pingdotgg/t3code. All authors. Drafts included. Default branch main. 570 issue assessments and 925 PR assessments. Initial inventory: 570 open issues and 924 open PRs. Current assessed open inventory: 570 issues and 924 PRs. Final reconciliation: 2026-09-01T11:57:41.491617+00:00.
Request. The thread sidebar briefly loses its rows when returning from Settings.
Audit finding. AppSidebarLayout still swaps out the thread sidebar and retains only useProjects. Sidebar still starts AutoAnimate when the list mounts, now with a 150 ms duration. The merged back-navigation change does not retain thread shells or prevent mount-time row animation.
Recommendation. Keep open: work remains. Keep thread-shell data subscribed across Settings and verify the remount animation path.
Request. Grok health checks start all configured MCP servers through a full ACP session and can time out.
Audit finding. Current discovery still creates a Grok ACP runtime in the server working directory and calls start before reading session models. The 15-second timeout still returns an error snapshot even after the version probe succeeds. Skill discovery and default-off providers do not remove this full-session cost for enabled instances, and both lightweight-probe PRs remain open.
Recommendation. Keep open: work remains. Choose and finish one lightweight Grok health-probe implementation, retaining last-good state on timeout.
Request. Desktop hides Send during an active turn even when the composer has a follow-up prompt.
Audit finding. ChatComposer still passes showSendWhileRunning only for mobile-width viewports. This keeps the desktop button hidden even though Enter can steer the running turn. The candidate removing that viewport restriction remains open.
Recommendation. Keep open: work remains. Review the open shared Send and Stop button fix.
Request. Codex model aliases do not match their available LiteLLM pricing keys.
Audit finding. lookupRate still uses an exact normalized key and has no mapping for the aliases named in this issue. The newer pricing work preserves provider-qualified keys but does not reconcile these model names. Tokens therefore remain unpriced when only the alternate LiteLLM key exists.
Recommendation. Keep open: work remains. Add the narrow aliases while preserving exact-rate precedence.
Request. Terminal escape sequences in OpenCode inventory become saved agent selections that fail later prompts.
Audit finding. The merged HTTP catalog change avoids new stdout contamination in normal provider discovery. Server option readers still return saved strings unchanged, and the adapter can forward those agent and variant values into promptAsync. Current clients can normalize some invalid choices when a valid catalog exists, so saved-thread recovery needs a focused check rather than closure.
Recommendation. Keep open: partial fix. Add read-time cleanup for saved OpenCode model, agent, and variant values.
Request. A packed server running under Bun can accept pairing without sending the session cookie.
Audit finding. The discussion isolates this to the packed Bun runtime and reports two copies of Effect pre-response state, while Node tests pass. Current auth code still sets cookies through appendPreResponseHandler and mergeCookies, and the server still loads the Bun HTTP implementation separately. The new remote-cookie naming fix preserves that mechanism and does not demonstrate that the packed Bun bug is resolved.
Recommendation. Keep open: work remains. Run the packed current server under Bun and Node and compare pairing Set-Cookie and no-cache headers.
Request. Claude skills accepted by the CLI are silently omitted when their frontmatter fails strict YAML parsing.
Audit finding. parseSkillFrontmatter still treats every YAML parse exception as malformed, and discovery silently skips that entry. This preserves the reported colon-space mismatch between SDK slash commands and the filesystem skill list. The later picker changes do not change this parser.
Recommendation. Keep open: work remains. Review #7814 with the two colon-space frontmatter examples in the issue discussion.
Request. Use Left and Right Arrow to move between expanded composer setting pickers.
Audit finding. Model, model options, and permission controls remain separate picker implementations. ChatComposer has no shared left/right navigation or conditional picker sequence, and the compact controls still use a different menu. This is an unimplemented keyboard interaction choice, not a landed fix.
Recommendation. Keep open: decision needed. Approve or reject the expanded-picker keyboard sequence before implementation.
Request. The desktop sidebar flickers on Fedora when its compound scroll fade mask is active.
Audit finding. The reporter isolated the flicker to the scroll-area mask and confirmed that disabling only that mask stops it. SidebarContent still enables scrollFade, whose viewport combines four directional masks. No matching compositor fix was found in the inspected main history.
Recommendation. Keep open: work remains. Reproduce the compound-mask flicker with the reporter's Fedora GPU and compositor.
Request. Hover tooltips can stay open over the composer after the chat timeline scrolls.
Audit finding. Tooltip remains a direct Base UI root and a portal at z-index 140, with no timeline hover-dismissal controller. The open fix adds scroll-driven dismissal while preserving keyboard-focus tooltips, but that behavior is not in main.
Recommendation. Keep open: work remains. Review the open timeline tooltip dismissal fix.
Request. Grouped tool activity remains clickable but no longer shows an expansion chevron.
Audit finding. The grouped tool row now renders an activity icon and summary, with aria-expanded and a working toggle handler but no chevron. This follows the merged one-line activity redesign. The missing visible expansion cue needs a design decision rather than closure as fixed.
Recommendation. Keep open: decision needed. Decide whether grouped tool rows should restore a visible disclosure chevron.
Request. Successful PM inspectTaskChanges results are marked failed in the activity timeline.
Audit finding. The report depends on DriverPmAdapter and PmEventProjection, neither of which exists in pinned main or the inspected local path history. Main's orchestration runtime contains no PM driver layer. A successful-looking result is not enough to decide whether an upstream MCP error should be ignored without the actual implementation.
Recommendation. Keep open: evidence needed. Request an immutable repository commit containing the PM adapter and its failing tool fixture.
Request. Old PM plan and land approval gates remain actionable after newer stage attempts.
Audit finding. Main's command union has project and thread operations, not the reported task.stage.start, task.gate.resolve, or task.land.approve commands. The PM gate projections and UI named in the report are absent from the inspected source and path history. Their absence does not prove that the stale approval defect was fixed in the branch that runs them.
Recommendation. Keep open: evidence needed. Request the immutable PM branch commit containing the stale-gate reproduction.
Request. A hung PM turn or failed subscription can stop the PM wake chain until restart.
Audit finding. The reported DriverPmAdapter wait, PmRuntime subscriptions, and PmReEntryQueue semaphore are not present in pinned main or the inspected path history. Main has provider and checkpoint reactors, but those alone cannot establish the state of the missing PM wake chain. No discussion identifies the code revision needed to verify the watchdog or restart behavior.
Recommendation. Keep open: evidence needed. Request the PM source commit and a trace for one missed wake after a provider exit.
Request. A missed PM stage-completed event is not redelivered until the server restarts.
Audit finding. The reported awaited-stage projection and PmRuntime consumption markers are absent from pinned main. Its current command and event model does not expose PM stage completion, so regular thread receipts cannot prove that this stage-redelivery defect is resolved. The report has no branch or commit and no discussion with a replacement.
Recommendation. Keep open: evidence needed. Request the PM branch commit and the missed-delivery test case.
Request. The report describes stuck project-manager stages, full-history sweeps, and leaked project-manager adapter fibers.
Audit finding. PmRuntime, DriverPmAdapter, OrphanTurnReconciler, and task.stage.interrupt are not present in pinned main or the inspected path history. Current OrchestrationReactor starts provider, checkpoint, deletion, settlement, and relay services, with no project-manager adapter. The issue supplies no affected commit or branch, so its three proposed fixes cannot be mapped to current upstream behavior.
Recommendation. Keep open: evidence needed. Ask the reporter for the affected commit or branch containing the named project-manager services.
Request. The PM verifier should finish its planned checks and report all findings in one pass.
Audit finding. The proposed change targets stageResolution, builtInPlaybooks, PmRuntime, and pmTools, which are absent from pinned main and the inspected path history. Current orchestration layers do not include that verifier role. Without its source revision, neither the quoted prompt nor a later prompt fix can be verified.
Recommendation. Keep open: evidence needed. Request the immutable commit that defines the PM verifier prompt.
Request. Turn checkpoint diffs show only state files, one file, or the full repository instead of that turn's edits.
Audit finding. Current turn queries require a checkpoint range and set fallbackFromToHead:false, so a missing baseline is not intentionally compared with an empty tree. The client still has an inferred checkpoint-count fallback, but the report gives hypotheses rather than a captured wrong range. Its .ged task files and stage-settlement flow are not in upstream main, so their capture order needs an upstream reproduction.
Recommendation. Keep open: evidence needed. Provide a current upstream multi-turn reproduction with checkpoint refs and the exact requested from/to counts for each wrong file set.
Limits. The report refers to task orchestration files and flow absent from upstream main. No checkpoint ref contents or failing request range were available.
Request. Turn chips in an embedded task diff should filter locally instead of navigating into a worker chat.
Audit finding. Upstream DiffPanel already updates useDiffPanelStore for turn selection and does not navigate from those handlers. Its current props have no explicit threadRef embedding mode, and OrchestratorRoutes.tsx is absent from upstream main. The reported task view cannot be checked against this checkout, so this is not a verified landed fix for that view.
Recommendation. Keep open: evidence needed. Identify the branch that contains the task route and supply a reproduction on upstream main or move the report to that implementation.
Request. Post-landing follow-up work should say Reworking instead of looking like initial work.
Audit finding. The named PM task board, landing projector, and OrchestratorRoutes files are absent from pinned main. They are also absent from the inspected head of the open orchestration rewrite, so its similar name is not proof that it owns this request. The issue needs its implementation branch or commit before the stale-landing behavior can be checked.
Recommendation. Keep open: evidence needed. Add the public branch or pull request that contains the PM task board and stale landing state.
Request. Show the chosen reasoning level in PM stage, helper, and task model labels.
Audit finding. StageTimeline, HelperRunTimeline, TaskBoard, and the reported stage-history modelOptions contract are not in pinned main. Current chat model controls are a different UI and do not satisfy the requested PM task views. No supplied commit or discussion identifies the implementation to audit.
Recommendation. Keep open: evidence needed. Request the PM UI branch commit containing the three task views.
Request. The PM should handle safe rebases without a new worker and verification cycle.
Audit finding. The cited PM tools, verification model, and taskRepositoryPreparation implementation are not in pinned main or the inspected orchestration rewrite head. Current main has Git actions, but those are not the claimed event-sourced PM landing gates. Without the target branch, the proposed verification-head reuse and document-only exception cannot be assessed against their actual trust checks.
Recommendation. Keep open: evidence needed. Identify the public implementation branch that owns the PM landing and verification gates.
Request. The app should open in an Orchestrator view, with a later visual design pass.
Audit finding. The issue explicitly leaves the work unscheduled and the design scope undefined. Pinned main routes the app root into chat and has no implemented PM board view matching the described switch. A default-versus-last-used rule and the owning Orchestrator implementation must be chosen before this can be treated as a concrete change.
Recommendation. Keep open: decision needed. Choose the owning Orchestrator view and whether startup restores the last view or always opens it.
Request. Neovim repaint chunks can leave the web and Android terminal display torn or stuck.
Audit finding. The web snapshot path still reads and clears dirty rows without checking synchronized-output mode 2026, and the Android snapshot path has no such mode gate. The merged oversized-grapheme fix prevents a different crash and does not add atomic repaint handling. The exact persistent-frame failure has not been reproduced in this audit.
Recommendation. Keep open: work remains. Verify split synchronized Neovim frames on both web and Android before choosing the renderer fix.
Request. Non-Git projects need a visible rewind action, either for conversation only or with app-managed file snapshots.
Audit finding. Checkpoint capture still gates on Git repository detection, and the web message revert map depends on completed checkpoint summaries. There is no alternate non-Git snapshot or conversation-only route in these paths. The choice between a new snapshot backend and an explicitly labeled conversation-only rewind needs a product decision.
Recommendation. Keep open: decision needed. Choose conversation-only rewind or a non-Git snapshot backend and define the confirmation text before implementation.
Request. Mobile renders file links outside the workspace as tappable but silently ignores them.
Audit finding. ThreadFeed still attempts to make file links workspace-relative and returns without feedback when that fails. The new native PDF and image preview work only runs inside the successful relative-path branch, so it does not handle the reported external path. The focused feedback fix remains open.
Recommendation. Keep open: work remains. Return an explicit unsupported-path message or an authorized file-preview path when mobile cannot resolve a file link inside the workspace.
Request. An iPhone thread can crash repeatedly when changed-file UI appears.
Audit finding. ReviewSheet still non-null asserts a native diff-view resolver that can explicitly return null, leaving a concrete render crash path. Other callers check that result, and the issue has no native or JavaScript stack proving this is the exact widget failure. The proposed guard is open, so the report needs that fix plus a test of the original iPhone thread.
Recommendation. Keep open: work remains. Guard the native diff-view resolver and retest the affected iPhone thread.
Request. Skill suggestions and tokens can break the custom-answer editor for pending questions.
Audit finding. The pending-answer path still detects composer triggers and passes provider skills into the same token editor. It stores plain answer strings, so this is not a provider-turn skill invocation path. A later comment reproduces the stuck editor on 0.0.36, and the remaining open proposal keeps the picker rather than meeting the issue's plain-text acceptance criteria.
Recommendation. Keep open: work remains. Decide the pending-answer contract and remove unsupported skill token handling from that path.
Request. Stop can leave pending Codex questions visible and prevent further conversation.
Audit finding. The client derives pending questions from request and resolution activities, without clearing them when a turn ends. Codex interrupt still sends turn/interrupt without directly settling pending question answers, so dismissal depends on later provider resolution events. The related remote Stop proposal is open and is not evidence that the question lifecycle is fixed.
Recommendation. Keep open: work remains. Add a focused Codex pending-question interruption test that verifies both provider cancellation and client dismissal.
Request. Copy buttons fail when the remote web app is opened over plain HTTP.
Audit finding. writeTextToClipboard still requires navigator.clipboard.writeText and throws ClipboardApiUnavailableError when it is absent. A non-loopback HTTP browser origin commonly lacks that secure-context API, and the reported update button uses this helper without a fallback. The plain-HTTP copy fix remains open.
Recommendation. Keep open: work remains. Review and land the plain-HTTP clipboard fallback with failure feedback.
Request. Codex Apps approval requests can be hidden outside Auto mode.
Audit finding. Merged MCP elicitation handling now shows app-access prompts across the clients. But the exact item/permissions/requestApproval method named here still has no runtime handler and still falls through the adapter's request mapping. The report did not capture a live request, so the working MCP path cannot prove this connector case is fixed.
Recommendation. Keep open: partial fix. Capture a failing Apps request and add support for its exact JSON-RPC method.
Request. Cursor transport failures emitted as assistant text are recorded as successful turns.
Audit finding. Cursor content deltas are still published directly, and sendTurn maps every non-cancelled stop reason to completed. There is no Cursor-specific recognition or bounded retry for the documented error-text sequence. A later nightly report confirms the same WritableIterable failure after the Grok reliability changes.
Recommendation. Keep open: work remains. Add a narrow Cursor transport-error adapter path with bounded retries and tests that preserve ordinary assistant prose.
Request. Nushell login shells reject the POSIX command used to capture PATH.
Audit finding. readEnvironmentFromLoginShell still passes the same printf and printenv command to every Unix shell. That command includes || true, which Nushell does not accept. Recent Windows PATH repairs do not alter this Unix probe, and the Nushell fix remains open.
Recommendation. Keep open: work remains. Review the Nushell-specific environment capture change.
Request. New-project lookup sends a full self-hosted GitLab URL as a project ID instead of a namespace path.
Audit finding. SourceControlRepositoryService only trims repository input before calling the provider. GitLabCli still encodes that entire input directly into projects/<id>, without separating host and namespace. The older proposal was closed unmerged and the replacement remains open.
Recommendation. Keep open: work remains. Normalize GitLab URLs into host plus namespace/project before repository lookup and cover a host with no gitlab substring.
Request. A valid server-side project script ID can crash web thread and project settings views during keybinding construction.
Audit finding. ProjectScript.id still accepts any trimmed nonempty string, while SCRIPT_RUN_COMMAND_PATTERN restricts it to a short lowercase slug. commandForProjectScript still calls the throwing schema constructor during rendering. A UUID accepted by the server therefore remains incompatible with the client, and the contract-alignment proposal is open.
Recommendation. Keep open: work remains. Align script ID validation and make already-persisted external IDs safe to render.
Request. Usage summaries double-count one transcript directory visible through both Windows and WSL.
Audit finding. UsageService still builds source identity from hostId, provider, the local directory string, and local volumeId. usageMerge deduplicates only an exact match of all four values, so Windows and WSL views of the same files remain distinct. Recent incremental scan and cache fixes change performance and retention, not cross-OS identity.
Recommendation. Keep open: work remains. Add an explicit trusted cross-OS source identity while preserving distinct sources on unrelated machines.
Request. A running agent can lose preview tools after the T3 server restarts.
Audit finding. The credential registry is still in memory, so old tokens cannot survive a process restart. However, the standard recovery path already calls prepareMcpSession before resuming an adapter, and the adapters read that replacement configuration. The landed liveness fix addresses idle expiry, not persistence. The downstream-fork report does not identify the upstream provider or recovery path that kept the stale token.
Recommendation. Keep open: evidence needed. Obtain an upstream provider-specific restart reproduction showing which resume path retains the old credential.
Request. Claude authentication failure is displayed as ordinary assistant text without a clear recovery action.
Audit finding. The adapter still ignores authentication_failed on assistant snapshots and treats subtype=success as completed even when the CLI marks it as an API error. The existing provider banner gives CLI sign-in guidance only when the provider snapshot is already error/unauthenticated, which the runtime failure does not establish. The open auth patch improves classification but does not by itself provide an in-app login flow for remote or mobile use.
Recommendation. Keep open: work remains. Review #8869 with same-instance auth-state refresh and a recovery path that is usable from remote clients.
Request. Publish agent activity is disabled although its description says it can work without a managed tunnel.
Audit finding. Current controls do not require managedTunnelActive to enable publishing. The controller explicitly selects publish_only when publishing is enabled without a tunnel, but the control still requires sign-in and relay-write scope. The report omits that session and account context, so it does not establish which prerequisite disabled the switch.
Recommendation. Keep open: evidence needed. Record the failing session scopes, sign-in state, and displayed disabled-control reason.
Request. Editing wrapped lines in the Files editor causes scroll jumps and a missing-line renderer error.
Audit finding. The Files editor still combines a content-editable Pierre File with Virtualizer and overflow:wrap. Recent file-panel changes refresh external content, but do not add a fix or focused test for editing wrapped lines while the caret moves. The issue itself labels the height-cache diagnosis untested, so that cause should not be treated as proved.
Recommendation. Keep open: work remains. Reproduce repeated Enter in a narrow wrapped file and trace the editor render range and caret position before changing geometry code.
Request. One Android T3 Connect connection can create two environment sessions and WebSockets.
Audit finding. authorizeDpop still reads the token cache, obtains a bootstrap credential, exchanges it, and writes the cache without a per-environment shared in-flight operation. Concurrent misses can therefore mint two sessions even though the connection supervisor is intended to own one connection. Recent changes add diagnostics and client metadata, not this serialization, while the desktop restart-session PR addresses a different client and credential path.
Recommendation. Keep open: work remains. Trace the duplicate Android startup attempts and share one DPoP authorization operation per environment.
Request. Opening the project filter with the mouse highlights a project that the pointer is not over.
Audit finding. The old MenuPopup was replaced by a searchable Combobox in a merged change. A search input now precedes the project settings buttons, removing the reported first-tabbable-gear path, but autoHighlight is enabled and no checked test proves the requested mouse-open highlight behavior. The old menu-specific candidate remains open and needs review against this replacement.
Recommendation. Keep open: retest. Retest mouse-open and keyboard-open highlighting in the current searchable project filter.
Request. A Windows file-search result opens a dot-directory as a file instead of showing its contents.
Audit finding. The current path index distinguishes files from directories and reconstructs directory ancestors. The file picker explicitly filters out directory entries, so a leading dot alone does not explain the reported result. The report has no version, selected-entry payload, or directory fixture to locate which entry point supplied the wrong kind.
Recommendation. Keep open: evidence needed. Attach a minimal dot-directory fixture and the selected search entry including kind and path on current Windows.
Request. Mobile can default a non-Git project to New worktree and disable Start because no branch can be selected.
Audit finding. The mobile flow still resolves workspace mode from project, t3.json, and server settings without checking isRepo. NewTaskDraftScreen then disables Start for worktree mode with no selected branch. Two dedicated fixes remain open, so the web fallback does not establish mobile coverage.
Recommendation. Keep open: work remains. Resolve non-Git drafts to current checkout, including persisted and offline drafts, and consolidate the overlapping mobile fixes.
Request. A new-thread checkout blocked by uncommitted changes needs an actionable Git safety error.
Audit finding. switchRef still supplies the fixed detail git checkout failed. executeGit builds GitCommandError from that detail and output lengths, discarding the Git reason, so the client cannot explain that local changes would be overwritten. No current branch-specific error classification handles this case.
Recommendation. Keep open: work remains. Classify the dirty-checkout refusal at the Git boundary and return a commit-or-stash action message.
Request. Mobile Markdown needs safe HTML rendering and SVG image support.
Audit finding. Native iOS currently strips HTML tags into text rather than creating image or layout nodes, while the Android fallback has no equivalent safe HTML conversion. The thread image renderer still uses React Native Image and has no SVG-specific path. The referenced image-URL proposal was closed without merging and cannot be counted as a shipped HTML fix.
Recommendation. Keep open: work remains. Implement a safe HTML subset and an SVG-capable image path in both mobile Markdown renderers.
Request. Cursor model discovery creates a slow ACP session on each health refresh and can exceed its timeout.
Audit finding. The current provider check still launches a new ACP runtime, starts a session, and calls cursor/list_available_models under a 15-second limit. The result is not independently cached between model-discovery cycles. Disabled-provider gating reduces unused probes but does not change this cost for an enabled Cursor instance.
Recommendation. Keep open: work remains. Separate cached Cursor model discovery from frequent health checks and measure the ACP startup phase.
Request. Recall sent prompts with ArrowUp and ArrowDown while preserving the unsent draft.
Audit finding. The current composer uses ArrowUp and ArrowDown for the active suggestion menu and otherwise returns control to normal editing. It has no sent-prompt history state or recall path. The replacement implementation is still open, so the requested interaction is not available in main.
Recommendation. Keep open: decision needed. Review the open prompt-history implementation against the issue's editing and draft rules.
Request. The current project switcher should show failure, input, and unseen-completion attention states.
Audit finding. The current switcher renders each project favicon, name, and settings button without a thread-attention rollup. Legacy sidebar status dots are a different component and do not cover this control. The dedicated attention-dot proposal remains open.
Recommendation. Keep open: work remains. Add the requested failure-first attention rollup to current project-switcher items and their accessible labels.
Request. Files tree labels remain 12px when Interface font size changes.
Audit finding. FileBrowserPanel still sets --trees-font-size-override to the literal 12px inside the tree host. That value does not derive from the interface font setting, and the proposed scaling change is open. Whole-app zoom does not address this setting mismatch.
Recommendation. Keep open: work remains. Derive the tree font size from the existing interface font setting while preserving its compact relative scale.
Request. Android project-filter rows omit the project favicon.
Audit finding. The shared mobile filter item contains only a key and label, and both project scope mapping and menu construction omit favicon data. The Android menu cannot show a project image that the filter does not supply. The linked favicon PR was closed without merging, so it is not a fix on main.
Recommendation. Keep open: work remains. Restore project favicon data and rendering in both Android project-filter entry points.
Request. Network-error turns without a rendered assistant message lose the user-row revert action.
Audit finding. The current web map still requires a following assistant message whose ID matches a turn-diff summary. Error checkpoints with no such message therefore remain invisible to the revert control. The proposed positional patch was closed without merging, and no equivalent turn-ID-based fallback is present.
Recommendation. Keep open: work remains. Associate user prompts with error checkpoints by turn identity and test synthetic or missing assistant messages.
Request. Redraw-heavy terminal output grows history without a byte limit and repeatedly rewrites the whole file.
Audit finding. capHistory still counts newlines, so output containing no newlines has no size bound. The persistence worker still writes request.history with writeFileString after each coalesced batch. Append and bounded-stream changes exist only in open PRs.
Recommendation. Keep open: work remains. Choose and finish the bounded-history persistence change before closing this report.
Request. Unchecked switches disappear when a custom theme's input color matches its background.
Audit finding. Both Switch and the switch-style menu checkbox still use data-unchecked:bg-input. The imported theme can therefore give the track and surrounding area the same color. The contrast-based replacement for both controls remains open.
Recommendation. Keep open: work remains. Review the open unchecked-switch contrast fix.
Request. Adding an image changes a valid Claude slash command into an unexpanded literal prompt.
Audit finding. buildUserMessageEffect still puts text first and appends image blocks, matching the broken request shape isolated in the report. The newer generic-file support leaves this image ordering unchanged. The open patch moves command text last, but its fixture assertions are not proof that the real CLI expands the command.
Recommendation. Keep open: work remains. Verify #8271 against the real CLI with the same slash command with and without an image.
Request. Cursor connection fails when its ACP implementation lacks cursor/list_available_models.
Audit finding. discoverCursorModelsViaAcp still calls only the Cursor-specific list_available_models method after session start. It does not fall back to the model catalog already returned by session/new when that method is missing. The earlier executable-name fix does not address this protocol-version mismatch.
Recommendation. Keep open: work remains. Add a Method-not-found fallback to session/new model metadata and cover both Cursor catalog protocols.
Request. A linked and reachable environment can be absent from the mobile T3 Connect list.
Audit finding. Merged PR 7086 fixes mobile filtering that hid a cloud environment when the same backend was saved directly, which can explain an empty list after LAN pairing. The later discussion proves manual relay access works, but does not identify a native client build containing that fix or provide the account discovery response. The duplicate-tunnel, unknown-command, and disabled-control observations are separate and are not resolved by the list fix.
Recommendation. Keep open: retest. Retest a current native client against one server and capture the sanitized discovery result before and after client filtering.
Limits. The installed native mobile build and raw account discovery response are missing. CLI typo handling and the disabled administrative controls were not independently reproduced.
Request. Preview automation needs a cheap logs tool, successful network requests, exception stacks, and visible buffer truncation.
Audit finding. Diagnostics are still returned as part of a full snapshot. The manager records failed HTTP responses or failed requests, flattens exceptions, and silently bounds the arrays. There is no preview_logs operation or cursor and dropped-count contract, so none of the four requested additions is complete.
Recommendation. Keep open: work remains. Define and implement a bounded logs-only response with cursor, stack, successful-request, and truncation metadata.
Request. Android cannot start a new thread in a home-directory project because Send stays disabled.
Audit finding. Current Send gating requires a project, a model, text, and a branch only when worktree mode is selected. Home-directory paths are not directly rejected, but a non-Git project in worktree mode can never supply that branch. The report does not state its workspace mode, provider availability, or whether the folder is a repository, so that cause is not yet proved.
Recommendation. Keep open: evidence needed. Capture the selected workspace mode and model for the blocked home-directory draft on the current Android build.
Request. Copying a code block's final line can include Markdown fences.
Audit finding. The plain-code clipboard branch still requires the selection common ancestor to be inside pre. A range that crosses the final block boundary instead reaches the Markdown serializer and can regain fences. The previous partial-selection fix does not cover that boundary, and the specific follow-up proposal remains open.
Recommendation. Keep open: work remains. Treat a selection containing only a partial code block and its trailing boundary as plain code.
Request. A project created from iPad does not become a usable choice in the new-task picker.
Audit finding. AddProjectScreen still opens NewTaskDraft immediately after project.create succeeds, without waiting for the shell snapshot to include the new ID. NewTaskDraftScreen treats that missing ID as a reason to return to the picker whenever other projects exist. The later draft-submission navigation fix changes a different transition, and the shell projection path can still drop a project update after two failed reads.
Recommendation. Keep open: work remains. Wait for the newly created project to enter the shell state before opening its draft and preserve recovery if the update is missed.
Request. Codex cannot update or start reliably through T3's Windows provider controls.
Audit finding. The discussion identifies both a missing Windows optional binary package and standalone installations updated through the wrong npm path. Main still has no Codex native updater, and its npm command does not force optional dependency installation. A manual repair from one commenter is not a source fix for either reported update route.
Recommendation. Keep open: work remains. Cover missing Windows optional binaries when testing installation-aware Codex updates.
Request. The annotation draw tool repeatedly copies and scans the whole stroke, and can exceed the JavaScript argument limit.
Audit finding. Current pointermove handling still copies every point and rebuilds the whole path for every sample. strokeBounds still maps coordinates and passes unbounded arrays to Math.min and Math.max. The performance proposals are open, and the separate snapshot-freeze reports are not evidence that this draw defect has been fixed.
Recommendation. Keep open: work remains. Use incremental bounds and bounded stroke updates, then verify long-stroke cost.
Request. The triage workflow cannot reliably apply its label for contributors without repository label permission.
Audit finding. The playbook still instructs the agent to label the issue via-triage without checking label permission or verifying the result. Its fallback URL specifies title and body but not the issue-form template that declares the label. Direct issue creation and issue-form submission therefore still have different label behavior.
Recommendation. Keep open: work remains. Use the named issue form for the fallback and verify label success after any direct GitHub submission.
Request. Explicit client-local preview URLs are rejected when the environment connects through a public T3 Connect host.
Audit finding. The resolver still converts explicit loopback URLs into environment-port requests whenever the backend host is not loopback. It then rejects public relay hosts before Chromium can navigate. The address-bar fix does not cover this MCP path, and comments add a separate requirement for ports that are not forwarded to the client. Both URL preservation and an actual relay route remain unmerged.
Recommendation. Keep open: work remains. Preserve explicit client URLs and keep relay-only environment-port routing tracked as a separate requirement.
Request. Large Azure DevOps merged-PR responses are truncated and make the repository appear unavailable.
Audit finding. AzureDevOpsCli.execute does not pass an output budget, so VcsProcess still limits stdout to 1,000,000 bytes in truncate mode. The PR-list adapter decodes that output as one JSON document, and row pagination does not prevent a single page from exceeding the byte limit. The larger-output fix remains open.
Recommendation. Keep open: work remains. Give Azure PR list reads an explicit bounded budget or reduce payload size and test a response above 1 MB.
Request. Azure DevOps PR comments load as an empty truncated conversation because the REST request uses the wrong authentication resource.
Audit finding. The thread request still invokes az rest without --resource. The provider converts every thread-read failure into comments:[] and truncated:true, which produces the misleading most-recent-0 message. The Azure response and authentication fix remains open.
Recommendation. Keep open: work remains. Set the Azure DevOps resource for thread REST requests and distinguish load failures from a truncated conversation.
Request. The Tasks list should return when an active desktop turn resumes after an update relaunch.
Audit finding. Merged PR 8734 now derives composer progress from persisted plan activities instead of process-local planProgress. That fixes the common relaunch path, but thread hydration still limits activities to 500 without preserving an older active-turn plan. The pending recovery PR addresses this remaining case, so a full closure is not yet supported.
Request. A second thread sharing a workspace appears to take the first thread's live file changes while the first view stops updating.
Audit finding. The recent right-panel fix now refreshes from the active thread's mutation activities and checkpoint time. Working-tree review diffs still represent the shared checkout, not agent ownership, while provider ingestion keys activity by threadId. Those paths distinguish expected shared files from misrouted chat events, but do not prove the reported stream reassignment fixed.
Recommendation. Keep open: retest. Repeat the two-thread reproduction and record whether the misplaced data is a shared working-tree diff or a thread-scoped tool event.
Request. A Windows host still rejects the environment credential after unlinking and relinking on matching nightlies.
Audit finding. Successful tunnel registration does not verify the later credential exchange. The merged DPoP diagnostics now distinguish proof rejection causes, while the server-update authentication retry is limited to an update window and does not prove clean-relink recovery. This report needs the new failure category before it can be assigned to a specific credential fix.
Recommendation. Keep open: retest. Retest the clean relink on the latest build and attach the new credential failure category and trace ID.
Request. Long-running iOS threads can stop accepting taps on Send, Stop, thread navigation, and image-viewer controls.
Audit finding. Main now coalesces live tool updates, but the shared client still processes each incoming item separately. The discussion includes navigation and image-viewer failures as well as a delayed Stop action, so reduced event volume does not prove all of this behavior is fixed. The broader mobile/client fix remains open.
Recommendation. Keep open: retest. Run one integrated iOS long-thread test covering Send, Stop, thread switching, and image-viewer controls.
Request. A physical keyboard loses terminal input focus after Enter on Android.
Audit finding. Android currently consumes hardware Enter only on ACTION_DOWN and returns false for the matching ACTION_UP. Its ordinary key listener also rejects key-up events, leaving that event to the hidden EditText. This path has not received an Enter-focus fix since the Android implementation, but the reported focus transition still needs a device check.
Recommendation. Keep open: work remains. Check and consume the full hardware Enter sequence on Android while keeping terminal input focused.
Request. A browser at a self-hosted localhost origin cannot sign in to T3 Connect with the bundled production Clerk key.
Audit finding. The web entry point still mounts the configured Clerk provider on localhost without a hosted sign-in handoff or origin check. Managed relay authentication remains gated on Clerk isLoaded, which explains why those controls cannot start when Clerk rejects the origin. Desktop Clerk integration and local T3 pairing use different paths and do not fix this browser-only limitation.
Recommendation. Keep open: work remains. Add a supported hosted sign-in handoff for self-hosted browser clients or document that limitation in remote access setup.
Request. A newer server's Usage data is excluded while the client incorrectly blames an older server.
Audit finding. The reporter corrected the deployment claim: selecting Nightly in the hosted client fixed their version mismatch. Main now accepts a range of older compatible contracts, but still excludes versions above the client's expected version and labels every mismatch as an older server on web and mobile. The mismatch-direction fix remains open.
Recommendation. Keep open: work remains. Review the open change that distinguishes an outdated client from an outdated server.
Request. The Codex initialize response fails schema decoding on Windows before a turn starts.
Audit finding. The current initialize schema still requires codexHome, platformFamily, platformOs, and userAgent. The report omits the Codex CLI version and rejected response fields, so it cannot distinguish an old executable from another protocol mismatch. Later account-plan and multi-agent enum fixes do not establish an initialize-response repair.
Recommendation. Keep open: evidence needed. Collect the exact resolved Codex CLI version and a redacted initialize response.
Request. A parent directory pointing at a sibling-worktree bare layout is accepted as a normal project root.
Audit finding. detectRepository trusts isInsideWorkTree and returns --show-toplevel plus --git-common-dir without checking their layout. Thus the reported parent root is still accepted when Git reports it as a working tree. The dedicated bare-root rejection change is open.
Recommendation. Keep open: work remains. Reject this bare-root parent layout during project creation and direct the user to an individual worktree.
Request. Reopening and editing a custom theme can restore colors from its first save.
Audit finding. The current editor resolves the stored theme on each new session, and updateCustomTheme replaces the saved definition by ID. The recent theme changes do not provide a verified fix for the reported second-edit rollback. The report does not identify which color roles, appearance, or guided/advanced mode lose their edits.
Recommendation. Keep open: evidence needed. Request an exported theme and exact edit-save-reopen steps on the current stable version.
Request. Start from origin cannot create a worktree from a local branch with no origin tracking ref.
Audit finding. Bootstrap still checks only whether the origin remote exists, fetches it, and requires resolveRemoteTrackingCommit to succeed. The earlier no-origin fallback does not cover an existing remote with an unpushed base branch. One proposed fix was closed unmerged and the local-only-base replacement is still open.
Recommendation. Keep open: work remains. Fall back to the verified local base when its origin tracking ref does not exist, without hiding fetch or permission failures.
Request. The native Android app clips text and mis-sizes content on DeX and external desktop displays.
Audit finding. The SDK 57 upgrade now includes react-native-screens 4.26.2, whose frame conversion uses the view display density. React Native 0.86.3 now preserves scaled font metrics, but its PixelUtil still uses global screen density for DP conversions and no app density correction is wired. The screen-frame correction is present, but the reported external-display text failure still needs a rebuilt-client check.
Recommendation. Keep open: partial fix. Correct React Native density for the active Android window and retest the DeX and Pixel external-display cases.
Request. The report titled java issues does not describe a T3 Code defect.
Audit finding. All four inspected attachments are the same Java mascot illustration, not application screenshots or error output. The body supplies no steps, expected behavior, actual failure, version, or environment beyond those images. There is no product path to diagnose or fix.
Recommendation. Keep open: evidence needed. Ask the reporter for an actual T3 Code failure with steps and error text.
Request. Windows Smart App Control can block unsigned native addons and crash-loop the packaged backend.
Audit finding. The signed Windows build still configures Azure signing without adding .node and .dll to signExts. The native-addon signing proposal remains open. The discussion reproduces the block in both app.asar and server.asar layouts, so packaging size changes do not establish a fix or a clean version boundary.
Recommendation. Keep open: work remains. Sign unpacked Windows native addons and verify the packaged build under Smart App Control enforcement.
Request. A turn that switches branches shows the previous branch's content as deletions in the new branch diff.
Audit finding. The latest-turn view still compares the previous checkpoint with the new checkpoint, without storing or consulting the branch transition. GitVcsDriver then diffs those two complete trees, so branch-A-only content necessarily appears deleted after switching to branch B. No branch-switch baseline policy or focused coverage is present in this path.
Recommendation. Keep open: work remains. Add branch-switch-aware turn baselines and test a turn that checks out B after edits on A.
Request. An unpushed feature branch tracking a non-default base inherits that base branch's PR.
Audit finding. resolveBranchHeadContext still prefers the upstream ref name as the PR head. The cache rejects that substitution only when the upstream is the default branch, so a feature branch tracking dev still queries dev PRs. The non-default-base fix is open.
Recommendation. Keep open: work remains. Use the actual feature branch as the PR head unless a distinct published-head mapping is verified.
Request. The macOS desktop becomes unresponsive and reports crashes with several concurrent agents.
Audit finding. The report has no crash stack, exact app build, or identification of the process that died. DesktopBackendManager supervises a separate child, so a surviving window is consistent with a backend failure and does not establish the preview main-process crash reported elsewhere. Recent memory changes cannot identify or prove a fix for this incident without that process evidence.
Recommendation. Keep open: evidence needed. Attach the macOS crash report and backend log covering one multi-agent failure.
Request. Files listed through a symlink outside the project cannot be opened or reviewed.
Audit finding. WorkspaceFileSystem resolves both root and target with realpath and rejects a target outside the canonical root. Discussion confirms that the index can nevertheless list those external files, so this is a listing/read-policy mismatch rather than an iCloud-only defect. Supporting explicitly authorized targets or filtering them from the tree needs a deliberate access decision.
Recommendation. Keep open: decision needed. Choose explicit authorization for external symlink targets or hide them with a clear explanation in the Files tree.
Request. Automatically settled threads should return to the top when new activity wakes them.
Audit finding. The server now persists inactivity and pull-request settlement through thread.auto-settle instead of leaving it as client-only display state. That state uses the existing activity wake event, whose projector stamps unsettledAt, and both web and mobile sort by that stamp. The server-side settlement merge is on main but is not in the inspected stable or nightly releases.
Recommendation. Close: fixed. Close as fixed on main and note that the server-side settlement change is not yet released.
Independent closure check. The report specifically identifies client-derived auto-settlement as the missing reason for a wake timestamp. Pinned main now dispatches thread.auto-settle from the environment server for inactivity and pull-request rules. That command produces the normal persisted settled state. New activity emits thread.unsettled, both projectors stamp unsettledAt, and web/mobile use the shared max(createdAt,unsettledAt) sort key. Ordinary active-thread activity still does not move the row. The server change is in main only, after the latest collected nightly.
Request. A relative file chip with a subdirectory opens against the project root instead of the agent's nested working directory.
Audit finding. The index fallback runs only for bare basenames. Paths containing a slash go straight to openFileInPanel, so docs/X.md is tried at the project root even when the only matching file is in a nested agent directory. This is an in-workspace resolution problem, not a request to bypass the workspace boundary.
Recommendation. Keep open: work remains. Resolve missing slashed paths against unambiguous workspace-index matches while preserving an exact root-relative match.
Request. FUTO Keyboard deletion does not reliably reach the Android terminal.
Audit finding. The Android terminal uses a hidden EditText, forwards added text and KEYCODE_DEL, then clears its editable buffer. Deletion-only TextWatcher updates are ignored, and there is no custom InputConnection bridge for IME deletion operations. Samsung key-event behavior therefore does not prove FUTO composition deletion works.
Recommendation. Keep open: work remains. Add an Android IME deletion path and test it with FUTO on the reported phone setup.
Request. The client overlay timeout expires after the broker can accept its useful error response.
Audit finding. requireReadyTab still passes request.timeoutMs unchanged to the overlay wait. The broker starts its own timeout before client work, then removes the pending response, so the overlay failure arrives too late. The client also serializes overlay failures as a generic timeout type. The specific deadline fix remains open.
Recommendation. Keep open: work remains. Give overlay readiness a shorter budget and preserve its error type before the broker deadline.
Request. Switching compatible Codex instances starts a second writer before releasing the first.
Audit finding. ProviderService still starts the target adapter before stopStaleSessionsForThread. The session runtime still permits recoverable resume failures to fall back to a new thread, so a safe handoff needs more than reversing two calls. The single-writer change and its failure-path work remain open.
Recommendation. Keep open: work remains. Finish the single-writer handoff with verified source release and strict same-thread resume.
Request. A thread with a removed worktree cannot resume when its branch is already checked out in another location.
Audit finding. The merged recovery path prunes and recreates a missing worktree at its saved path. It does not find an existing checkout of the branch or move the thread to it, and a creation failure only logs a warning before the turn continues with the stale path. The requested branch-in-another-checkout case remains unsupported.
Recommendation. Keep open: partial fix. Handle an existing checkout of the saved branch during missing-worktree recovery and update the thread path before starting the provider.
Request. The thread PR sidebar fails to show an open PR that exists for the current work.
Audit finding. The sidebar still requires live checkout refName to match the saved thread branch before it shows an automatically detected open PR. Explicit linking is now available, but it does not prove automatic detection fixed. The report does not supply those branch values, remote identity, or the server PR result, and its proposed checkout-PR fix was closed unmerged.
Recommendation. Keep open: evidence needed. Capture the saved thread branch, live vcs status response, and PR head repository for one failing thread on current main.
Request. Remote editor links target an SSH host but cannot enter the Docker container that owns the project.
Audit finding. The shared remote-open contract describes only an SSH host and path, and buildRemoteOpenUrl always emits ssh-remote links. resolveRemoteOpenState prefers an SSH alias without any container identity or second-hop information. This cannot represent the reported VM-plus-docker-exec route, and the later editor changes do not add that topology.
Recommendation. Keep open: work remains. Add a container-aware remote-open target or show that the current SSH-only route is unsupported.
Request. A macOS Homebrew Claude update waits over two minutes and then leaves an outdated-provider warning.
Audit finding. The stale warning is explained by main still comparing a Homebrew install with npm latest. The update runner separately waits up to five minutes, shares a Homebrew lock, and always calls child.kill in its finalizer, so the version-source fix does not establish that the long update wait is fixed. The author explicitly separates this macOS case from the Linux path-classification report in comments.
Recommendation. Keep open: work remains. Record one current no-op Homebrew update through command exit, finalizer completion, and provider refresh.
Request. Sending a Grok follow-up during a turn queues another ACP prompt instead of interrupting current work.
Audit finding. Grok sendTurn still reuses the active turn when promptsInFlight is nonzero and sends another session/prompt without cancelling the first. #8358 changed liveness and error handling but left this steering behavior intact. The cancel-and-resend implementation is still open.
Recommendation. Keep open: work remains. Review #8286 with a long tool call and a mid-turn follow-up.
Request. Accepting a slash-menu skill inserts a dollar mention that cannot invoke a user-only Claude skill.
Audit finding. The shared web menu handler still inserts $name for every skill entry regardless of the trigger. Recent filtering and deduplication do not change that insertion or expose Claude's invocation flags. Discussion confirms the claimed repair is on an open branch, not in main.
Recommendation. Keep open: work remains. Review the open invocation-aware insertion fix for web and mobile.
Request. WSL cannot start with Windows-drive automount disabled, and fallback status is misleading.
Audit finding. Merged PR 5769 adds a Linux runtime cache, but prepareWslRuntimeImpl still translates the Windows archive path before it can use that cache. If automount is disabled, that translation fails and the mounted-tree fallback repeats the same failure. The nonfatal retry classification and primary-only error dialog remain, and the picker still reads the in-memory disabled state.
Recommendation. Keep open: work remains. Remove the Windows-mount requirement from runtime staging and show secondary-backend preflight failures.
Request. Windows relay installation rejects a valid cloudflared binary during version validation.
Audit finding. The installer still validates the staged executable with --version and treats a nonzero exit as validation_failed before activation. That is the exact command the report shows failing while the version subcommand succeeds. Relay retry backoff addresses a later running-child failure and does not change installation validation.
Recommendation. Keep open: work remains. Accept the supported cloudflared version command on Windows and test failure cleanup before activation.
Request. Windows Codex Computer Use fails before app approval because its configured native pipe is unavailable.
Audit finding. Main starts the Codex app server with supplied or inherited environment and does not provision a Windows pipe. The new issue comment reports full Computer Use success after removing stale Desktop pipe overrides with a newer sky package, so a bridge is not yet proved necessary for every setup. The app-access approval fix concerns a later step, and the proposed native bridge is still open.
Recommendation. Keep open: retest. Retest a new Windows Codex session without stale native-pipe overrides before choosing the full bridge.
Request. HTTP turn dispatch accepts bootstrap metadata but does not run the WebSocket bootstrap flow.
Audit finding. The HTTP dispatch handler still normalizes the shared client command and sends it directly to the engine. Bootstrap creation and worktree preparation remain in the WebSocket path, so a fresh thread can reach the engine without creation and fail as an internal error. The typed HTTP rejection change is still open.
Recommendation. Keep open: work remains. Review the open transport-specific HTTP bootstrap validation fix.
Request. A mid-turn SIGKILL needs an identifiable runtime termination record and a confirmed cause.
Audit finding. T3 intentionally closes idle sessions, but the reaper skips active turns and background work and logs an inactivity reason. Claude SDK query.close can escalate termination to SIGKILL, while the resulting session.exited event only says Session stopped with a graceful exit kind. These paths explain possible runtime termination but do not prove what killed the reported process or provide a distinct origin for every stop.
Recommendation. Keep open: evidence needed. Capture a current reproduction with session-stop spans and provider exit records to identify the termination caller.
Request. An expired relay DPoP token leaves HTTP calls failing while the WebSocket remains connected, and session probes mislabel it as denied access.
Audit finding. getSessionState still maps credential errors to authenticated:false under a success response. PR diff HTTP requests still use the token captured in PreparedConnection, while expiry is checked when authorizing a connection rather than before each HTTP request. Discussion confirms the same expired-token failure on the Code tab, so changing only the session response would leave a material part of this issue open.
Recommendation. Keep open: work remains. Refresh near-expiry DPoP authorization before HTTP requests, retry one invalid-credential response, and distinguish expired credentials from an absent session.
Request. Bitbucket write actions fail when the removed repository-permissions endpoint returns 404 rather than 410.
Audit finding. The current removal predicate still accepts only HTTP 410, and getRepositoryPermission still calls the removed user/permissions/repositories endpoint. getViewerPermissions propagates a 404 into both merge and comment preflight, so working read credentials do not repair this path. Both the 404 fallback and workspace-endpoint replacement are still open.
Recommendation. Keep open: work remains. Choose and complete one Bitbucket permission fix that covers both merge and comments on accounts returning 404.
Request. Pasting decorators such as @foo(bar) turns them into invalid file mentions.
Audit finding. The paste plugin appends a virtual newline and feeds plain clipboard text into the generic mention parser. That parser accepts an unquoted at-token containing parentheses, so the plugin creates a mention node for the decorator. Scoped-package exclusions do not cover this syntax, and the decorator-specific proposal is still open.
Recommendation. Keep open: work remains. Keep unstructured pasted at-tokens as text unless they carry an explicit file-mention representation.
Request. Preview webview and CDP lifecycle work can abort the macOS Electron main process.
Audit finding. Current registration has tab and guest identity checks, but it still starts control-session restoration with runFork and calls debugger.attach during that work. The later comment identifies a separate native DevTools notification SIGSEGV, so an attach-only guard would not prove the full report fixed. Main also upgraded Electron to 43.4.1, which needs a current lifecycle stress test rather than a closure based on the version change.
Recommendation. Keep open: retest. Retest background preview open, redirect, close, and teardown on Electron 43.4.1 with native crash capture.
Request. Using T3 Code on Windows appears to hydrate unrelated OneDrive files.
Audit finding. The file finder is created with a specific basePath and separates path indexing from content indexing. Its home/root options permit those roots as selected workspaces, but do not by themselves prove an unrelated OneDrive directory was scanned. The report does not identify the process or file-open operation, so an app indexer, provider child, or selected parent folder cannot yet be separated.
Recommendation. Keep open: evidence needed. Capture a Windows file-access trace with process IDs and the affected OneDrive paths while reproducing the downloads.
Request. A surviving encrypted connection catalog blocks all targets after the Windows Electron encryption key is replaced.
Audit finding. Catalog get still maps decryptString failure to DesktopConnectionCatalogStoreProtectionError with no empty-catalog recovery. Atomic file replacement protects new writes but does not repair an orphaned encryption key. The targeted recovery PR remains open.
Recommendation. Keep open: work remains. Review the obsolete-key recovery change without treating unrelated catalog write fixes as sufficient.
Request. Linux service updates retain every completed runtime and use increasing disk space.
Audit finding. installPinnedRuntime still removes only an incomplete target and its temporary staging directory. The service CLI has install, uninstall, update, and status commands but no prune command. WSL runtime-cache cleanup is a different desktop path, and the service pruning PR remains open.
Recommendation. Keep open: work remains. Review the service runtime-pruning command with its active and rollback version protections.
Request. Opening a large source file can stall the renderer during syntax highlighting.
Audit finding. ChatView already has a worker pool, so the report is not explained by a missing provider wrapper. The editable File path still creates an Editor for the full contents, and the library also initializes an editor tokenizer on the renderer thread. The shared highlighter still selects the JavaScript engine and there is no application-level large-file fallback. The WASM-engine proposal remains open.
Recommendation. Keep open: work remains. Profile the reported Go file on current main and verify the editable tokenizer and worker paths separately.
Request. Windows remote-terminal selection copy and OSC 52 copy fail while chat copy works.
Audit finding. The generic terminal-selection repair already landed before the reported v0.0.34, so it is not proof that this Windows failure is resolved. Desktop still installs Electron's default Edit menu, while the pending Windows fix changes that shortcut path. The Ghostty embedder also has no OSC 52 clipboard callback, which is a separate unmet part of this report.
Recommendation. Keep open: work remains. Verify Windows selection copy separately from OSC 52 and keep the report open until both paths are handled.
Request. Three temporary Linux screenshot attachments can become unreadable before a message is sent.
Audit finding. Main now starts uploads as attachments enter the composer, sends persisted attachment references, and reports failed uploads before dispatch. The focused queue test covers immediate upload, and this change is in v0.0.37. The report names main without a commit, so the KDE temporary-file failure still needs a fresh check with attachmentUploads enabled rather than assuming every path used the new flow.
Recommendation. Keep open: retest. Repeat the three-Spectacle-image reproduction on a matched v0.0.37 client/server and capture each upload result before Send.
Request. Grok threads do not emit live context usage for the composer meter.
Audit finding.PR 8358 added historical usage records, but GrokAdapter still does not emit thread.token-usage.updated and the shared ACP event model does not retain a usage snapshot for this path. The existing context meter cannot receive used and maximum token values without that provider event. The older meter implementation remains open and needs integration with the newer Grok structure.
Recommendation. Keep open: work remains. Port PR 5405 onto current Grok code and test live usage, model capacity, and interrupted-turn preservation.
Request. A server bound to all interfaces advertises an unreachable container IP in its pairing link.
Audit finding. Startup still replaces a wildcard bind address with the first noninternal network interface, which can be a Docker-only address. The reported failure is real for that topology, but 0.0.0.0 is also a bind address rather than a generally reachable address for remote clients. The open proposal changes that choice, so the advertised-origin rule needs a decision that covers containers and remote pairing.
Recommendation. Keep open: decision needed. Define an explicit advertised-origin override and use it for pairing links without changing the bind address.
Request. OpenCode provider discovery fails when parallel CLI inventory commands contend on OpenCode SQLite state.
Audit finding. The reporter withdrew the original models --json diagnosis, and a later comment reproduced a database lock by running the inventory commands together. The merged catalog change replaces those production CLI calls with provider.list, app.agents, and app.skills on a managed OpenCode server. The current provider test covers that HTTP discovery path, and the merge is an ancestor of stable v0.0.36 and v0.0.37.
Recommendation. Close: fixed. Close as fixed by the HTTP inventory change released in v0.0.36.
Merged pr: PR #8480. Merged replacement of production CLI catalog discovery.
Independent closure check. The full issue discussion corrects the unsupported-flag theory and identifies concurrent inventory subprocesses as the reproducible failure. Pinned main uses one managed server and HTTP inventory for local discovery, and HTTP inventory for configured servers. The old CLI loader has no production caller. Merged 8480 is an ancestor of stable 0.0.36 and 0.0.37, and no later comment reports failure after that replacement.
Request. OpenCode threads routed through OpenRouter show no context-window meter.
Audit finding. The current OpenCode adapter emits no thread.token-usage.updated event for any upstream provider. Its assistant message handler tracks role and text but does not forward token counts or the model context limit, which the shared ingestion path needs for the meter. This gap is wider than OpenRouter and is not fixed by model catalog discovery.
Recommendation. Keep open: work remains. Emit normalized OpenCode context usage with the active model context limit.
Request. User messages with nonsequential numbered lines render as a consecutive Markdown list.
Audit finding. User text still passes through ChatMarkdown. Its ordered-list renderer preserves only the list's initial start value, and list items do not restore each typed marker value, so later numbers are renumbered by HTML list rendering. The number-preservation change remains open.
Recommendation. Keep open: work remains. Review the open typed-list-number preservation fix.
Request. Selecting a 200k Claude context window does not disable the CLI default 1M window.
Audit finding. resolveClaudeApiModelId still represents 200k only by omitting the [1m] suffix, and session options do not set CLAUDE_CODE_DISABLE_1M_CONTEXT. The reactor already restarts Claude sessions for model-option changes, so that path must be verified rather than assumed missing. The actual 200k opt-out change remains open.
Recommendation. Keep open: work remains. Review #8409 using SDK-reported context windows when switching 200k to 1M and back.
Request. Preview discovery sends HTTP and HTTPS requests to unrelated local binary-protocol listeners.
Audit finding. PortScanner still enumerates all listeners and adds HTTP and HTTPS candidates for every discovered server. Terminal ownership is metadata, not an eligibility check before the GET request. The specific restriction proposal remains open, and the earlier browser-ready filtering change introduced this probe behavior rather than fixing it.
Recommendation. Keep open: work remains. Restrict active HTTP probes to eligible managed or explicitly configured preview listeners.
Request. Project browsing and path completion omit symbolic links to directories.
Audit finding. WorkspaceEntries.browse still accepts only dirent.isDirectory, which is false for a symbolic link. Both client entry points use that same browse RPC, so the defect applies to local and SSH environments. The earlier discussion and closed proposal are not a landed fix, and the focused symlink PR is open.
Recommendation. Keep open: work remains. Follow directory-link targets during browse while retaining the entered link path and excluding broken links.
Request. Turning Advanced colors off changes the default theme even when no color was edited.
Audit finding. handleAdvancedChange still marks each saved appearance dirty and calls getManagedEditorColors whenever Advanced turns off. It does not check whether any color changed. The same handler serves the editor opened by the command palette or keybinding, and its preservation fix is still open.
Recommendation. Keep open: work remains. Review the toggle-only palette preservation fix.
Request. Render LaTeX formulas in web and desktop chat without changing currency, code, or copied source.
Audit finding. Both chat Markdown plugin lists still omit math parsing and KaTeX rendering. The original proposed implementation was closed without merging, and a newer math-rendering proposal remains open. Neither proposal is a source fix on main.
Recommendation. Keep open: work remains. Review the current math-rendering proposal against the issue's delimiter, copy, and malformed-input requirements.
Request. Integrated terminal shells have no T3-specific TERM_PROGRAM or TERM_PROGRAM_VERSION.
Audit finding. createTerminalSpawnEnv copies inherited variables and caller overrides but sets no terminal identity. Neither PTY adapter adds TERM_PROGRAM or TERM_PROGRAM_VERSION. The pending truecolor change concerns COLORTERM and does not supply the requested identity.
Recommendation. Keep open: work remains. Add T3 terminal identity variables at the shared PTY environment boundary.
Request. Stopping a Grok turn can leave the old prompt running while the new prompt waits.
Audit finding. Current Grok interruption marks the interrupted turn before locking, sends ACP cancel, and settles every prompt slot so late responses cannot revive the turn. PR 8358 added substantial settlement protection, but cancellation errors are still ignored and the same ACP session can be reused. The report gives no T3 or Grok version, so it is not clear whether it exercises these current safeguards or a distinct MCP command path.
Recommendation. Keep open: retest. Reproduce stop followed by a new prompt on current Grok while recording the exact T3 MCP stop command and ACP cancel result.
Request. Closing an edited file tab can overwrite newer server-side file contents with an already-saved stale buffer.
Audit finding. FileSaveCoordinator.dispose still saves whenever latestRevision is greater than zero. Successful saves clear the pending indicator but do not clear that revision or record a saved revision, so closing the tab repeats the old write. The recent file-refresh work does not remove this write path, and both targeted fixes remain open.
Recommendation. Keep open: work remains. Track successfully saved revisions and flush only unsaved edits when the editor is disposed.
Request. A failed first service install leaves an enabled but inactive unit that future install commands consider complete.
Audit finding. Fresh activation failure still takes the Effect.void recovery branch after the unit and runtime state have been written. Status checks files and versions but not whether systemd is active, and reconcileService returns early when those files look current. The rollback proposal is open, so the exact dead-unit recovery defect remains.
Recommendation. Keep open: work remains. Roll back a failed fresh service activation so the next install can repair it.
Request. Active Codex children do not appear in the Agents panel.
Audit finding. The reported commit already includes the 0.150 multi-agent enum fix, so that merge cannot be treated as a later repair. Main creates Agents state from native child registration events, and receiver-only children still have a separate gap. The attached logs show desktop startup and update polling, not the child notifications needed to identify which path failed.
Recommendation. Keep open: evidence needed. Capture child registration notifications from the affected Codex version and check whether they are receiver-only spawns.
Request. Windows users see empty review and last-turn diff views after agent edits.
Audit finding. ReviewService still allows only the server configured cwd and its worktree root, not every registered project root, so a valid checkout elsewhere can fail before Git runs. The dedicated project-root fix is still open. Last-turn diffs use the separate checkpoint query path, so this one restriction does not yet explain every empty tab in the report.
Recommendation. Keep open: work remains. Correct review validation for registered projects and verify both working-tree and checkpoint diffs in the reported Windows layout.
Request. Provider settings should prioritize models and status over the Configuration form.
Audit finding.PR 8504 improves list status text and the editor header, but ProviderInstanceCard still defaults to configuration and the desktop grid still reserves 20rem for the list. It also puts Configuration first in the tab order, so the requested default hierarchy has not changed. The remaining request is a UI priority choice, with an open PR for a Models default.
Recommendation. Keep open: decision needed. Decide whether Models or the last-used tab should be the default, then review PR 8543 against that choice.
Request. Ctrl+Insert does not copy terminal selections on Linux and Windows.
Audit finding. isTerminalCopyShortcut still rejects every key except C, while paste has a separate Insert branch. The merged Shift+Insert change therefore does not cover the missing copy chord. Both Ctrl+Insert proposals remain open.
Recommendation. Keep open: work remains. Review the focused Ctrl+Insert fix and reconcile it with the broader Linux clipboard proposal.
Request. Add author headings so screen reader users can navigate between chat messages.
Audit finding. Timeline message rows remain div elements with data attributes, and assistant content is rendered directly through ChatMarkdown without an author heading. The existing visual minimap does not add those semantics. The heading implementation is still open and must also keep Markdown heading levels below the message heading.
Recommendation. Keep open: work remains. Review the open message-heading change with screen reader navigation and nested Markdown headings.
Request. Provide read-only CLI commands for canonical thread export and filtered history search.
Audit finding. The CLI command registry has no history, search, or conversation export command. A supported HTTP thread-snapshot route exists, but it is not the requested canonical export and cross-project search interface. This needs a CLI and export-contract decision, not closure based on existing internal reads.
Recommendation. Keep open: decision needed. Define the read-only CLI search filters and canonical export schema.
Request. Returning to a macOS terminal sometimes sends raw mouse-report sequences to the shell.
Audit finding. The prior history fix strips queries and responses, not mouse-mode setters, and the renderer still sends mouse reports when mode 1003 is active. The reporter says this happens with plain zsh and no mouse-aware TUI, so the mode transition causing the failure is not established. Mouse-motion deduplication and query filtering do not prove this newer report fixed.
Recommendation. Keep open: evidence needed. Capture a minimal sanitized PTY stream around the thread switch to find when mouse tracking becomes enabled.
Request. Auth-like files outside the exact private-name list are linked into Codex shadow homes.
Audit finding. The private-entry set still contains only auth.json and models_cache.json. Materialization links other shared entries, so the fixture filenames in the report still pass into another account's shadow home. This confirms the filesystem-isolation gap without claiming Codex consumes those files.
Recommendation. Keep open: work remains. Extend private-entry classification and reject existing auth-like shadow symlinks.
Request. Git diff prefix settings produce empty file names and unusable headers in review patches.
Audit finding. Review and checkpoint patch commands still inherit Git prefix configuration and do not force standard a/ and b/ prefixes. The installed Pierre parser still requires those prefixes for Git filenames, matching the reported empty-name path. The dedicated prefix-normalization fix is open.
Recommendation. Keep open: work remains. Force standard source and destination prefixes on every patch-producing review and checkpoint command.
Request. Cumulative Claude session usage can overwrite the active-context meter at turn completion.
Audit finding.#8610 removed getContextUsage and now prefers the last assistant request usage, and that fix is in v0.0.37. The reporter saw no saturated meters in 298 events after upgrading. Main still prefers cumulative result usage over lastKnownTokenUsage when no assistant snapshot exists, so the residual described in both follow-up comments remains open.
Recommendation. Keep open: partial fix. Check #8617 with parent message_delta usage and result-only turns before closing the residual.
Request. An old Codex CLI cannot read service-tier values written by a newer Codex client.
Audit finding. The screenshot is a Codex config-reload error, not a T3 enum rejection. Main accepts serviceTier as a string and builds tier choices from the provider's model catalog. The reporter found an old CLI and then upgraded it, but did not confirm that provider startup succeeded afterward; clearer version diagnostics remain open.
Recommendation. Keep open: retest. Ask the reporter to confirm provider startup after the CLI upgrade already reported.
Request. Remote Stop has no pending feedback and can leave a thread showing Thinking after interruption.
Audit finding. Claude Stop now closes its query through session teardown, so the report describes an older Claude path, but that fix does not cover every provider. Web Stop still has no pending stopping state, and an interrupt event without turnId still leaves the turn projection unchanged. Generic recovery still stops the session only when interrupt fails, not when it succeeds without a terminal state.
Recommendation. Keep open: partial fix. Complete the web and mobile stopping state and provider-independent terminal recovery, including missing turn IDs.
Request. External Chrome aborts when a Codex-sandboxed helper launches it on macOS.
Audit finding. T3 supplies the workspace-write policy to Codex and recommends its preview tools when they are attached. It does not broker external Chrome launches or detect this macOS registration failure in the provider path. The matching Codex sandbox issue remains open, so maintainers must choose whether T3 should add a diagnostic or a brokered launch path.
Recommendation. Keep open: decision needed. Choose the T3 mitigation for sandboxed external-browser launches while keeping the upstream defect linked.
Request. Long project names make the searchable project popup overflow its sidebar width.
Audit finding. The attached screenshot shows the popup's inner content wider than its anchored shell. The merged containment fix adds min-w-0 and overflow-hidden to both the project popup shell and the shared inner combobox, while project labels already truncate. This source fix matches the pictured defect and is included in v0.0.37.
Recommendation. Close: fixed. Close as fixed in v0.0.37.
Independent closure check. I read the full report and viewed its image. The project name, selected row, gear, and search underline extend beyond the popup background, which is the exact intrinsic-width overflow fixed by merged 8627. Pinned main makes both the outer project popup and inner flex item shrink and clip overflow, while labels already truncate. There is no later discussion or separate failure scope. The fix is in stable 0.0.37.
Request. A visible PR detail panel can stay stale after automatic refresh, requiring a manual refresh to show new host data.
Audit finding. The reported commit predates the merged change that removed stale-while-revalidate for detail and activity reads, so an expired detail cache now waits for fresh data. The client still polls every five minutes and stops after six minutes without input, which leaves later passive CI monitoring outside that fix. The first-poll cache defect is addressed, but continuous visible-panel monitoring is not.
Recommendation. Keep open: partial fix. Decide whether a visible PR panel should keep polling after six idle minutes and verify the full passive-monitoring flow.
Request. The desktop backend still reaches the V8 heap limit after many idle hours on a large profile.
Audit finding. This report already contains the 500-activity and 1000-event bounds and records an abort with no new orchestration events. New nightly work batches client snapshot payloads and bounds retained raw provider messages, but neither supplies a causal explanation or idle-soak result for this profile. The raw full-snapshot reader also remains, although ordinary routes no longer use it, so its presence alone is not proof of the crash cause.
Recommendation. Keep open: retest. Run a 24-hour idle soak with the affected profile and capture backend heap growth.
Request. Allow project creation inside the new-thread project picker and continue into that project's draft.
Audit finding. The new-thread submenu is still built only from existing project actions. Add project remains a separate top-level command, so the nested flow has no create row or cancel/back path that preserves the pending new-thread selection. Recent project location and icon changes do not add this flow.
Recommendation. Keep open: work remains. Add the existing project-creation flow to the new-thread picker with a return path on cancel.
Request. The GitHub clone step should search accessible repositories by name while retaining manual URL entry.
Audit finding. The current clone flow reads one typed repository string and calls lookupRepository. Contracts and the repository service expose exact lookup, clone, and publish operations, with no account repository search or paged result selection. The requested authenticated search is not implemented by the recent HTTPS-clone default change.
Recommendation. Keep open: work remains. Add bounded GitHub repository search to the clone step with a result picker and manual URL fallback.
Request. Users want an optional cross-provider backup model for automatic thread titles.
Audit finding. The settings contract still contains a single textGenerationModelSelection and no independently configured backup. PR 8087 retries the same model, while the disabled-provider fallback chooses from existing defaults before an attempt rather than trying a user-selected backup after failure. This request adds a policy choice beyond the health and error-reporting bugs in issue 5359.
Recommendation. Keep open: decision needed. Decide the backup provider and instance rules before adding one optional title-generation retry target.
Request. T3 does not expose the host tool needed by Codex bundled artifact skills.
Audit finding. Thread start still registers no dynamicTools, and the runtime has no workspace-dependency loader handler. Unknown server requests return method not found. Rendering artifact links is separate from providing the runtime loader, so recent artifact display changes do not meet the requested fresh and resumed thread behavior.
Recommendation. Keep open: work remains. Implement and test host registration and handling for the workspace-dependency loader.
Request. The environment version pill can overflow the sidebar at its minimum width.
Audit finding. The current header still gives the brand shrink-0 and appends the environment Badge without a width bound or truncation rule. The referenced narrow-sidebar fix is still open, and the earlier wordmark fix does not constrain the later pill. The reported layout path therefore remains in source.
Recommendation. Keep open: work remains. Review the narrow-sidebar pill fix at the minimum supported sidebar width.
Request. The Files panel omits unignored dotfiles and dot-directories in non-Git projects.
Audit finding. Files listing still delegates to the native finder with no non-Git dot-entry fallback or include-hidden option. The separate path browser's dot-directory support does not feed the Files tree, and the proposed non-Git listing fix is open. The report's git check-ignore hypothesis is not the listing call path shown by current source.
Recommendation. Keep open: work remains. Handle non-Git dot entries in the workspace index and verify the minimal hidden-file and hidden-directory fixture.
Limits. The native finder was not rerun against the attached minimal fixture. An older related reference could not be retrieved from GitHub. It is excluded from verified dependencies and fix evidence.
Request. The Linux AppImage does not use embedded bitmap strikes for fonts such as Terminus.
Audit finding. Desktop startup still has no FontDataServiceLinux FreeType selection or Fontations override. The recent Electron 43 upgrade changes Chromium, but neither its diff nor the current startup code verifies the requested 16px bitmap rendering. The supplied pixel-mask evidence needs a check against the newer packaged runtime.
Recommendation. Keep open: work remains. Compare Terminus at 16px in the Electron 43 AppImage with the explicit FreeType launch flags.
Request. Linux window controls should follow the system button layout and placement.
Audit finding. Merged PR 8626 upgrades T3 to Electron 43.4.1, which includes upstream support for system-configured Linux Window Controls Overlay buttons. T3 still uses that native overlay rather than drawing fixed buttons itself. The change is in nightly but not v0.0.37, and a GNOME layout check is needed before closure.
Recommendation. Keep open: retest. Retest left-side and close-only GNOME controls on the latest Electron 43 nightly.
Request. A hanging OpenCode version wrapper leaves discovery blocked and CPU-heavy descendants alive.
Audit finding. The local --version probe still has no timeout. runOpenCodeCommand waits on the child exit and output streams without a detached probe group or descendant cleanup. The five-second HTTP health timeout added with the catalog change applies after this probe and cannot bound it.
Recommendation. Keep open: work remains. Review PR #8750 for the version timeout and full probe-process cleanup.
Request. On iOS 27 the composer can stay above the bottom of the screen after the keyboard closes.
Audit finding. The report concerns retained keyboard height after send, not the visible-keyboard hydration failure in the older report. Main now has a newer native keyboard stack, but its stale-state quarantine remains Android-only and iOS keeps the sticky view enabled throughout keyboard transitions. Without the app build and keyboard geometry, those changes are not proof that this iOS symptom is gone.
Recommendation. Keep open: retest. Retest send and scroll on the current native iOS build while capturing keyboard visibility and sticky-view height.
Request. Ghostty receives a 10,000-byte scrollback budget where T3 intends 10,000 rows.
Audit finding. Web and Android still pass 10,000 through the ambiguous max_scrollback field at the unchanged Ghostty pin. A read-only run of main's shipped WASM retained 800 rows at 80 columns, 447 at 160 columns, and 151 at 320 columns after 12,000 numbered lines. Both the byte-budget mitigation and the explicit line/byte ABI upgrade remain open.
Recommendation. Keep open: work remains. Review the mitigation and ABI upgrade as separate changes while retaining coverage for wide terminals.
Request. Wide Markdown tables overflow the chat lane without a clear horizontal scrolling affordance.
Audit finding. The merged table change removes hideScrollbars, so the shared horizontal scrollbar appears on hover or scroll. Expanded tables still keep min-width: max-content, nonwrapping headers, and the measured header-width floor, so Word wrap still does not make them fit the chat lane. The scrollbar improvement is in the inspected nightly release, not v0.0.37.
Recommendation. Keep open: partial fix. Verify whether the hover scrollbar meets the request or keep the remaining fit-to-lane behavior as the issue's scope.
Request. Mobile needs editable voice input on iOS and Android with selectable transcription services.
Audit finding. Merged offline dictation now inserts editable text on supported iOS 26 iPhones. Other platforms still return no local transcriber, and the requested OpenAI/Groq device-key settings do not exist. Current architecture instead assigns remote transcription credentials to the environment, with that mobile implementation still open.
Recommendation. Keep open: partial fix. Confirm Android, older-iOS, and provider coverage in the environment-backed mobile transcription work.
Request. A workflow coordinator still running between phases is excluded from all live-agent counts.
Audit finding. deriveAgentPanelModel still skips a workflow whenever it has any members, even if all members are settled and the coordinator is running. That leaves runningCount and liveCount at zero during a phase gap. Discussion correctly narrows the fix to live coordinators with no live members so finished workflows are not counted twice.
Recommendation. Keep open: work remains. Count a live coordinator only when none of its members is live and add the between-phases case beside the existing count tests.
Request. The Windows All projects popup lets its content extend beyond its background.
Audit finding. The screenshot matches the searchable-combobox overflow repaired by merged PR 8627. Current Sidebar constrains the anchored popup, and the shared combobox now lets its inner content shrink and clips overflow. The fix is included in v0.0.37, while the later linked menu proposal closed without merging.
Recommendation. Close: fixed. Close as fixed in v0.0.37.
Merged pr: PR #8627. Merged fix includes before/after evidence for this exact sidebar overflow.
Independent closure check. I read the entire report and timeline and viewed the attached image. The image shows searchable project-popup content extending past its glass background on stable 0.0.36. Pinned main constrains the outer sidebar popup and lets the shared inner flex item shrink while clipping overflow, directly removing the displayed geometry defect. The fix merged after 0.0.36 and is in stable 0.0.37. The only linked later PR closed without merging, and no later reproduction is present.
Limits. The audit inspected the report image and source, not a packaged Windows runtime.
Request. Preview navigation can time out at the broker even though the destination has loaded.
Audit finding. The client still awaits bridge.navigate before starting a separate full readiness wait, while the broker deadline covers the entire request. No completed navigation result is preserved for the caller when that outer deadline expires. The navigation-result proposal is still open, and the overlay-timeout proposal addresses a different wait.
Recommendation. Keep open: work remains. Use one navigation budget and return the effective completed page state before reporting timeout.
Request. Android shows the internal AddProjectDestination route name as its header title.
Audit finding. The stack still registers AddProjectDestination without a title option. The destination route only forwards parameters into AddProjectDestinationScreen and supplies no display-title override. The title-only proposal remains open.
Recommendation. Keep open: work remains. Set a readable title for the AddProjectDestination stack screen.
Request. Packaged desktop reports user Claude skills as project skills when discovery scans the home directory twice.
Audit finding. Packaged desktop still starts the backend in the user home. Discovery scans the user config skills first and then cwd/.claude/skills as project scope, and its name-keyed map lets the second scan replace the first. No path deduplication or scope guard exists in main.
Recommendation. Keep open: work remains. Review #8815 with identical user/project roots and a distinct real project root.
Request. Switching right-panel tabs resets diff scroll position and collapsed files.
Audit finding. ChatView still mounts DiffPanel only while the Diff tab is active, and collapsed file keys remain component-local state. The persistent diff store saves selection and view mode, but not collapse keys or scroll position. The open candidate covers collapse keys only and explicitly leaves scroll restoration unresolved.
Recommendation. Keep open: work remains. Keep both collapse and scroll restoration tracked while reviewing the partial collapse-state proposal.
Request. A cloudflared child that exits immediately is restarted in a tight loop until the server runs out of heap.
Audit finding. superviseConnector still waits for child exit, stops that connector, and calls reconcileConfig immediately under the same supervisor path. There is no retry delay or limit, and both proposed backoff fixes are open. Provider queue bounds and boot-service OOM policy do not stop this relay process storm.
Recommendation. Keep open: work remains. Add interruptible backoff after rapid connector exits without blocking configuration changes.
Request. Operators cannot disable the server's local trace-file exporter.
Audit finding. ObservabilityLive still creates the local sink and file tracer unconditionally, even without an OTLP endpoint. Trace level, timing, rotation size, and path are configurable, so volume is not wholly unconfigurable, but none disables the local exporter and its file setup. The dedicated disable proposal remains open.
Recommendation. Keep open: work remains. Add a documented local-tracing disable setting that skips sink creation and file export.
Request. Automatic Claude title generation can execute the embedded user task and modify the project without approval.
Audit finding. The current title runner invokes Claude with --dangerously-skip-permissions, the project cwd, and no restricted tool set. The title prompt still embeds the user message and permits tool inspection, so the process remains capable of the reported writes even though current source uses a CLI runner rather than the report's SDK description. The isolation fix is open and title-retry changes do not limit these permissions.
Recommendation. Keep open: work remains. Isolate title generation in a neutral directory with no write-capable tools and verify an imperative title input cannot modify project files.
Request. Project-local Codex and OpenCode skills are absent from the skill and slash-command menus.
Audit finding. Codex still requests skills for process.cwd(), and OpenCode still builds its catalog with serverConfig.cwd. Neither request uses the active thread or project directory. The merged composer deduplication change does not alter discovery, and the project-scoped discovery proposals remain open.
Recommendation. Keep open: work remains. Finish project-scoped discovery in PR #8778 and verify both composer menus.
Request. Listing live provider sessions rereads every historical binding and stalls unrelated server work.
Audit finding. ProviderService still asks for every persisted thread ID, then calls getBinding for each with unbounded concurrency before matching live sessions. The directory already reads the full runtime table to produce those IDs. Recent message and activity optimizations do not change this query pattern, and the active-session lookup proposals remain open. Bootstrap now waits for a config stream snapshot rather than serverGetConfig. The historical provider binding scan still stalls the server.
Recommendation. Keep open: work remains. Look up bindings only for the deduplicated live adapter session IDs.
Latest main change. Bootstrap now waits for a config stream snapshot rather than serverGetConfig. The historical provider binding scan still stalls the server. Keep open. Update any current-code statement that describes bootstrap as a unary getConfig call.
Request. An OpenCode abort settles the turn but leaves its session running and prevents settlement.
Audit finding. ProviderRuntimeIngestion still applies session lifecycle updates to turn.completed but not turn.aborted. The later turn-event branch accepts both event types, which permits exactly the reported split between an interrupted turn and a running session. New child-session cleanup and startup reconciliation do not repair a live parent session after an authoritative abort.
Recommendation. Keep open: work remains. Complete PR 8859 with matching-turn guards and tests for aborts during streaming and stale late aborts.
Request. The global Claude probe can load another account configuration through home-directory project settings.
Audit finding. The capability probe still receives ServerConfig.cwd and still reads user, project, and local setting sources. An isolated CLAUDE_CONFIG_DIR therefore does not prevent cwd/.claude/settings.json from overriding the probe configuration in a packaged desktop process. Hook and IDE suppression do not remove these setting sources, and both proposed isolation fixes remain open.
Recommendation. Keep open: work remains. Review #8835 and #8908 against separate Bedrock and OAuth config directories.
Request. OpenCode reasoning text should stream into the thread and remain available in a reasoning view.
Audit finding. The adapter recognizes reasoning parts and emits reasoning_text deltas. Ingestion returns before loading the thread for every content delta other than assistant_text, so those reasoning deltas never enter the saved client model. Current tests explicitly expect non-assistant deltas to be ignored.
Recommendation. Keep open: work remains. Review the shared reasoning ingestion path in PR #8628.
Request. Automatically seeded project defaults override the user's sticky model and reasoning choices.
Audit finding. Server bootstrap and web project creation still save a concrete model as a project default. Both new-thread paths prefer any project default to sticky state, and the web composer still turns capability defaults into dispatch options. The provenance and dispatch correction remains open, so an automatic seed is still treated as a deliberate override.
Recommendation. Keep open: work remains. Review the open project-default provenance and explicit-option dispatch fix across clients.
Request. An iOS client can discover a Windows environment but fails during T3 Connect credential minting.
Audit finding. EnvironmentConnector still maps every mint-request failure to EnvironmentMintRequestFailed, including decoded server errors, so endpoint_request_failed does not identify a transport cause. The linked open PR improves that classification but does not repair or reproduce the actual Windows-to-iOS connection failure. Visible activity and a healthy local server do not prove the credential-mint endpoint succeeded.
Recommendation. Keep open: evidence needed. Inspect the reported failed-connect trace for the underlying mint response before selecting a fix.
Request. Wayland tiling below the desktop minimum width clips the renderer instead of reflowing it.
Audit finding. DesktopWindow still sets minWidth to 840 and minHeight to 620 on every platform. There is no Wayland-specific minimum-size branch, so the source condition identified by the 664px and 864px comparison remains. The Electron upgrade does not change these application limits.
Recommendation. Keep open: work remains. Adjust the Linux window minimum-size policy and verify the 664px Wayland case.
Request. Preview recording files contain uniform empty frames although snapshots show the page.
Audit finding. The recording-quality change replaced the canvas-frame path with native tab media capture and is available in nightly, not stable v0.0.37. Current code still uses the tab getUserMedia capture path, while two recording compatibility fixes remain open. The report spans multiple dates without an exact commit, and no current decoded-frame evidence proves that the empty output is fixed.
Recommendation. Keep open: retest. Record a non-uniform page on current Linux nightly and compare decoded video frames with a same-tab snapshot.
Request. A busy terminal can prevent another terminal from closing and block new terminals in that thread.
Audit finding. The keyed worker still recursively processes the same key while newer data is pending, so another queued key can wait without a bound. Terminal close waits for drainKey while holding the thread lock. The fairness repair is open and the separate history-size issue makes the starvation worse.
Recommendation. Keep open: work remains. Review the worker fairness fix with the terminal history changes.
Request. An incomplete .git directory admits a non-repository into checkpoint handling and causes repeated VCS warnings.
Audit finding. The reactor and provider placeholder path still use isGitRepository, which only checks whether .git exists. CheckpointStore already uses driver detection and can reject the same directory, leaving these checks inconsistent. The authoritative-detection fix remains open.
Recommendation. Keep open: work remains. Use authoritative repository detection for both reactor admission and provider placeholder checkpoints, with partial-.git coverage.
Request. A persisted Codex rate-limit error makes thread resume fail schema validation.
Audit finding. The current resume CodexErrorInfo union still excludes rateLimitExceeded. Parent resume still decodes the full generated response, so a rejected value in one historical turn can prevent the conversation from opening. Earlier account and multi-agent schema fixes do not cover this enum, and the named-value fix is still open.
Recommendation. Keep open: work remains. Add the rate-limit value and verify that unsupported historical error values cannot permanently block resume.
Request. Start from origin is hidden when Local is the new-thread default even though it still affects manually created worktrees.
Audit finding. SettingsPanels still renders the control only when defaultThreadEnvMode is worktree. The stored newWorktreesStartFromOrigin value is independent of that mode and is used when a worktree is selected later, so a hidden setting still changes behavior. The visibility fix is open.
Recommendation. Keep open: work remains. Keep Start from origin visible regardless of the new-thread default.
Request. Bullet items that begin with numbered-list syntax can have colliding markers.
Audit finding. The supplied Markdown parses as an unordered list containing nested ordered lists, which I confirmed with the installed parser. Main preserves those start numbers and only widens the ordered-list marker gutter for three-digit values, leaving the reported two-digit nested case unchanged. The screenshot shows a marker-layout problem, not missing message data.
Recommendation. Keep open: work remains. Check nested unordered and ordered marker spacing with the supplied two-digit example.
Request. Published Bun-run servers lose CORS and compression headers because the bundle loads two Effect instances.
Audit finding. The latest discussion compares the same published build under Node and Bun and confirms that only Bun loses both CORS and gzip. Current build rules still bundle Effect but leave the Bun platform external, and server startup imports that external platform at runtime. The source therefore retains the reported split-runtime mechanism; the Node workaround is not a Bun fix.
Recommendation. Keep open: work remains. Keep Effect and the Bun HTTP platform in one runtime module graph and verify headers from the packaged CLI.
Request. Turn folding can hide a substantive Grok answer when a later assistant segment is only a progress note.
Audit finding. Web folding still retains the last assistant message and hides other entries in that response group. Mobile now preserves the first and last assistant messages after PR 7723, but can still hide a substantive middle segment. Neither rule identifies all answer-bearing messages, so the broader reported loss remains.
Recommendation. Keep open: partial fix. Finish PR 8903 with coverage for substantive first, middle, and last assistant segments on web and mobile.
Request. A Claude thread repeatedly prints short statements about running a command without making progress.
Audit finding. The report supplies repeated rendered text but no native event IDs, selected model, tool events, or corresponding CLI transcript. The adapter forwards text and backfills assistant snapshots without persistent replay deduplication, so source inspection cannot separate a provider-generated loop from repeated rendering. No recent merge is demonstrated to fix this particular sequence.
Recommendation. Keep open: evidence needed. Provide sanitized SDK events and the matching native Claude transcript for one affected turn.
Request. Top-right tooltips can appear behind native desktop window controls on Linux.
Audit finding. Non-macOS desktop windows still use Electron's native title-bar overlay, while TooltipPopup has no collision padding for that reserved strip. The diff wrapping tooltip explicitly opens above its control, so increasing its DOM z-index cannot place it above native window buttons. The overlay-aware placement fix remains open.
Recommendation. Keep open: work remains. Review the open tooltip collision-padding fix for native window-control geometry.
Request. Explicit loopback navigation is rewritten to a private environment host and can report a failed load as success.
Audit finding. The MCP resolver still rewrites explicit loopback targets when the backend is on a LAN host. Navigation readiness accepts any available non-loading tab, and automation status has no navigation-failure field. The earlier address-bar fix does not change either path, and the explicit-navigation proposal is open.
Recommendation. Keep open: work remains. Preserve explicit URLs and report navigation error state instead of treating all stopped loads as success.
Request. A successful OpenCode abort leaves the saved session running and prevents thread settlement.
Audit finding. The adapter clears its in-memory active turn and emits turn.aborted. Ingestion still excludes turn.aborted from the lifecycle events that dispatch thread.session.set, matching the reported saved-state mismatch. The merged child-stop change does not alter this path, and the durable-state fix is still open.
Recommendation. Keep open: work remains. Review PR #8939 for durable abort settlement and stale-turn protection.