaves SDK resumeSessionAt unset, but main has no equivalent replay guard. The open patch skips the cursor-matching UUID only, so older replayed messages remain an acceptance case to check.

Recommendation. Keep open: work remains. Review #8842 with the reported compact replay and more than one historical assistant UUID.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author reed-yang. Updated 2026-07-30T08:47:35Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8842, #6606, #4944.

Issue #4934. [Bug]: Headless connect page accepts malformed state and PKCE challenge values

Request. The headless Connect page accepts corrupted state and PKCE challenge values until the CLI rejects the returned code.

Audit finding. readConnectAuthorizeRequest still trims state and challenge and checks only that they are nonempty. Port validation was added, but there is no base64url alphabet or length check for the two authorization values. The linked validation change remains open.

Recommendation. Keep open: work remains. Review the existing malformed-fragment fix and add coverage for both state and challenge.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Zeus-Deus. Updated 2026-07-30T07:51:37Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4946.

Issue #4940. [Bug]: Moving a project folder reports a Codex spawn failure instead of the missing folder, and the project cannot be re-linked

Request. Moving a project leaves a misleading provider error and no way to relink its existing threads.

Audit finding. Main can now recreate a missing managed worktree when its branch and project root still exist, which covers one case added in the discussion. A moved project root still reaches the provider spawn path, and the CLI project commands still have no relink action. The open error-message fix explicitly excludes relinking, so neither it nor worktree recovery covers the full request.

Recommendation. Keep open: partial fix. Add project relinking and missing-root diagnostics while preserving the existing thread association.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author AngeloTadeucci. Updated 2026-08-27T23:10:16Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5040, #7839, #8125, #6622. Merged PRs that cover all or part: #7839.

Issue #4944. [Bug]: Claude provider switch hangs on stale session shutdown and accepts late events

Request. Replacing a Claude provider session can wait on stale shutdown and allow old lifecycle events to overwrite the replacement.

Audit finding. #5891 changed Claude close to a synchronous termination request before cleanup, removing the specific awaited query.close path in the report, and is in v0.0.37. ProviderService still waits for all stale adapter stops before saving the replacement binding, without a deadline. Runtime ingestion also accepts session state from the old provider instance without checking it against the current binding, so the atomic replacement requirement remains unmet.

Recommendation. Keep open: partial fix. Add a provider-replacement test with a never-finishing stale stop and a late lifecycle event from the replaced instance.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author reed-yang. Updated 2026-07-30T08:53:42Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5891, #7071, #6517, #4766, #8259. Merged PRs that cover all or part: #5891.

Limits. The reported gateway retry and 12-minute switch were not reproduced after the cleanup change.

Issue #4952. [Bug]: Mobile thread list never shows Done after a turn completes

Request. Native mobile thread lists omit the unread Done state after background work finishes.

Audit finding. Both current and legacy mobile status helpers derive activity from the session and return ready or no label after completion. Neither accepts a persisted visit timestamp or implements an unread-completion state. The dedicated Done proposal remains open.

Recommendation. Keep open: work remains. Add per-thread visit state and use it to show and clear Done in both mobile thread lists.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author danvernon. Updated 2026-07-30T09:31:45Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4961.

Issue #4962. [Bug]: Mobile looks idle while background subagents are still working

Request. Native mobile threads appear idle while their background subagents still work.

Audit finding. The current mobile list still marks Working only from the parent session. The composer activity timer likewise uses the parent latest turn and session, even though the server now tracks background liveness for reaping. Server protection for live child work does not provide the required mobile aggregate indicator.

Recommendation. Keep open: work remains. Use background liveness in mobile list status and the open-thread activity indicator.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Zeus-Deus. Updated 2026-07-30T10:29:51Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4952, #5677, #538.

Issue #4970. [Bug]: Reused long-lived branch remains associated with a historical merged PR

Request. A new thread on a reused long-lived branch inherits an unrelated historical merged or closed PR.

Audit finding. The status lookup still requests all PR states and returns the most recently updated terminal PR when none is open. Merged timestamp gating prevents many old PRs from settling newer work, and the new server policy preserves that protection. It does not remove the incorrect PR badge or make branch-derived association thread-specific, and comments after closure can still change updatedAt.

Recommendation. Keep open: partial fix. Make historical PR association thread-aware instead of accepting a terminal match by branch name alone.

Confidence high. Release: Main only.

Observed GitHub metadata. GitHub state OPEN. Author Ionmi. Updated 2026-08-18T10:25:04Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5514, #6417, #7517, #7394, #8160. Merged PRs that cover all or part: #7454, #8600.

Issue #4991. [Bug]: semi-new install trying to add ssh host

Request. An unreadable legacy saved credential blocks the desktop connection catalog and SSH setup.

Audit finding. Legacy migration still maps any getSecret failure to DesktopConnectionCatalogStoreMigrationError and aborts the migration. That matches the exact read-legacy-secret error in the issue and prevents unrelated targets from being listed. The linked migration-recovery proposal was closed without merging.

Recommendation. Keep open: work remains. Let an unreadable legacy credential require re-pairing without blocking the whole catalog.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author nolram88. Updated 2026-07-30T13:59:49Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5105, #8341.

Issue #5002. [Bug]: Cloudflare Turnstile challenge loops indefinitely in the built-in browser preview

Request. Cloudflare Turnstile repeatedly restarts in the desktop preview browser.

Audit finding. Preview session setup still changes the native User-Agent, and the PR intended to keep the native identity remains open. No landed change or later comment demonstrates that the Cloudflare login challenge completes. OAuth popup support does not address an iframe challenge loop, so this report should not be closed with that fix.

Recommendation. Keep open: work remains. Test the Cloudflare login reproduction with the native User-Agent proposal and record whether the challenge completes.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author akriaueno. Updated 2026-07-30T15:45:31Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3700, #7110.

Limits. A User-Agent mismatch is a proposed cause, not a confirmed diagnosis from this audit.

Issue #5024. [Bug]: Hook audits for codex don't block threads

Request. Unapproved Codex hooks can be omitted while T3 starts a thread without a warning.

Audit finding. The generated protocol exposes hooks/list and hook trustStatus, including untrusted and modified states. T3 does not call hooks/list during provider probing or session startup, and its thread-start request has no hook-audit gate. Hook lifecycle notifications alone do not prevent the silent omission described here.

Recommendation. Keep open: work remains. Check hook trust before a turn and show a clear blocked state when required hooks need approval.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author ryanswilson59. Updated 2026-07-30T19:00:29Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Issue #5031. [Bug]: Mobile cannot connect to online relays after updating to 0.0.32-nightly.20260730.958

Request. Mobile clients cannot use otherwise online T3 Connect environments after a server update.

Audit finding. The forward-compatible ServerConfig decoder addresses the documented post-getConfig disconnect, and current tests cover that case. Later comments explicitly confirm a separate relay-to-environment request failure after the client update fixed direct Tailscale access. Those later failures occur before the backend receives the mint request, so the decoder fix does not close the whole report.

Recommendation. Keep open: partial fix. Capture one current relay endpoint failure with matching client and relay trace IDs after confirming the client includes the decoder fix.

Confidence medium. Release: Release not verified.

Observed GitHub metadata. GitHub state OPEN. Author tradesdontlie. Updated 2026-08-08T08:03:34Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4901, #5055, #5744, #7139. Merged PRs that cover all or part: #5055.

Limits. No current deployed relay trace or current native-store build comparison was inspected.

Issue #5035. SQLite projector fails with no such savepoint: effect_sql_1

Request. Starting a turn sometimes fails because SQLite cannot find an Effect transaction savepoint.

Audit finding. Main still wraps each projector application in a transaction, using one semaphore-controlled SQLite connection. Current projector changes concern replay and message writes, not a demonstrated repair for this missing-savepoint failure. The report lacks a build identifier and the preceding transaction sequence needed to distinguish cancellation, nesting, and an external writer.

Recommendation. Keep open: evidence needed. Capture the exact build and transaction error sequence from one fresh failure without modifying the database.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author ahammednibras8. Updated 2026-07-30T21:17:47Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Limits. No reliable reproduction, exact build, or preceding transaction log is present.

Issue #5045. App can hang during startup until the T3 Code Bun process is force-quit

Request. The macOS desktop app can stall at startup until a Bun process is terminated.

Audit finding. Current packaged desktop startup runs the backend through Electron in Node mode and has a bounded backend readiness wait. That differs from the process described, but does not establish whether the reported Bun process was an old backend, provider, or external service. There is no version, process tree, or startup log that connects this symptom to a landed fix.

Recommendation. Keep open: evidence needed. Request the exact build and a startup log plus the process tree before any process is terminated.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author ahammednibras8. Updated 2026-07-30T20:57:59Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7460.

Limits. The affected Bun process role and build are unknown, and no current reproduction is available.

Issue #5061. [Bug]: iOS Local Network permission sheet leaves pairing stuck until force-quit

Request. Granting iOS Local Network permission can leave the initial LAN connection stuck until restart.

Audit finding. During establishment the supervisor still ignores application-active-probe and only restarts for application-active-reconnect. Mobile wakeups still record background transitions but not inactive permission-sheet transitions. The exact proposed fix remains open, so later resume and VPN fixes do not close this first-pairing path.

Recommendation. Keep open: work remains. Review the permission-sheet recovery change using an interrupted initial pairing attempt.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author overra. Updated 2026-07-31T01:06:17Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7257.

Issue #5078. [Bug]: Open in detects Antigravity CLI as an IDE and misses installed Zed on macOS

Request. The macOS Open menu detects the Antigravity CLI as an IDE and misses Zed without its CLI.

Audit finding. The editor catalog still identifies Antigravity solely by agy and Zed by zed or zeditor. Discovery only resolves those commands and does not check the macOS app bundles, so both reported detection errors remain possible. The specific app-bundle detection proposal is open.

Recommendation. Keep open: work remains. Use macOS app-bundle discovery for Zed and distinguish the Antigravity IDE from its standalone CLI.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author ishaanko. Updated 2026-07-31T06:54:20Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7079.

Issue #5079. [Bug]: browser zoom (ctrl+plus/minus) breaks file picker

Request. Changing desktop app zoom can make the composer file-mention picker disappear on Linux.

Audit finding. The current command menu measures the composer in CSS pixels and updates on window resize and ancestor resize. Its anchoring and drawer layout changed after the report, but neither change proves that the Fedora zoom-specific rendering failure is gone. The related title-bar issue is a different control and should not replace this report.

Recommendation. Keep open: retest. Repeat the file-mention picker test on current Linux desktop and record the failing zoom percentages.

Confidence medium. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author Xyz3R. Updated 2026-07-31T07:10:27Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5336, #7150, #5232. Merged PRs that cover all or part: #5336.

Limits. The report gives no failing zoom percentage, and no current Fedora client run was performed.

Issue #5110. [Bug]: Per-chunk assistant persistence causes progressive live output lag and rapid SQLite growth

Request. Legacy token streaming persists tiny assistant deltas separately and slows down as stored history grows.

Audit finding. The current legacy streaming path still dispatches one assistant-delta command per provider chunk. Recent main changes append message text in SQL and avoid unused activity reads, which remove two costs but do not batch durable events or receipts. Database growth and per-event client publication therefore remain within this report.

Recommendation. Keep open: partial fix. Coalesce assistant deltas before durable dispatch and flush them at turn and approval boundaries.

Confidence high. Release: Main only.

Observed GitHub metadata. GitHub state OPEN. Author ognjeeen. Updated 2026-08-26T07:00:48Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4596, #4349, #8187, #8988, #9032. Merged PRs that cover all or part: #8988, #9032.

Issue #5113. [Bug]: Clicking on a file when it shows the changed files show the file above in i3

Request. Clicking a changed file on an i3 desktop reveals the preceding file.

Audit finding. The report has no app version, display scale, or recording. Current navigation resolves the selected file by exact path and scrolls to its stable item key. A merged virtual-height correction changed the shared diff layout, but it was tested for clipped rows, not this i3-specific selection error.

Recommendation. Keep open: retest. Retest the file selection on a current build and capture the selected path, display scale, and visible target.

Confidence medium. Release: Release not verified.

Observed GitHub metadata. GitHub state OPEN. Author csaarhustrading. Updated 2026-07-31T12:24:57Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #6423.

Limits. No version or deterministic i3 reproduction is supplied. The cited change did not test this exact symptom.

Issue #5157. [Bug]: T3Connect iOS App does not allow horizontal scroll when viewing documents

Request. The iOS file viewer cuts off wide document content without usable horizontal scrolling.

Audit finding. Current source-file rendering has a horizontal ScrollView on the JavaScript path and a horizontal pan recognizer on the native iOS path. Those mechanisms existed before the report, and the issue does not identify the file type or whether the source or Markdown preview was open. New file-preview work does not prove that the reported gesture failure is fixed.

Recommendation. Keep open: retest. Retest the same file in the current iOS source view with code wrapping both enabled and disabled.

Confidence medium. Release: Release not verified.

Observed GitHub metadata. GitHub state OPEN. Author LankyTurtle. Updated 2026-07-31T23:50:17Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3155, #3514, #8959.

Limits. The attached recording, file type, and physical iOS gesture behavior were not inspected.

Issue #5174. [Bug]: Windows Start Menu shortcut disappears after Nightly updates

Request. Windows updates can remove the installed Start Menu shortcut and leave later installs unable to restore it.

Audit finding. The installer still uses the default NSIS shortcut handling with no missing-shortcut repair hook. Packaging and update-speed changes do not add that repair. The discussion reports the same loss on stable, so this is not limited to Nightly, and the repair PR remains open.

Recommendation. Keep open: work remains. Review the missing-shortcut repair and verify one stable and one Nightly install-update cycle.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author itsmeares. Updated 2026-08-02T09:17:41Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7829.

Issue #5191. [Bug]: Codex edited files, but missing in the diff

Request. A completed Codex turn's changed-files list can omit a file that git reports as changed.

Audit finding. The attached image shows the inline checkpoint file list, not a live branch-diff view. That list still comes from the difference between captured checkpoints. The recent live right-panel refresh fix does not repair a missing checkpoint entry, and the issue provides no turn/checkpoint trace to locate the omission.

Recommendation. Keep open: evidence needed. Collect one affected turn's checkpoint refs and file summary alongside the matching git diff.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author ernestoalejo. Updated 2026-08-19T07:08:52Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8803.

Limits. No affected checkpoint pair or provider completion trace is available.

Issue #5210. [Bug]: WSL + T3 Connection not publishing workspaces

Request. T3 Connect linking fails for a WSL-only environment with Invalid managed endpoint origin.

Audit finding. The discussion supplies the missing error and confirms that mirrored WSL networking works around it. Under NAT, the desktop can select the WSL interface address, while link-proof validation still requires the request hostname to be loopback. That mismatch remains in main and applies to both managed and publish-only proof requests.

Recommendation. Keep open: work remains. Make WSL-only link proofs use a verified loopback connection in NAT and mirrored networking modes.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author dmanexe. Updated 2026-08-29T23:01:34Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4028, #5211.

Issue #5211. [Bug]: Desktop stuck on "Connecting to WSL" , getDistroIp picks unreachable Docker bridge IP instead of eth0

Request. WSL startup can choose a Docker bridge address and can miss a backend that becomes ready late.

Audit finding. The stable WSL runtime cache reduces the slow mounted-filesystem startup described in the follow-up comment. It does not fix address selection: getDistroIp still returns the first IPv4 from hostname -I, which can be a Docker bridge. The route-selection fixes remain open, and there is no evidence that the original address failure or all late-readiness cases are resolved.

Recommendation. Keep open: partial fix. Finish route-based WSL address selection and verify startup with Docker bridges present.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author 9jaGuy. Updated 2026-08-11T21:54:31Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5769, #8438, #5889, #5998. Merged PRs that cover all or part: #5769.

Issue #5221. [Bug]: "Open preview automatically when this action runs" has no effect

Request. A saved project action can promise to open the preview but never opens it when run.

Audit finding. The merged persistence fix restores previewUrl and autoOpenPreview in saved actions and is in stable v0.0.37. Current runProjectScript still runs the terminal command without reading either preview option. The runtime consumer fix remains open, so persistence is only partial coverage.

Recommendation. Keep open: partial fix. Restore the desktop action-run preview call after a successful terminal write.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author matthias-trip. Updated 2026-08-02T07:27:23Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5223, #3842. Merged PRs that cover all or part: #3842.

Issue #5232. [Bug]: Linux desktop title-bar controls touch the window edge when UI is zoomed

Request. Linux title-bar controls lose vertical space when the app is zoomed.

Audit finding. DesktopWindow still fixes the native overlay height at 40 pixels. The web client uses the overlay height as the complete top-bar height, and app zoom changes the renderer without resizing the overlay. The zoom-aware header PR is still open.

Recommendation. Keep open: work remains. Make the Linux title-bar height track renderer zoom and verify its control padding.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author r6mez. Updated 2026-08-02T12:48:15Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5235.

Issue #5236. [Bug]: Desktop app crashes on launch on Windows (Chromium sandbox failure, exit 0x80000003)

Request. The Windows desktop exits before showing a window when Chromium sandbox startup fails.

Audit finding. The report isolates a sandbox-sensitive launch failure because --no-sandbox changes the result and another Electron app also fails. T3 still enables the sandbox, but main now uses Electron 43.4.1 instead of the reported Electron 41-era runtime. No current-build result proves that the runtime upgrade resolves this machine-specific failure.

Recommendation. Keep open: retest. Retest the affected Windows machine on the Electron 43.4.1 build with the sandbox enabled.

Confidence medium. Release: Release not verified.

Observed GitHub metadata. GitHub state OPEN. Author mohit-dayma. Updated 2026-08-02T13:45:27Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8626.

Limits. No current-build GPU or renderer crash dump is available.

Issue #5241. [Bug]: OpenCode leaks orphaned /opencode serve processes that survive backend crash/restart

Request. Locally spawned OpenCode servers survive abrupt T3 backend death and accumulate across restarts.

Audit finding. OpenCode servers still run in detached POSIX process groups and depend on an Effect scope finalizer for termination. A killed backend cannot run that finalizer, and the current owner only tracks processes in memory. The new shared catalog helper and its idle timeout do not detect processes left by an earlier backend.

Recommendation. Keep open: work remains. Add process ownership that can clean up an OpenCode server after abrupt backend death.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author HI0890. Updated 2026-08-02T17:34:54Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8480, #5410.

Limits. Abrupt backend death was not reproduced during this read-only audit.

Issue #5248. [Bug]: systemd-oomd kills the entire T3 Code scope when an agent-spawned child workload exhausts memory (Linux)

Request. A memory-heavy agent child can cause systemd-oomd to kill the whole Linux desktop scope.

Audit finding. ProcessRunner still spawns child commands directly, without a separate systemd scope for each agent or terminal workload. The OOMPolicy=continue change applies only to the generated boot-service unit. It does not split the desktop app scope that systemd-oomd killed in this report, so that merge is not a fix for this incident.

Recommendation. Keep open: work remains. Isolate managed agent and terminal process trees from the Linux desktop scope, with a non-systemd fallback.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Robertg761. Updated 2026-08-02T20:49:50Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5788, #5147, #5148.

Issue #5255. [Bug]: File-change approval prompt shows no filename or change details

Request. Codex file-change approvals show no filename or patch when the provider gives no reason text.

Audit finding. The Codex adapter still uses only payload.reason for file-change approval detail. The session runtime has the item ID but does not attach the file-change data to that approval event. The focused proposal to recover filenames and changes remains open.

Recommendation. Keep open: work remains. Join file-change approvals to their item data and show the requested file operations before approval.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author lachlanmcmillan. Updated 2026-08-03T04:13:04Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8669, #6445.

Issue #5278. [Bug]: Thread interaction and runtime modes do not sync between desktop clients

Request. Changing a thread's Plan or permission mode on one desktop client does not immediately update another client.

Audit finding. Both mode-change handlers still update the local composer draft and only update draft-thread context for a local draft. Existing server-thread settings are still persisted by persistThreadSettingsForNextTurn during submission. The other connected client therefore cannot observe the selection when it is changed without sending a prompt.

Recommendation. Keep open: work remains. Persist existing-thread mode changes immediately and remove stale local overrides on incoming changes.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author SeoFood. Updated 2026-08-03T14:45:18Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Issue #5285. [Bug]: macOS TCC permission prompts attributed to T3 Code are raised by agent CLI probes at startup

Request. Startup provider probes can cause macOS privacy requests to be attributed to T3 Code before any user action.

Audit finding. Provider initialization still starts an immediate background health check, and Claude checks still launch the CLI and its capability probe. Recent hook and IDE-probe restrictions reduce unrelated work but do not change macOS responsibility attribution or defer probing until a user action. The report itself distinguishes a logged TCC preflight from a visible prompt, so the exact resource access that draws a dialog still needs tracing.

Recommendation. Keep open: work remains. Trace which startup Claude probe touches a protected resource before choosing a deferred-probe fix.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author willsheldon. Updated 2026-08-03T15:19:40Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8634, #4466, #2745.

Limits. The issue does not identify which probe performed the protected-resource access that caused a visible dialog.

Issue #5297. Claude stop-hook continuation hides the original assistant response

Request. A Claude Stop-hook continuation can hide the substantive response produced before the hook.

Audit finding. #7723 preserved first and last assistant messages, and mobile still has that behavior. #8828 then restored terminal-only folding on web, so its pre-hook response can again be hidden. Neither client has a persisted Stop-hook boundary, and hook lifecycle events are not converted to visible activities, so the requested chronological sequence is still incomplete.

Recommendation. Keep open: partial fix. Add a persisted Stop-hook boundary that keeps both the pre-hook and post-hook responses visible across clients.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author ElliotDrel. Updated 2026-08-03T20:21:01Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7723, #8828, #5506, #7518. Merged PRs that cover all or part: #7723.

Issue #5313. [Bug]: restore text paste in the iOS chat composer

Request. iOS text paste can fail in the composer, with a separate report of chat-to-terminal paste failure.

Audit finding. The composer still intercepts clipboard items that advertise an image and returns before UIKit text paste. If those providers load no image, the asynchronous path does nothing instead of trying text, matching the proposed swallowed-paste mechanism. The linked multi-fix proposal was closed without merging, and the terminal report needs separate coverage.

Recommendation. Keep open: work remains. Restore text fallback after an image-provider paste yields no image, then check both reported paste destinations.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author MatthewFeroz. Updated 2026-08-11T12:32:37Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #6607.

Limits. The exact clipboard item types from Google Docs and the terminal failure are not captured.

Issue #5323. [Bug]: Claude runtime stream failed when closing T3Code

Request. Quitting and reopening the macOS app leaves a Claude runtime-stream error in an otherwise healthy thread.

Audit finding. #5891 improved intentional shutdown by closing the query before cleanup waits. Main still does not classify SDK SIGTERM/SIGINT exit messages as interruption when the child exits before context.stopped is set, and #5142 targets that separate race. The issue contains no exit reason or current-release reproduction, so the cleanup improvement alone is not closure evidence.

Recommendation. Keep open: retest. Retest Cmd+Q on v0.0.37 and capture the Claude child exit reason before deciding whether the signal-classification patch is needed.

Confidence medium. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author marcoamt. Updated 2026-08-04T07:37:44Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5891, #5142, #5557. Merged PRs that cover all or part: #5891.

Limits. No T3 version or subprocess exit details were supplied for the app-quit report.

Issue #5338. [Bug]: Android tablet view differs from phone and lacks new-task sidebar controls

Request. Android tablet split view lacks the phone-style new-task and sidebar controls.

Audit finding. The merged Android change adds the persistent new-task button, shared settings control, and header improvements. Its description explicitly leaves sidebar collapse out of scope, and WorkspaceSidebarToolbar still returns null on Android. The Android thread header also lacks a primary-sidebar toggle, so the full issue is not fixed.

Recommendation. Keep open: partial fix. Keep the issue for the missing Android primary-sidebar collapse and restore control.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author MajesteitBart. Updated 2026-08-18T02:20:27Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5385, #7352. Merged PRs that cover all or part: #5385.

Limits. The source fix is in stable Git ancestry. Android store rollout was not checked.

Issue #5340. [Bug]: Android thread content overlaps after switching directly between threads

Request. The native Android timeline can overlap messages after a quick switch between threads.

Audit finding. Main keys ThreadFeed by thread ID, so it remounts when the selected thread changes. A later Android fix pins user-bubble width for fenced code and tables, which removes a confirmed overlapping-layout cause. That fix does not prove the intermittent thread-switch trigger or all assistant rows in this report are covered.

Recommendation. Keep open: retest. Repeat rapid thread switching on the current Android build with the same affected message shapes.

Confidence medium. Release: Release not verified.

Observed GitHub metadata. GitHub state OPEN. Author fionn77. Updated 2026-08-06T16:53:52Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5659. Merged PRs that cover all or part: #5659.

Limits. The reported Android build was not recorded and the current Play Store rollout was not checked.

Issue #5359. [Bug]: Thread title and branch-name generation fail silently when the text generation provider is unhealthy

Request. Unhealthy text-generation providers leave thread titles and branch names unchanged without a visible failure.

Audit finding. Merged PR 8087 retries automatic title generation twice, but retries still target the same selected provider. Provider selection checks enabled state rather than health, and its fallback still reads the legacy provider map. Automatic title and branch failures still end in logWarning, so a persistently broken provider leaves the reported silent failure intact.

Recommendation. Keep open: partial fix. Use a healthy enabled instance for auxiliary generation and report final title or branch failures in thread activity.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author gustavohariel. Updated 2026-08-04T23:43:26Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7533, #8656, #8087, #7328. Merged PRs that cover all or part: #8087.

Issue #5369. [Bug]: Windows UI shifts vertically while app is unfocused

Request. The Windows desktop UI shifts while unfocused and moves back when focused.

Audit finding. The only discussion evidence connects a similar browser shift to the old Syncing messages pill. Nightly composer changes removed that component and now render sync status in the shared composer banner. That is a reason to retest, not proof that the reported Windows visual and hit-target shift is fixed, since the original report has no version or recording.

Recommendation. Keep open: retest. Capture the focus transition on the latest Nightly with the app version, display scale, and sync banner visible.

Confidence medium. Release: In nightly source.

Observed GitHub metadata. GitHub state OPEN. Author ElliotDrel. Updated 2026-08-05T18:34:30Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8734, #8855. Merged PRs that cover all or part: #8734, #8855.

Limits. The original Windows report lacks a version and recording. No full Windows focus-transition reproduction was run.

Issue #5392. Claude provider probe fails with enterprise-managed MCP configuration

Request. The Claude capability probe fails when enterprise-managed MCP configuration rejects strict MCP mode.

Audit finding. Main still sets strictMcpConfig=true for every capability probe and suppresses its stderr. #4015 intentionally added this isolation for user MCP processes, but it has no enterprise-config exception or separate authentication path. The current probe test explicitly requires the same strict flag, so the managed-MCP case is not covered by the later hook and IDE probe fixes.

Recommendation. Keep open: work remains. Add an enterprise-compatible capability probe that does not start configured MCP servers.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author mishonenchev. Updated 2026-08-05T07:42:51Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4015, #4466, #4928, #8634.

Limits. The enterprise-managed CLI rejection is supplied by the report, not a local reproduction.

Issue #5395. [Bug]: Claude provider leaks subagent (sidechain) stream into the parent thread , only the message_delta branch checks parent_tool_use_id

Request. Claude child streams can corrupt parent text and tool state when content-block indexes overlap.

Audit finding. #5219 now drops child narration and child assistant snapshots and attributes child tools, so the main text leak has been addressed. However, child tools still use the same index-keyed inFlightTools map as parent tools, and a child content_block_stop still checks the parent text map first. Those collisions are material parts of the original report and prevent closure.

Recommendation. Keep open: partial fix. Partition Claude streaming block state by parent_tool_use_id and test overlapping parent and child indexes.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author albert-zen. Updated 2026-08-05T09:44:32Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5219, #5456, #6389. Merged PRs that cover all or part: #5219.

Limits. The remaining overlapping-index case was checked in source, not reproduced with a live Claude subprocess.

Issue #5401. [Bug]: OpenCode turn fails with "Endpoint is unavailable" in T3 Code while identical CLI run completes

Request. A multi-tool OpenCode turn fails in T3 with Endpoint is unavailable while the same CLI task completes.

Audit finding. The report proves a same-server difference but supplies no upstream status or failing continuation payload. The adapter carries the native error object in runtime.error detail, while ingestion retains only the message in the client work-log activity. Current lifecycle and catalog changes do not establish a fix for this model-continuation failure.

Recommendation. Keep open: evidence needed. Capture paired sanitized native traces for the failing T3 turn and the successful CLI run with matching model and variant.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author utkuvibing. Updated 2026-08-05T11:20:22Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8480.

Limits. No upstream status, response body, or paired continuation traces are available.

Issue #5410. [Bug]: Desktop server private memory climbs ~25-30 MB/h while idle (immortal Effect parent spans + always-on tracing)

Request. Idle server tracing retains state under long-lived parent spans and private memory keeps rising.

Audit finding. forkParked still forks long-running work with the current context, and ServerSecretStore.get and PortDiscovery polling still create traced spans. The recent provider-buffer and idle-sampling fix does not remove these tracing paths. The specific tracing proposal is still open, so the reported idle-growth mechanism has not been removed from source.

Recommendation. Keep open: work remains. Break lifetime-long trace parent retention and verify idle private-memory growth after the change.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Benchance. Updated 2026-08-05T13:50:24Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5411, #8187.

Issue #5421. Web: sticky provider options win over stale thread selection

Request. Saved cross-thread provider options should override stale thread options without changing the thread model.

Audit finding. deriveEffectiveComposerModelState still falls back from draft options to persisted thread and project options, without reading the cross-thread sticky options map. The composer uses that result for dispatch, so the requested options-only sticky precedence is not implemented. Grok also still carries the Early Access badge, and the linked replacement PR remains open.

Recommendation. Keep open: work remains. Finish PR 5504 with options scoped to the selected provider instance and tests that preserve the thread model.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author EnzoTironi. Updated 2026-08-05T15:52:05Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5504, #8358, #6508.

Limits. No browser reproduction of the reported displayed-versus-sent effort mismatch was run.

Issue #5436. [Bug]: Mobile: message queued while agent is working is never sent if the app goes to background , only delivered on next app open

Request. A follow-up left in the mobile outbox is sent only after the app returns to the foreground.

Audit finding. Main delivers connected follow-ups immediately after the steering fix, so parent-turn activity no longer blocks them. Disconnected messages still belong to the mobile outbox, and the drain skips a waiting message until client state changes. The requested server-owned delivery after backgrounding is still missing, as the discussion explicitly confirms.

Recommendation. Keep open: partial fix. Move acknowledged queued follow-ups to durable server-owned delivery before the mobile app can suspend.

Confidence high. Release: Release not verified.

Observed GitHub metadata. GitHub state OPEN. Author iamtoled. Updated 2026-08-16T16:04:11Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #6543. Merged PRs that cover all or part: #6543.

Limits. The fix commit is in the v0.0.37 source tag, but the current mobile-store rollout was not verified.

Issue #5439. [Bug]: Pressing Enter with an external keyboard should send the prompt on iPad

Request. External-keyboard Enter should send on iPad while Shift+Enter inserts a newline.

Audit finding. The native iOS editor registers only Command+Return as a send command. Plain Return remains UITextView input, so the requested Enter and Shift+Enter behavior is not implemented. The discussion adds an Android modifier-key problem, which the iOS command cannot resolve.

Recommendation. Keep open: work remains. Implement explicit hardware-keyboard Enter and Shift+Enter behavior on iPad without changing software-keyboard newline entry.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author magofdl. Updated 2026-08-13T16:21:54Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8362.

Issue #5441. [Bug]: Composer command menu stays behind when the right panel or terminal drawer opens

Request. The composer command menu can keep its old position when the side panel or terminal drawer opens.

Audit finding. The position layer still relies on window resize, captured scroll, and ancestor ResizeObserver callbacks, and its effect still depends only on the anchor. The current composer rewrite changed which element is measured and how the menu overlaps it, but it did not add explicit panel-state invalidation. Since the report could not explain the missing observer callback, the changed layout needs a fresh wide-window reproduction before calling this fixed.

Recommendation. Keep open: retest. Repeat the reported wide-window panel and drawer toggles while recording menu and anchor coordinates.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author rynfar. Updated 2026-08-05T18:15:15Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5336, #8734.

Limits. No browser reproduction of the changed composer geometry was run.

Issue #5447. [Bug]: One submitted prompt spawned a second, invisible agent session on a different model, which ran gh write commands unsupervised

Request. Claude metadata generation can execute the user task in an invisible second session with unrestricted tools.

Audit finding. runClaudeJson still launches the CLI in the supplied project cwd with dangerously-skip-permissions and no tool restriction. The same helper produces titles and branch names, matching the two-machine transcript evidence and the canonical duplicate links in the discussion. Prompt and title-retry changes do not enforce isolation, so the write-capable hidden-session path remains.

Recommendation. Keep open: work remains. Disable task tools and project instructions for Claude metadata generation and test that a quoted task cannot mutate a marker file.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author darrynhoskingluna. Updated 2026-08-27T23:10:31Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5734, #4061, #3594.

Limits. No write-capable helper was run during this read-only audit.

Issue #5454. [Bug]: Pending user-input popup can never be dismissed after the provider session dies (e.g. server restart)

Request. Pending questions and approvals cannot be dismissed after their provider session disappears.

Audit finding. Clean Claude teardown now resolves pending requests through merged PR 5127. The generic missing-session failure still uses No active provider session is bound to this thread, which web, mobile, the decider, and the projector do not recognize as stale. The discussion confirms that the same gap affects Cursor approval cards, so Claude-only cleanup does not close this report.

Recommendation. Keep open: partial fix. Handle the missing-session response as terminal for both approval and user-input requests across clients and server.

Confidence high. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author NeilTheFisher. Updated 2026-08-13T21:15:03Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5127, #5453. Merged PRs that cover all or part: #5127.

Issue #5474. [Bug]: t3code --version segfaults without a display instead of printing the version

Request. The Linux desktop executable cannot print its version without a display.

Audit finding. Desktop startup still enters Electron readiness without a version-only exit path. The dedicated early-version proposal remains open, and the discussion reproduces the failure again on 0.0.36. The server CLI version path is a different executable and does not cover AppImage or package launchers.

Recommendation. Keep open: work remains. Add a version-only desktop launcher path before Electron initializes the GUI.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author SlanyCukr. Updated 2026-08-31T10:33:36Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7256.

Issue #5475. [Bug]: Sidebar V2 (desktop): selecting a remote (Tailscale) project in the new-thread picker opens an existing thread , no way to start a new thread on a remote environment

Request. Choosing a remote project for a new thread opens an existing thread and hides its environment identity.

Audit finding. The new-thread picker now shows the project environment, which directly addresses the identification gap. Current Sidebar routes New through the dedicated new-thread-in picker, whose action passes a scoped remote project to handleNewThread rather than the separate open-latest-thread action. No source change was found that proves the reported existing-thread symptom itself is resolved, so that behavior still needs confirmation.

Recommendation. Keep open: partial fix. Retest New thread on a remote project that already has both a server thread and an unsent draft.

Confidence medium. Release: In stable source.

Observed GitHub metadata. GitHub state OPEN. Author iamtoled. Updated 2026-08-16T03:09:11Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7392, #5994, #4589. Merged PRs that cover all or part: #7392.

Limits. No current remote-project UI reproduction was performed.