* fix(agents): bundle agent icons instead of loading them from Google's favicon service (#8451)
Agents without a hand-authored SVG glyph loaded their icon live from
Google's favicon service (www.google.com/s2/favicons). That service is
unreachable in some regions (e.g. mainland China) and offline, so ~23
agent icons rendered as broken images on the agent settings page, the
terminal title bar, and the status bar.
Bundle each favicon as a build-time asset under resources/agent-icons/
and render it via a new agent id -> URL map (agent-favicon-assets.ts).
The remote favicon service now only serves as a last-resort fallback for
any future agent that lacks a bundled icon. Follows the same pattern as
#7373, which bundled the OpenCode mark.
* fix(agents): bundle mobile agent icons too; drop dead omp faviconDomain (#8451)
Mobile had the same offline/region bug: MobileAgentIcon rendered every
non-glyph agent from Google's favicon service. It actually affected more
agents than desktop, since mobile lacks hand-authored glyphs for
Copilot, OpenCode, Kilocode, Droid, and OpenClaude — all fell through to
the favicon path.
Bundle the 28 favicon-path icons under mobile/assets/agent-icons/ and
render them via a Metro static require() map (mobile-agent-icon-assets.ts).
A node-env invariant test asserts every favicon-path agent ships a
bundled PNG and is wired into the map.
Also remove omp's vestigial faviconDomain from the desktop catalog — omp
renders the hand-authored OmpIcon glyph, so the favicon fallback was
never reachable.
* refactor(agents): share one set of bundled agent icons between desktop and mobile
Desktop and mobile each shipped their own copy of the favicon PNGs (23 +
28, with 23 byte-identical duplicates). Consolidate them into a single
source of truth at src/shared/agent-icons/, reachable by both bundlers:
- Desktop (Vite) imports them via `?url`.
- Mobile (Metro) requires them; Metro already watches src/shared via
metro.config.js sharedRoot, so no config change is needed.
The two per-platform maps stay separate because the import syntax differs
(`?url` string vs `require()` asset ref), but they now point at the same
files. Verified with a real `expo export`: Metro bundles all 28 shared
icons from src/shared/agent-icons.
* fix(pr-comments): let users mark comment authors as bots for the Humans/Bots filter
Some review bots post from regular user accounts that defeat both provider
bot metadata and login heuristics, so their comments were misclassified as
human. Adds a persisted prBotAuthorOverrides setting with a "Mark author as
bot" comment action, applied consistently across desktop and mobile.
Fixes#7597
Generated with [Devin](https://devin.ai)
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix(pr-comments): address review feedback on bot-author overrides
- Cap sanitized prBotAuthorOverrides at 500 entries so malformed payloads
can't bloat GlobalSettings or slow comment classification
- Reuse the shared normalizePRCommentAuthorLogin in isBotPRComment on
desktop and mobile instead of duplicating the normalization inline
- Pass botAuthorOverrides from CommentRow to CommentMoreMenu instead of
re-subscribing per menu instance
- Re-fetch mobile bot-author overrides alongside each PR refetch so they
don't stay a stale one-shot snapshot for the whole session
Generated with [Devin](https://devin.ai)
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
* fix(pr-comments): harden bot author override sync
* fix(pr-comments): bound and recover override updates
* fix(pr-comments): merge overrides from canonical settings
* fix(pr-comments): make bot override updates atomic
* fix(pr-comments): surface rejected bot overrides
* fix(i18n): translate bot override warning
* fix(i18n): translate bot author actions
---------
Co-authored-by: Dzmitry Bachko <dbachko@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Brennan Benson <brennanbenson@Brennans-MacBook-Pro.local>
Prod-release-scan P1+P2 from v1.4.137-rc.1 mobile host-remove.
P1: Host remove could orphan a SecureStore pairing token with no Settings
retry when BOTH the durable pending-queue write failed AND the native delete
rejected/stalled. recordCleanupIntent swallowed the queue-write failure, so
the only recovery handle for the failed keychain delete was silently lost.
Now scheduleHostCredentialCleanup keeps a session-scoped in-memory fallback
handle when the durable write fails, so Settings still surfaces the pending
cleanup and offers a retry; confirmNativeCleanup clears the fallback if the
native delete later lands. removeHost stays non-blocking on the keychain
(freeze fix intact).
P2 (updateLastConnected): the fire-and-forget `void updateLastConnected(...)`
call site threw on unreadable storage, producing an unhandled rejection.
updateLastConnected now swallows unreadable-storage failures internally since
it's a best-effort timestamp.
P2 (soft-read): loadPendingHostCredentialCleanup now reports storageUnreadable
instead of pretending the queue is empty, and Settings surfaces a
"couldn't check cleanup status — retry to be safe" affordance rather than
hiding the section when the durable queue can't be read.
Tests: dual-fault fallback + no-clobber, storageUnreadable reporting,
fallback self-heal on late delete success, and updateLastConnected non-throw.
* Add host removal lifecycle safeguards and credential cleanup retry UI
- Sequence host removal so metadata commits before the client socket
closes, avoiding a stranded host when storage fails, and add a
cancellable open-registry to stop races between host-client opens
and closes/unmounts.
- Queue AsyncStorage host-list mutations (rename/removal/lastConnected)
to prevent concurrent writers from clobbering each other's changes.
- Track keychain credential cleanups that fail or time out as durable
pending intents, surfaced with a manual retry affordance in Settings.
* Fix host removal error handling to reopen confirm dialog and alert user
Previously a failed host removal silently closed the confirm dialog,
leaving the host listed with no feedback and no easy retry path. Now
the confirm modal reopens and an alert surfaces the failure so the
user can retry.
* test: reconcile settings tests with universal right-click paste and promoted worktree symlinks
Merging main surfaced two semantic conflicts against this branch's tests:
- #8322 exposed right-click paste on every platform, so the settings
navigation metadata now indexes it even when only the terminal host is
Windows. Update the stale assertion accordingly.
- #8318 promoted APFS worktree shared paths by dropping the
experimentalWorktreeSymlinks gate, so WorktreeSymlinksSection now always
mounts inside RepositoryPane and reads window.api.fs. Stub a minimal
renderer fs bridge in the pane test, matching the AppearancePane pattern.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* Fix stale terminal panes after backgrounding by retrying foreground reco
- Foreground recovery was skipping the replay when resume landed mid-reconnect
(socket typically dies after 60-80s backgrounded), leaving WKWebView panes
blank until a manual tab switch. Recovery now returns a 'deferred' outcome
and the session screen retries it once connState flips back to connected.
- Fix a related race where a newly created tab's web-ready subscribe could be
skipped if a lagging session-tab snapshot reset activeHandleRef before the
subscribe fired; track the intended active handle separately.
* Fix stale pending terminal handle outliving a failed create
Clear pendingActiveTerminalHandleRef when terminal creation returns
no handle, since web-ready subscribe logic gates on this ref being
active and would otherwise see a stale value.
* Fix mobile terminal query reply authority
* fix(terminal): harden mobile query reply handoffs
* fix(terminal): exclude passive mobile query responders
* fix(terminal): gate mobile query replies on host capability
Older hosts strip terminal.send's inputKind (zod drops unknown keys), so a
forwarded xterm reply would land as ordinary floor-taking shell input. Hosts
now advertise terminal.query-reply-input.v1 via status.get and mobile drops
replies unless the host advertises it (pre-fix behavior). Also documents the
bounded desktop-to-mobile handoff double-reply residual.
Co-authored-by: Orca <help@stably.ai>
* fix(terminal): advance snapshot seq across recovery snapshots
The pending-overflow recovery loop trims buffered output against
recovery.seq while query replay and boundary strips kept using the
initial snapshot seq. Unreachable under today's control flow (no await
separates the initial-overflow consume from the loop), but the stale
seq would silently drop covered query replies if that ordering ever
changes. Track the seq that actually covered the buffered chunks.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* fix(mobile): bump Android versionCode to 7 for 0.0.27
Android 0.0.26 shipped with versionCode 6. Align Android on marketing
version 0.0.27 with a higher versionCode so side-loaded upgrades install.
* test(mobile): expect direct cmd syntax for live Windows resume
Resume commands are typed into the host terminal; when that shell is
already cmd, wrap with cmd /d /s /c is wrong. Align the mobile unit
test with shared buildAiVaultResumeShellCommand behavior.
* Prevent mobile screen locking during voice dictation
Integrate expo-keep-awake to prevent the mobile device from locking or
sleeping while a voice dictation session is active.
- Modularize useMobileDictation logic into separate helper files for
keep-awake, audio chunking, session state, and desktop startup.
- Acquire keep-awake lock only after successfully establishing a
desktop session to avoid locking on stale start attempts.
- Release the keep-awake lock on all completion, cancellation, error,
and unmount paths.
- Add source invariant unit tests to verify keep-awake ownership and
strict cleanup ordering.
* serialize keep-awake operations and avoid stale dictation start races
- Implement a global execution queue and tag tracking for keep-awake
operations to prevent concurrent races and stale deactivations.
- Track failed native deactivations and retry them when a replacement
hook owner mounts or starts a new dictation session.
- Ensure stale or canceled desktop dictation starts do not reset the
UI state or propagate outdated start/keep-awake failures.
- Reuse the audio chunk queue wiring in useMobileDictation to avoid
allocating new closure objects on the high-frequency microphone path.
- Add comprehensive unit tests for the keep-awake and desktop start hooks.
* Commit native recording during dictation session startup
Commit native recording in the same continuation as the final session
stale check. This prevents a queued cancellation from resurrecting the
microphone recording after cleanup has already run. If microphone
initialization fails or throws, acquired resources (like keep-awake
locks and the remote desktop session) are properly rolled back.
* Make keep-awake acquisition best-effort with a bounded startup timeout
- Recording start no longer blocks (or fails) on keep-awake acquisition:
a hung or failing native call is capped at a short budget and logged
instead of delaying or aborting dictation.
- Add native-call timeouts, orphan-tag tracking, and reacquire/drain
logic in mobile-dictation-keep-awake.ts so Activity recreation on
Android and stale tags no longer wedge the keep-awake queue.
- Add useMobileDictationForegroundKeepAwake to refresh the wake tag on
Android foreground and retry failed refreshes/deactivations.
- Hold the wake tag through chunk drain and the finish RPC so a screen
lock can't suspend the app before the transcript arrives, and keep
cleanup running even if native recording shutdown throws.
- Loosen expo-keep-awake to a caret range to unblock the patch pulling
in these native fixes.
* Fix cancellation races in mobile dictation keep-awake handling
- Run wake-lock release and dictation cancel concurrently on stale
starts so a hung acquisition no longer delays the native cancel
- Guard foreground reacquire retries with a run token so a stale
retry chain can't deactivate a wake lock reacquired by a newer
AppState transition
* Update source invariant test for concurrent stale-start cleanup
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* Fix mobile source control drawer overflow and branch-compare state loss
- Render BottomDrawer in a native Modal so it covers the full viewport
even when mounted inside a ScrollView.
- Move the conflict/Abort row onto its own line so it never overflows
the branch card, and enlarge the Abort hit target.
- Show the committed-on-branch footer even when the changed-files
SectionList has no sections, since RN skips ListFooterComponent for
empty sections.
- Stop branch-compare state from collapsing to idle/error on transient
base-ref resolution failures when a ready result should be preserved.
* Add mobile source control drawer reload screenshot
Attaches an evidence screenshot for the mobile source control drawer overflow / branch-compare state loss fix.
* Remove stray temp screenshot file
Accidentally committed debug artifact from mobile source control drawer work; not needed in the repo.
* perf(mobile): replace worktree name polling with events
* fix(worktrees): push rename invalidation to remote clients
worktrees:updateMeta deliberately skips the renderer notifier (PR #209),
but paired mobile clients no longer poll for titles, so a manual rename
would never reach them. Emit the remote-only worktreesChanged client
event (with resolved-cache invalidation), gated on displayName so
per-click isUnread writes stay event-free.
Co-authored-by: Orca <help@stably.ai>
* test(worktrees): add missing runtimeStub type member for typecheck
Co-authored-by: Orca <help@stably.ai>
* fix(worktrees): derive rename event repoId with the shared non-throwing parser
getRepoIdFromWorktreeId matches the mobile client's event filter exactly
and cannot throw after the meta write already persisted.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* fix(mobile): recover terminal state after iOS resume
* Refactor terminal record merge to extract snapshot-reconciliation helper
Split the inline merge logic in mergeTerminalRecordsByCurrentOrder into a
named mergeTerminalSnapshotWithKnownRecord function for clarity, preserving
the existing behavior of keeping the last known theme when a snapshot omits it.
* Redesign mobile search field as a shared, raised component
- Extract MobileSearchField from duplicated Search icon + TextInput + clear
button markup in worktree list and tasks screens into a reusable component
- Give the field a raised bgRaised shell with focus/disabled states so it
reads as a tappable control instead of blending into panel chrome
- Fix delayed autoFocus via InteractionManager + timeout so the keyboard
reliably appears after the search bar opens
- Preserve per-screen clear behavior (preset/query fallback for GitHub,
project-view filter) via configurable showClear/onClear props
* Simplify GitHub project search state checks and fix stuck clear button
- Extract `isGithubProjectSearch` to dedupe repeated `provider === 'github' && githubMode === 'project'` checks
- Fix showClear so an explicit empty applied override doesn't leave the clear button visible forever
* fix(linear): guard mixed-version RPC filtering
* fix(linear): surface filter capability failures correctly
Prevent capability checks from pinning to rejected compatibility cache
entries, and rethrow typed attribute-filter unsupported errors from the
Linear store so TaskPage can show an upgrade message instead of an empty
filtered list.
* fix(runtime): refresh cached capability verdicts
* test(linear): mock isLinearIssueAttributeFilterUnsupportedError
Prevents the invalidation slice test from failing after the runtime
client gained this export, which was otherwise undefined in the mock.
* Fix cold-cache capability probes firing duplicate status.get calls
Coalesce concurrent status.get requests for the same environment by
publishing the in-flight probe to the compatibility cache before
awaiting it, so parallel capability checks share one RPC call. On
failure, drop the cache entry immediately since this probe always
re-fetches and must not leave a stale cached verdict.
Aligns status bar, tooltip, popover mocks, and mobile usage bars with the
Claude/Codex harness convention (consumption meters) so a fresh account
reads empty/green and a depleted one reads full/red, instead of the
inverted "left" framing that misread as "full = exhausted".
* Show agent session history on mobile
Bring the desktop "Agent Session History" panel to Orca Mobile as a
per-worktree screen: browse past agent transcript sessions across the
host with scope tabs (Workspace/Project/All), search, grouping, session
cards, and tap-to-read message previews.
The transcript scan previously ran only over Electron IPC, so mobile
could not reach it. Expose it over the runtime RPC protocol mobile
already speaks (aiVault.listSessions) so the scan runs on whichever host
owns the transcripts — correct for local and SSH/remote hosts. Both the
desktop IPC handler and the new RPC method share one cache, so opening
the desktop panel and the mobile screen never double-scan.
The pure filter/group/display logic is lifted into /shared (the renderer
re-exports it) so the standalone mobile package can reuse it. Mobile
narrows scoped tabs client-side by cwd path-prefix because the host scan
treats scope paths as a widening union.
Resume-from-mobile is intentionally a follow-up.
* Fix mobile agent history list rendering and RPC authorization
- Authorize aiVault.listSessions in the mobile RPC allowlist so the
mobile client's call is not rejected before dispatch (without this the
screen could never load sessions at runtime).
- Name each SectionList section's rows `data` (the field React Native
reads) instead of `cards`, fixing a type error and silent empty-section
rendering.
* Address review feedback on agent session history
- Match quoted repo:/path: search operator values so labels and paths
with spaces match (e.g. path:"/Users/ada/My Project").
- Hold a scoped tab in loading until the worktree list resolves instead
of firing an unscoped fetch that briefly shows unrelated host history;
proceed once loaded even if the worktree is absent (no stuck spinner).
- Clear cached host capabilities on disconnect/host-switch and failed
status.get so a capability-gated action can't linger for a host that
doesn't support it.
- Cover the real OrcaRuntimeService codex-home forwarding path and the
quoted-operator parser with tests.
* Hide redundant mobile current worktree badges
Co-authored-by: Orca <help@stably.ai>
* Resume agent sessions from mobile history (#6969)
Co-authored-by: Orca <help@stably.ai>
* Adapt merged seams to main's lint and reply-sender hardening
Co-authored-by: Orca <help@stably.ai>
* Cap mobile project-scope paths to the aiVault RPC bound
Co-authored-by: Orca <help@stably.ai>
* Share the aiVault scopePaths bound between the RPC schema and mobile
Co-authored-by: Orca <help@stably.ai>
* Guard shared AI Vault inflight cleanup against concurrent key replacement
The extracted cache module's .finally() cleared inflight tracking
unconditionally, dropping the if (inflightKey === key) guard its sibling
outer cache kept: an older scan resolving after a different-key scan
replaced the tracking would null the newer scan's dedup slot, so a
re-request started a duplicate transcript rescan. Mirrors the sibling
guard; the regression test flushes a macrotask so a reverted guard fails
fast on the call count instead of hanging.
Co-authored-by: Orca <help@stably.ai>
* Harden aiVault.listSessions contract and gate mobile header entry on capability
- Clamp scopePaths (64) instead of rejecting, cap limit at 2000, and make
executionHostId optional so mobile can omit it; restamp per caller.
- Retain successful mobile terminal-create mutation ids for 60s so resume
retries dedupe after transient socket drops.
- Gate the session-header Agent History action on the aiVault.v1 capability
(mirrors the host-list action) so old hosts never show a dead-end entry.
- Fix stale contract comments (scopePaths clamp semantics; filters move
includes quoted repo:/path: operator parsing).
* Add subagent field to session test fixtures after #7423 merge
AiVaultSession.subagent became required on main; the five fixtures added on
this branch predate it. Top-level scanned sessions carry null.
---------
Co-authored-by: Orca <help@stably.ai>
Co-authored-by: Brennan Benson <brennanbenson@Brennans-MacBook-Pro.local>
Here is a summary of how the sandbox behaves on your macOS system:
### ⚙️ How it Works
When `--sandbox` is enabled (either via the launch flag or the `enableTerminalSandbox` setting in your `settings.json`), terminal commands run inside a lightweight containment boundary:
- **macOS Native Isolation**: It utilizes macOS's native `sandbox-exec` utility to restrict system calls, network sockets, and directory access.
- **Secure File Boundaries**: File system writes are locked down to designated safe zones (such as your designated workspace or scratch directory). Access to critical system paths, private user data, and external network resources is restricted.
---
### 🛡️ Active Permissions for this Session
In this current session, the permission model is configured as follows:
| Action / Resource | Permission Status | Details / Paths |
| :--- | :--- | :--- |
| **Command Execution** | ✅ **Allowed** | Terminal command execution is enabled. |
| **File Reads (Allowed)** | ✅ **Allowed** | `/scratch`, `/browser_recordings`, `/html_artifacts`, `/knowledge`, `/worktrees`, `/skills`, `/builtin` |
| **File Writes (Allowed)**| ✅ **Allowed** | `/scratch`, `/browser_recordings`, `/html_artifacts`, `/knowledge`, `/worktrees` |
| **Sensitive Files** | ⚠️ **Ask** | `.env`, `.npmrc`, `.vscode`, `.git-credentials`, etc. |
| **Root/App Settings** | 🚫 **Denied** | Direct modifications to `/config` and main `.gemini` configurations |
---
### 🔧 Configuration and Management
* **Persistent Settings**:
To enable sandboxing by default for all future sessions, configure the `enableTerminalSandbox` setting in your `~/.gemini/antigravity-cli/settings.json`:
```json
{
"enableTerminalSandbox": true
}
```
* **Dynamic Adjustments**:
Within an active CLI (`agy`) session, you can run the `/permissions` slash command to view or modify your autonomy and sandboxing levels on the fly.
> [!NOTE]
> Running in sandbox mode provides an excellent balance of autonomy and security, allowing me to execute build commands, run test scripts, and manage project files safely without risk to your primary host environment.
Please let me know if you would like me to set up a new project workspace or run any specific tasks within this session!
* Support WSL Codex settings promotion and harden config write-back
- Enable settings promotion for WSL runtimes using per-distro baselines.
- Create parent directories if missing to prevent promotion ENOENTs.
- Keep restrictive permissions (0600) and follow symlinks on promote.
- Respect CRLF line endings when inserting keys into CRLF config files.
- Skip redundant baseline file writes when settings are unchanged.
- Include the release scan report for the 1.4.131-rc2 prep.
* Refactor sleeping agent wake flow and fetch rate limits via backend
- Background-mount only targeted terminal tabs during passive wake to
prevent spawning unnecessary PTYs for unvisited tabs.
- Latch edge-triggered wake requests that arrive mid-hibernation and
track active claims to prevent double-resuming a provider session.
- Query the ChatGPT wham usage backend API directly with fetch for
rate limits, avoiding launching Codex or WSL login shells.
- Asynchronously probe and serialize WSL auth files with timeouts to
prevent synchronous I/O from stalling Electron's main process.
- Fix config promotion edge cases such as missing parent directories,
dangling symlinks, and atomic write permission widening.
* Support WSL dotfile-symlink write-back and lengthen redeem timeout
- Preserve symlinked Codex config on WSL by writing through the
existing file instead of atomic-rename, since \\wsl$ symlink
metadata isn't reliably detected and rename would clobber the link.
- Tighten new ~/.codex directory creation to 0700 (holds auth.json).
- Give explicit reset-credit redemption a 30s backend timeout instead
of the 10s background-poll default, since it's user-triggered.
- Read sleeping-agent session state from the worktree's actual
execution-host partition instead of always the local one, so the
headless-wake check works correctly for SSH-hosted worktrees.
- Isolate serve-sim watcher tests from the real $TMPDIR/serve-sim
state file to avoid leaking unrelated events.
The longer-hyphen recovery path (#5222) reconstructed runs by writing a
value that differed from the native field text. After #7933 stores raw
field text and normalizes only on send/PTY, that recovery is unreachable
and any write-back would reintroduce dictation kill. Map each smart dash
to exactly "--" with a single-arg normalizer.
* Consolidate mobile source control into a single tabbed hub
Unify the changes list, pull request details, and commit history into
a single multi-segment panel. This improves navigation and state sharing
across different lenses of a worktree's source control.
- Add a segmented control to switch between Changes, PR, and History
- Introduce a persistent branch status card with an integrated PR chip
- Redirect standalone PR and history routes to the new unified hub
- Extract reusable UI and logic for the history list and PR summary
* Keep mobile source control tabs mounted to preserve view state
* Keep PR and History segments mounted (using display: 'none' when hidden) to preserve fetch, scroll, and expand states during tab switches.
* Decouple the History list from blocking on Git status loading.
* Support deep linking directly into the history tab of the main panel instead of using a standalone route.
* Enable retrying failed loads by reviving the transport loop if parked.
* Fix PR chip accessibility label and comment check.
* Optimize and integrate mobile PR view within source control hub
- Lazy-load heavy PR comments and descriptions (Phase 2) only when the
PR tab is active, using fast metadata (Phase 1) for the branch chip.
- Unmount the PR body when inactive to avoid unnecessary comment tree
re-renders and preserve WebView resources during commit text editing.
- Implement soft-refresh on HEAD advancement to keep the ready UI
visible while re-fetching checks post-commit.
- Display the "Aborting..." label only when a merge or rebase abort
is actively in flight.
- Memoize the git history list and skip branch identity RPCs when
gating the dock icon.
* Improve mobile git views and concurrent rendering safety
- Pass the `origin` parameter through history and PR redirect routes.
- Move source control panel ref updates to `useEffect` to prevent side
effects during concurrent renders.
- Resolve commit file changes to empty if disconnected to avoid a stuck
loading spinner.
- Standardize PR sidebar header button styling and accessibility labels.
* Resolve PR repo probe without active branch to avoid forever spinner
Previously, checking if a repository is a GitHub remote required an
active branch. In a detached HEAD or mid-rebase state (where the branch
is null), the probe never resolved, leaving the PR panel on a forever
spinner.
Decouple the repository probe from the branch presence so the panel
can correctly display the "Current branch unavailable" state. Also,
hide the PR status chip when no branch is active to avoid a spinner
on the chip.
The rpc-client has always emitted a detailed connection lifecycle log
(dials, timeouts, close codes, handshake steps, retries) via onLog, but
only the pairing screen wired it up — for long-lived host connections
everything went to console.log, invisible to users. Debugging reports
like #7824/#6928 meant asking reporters for facts the app already knew.
- connection-log-buffer: bounded (200/host) module-level ring buffer with
referentially-stable snapshots for useSyncExternalStore; survives
client swaps and provider remounts.
- client-context: wire onLog for every shared host client.
- connection-log screen: live per-host log (reuses the pairing
ConnectionLog component), host picker, and a Copy Diagnostics button
that bundles app/platform versions, endpoint (flagged if Tailscale),
state, attempt count, last-connected, and the event log into one
shareable blob.
- troubleshoot: 'View connection log' entry point.
Co-authored-by: Orca <help@stably.ai>
A wedged Tailscale tunnel (known iOS failure mode) produces no AppState
or network-type transition, so no revival nudge ever fires and the
reconnect loop parked permanently at its give-up cap — users had to
toggle Tailscale off/on just to force a transition (#7824).
- rpc-client: past the give-up cap, drop to a 90s trickle dial instead
of parking so the session self-heals once the tunnel recovers.
- host screen: nudge the shared client on focus so opening the host
retries immediately instead of waiting out a backoff/trickle timer.
- connection-health: warning/unreachable verdicts on 100.64/10 or
*.ts.net endpoints now carry a 'check Tailscale' hint, shown on the
home host list and the in-session status line after ~3 failed
attempts.
- troubleshoot: 'Cannot reach <tailnet-ip>' now says to check
Tailscale, adds a dedicated Tailscale section, and stops telling
Tailscale users to disable their VPN (that advice killed their only
route to the host); sections extracted to
troubleshoot-common-issues.tsx to stay under the max-lines cap.
Co-authored-by: Orca <help@stably.ai>
Introduce an external link action in the header of the Mobile PR View
Panel. This provides a persistent and easily accessible shortcut to open the
current pull request's canonical URL in the system browser.
* feat(mobile): add explicit keyboard dismiss control to terminal command dock
Add a fixed Hide control at the left of the terminal command dock accessory
bar whenever the software keyboard is open (keyboardHeight > 0). Tapping it
clears any pending live-input focus timer, blurs the live and buffered command
inputs, and dismisses the keyboard without sending bytes, switching input mode,
or clearing typed text.
The dismiss behavior lives in a dedicated, unit-tested terminal-keyboard-dismiss
module rather than the customizable accessory-key path, so the escape hatch
cannot be hidden by user shortcut customization. Available on every platform
where the IME covers the app (iOS and Android).
* review: harden keyboard dismiss control per adversarial review
- document the load-bearing clear-before-blur order in dismissTerminalKeyboard
- cover the both-handles-missing case in unit tests (5/5)
- move the #5106 first-tap comment onto the accessory ScrollView and add a
why-comment for the fixed Hide control
- add accessibilityRole=button and hitSlop to the Hide control for a larger,
semantically-correct touch target
* fix(mobile): harden hide button visibility and scroll layout
* refactor(mobile): use stacked keyboard+chevron glyph for dismiss control
Replace the icon+'Hide' text with the iOS-native dismiss glyph (keyboard
with a chevron-down beneath it). Narrower in the accessory row, removes the
icon/word redundancy, and reads as distinct from the >> input-mode toggle.
Accessibility label/hint/role unchanged.
* fix(mobile): align keyboard dismiss accessory height
* test(mobile): align vitest transform with Vite 8
---------
Co-authored-by: Wolfgang Schoenberger <221313372+wolfiesch@users.noreply.github.com>
Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
scheduledNotificationsByHostAndNotificationId (mobile-notifications.ts)
retained one entry per scheduled desktop notification. The key embeds
notificationId, which carries a per-completion timestamp
(buildAgentNotificationId), so every agent-task-complete inserts a new,
never-reused key. Entries are removed only when the desktop sends a
matching dismiss — which a remote mobile user (not sitting at the
desktop) frequently never receives — so the module-level map grew for
the app's whole lifetime. Small per entry, but genuinely unbounded.
Fix: bound the map to the 256 most-recent SETTLED entries (never evict
one mid-schedule). A settled entry only retains a small identifier used
for later programmatic dismissal, which is unnecessary for long-past
completions, so eviction has no user-visible effect.
Also FIFO-cap RootLayout's handledNotificationIdsRef tap-dedup Set
(RootLayout never unmounts, so it otherwise grew one id per tapped
notification forever).
Test (red->green): with the cap at 1, scheduling a second notification
evicts the first, so a later dismiss for the evicted id is a no-op while
the retained one still dismisses; without the cap the old entry survives.
110 files carried an eslint/oxlint-disable max-lines directive but are
already under the default max-lines budget (300 .ts / 400 .tsx / 600 .mjs
/ 800 test), so the suppression is dead. Removing it restores real
max-lines coverage on these files with zero behavior change.
Each removed directive had max-lines as its only rule; verified via a
full oxlint run (0 max-lines violations, 0 new errors). Diff is pure
deletions (200 lines, 0 additions) — no code touched.
Co-authored-by: Orca <help@stably.ai>
Bump marketing version 0.0.22 -> 0.0.24 and Android versionCode 4 -> 5.
The 0.0.22 base was never committed after prior releases, so the Jul 6
builds carrying the show-all-worktrees fix (#7500) regressed below the
0.0.23 already on TestFlight (iOS) and collided with the existing
0.0.22/versionCode 4 APK (Android, no upgrade signal). Committing the
bump makes app.json authoritative again so 0.0.24 supersedes both.
Co-authored-by: Orca <help@stably.ai>
Enable three unicorn rules — one correctness, two performance — and fix every
existing violation repo-wide so the rules pass as errors.
prefer-number-properties (76 sites)
- parseInt/parseFloat/NaN -> Number.* : safe aliases (autofixed).
- isNaN -> Number.isNaN (12 sites, hand-converted): global isNaN coerces its
argument, Number.isNaN does not. Verified every call site already passes a
number (Number.parseInt results, number-typed fields, Date.getTime()), so the
conversion is behavior-preserving today and guards against a future non-numeric
argument silently coercing.
prefer-array-find (26 sites)
- .filter(pred)[0] -> .find(pred); .filter(pred).at(-1) / .pop() -> .findLast(pred).
Drops the intermediate array and short-circuits.
prefer-array-index-of (5 sites)
- .findIndex(x => x === v) -> .indexOf(v).
Verified: typecheck (node/cli/web) clean, 53 affected suites pass (1679 tests),
oxlint clean repo-wide. mobile/ uses findLast safely (already ships ES2023
.toReversed()); config scripts and e2e helpers run on Node 24.
* Show all worktrees across all hosts on mobile
Avoid honoring desktop's host-filtering settings since mobile lacks the
UI to manage or unhide them. This prevents worktrees from being silently
hidden under certain host scopes.
Additionally, this removes worktree filtering based on repo metadata, which
previously caused worktrees to vanish when same-named repos on different
hosts collapsed to a single ID.
* fix(daemon): preserve promisify.custom type through wrapChildProcessApi
The windows-hidden-console-children test (from #7499, admin-merged with a
failing verify) failed tsgo: promisify(wrapped) resolved to its zero-arg
overload because the wrapper erased its argument to a bare variadic function
and the fake never statically carried promisify.custom. Preserve the wrapped
type via a generic overload (accurate: the wrapper copies the call signature
and symbols verbatim) and build the fake as a real CustomPromisify, so
promisify routes through the custom overload as it does in production.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
Prevent enabling auto-merge when a PR is in an UNSTABLE merge state.
GitHub auto-merge mutations reject UNSTABLE PRs directly instead of
allowing them to wait, so we should suppress the option.
* fix(mobile): avoid SF Mono fallback on iOS terminal
* test(mobile): cover touch iPadOS terminal font fallback
* refactor(mobile): share terminal font fallback tail across platforms
Dedup the identical fallback chain that the iOS/non-iOS branches each
repeated so the two platforms can only differ in the lead family and
cannot silently drift. Make the regression tests behavioral: assert the
resolved chain always terminates in the generic monospace (the real iOS
bug) and that both platforms share an identical tail.
Co-authored-by: Orca <help@stably.ai>
* test(mobile): anchor font-block extraction on font markers only
The VM-slice end boundary was an unrelated text-scale comment; re-anchor
it on the terminalFontFamily declaration so edits below the font block
cannot break the extraction.
Co-authored-by: Orca <help@stably.ai>
* chore(mobile): bump terminal-webview-html max-lines ratchet to match file size
The iOS-safe font selection block adds a few code lines to
terminal-webview-html.ts, pushing it to 1784. Bump the grandfathered
per-file ratchet to match, consistent with prior ratchet bumps.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Neil <4138956+nwparker@users.noreply.github.com>
Co-authored-by: Orca <help@stably.ai>
* feat: 모바일 터미널 한글 미러 스텝 순수 모델 추가
* feat: 미러 델타 순서 보장용 send 체인 추가
* fix: 모바일 터미널 한글 입력을 미러 모델로 전환
* fix: 탭 상태 지연 중 한글 조합 상태 소실 방지
* fix: 미러 가드와 send 체인 리뷰 지적사항 반영
탭 상태 지연으로 활성 탭 타입이 일시적으로 null이 될 때 runMirrorStep의 stale-handle 가드가 조합 중 음절을 버리지 않도록 pending-clear 효과와 동일한 null 허용 패턴 적용. 테스트 하네스가 ref와 prop을 동일 소스에서 파생하도록 결합해 실제 경로의 lag 프레임을 검증. queueTerminalLiveMirrorSend의 previousSend await를 catch로 보호.
* refactor(mobile): drop dead queueTerminalLivePendingFlush orphaned by the mirror model
The mirror model migrated all live-input sends to queueTerminalLiveMirrorSend,
leaving queueTerminalLivePendingFlush referenced only by its own tests. Remove
the dead function and its three tests.
Co-authored-by: Orca <help@stably.ai>
* fix(mobile): expose live terminal keyboard target
Co-authored-by: Orca <help@stably.ai>
* fix(mobile): refocus live keyboard after dismissal
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: realitsyourman <wongil@demodev.io>
Co-authored-by: Neil <4138956+nwparker@users.noreply.github.com>
Co-authored-by: Orca <help@stably.ai>
* fix(mobile): bundle terminal engine and show load errors instead of a blank pane
The mobile terminal WebView loaded xterm.js from cdn.jsdelivr.net at
runtime; old WebViews (< Chrome 85) fail to parse the modern bundle and
blocked-CDN networks fail to fetch it, and the resulting error was
silently dropped, leaving the pane permanently blank (#7030).
Bundle the engine into the app via exact-pinned npm deps + a postinstall
esbuild step (chrome74 target, guarded WeakRef/structuredClone/
replaceChildren shims) emitting a gitignored generated module, inline it
into the terminal document, and surface fatal engine failures as a
visible overlay with diagnostics and a Reload wired into the existing
resubscribe path. Non-fatal errors log without covering a live terminal.
Co-authored-by: Orca <help@stably.ai>
* fix(mobile): add a native watchdog so a dead terminal document can't stay silently blank
CodeRabbit round: if the webview document dies before the glue can post
anything (or the RN message bridge never comes up), no error message and
no native handler fires. Arm a 15s foreground-gated watchdog per document
generation that paints the fatal overlay when web-ready never arrives;
first fatal diagnostics win over later cascades. Extract the watchdog and
the public contract types to keep TerminalWebView under the line cap, and
document the SVG xmlns percent-encoding transform.
Co-authored-by: Orca <help@stably.ai>
* test(mobile): unmount TerminalWebView renderers so watchdog timers can't leak across tests
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
Fixes #6972.\n\nPreserves mobile terminal buffered/live input mode across Android terminal re-entry and session refreshes. Includes follow-up hardening for pre-hydration preference edits and failed storage reads.