Commit Graph
493 Commits
Author SHA1 Message Date
SSU-WEI HUANGandGitHub 6c6f4b4929 feat(agy): replace fragile PTY/TUI wrapper with headless print-mode transport (#1591)
Replace the Antigravity (agy) integration — a PTY wrapping the TUI with
output-marker scraping ('? for shortcuts', 'Generating', trust dialogs,
/model picker navigation, quota-screen regex) — with a headless print-mode
transport: every user turn spawns `agy -p <msg> --conversation <uuid>
--output-format stream-json`, and NDJSON events (init/step_update/result)
map onto the existing transcript-entry channel (sendAgySessionMessage), so
hub/web rendering is unchanged. ~8.3k LOC (incl. tests) removed.

Fixes #1588. Design: docs/design/agy-headless-transport.md.

CLI:
- new cli/src/agy/headless/: agyNdjsonParser (pure functions, malformed-line
  tolerance, step conversation-id adoption), AgyPlannerAccumulator (per-step
  delta accumulation with settling retries), AgyHeadlessDriver (per-turn
  spawn/kill loop, NDJSON chunk buffering, authoritative delivery ack via
  user_input/result, interrupt + retry + shutdown lifecycle with consume/
  restore, process-tree termination, SSH agent preserved, prompt log
  redaction, per-turn model snapshot with conversation-DB fallback)
- runAgy/loop/session rewired; agy is remote-only (no PTY, no local mode,
  no local-switch action); queued batches snapshot model/effort/mode
- deleted agyPty, agyPtyLauncher, agyHookCarrier(+scope cache), agyModelKeys,
  agyQuestionKeys, agyAskQuestion, agySessionScanner, agyPermissionHandler
  (+tests); buildAgyHooksJson removed; startHookServer agy-pre-invocation
  route → 200 no-op
- runner: agy reopen/resume via generic --existing-session-id; commands/
  agy.ts defaults remote; resume rejects ACTIVE agy sessions (remote-only,
  in-flight turns cannot hand off)
- MCP stays user-managed (agy reads ~/.gemini/config/mcp_config.json and
  workspace .agents/mcp_config.json natively in headless — verified)

Hub/web:
- machines.ts drops agy→pty forcing and rejects non-remote startingMode
- NewSession drops agy startingMode='pty'; terminal toggle disappears
  automatically; RemoteModeDisplay hides the local-switch hint when absent
- docs/guide/agents.md updated: headless print mode, no PTY/hooks, MCP via
  user's own mcp_config.json

Tests: 47 parser+driver tests (fake-binary e2e, chunk-split NDJSON, delivery
ack semantics, interrupt/retry/shutdown races, model attribution, EOF
framing, malformed envelopes); full suite green (cli ~2340, hub 1093,
web 2474, shared 262). Real-binary smoke on agy 1.1.13: single turn exit 0,
--conversation resume keeps the same conversation_id.
2026-08-16 22:44:27 +08:00
SSU-WEI HUANGandGitHub a6feb6e8ba feat: unified agent configuration descriptors (session config consolidation) (#1469)
* feat(config): add agent config descriptor protocol and advertise via runner capability

Introduce shared agent configuration descriptors covering model, effort,
permission, and secondary settings per agent flavor, plus the canonical
HAPI YOLO -> native permission mode mapping. Runners advertise the
builtin descriptors through the runner-state capability so hubs and web
can render configuration without hardcoded flavor branches.

Migrate the OpenCode create-session model picker from a bespoke radio
list to the shared SelectControl combobox.

* feat(web): render create-session permission from agent config descriptor

Replace the flavor-branched Grok/Codex-family/YOLO permission block with
a descriptor-driven PermissionField. Pi now reports permission as managed
instead of silently ignoring the YOLO toggle, and YOLO-only flavors show
the native permission mode the preference maps to.

Removes the superseded GrokPermissionModeSelector and
CodexFamilyPermissionModeSelector components.

* ci: retry flaky claudeRemote 5s-timeout failure

* fix(web): persist explicit OpenCode Default selection instead of restoring a concrete model

The parent initialization effect treated every null selected model as
'uninitialized' and auto-picked a concrete advertised model, clobbering
the user's explicit Default choice (and a restored Default preference).
null now means explicit Default and is preserved; only undefined (no
choice made yet) triggers probe-based initialization. Add parent-level
regression tests for Default persistence and remembered-model restore.

* fix(web): accept undefined selected model in OpencodeModelSelector props

* feat(web+cli+hub): unify create-session model/effort fields and add Pi model/effort support

Pi's agent config descriptor now advertises model (machine) and effort
(static thinking levels) for create AND session availability:
- cli: ListPiModelsForMachine RPC runs 'pi --list-models' (cached, inflight
  deduped) and parses the provider/model table; startup model match accepts
  provider-qualified ids
- hub: GET /api/machines/:id/pi-models route + rpcGateway/syncEngine passthrough
- web: NewSession renders Pi models grouped by provider through the generic
  ModelSelector and a new descriptor-driven EffortField (replaces the
  per-flavor LaunchEffortSelector/ReasoningEffortSelector pair); launch payload
  forwards Pi model + thinking-level effort (runner already supported --model/
  --effort for pi)

* fix(web): render Pi provider groups in ModelSelector and scope Grok availability warning

- ModelSelector now renders grouped options as <optgroup> (Pi models are
  provider-grouped; identical modelIds from different providers stay distinct)
- PermissionField only receives autoPermissionModeSupported for Grok — a
  cached Grok probe result no longer leaks the Grok warning onto other agents

Addresses HAPI Bot Minor findings on #1469.

* fix(web): drop Object.groupBy from ModelSelector; revalidate restored Pi models against the catalog

- ModelSelector buckets options with a reduce instead of Object.groupBy
  (Safari < 17.4 has no polyfill — New Session would throw on those clients)
- Pi restored model/effort are cleared when the value is absent from the live
  machine catalog, and Create waits for the catalog while a non-default Pi
  choice is being validated (mirrors Codex/Grok/Copilot handling)

Addresses HAPI Bot findings on #1469.

* fix(pi+web): serialize startup model before thinking level; hide Pi launch controls during history import

- PiSession gains startupModelSettled; the startup set_thinking_level waits for
  the requested model's set_model attempt to settle first, so a level the
  default model rejects is not lost before the requested model is confirmed
  (set_model and set_thinking_level were already serialized by the runtime
  mutation lock; this pins the model-first ordering)
- Create Session hides Pi model/effort controls while a Pi history import is
  selected — the import reopens the native session as-is and would silently
  ignore launch-only model/effort values

Addresses HAPI Bot findings on #1469.

* fix(pi): settle startup-model gate when model discovery fails or returns no models

A failed or empty get_available_models response would leave the
startupModelSettled gate unresolved, stranding a requested startup effort
indefinitely. Resolve the gate on the error path and the empty-models path;
adds regression tests for both.
2026-08-16 22:43:39 +08:00
SSU-WEI HUANGandGitHub 79ffe9aa0e feat(web): composer model/effort value buttons and first-class permission (part of #1438) (#1475)
* feat(web): composer model/effort value buttons and settings order

Wide composers now show [model] and [effort] value buttons for non-Pi
flavors (labels from the current session values), opening the settings
sheet on click. Narrow viewports collapse to the settings button only
via a new useNarrowViewport hook. The settings sheet reorders to
Model -> Effort -> Permission -> other settings (Fast mode,
collaboration, Copilot agent mode) so permission is first-class.

Toolbar customization gains 'model'/'effort' items with settings labels.
Pi keeps its dedicated model/thinking panels unchanged (unified
descriptor-driven sheet is a follow-up).

* fix(web): satisfy strict types in composer value-button test harness

* fix(web): address review findings on composer model/effort value buttons

- Normalize null/'auto'/'default' model wire values onto the value:null
  option so default-model sessions keep a localized label button (Major)
- Exempt model/effort value buttons from the settings outside-click
  dismissal so a second click closes the sheet instead of reopening it
- Read matchMedia synchronously in useNarrowViewport so narrow first
  paints never flash the wide toolbar
- Add regression tests: model=null/'auto' labels, toggle-close behavior,
  and initial narrow-viewport render

* feat(web): fold Pi into the generic composer model/effort value buttons

Pi sessions previously exposed model/effort twice: dedicated 'Pi model' /
'Pi thinking level' toolbar buttons (PiModelPanel/PiThinkingLevelPanel)
AND the settings sheet's generic Model/Effort sections. Consolidate so Pi
looks exactly like every other flavor:

- Pi now uses the generic model/effort value buttons; labels resolve from
  the provider-qualified piModels catalog (name -> modelId -> session id).
- The settings sheet's Model section already renders provider-grouped Pi
  rows and Effort renders Pi thinking levels, so the dedicated panels and
  their toolbar slots are deleted.
- Keep Pi's mid-turn control affordance (#1442): Pi turns hold
  thread.isDisabled for minutes, so Pi model/effort controls stay enabled
  while a turn is running (configurationControlsDisabled instead of
  controlsDisabled), including the sheet rows.
- Drop 'piModel'/'piThinking' toolbar layout items; persisted layouts
  normalize them away automatically.

Tests: pi value-button label/sheet tests, mid-turn model selection via the
unified sheet, toolbar layout defaults.

* fix(web): keep a session-settings trigger on narrow viewports and mid-turn Pi

Address the HAPI review bot's two Minor findings on the Pi consolidation:

- Narrow viewports collapse the model/effort value buttons into the
  settings sheet, so a persisted toolbar layout hiding the gear left no
  session-settings trigger at all. ComposerButtons now forces the gear
  back into the rendered layout on narrow viewports (wide layouts keep
  honoring the user's hidden choice).
- The Pi mid-turn live-control rule only reached the value buttons and
  sheet rows; with those buttons gone on narrow, the gear was still
  disabled by controlsDisabled for the whole (minutes-long) Pi turn.
  HappyComposer now passes settingsDisabled={modelEffortControlsDisabled}
  so the gear stays clickable mid-turn for Pi exactly like the buttons.

Tests: narrow + hidden-gear layout keeps Settings; narrow Pi mid-turn
gear stays enabled and opens the provider-grouped sheet.

* fix(web): address HAPI Bot Pi settings-sheet findings

Three Minor findings from the review bot on the unified Pi sheet:

- Provider-qualified selection: rows compared only modelId, so duplicate
  model IDs across providers all looked selected. Compare against
  piSelectedModel's provider+modelId when available.
- Thinking-level reset: the removed Pi panel toggled the current level
  back to null; the unified effort rows only submitted concrete values.
  Re-clicking the selected effort row now clears it for Pi.
- Memo staleness: the settings-sheet memo did not depend on
  modelEffortControlsDisabled, so a Pi disabled-state transition while
  the sheet was open left rows enabled from the prior render.

Tests: colliding model IDs highlight only the matching provider row,
re-clicking the selected effort row sends null, and a rerender with
active=false disables the open sheet's rows.

* fix(web): include piSelectedModel in settings-sheet memo deps

The overlays memo reads piSelectedModel for provider-qualified row
highlighting but only declared the derived selectedPiModel. When
piSelectedModel hydrates from absent to a qualifier that resolves to
the same catalog object, the memo is reused and duplicate model IDs
stay highlighted across providers. Add the raw prop to the dep array.

* fix(web): gate Pi model rows on catalog; reset drill-down via value button

Address the HAPI Bot review on the unified composer settings sheet:

- Pi no longer falls back to the generic synthesized modelOptions rows
  when its provider catalog is empty/loading. Selecting one of those
  would post a bare model id that runPi cannot resolve to a provider
  (first cached match or 409). The Model section now only renders for
  Pi when piModelGroups exists, and renders grouped rows exclusively.
- Closing the sheet through the model/effort value button now goes
  through handleSettingsToggle, so a Cursor variant drill-down resets
  to the base model list on reopen (previously only the gear and
  outside-click paths cleared it).

Tests: empty Pi catalog hides Model section; value-button close resets
Cursor drill-down.

* fix(web): hide Pi effort controls until the selected model resolves

Address the HAPI Bot review: with the catalog still loading/failed there
is no selectedPiModel to derive a capability map from, but the unified
effort control stayed enabled (mid-turn Pi controls are intentionally
live). Selecting a level would send set_thinking_level for a model that
may not support reasoning, and the RPC can be rejected after the sheet
closed. The old dedicated panel guarded this state.

showEffortSettings now requires a resolved, reasoning-capable Pi model;
the effort value button hides the same way. With an empty catalog Pi
exposes no settings trigger at all, matching the old control states.

Tests: unresolved Pi catalog mid-turn exposes no effort action.

* fix(web): hide the Pi model trigger until the catalog resolves

Address the HAPI Bot Minor finding: with an empty/loading Pi catalog the
model value button fell back to the bare session model id and rendered
an enabled trigger that opens no Model section. Show the button only
once the provider-qualified catalog entry resolves.
2026-08-16 22:43:10 +08:00
AnanovoandGitHub 7909c46fff feat(search): support wildcard patterns across search fields (#1571)
* feat(search): add wildcard matching to search fields

* fix(search): harden wildcard matching and file globs

* fix(search): align file matching with shared wildcard semantics

* fix(search): bound file wildcard search in runner

* fix(search): normalize outline queries through shared matcher

* fix(web): remove duplicate markdown test context field
2026-08-16 22:41:24 +08:00
AnanovoandGitHub 8dc4a50fee fix(web): prevent replaying historical assistant output (#1572)
* fix(web): prevent replaying historical assistant output

* fix(web): handle history pagination during typing handoff

* fix(web): preserve streaming handoff across history windows

* fix(web): distinguish hydrated active runs from new output

* fix(web): preserve handoff across tail hydration

* fix(web): preserve first output in user-only turns
2026-08-16 22:41:08 +08:00
AnanovoandGitHub ec19699418 fix(web): preserve session sidebar scroll during navigation (#1552)
* fix(web): preserve session sidebar scroll during navigation

* fix(web): preserve nested session pane scroll

* fix(web): avoid repeated file scroll restoration

* fix(web): preserve scroll when leaving chat file previews

* fix(web): preserve scroll after session resolution
2026-08-16 22:39:07 +08:00
AnanovoandGitHub 767e40a71f fix(web): preserve current Fork action while reading history (#1573)
* fix(web): preserve current Fork action while reading history

* fix(web): invalidate stale Fork boundary during history updates

* fix(web): invalidate Fork boundary after message consumption
2026-08-16 22:36:37 +08:00
SSU-WEI HUANGandGitHub 30504252b9 feat(web): keep quiet active sessions in the pinned top section — Running / Active / Inactive tiers (#1590)
* feat(web): keep quiet active sessions in the pinned top section (#1589)

When pin-in-progress is on, any connected session now floats above the
project folders instead of dropping down the moment it finishes
executing. The sidebar reads as three tiers:

1. In progress - running and pending work (unchanged)
2. Active sessions - quiet but connected (finished executing, operator
   usually continues the conversation)
3. Inactive - everything else, in directory groups

Also remove the duplicate showSessionSummaryInChat fixture property in
markdown-a.test.tsx that fails web typecheck on upstream main.

* test(web): cover Active section collapse, keyboard toggle, and search expansion

* fix(web): keep action-only project headers when every row floated

A directory whose sessions all floated to the pinned sections lost its
header entirely, taking copy-path and new-session-in-directory with it.
Render an action-only header for fully-floated projects so the directory
actions stay available.
2026-08-16 22:36:20 +08:00
SSU-WEI HUANGandGitHub 72483229c7 fix(web): restore Ctrl+A select-all on the chat page (#1595)
* fix(web): restore Ctrl+A select-all on the chat page

Chromium's SelectAll collapses to an empty caret when the page contains
a contenteditable (the rich composer) but focus is outside it, so
Ctrl+A + Ctrl+C on the Happy page copied nothing. Take over Ctrl/Cmd+A
at window scope when focus is outside the composer/inputs and select
the message thread manually.

Also removes a duplicate property in markdown-a.test.tsx that broke
`bun typecheck` on upstream/main.

* fix(web): restrict select-all takeover to unshifted Ctrl/Cmd+A; wire e2e spec into CI

Address review findings:
- leave Ctrl+Shift+A to the browser (matches native Chromium, where
  the shift variant is unbound)
- run the composer-copy Chromium regression spec in CI alongside
  terminal-wrap-fidelity.spec.ts
- move the spec to the root e2e/ dir so the root playwright config
  picks it up
2026-08-16 22:35:53 +08:00
SSU-WEI HUANGandGitHub 1f2fbcb142 fix(web): map codex-enveloped compact-summary to the chat block (#1582)
* fix(web): map codex-enveloped compact-summary to the chat block

The merged #1570 renders Pi compaction summaries as a dedicated chat
block via the event envelope. A compact-summary arriving in the codex
payload envelope (older import paths, future producers) would still be
silently dropped by the codex-content filter; map it to the same
agent-event the live pi wrapper emits, mirroring the existing
context_compacted handling. Adds a normalizeAgent regression test and
tightens the /compact thinking-state test to assert the last keepAlive
flips true (RPC outstanding) then false (settled).

Verified: bun typecheck clean; web normalizeAgent 12/12, cli runPi
57/57 in an isolated TMPDIR.

* fix(web): remove duplicate showSessionSummaryInChat in markdown-a fixture

Regression from #1530: the fixture object literal sets the key twice,
which breaks `bun typecheck` on upstream/main (Test workflow failing on
push). One-line cleanup; no behavior change.

Verified: bun typecheck exit 0 across cli/web/hub.
2026-08-16 22:35:31 +08:00
901f17d0ca feat(pi): support Pi slash commands from HAPI web (compact/session/model/help) (#1570)
* feat(pi): support Pi slash commands from HAPI web (compact/session/model/help)

Pi runs as 'pi --mode rpc' over piped stdio, so TUI slash commands typed in
web chat previously fell through to the LLM as plain text and silently did
nothing (notably /compact).

- shared: add Pi builtin slash command list (help/compact/session/model) so
  the web / menu exposes them; web test updated to match
- cli: intercept Pi builtin commands in runPi's user-message path
  * /compact [instructions] -> Pi compact RPC (120s timeout, works while
    streaming; summary + token delta reported back as chat messages)
  * /session -> get_session_stats formatted stats
  * /model [modelId] -> list/switch via set_model
  * /help -> supported-commands list
  * other Pi TUI builtins (/tree, /export, /reload, ...) -> explicit
    terminal-only notice instead of silent LLM pass-through
  * unknown slash text still passes through (extension commands, skills,
    templates keep working)
- gate the prompt pump with piCompactInFlight so queued prompts are not
  rejected by Pi mid-compaction; buffer commands until ready like prompts
- ListSlashCommands RPC merges HAPI builtins with Pi extension commands
- tests: parser unit tests + runPi integration tests (compact execution,
  streaming steer interception, failure reporting, FIFO blocking, model
  switch, unsupported commands, slash list merge)
- docs: document Pi slash command support in docs/guide/agents.md

* fix(pi): address review findings on slash command lifecycle

- compact timeout: fail the session (indeterminate outcome, runtime lease
  poisoned) instead of reopening the prompt FIFO into a possibly-compacting
  Pi; pump only when cleanup has not been initiated
- special commands: release the cancellation reservation before executing so
  a cancel landing mid-command is not acknowledged (hub would delete the
  queued row while the command still runs)
- tests: drop the duplicated slash-command describe block; add focused tests
  for compaction timeout with a queued prompt and cancellation during an
  in-flight special command

* fix(pi): route slash commands through the prompt FIFO and reject ambiguous models

- slash commands now share the prompt FIFO with ordinary messages: a
  /compact or /model typed after a queued prompt dispatches only after it
  (and after the active turn settles), instead of jumping the queue from
  the preparation chain
- the pump dispatches special entries out-of-band while piSpecialCommandInFlight
  keeps the FIFO blocked; steer promotion refuses slash commands
- /model <id> prefers an exact provider/modelId match and reports bare IDs
  shared by multiple providers as ambiguous instead of picking the first
- tests: FIFO ordering (queued prompt before /compact), steer-delivered
  /compact queued until settle, ambiguous/qualified model selection

* fix(pi): keep /compact interruptible, honor extension precedence, require token boundary

- head-of-line /compact dispatches even while Pi is streaming (Pi's
  compact() aborts the active generation itself); every other queued item
  still waits for the stream to settle, preserving FIFO order
- discovered extension commands / prompt templates override same-name
  builtins at message time, matching the slash-list merge precedence
- parsePiSpecialCommand requires a command-token boundary, so path-like
  text such as /compact.md or /model/config stays an ordinary prompt
- tests: interrupt rule, extension collision, reserved-name path prefixes,
  non-compact commands waiting for stream settle

* fix(pi): honor cancellation acknowledged during slash-command discovery

A cancel arriving while the chain awaits get_commands (cold cache) was
acknowledged via the preparing reservation but never re-checked, so a
canceled /compact could still execute. Re-check the cancellation marker
after discovery and drop the message before dispatch.

* fix(pi): qualify /model selectors and report failed slash RPCs once

- /model lists provider-qualified selectors (openai/gpt-5.2) so duplicate
  bare IDs remain usable and copy-pasteable; current model is qualified too
- compact/set_model failures are owned by the awaited slash/config handlers:
  the common response handler no longer emits the raw Pi error a second time
- tests: qualified listing with duplicate providers, single-message failure
  reporting for rejected /compact and /model

* fix(pi): consume slash-command queue row at dispatch

Special commands (/compact, /session, /model, /help) are executed by HAPI
itself and never delivered to Pi as prompts. Consumption was deferred until
the command finished, so a /compact run — an LLM summarization pass that can
take minutes — left the row stuck in the web queued bar for its whole
duration, then surfaced as a sent message. Consume the row the moment
dispatch starts; failures still surface via the explicit event message.

* fix(pi): guard special-command dispatch against unexpected rejections

* ci: retry Codex PR Review after infra failure (proxy 503)

* fix(pi): keep session queued-thinking grace during /compact dispatch

The queued-thinking grace is session-scoped, so clearing it while
acknowledging a dispatch-time /compact row also drops the grace for any
prompt queued behind it. /compact keeps running for minutes without
toggling Pi thinking state, which would leave the web session looking idle
while compaction and the following prompt are still pending. Only the
fast, synchronous commands (/session, /model, /help) clear the grace.

* fix(pi): render compaction summary as a dedicated chat block

The manual /compact RPC result was reported as two plain message
events ("📦 Compaction completed (tokens: …)" + "📦 Compaction
summary: …"), which the web chat renders as tiny centered status
lines — unusable for a real summary payload. Emit a structured
compact-summary event instead (summary + token delta) and render
it as an independent block: header with the delta and the summary
markdown in a scrollable panel.

Also emit the same structured event when importing Pi session
files (compaction entries), and queue the event lossless like
other user-visible messages so a disconnect cannot drop it.

Verified: bun typecheck clean; bun run test exit 0 (cli 2481
passed, web 2451 passed, hub/shared clean); runPi/loop/apiSession/
piSessions/presentation suites green.

* fix(pi): address HAPI Bot findings on compact dispatch and import

- Track compaction as thinking for its whole duration: /compact runs for
  minutes without a Pi streaming event, so the 15s queued-thinking grace
  alone left the web session looking idle while compaction and any queued
  prompts were still pending (updateThinkingState around the compact RPC).
- Imported Pi compaction summaries must use the event envelope
  (content.type: 'event') like the live wrapper's compact RPC result; the
  codex payload envelope is dropped by the web normalizer. Extend
  CodexImportedMessageSchema with the event variant.

* fix(pi): /model retries discovery when the model cache is empty

Startup model discovery can be late or fail once; using only the cached
catalog made /model report valid models as unknown. getPiModels() falls
back to the get_available_models RPC on an empty cache, used for both
listing and switching.

* fix(pi): interrupt in-flight /compact on Abort; surface startup model rejection

- The Abort action no longer waits on the runtime-mutation lease when a
  manual /compact is in flight (compaction can hold it for up to 120s,
  blowing the 25s abort deadline and failing closed). It sends the abort
  RPC directly so Pi cancels its compaction AbortController; the compact
  RPC's 'Compaction cancelled' error is not double-reported as a failure
  since Pi already emits the compaction_end(aborted) lifecycle event.
- A rejected detached startup set_model now emits a visible ⚠️ event into
  chat instead of only a debug log, restoring the pre-existing behavior.

* fix(pi): close the Abort race when /compact is queued on the mutation lock

Abort previously assumed an in-flight /compact always had its RPC issued;
the command is marked active at queue dispatch, but the compact RPC is sent
only after the runtime-mutation lock is acquired. An Abort landing in that
gap acknowledged success while the compact RPC still ran afterwards.
Track the compact's rpcStarted/cancelled state: Abort cancels a not-yet-
started compact in place (the queued callback skips it), and interrupts a
started one via the abort RPC as before.

* fix(pi): persist provider-qualified selection after /model switch

The success path updated currentModel/currentProvider and keepalive with a
bare model ID, leaving metadata.piSelectedModel on the previous provider.
The web picker prefers that metadata for selection, context-window
resolution, and effort options, so a switch like openai/gpt-5.2 ->
azure/gpt-5.2 was invisible. Persist piSelectedModel with the full
provider/modelId pair on every confirmed switch.

* fix(pi): retire pending extension UI requests when /compact interrupts a turn

The streaming-interrupt path sent the compact RPC without cancelling
pending extension UI requests first, unlike the Abort path. Editor
requests have no timeout, so the web could stay stuck on a stale
input/permission card and a later answer could be routed to the aborted
turn. Cancel all pending requests (with a response) before compacting.

* fix(pi): fail closed when the direct compact-abort RPC times out

The in-flight /compact abort branch awaited the abort RPC without the
ordinary Abort path's timeout handling: an unanswered abort left the
compaction outcome indeterminate (the compact RPC keeps the mutation
lease for up to 120s) while the wrapper still looked live. Fail the
session on PiRpcTimeoutError, mirroring the standard abort fail-closed
path.

---------

Co-authored-by: swear01 <swear01@users.noreply.github.com>
2026-08-15 11:21:45 +08:00
Kong ZhiyangandGitHub 339607bf3e fix(web): keep single tildes literal in markdown (#1471) 2026-08-15 11:18:12 +08:00
AnanovoandGitHub 386ee4121b fix(web): hide chat viewport focus outline after Home/End (#1495)
* fix(web): hide chat scroll focus outline

* fix(web): keep chat viewport keyboard focus visible

* test(web): cover chat viewport keyboard focus
2026-08-15 11:17:43 +08:00
AnanovoandGitHub 0e60697895 fix(web): prevent Rewind crashes when message history resets (#1530) 2026-08-15 11:17:25 +08:00
AnanovoandGitHub e83dbdd40a fix(web): add clear action to collapsed session search (#1544)
* fix(web): add clear action to collapsed session search

* fix(web): improve light theme clear icon contrast
2026-08-15 11:17:10 +08:00
AnanovoandGitHub 44703d0153 fix(web): localize Fork and Rewind labels in Simplified Chinese (#1546)
* fix(web): localize Fork and Rewind labels in Chinese

* test(web): cover localized history confirmation dialogs
2026-08-15 11:16:59 +08:00
AnanovoandGitHub f803967e5d fix(web): stabilize autocomplete dropdown layout (#1547) 2026-08-15 11:16:48 +08:00
AnanovoandGitHub b2ae6b90a3 fix(web): keep share actions visible during generation (#1550)
* fix(web): keep share actions visible during generation

* test(web): cover sharing during generation
2026-08-15 11:16:32 +08:00
SSU-WEI HUANGandGitHub a794be0811 fix(web): recover silently-dead SSE connections quickly, stop banner noise (#1562)
A suspended mobile tab can lose its SSE connection without the browser
ever noticing (no FIN/RST arrives). On resume the client used to wait
for the 90s heartbeat watchdog or lean on the native EventSource retry,
which can hang on a dead pooled socket - leaving a persistent
"Reconnecting... (stream error)" banner while the UI keeps working.

- useSSE: on visibility resume, distrust the connection after one missed
  heartbeat interval (45s) instead of 90s
- useSSE: abandon connection attempts that don't open within 10s (hung
  on a dead pooled socket after resume) instead of waiting for the
  watchdog; force bypasses the one-shot reconnect guard for the new
  attempt cycle
- useSSE: first reconnect attempt is immediate; exponential backoff
  starts from the second attempt
- ReconnectingBanner: localize connect-timeout and transport-error
  reasons (transport-error is already emitted by current code but fell
  through unlabeled)

Fixes #1559. Reimplements the reconnect half of #989 (closed unmerged)
on top of the current scheduler (hidden-tab deferral, slow backoff,
replay cursor).
2026-08-15 11:16:19 +08:00
AnanovoandGitHub 235d6dd6fd fix(web): clarify displayed media labels (#1565) 2026-08-15 11:15:42 +08:00
AnanovoandGitHub 7be4babfbd fix(web): shorten Codex sync label and size action menu to content (#1569)
* fix(web): refine Codex sync action menu

* test(web): cover action menu trigger anchoring
2026-08-15 11:14:45 +08:00
AnanovoandGitHub e314522982 fix(web): lower context warning thresholds (#1576) 2026-08-15 11:14:31 +08:00
AnanovoandGitHub e0354b09c0 fix(web): align new-session and settings controls (#1578) 2026-08-15 11:14:12 +08:00
AnanovoandGitHub ad72229923 feat(sessions): add on-demand AI title suggestions (#1577)
* feat(sessions): add on-demand AI title suggestions

* fix(sessions): address title suggestion review feedback

* fix(web): ignore stale title generation results
2026-08-15 11:13:49 +08:00
AnanovoandGitHub febbf8ff58 fix(web): improve session search UI (#1545)
* fix(web): improve session search UI

* fix(web): reserve space for search clear control
2026-08-13 10:14:55 +08:00
df1a56e1db fix(cursor): exclusive agent spawn lease for list-models vs ACP (#1529)
* fix(cursor): exclusive agent spawn lease for list-models vs ACP (#1520)

Add a proper-lockfile spawn lease beside agent-acp-active so model probes
and ACP transport acquire mutual exclusion atomically before spawning
agent children, closing the post-#1518 check-then-act overlap window.

Fixes #1520

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore(web): fix markdown-a test HappyChatContext mock for typecheck

Adds showSessionSummaryInChat to chatContext() so CI typecheck passes on
the PR branch (pre-existing main breakage unrelated to #1520).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Revert "chore(web): fix markdown-a test HappyChatContext mock for typecheck"

This reverts commit 4973f321a31fda772e8990ea6cda20517ca906aa.

* fix(cursor): scope spawn lease to agent spawn window only (#1520)

Hold agent-cli.spawn only around spawn('agent') in AcpStdioTransport, not
for the full ACP session. Restores N concurrent cursor sessions per host;
list-models probe lease unchanged.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(cursor): tighten spawn lease lifecycle for babysit (#1520)

Acquire spawn lease before ACP marker publish; unregister on spawn failure.
Hold list-models probe lease until child exit on timeout. Add missing
showSessionSummaryInChat to markdown-a test mock (unblocks CI typecheck).

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(cursor): re-check ACP marker after spawn lease acquire (#1520)

Close check-then-act window where ACP could publish its marker between
the inactive guard read and list-models spawn. Add regression test.

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(cursor): fix ACP-after-acquire mock call order (#1520)

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(cursor): async spawn lease + force-kill probe timeout (#1520)

Add acquireAgentCliSpawnLease (setTimeout yields) for ACP create path;
AcpStdioTransport.create() async factory. Probe timeout uses
killProcessByChildProcess(force) while holding lease until child exit.

Addresses Bugbot Majors: session-lifetime mutex (fe07b708d), probe lease
release, post-acquire re-check (137baa779), sync loop starvation, timeout
escalation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(acp): coalesce concurrent initialize() transport spawns (#1520)

Await shared bootstrapTransport promise so overlapping initialize calls
do not spawn duplicate ACP children while create() is in flight.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-12 18:42:43 +01:00
SSU-WEI HUANGandGitHub b9d1abed1d fix(web): restore scroll chaining from reasoning panel to chat viewport (#1501)
The reasoning panel carried overscroll-y-contain, which disables native
scroll chaining: after scrolling the panel to its bottom, the outer chat
viewport could not keep scrolling. #1264 removed the containment for
exactly this reason; #1398 re-added it while adding nested follow-tail
coordination, silently reverting #1264.

The coordination (onNestedScrollFollowChange pauses the outer auto-follow
while the user scrolls inside the panel) already resolves the #1397
fighting; containment is unnecessary. Drop it and add a regression test
guarding the class list.

Fixes #1500
2026-08-12 10:10:48 +08:00
51ae260a3f feat(web): settings for AGENT_NOTIFY_SUMMARY chat display (default hide) (#1477)
* feat(web): render AGENT_NOTIFY_SUMMARY as compact metadata

* fix(web): defer summary rendering until completion

* fix(shared): preserve indentation when splitting summaries

* fix(web): guard unknown summary statuses

* feat(web): settings for AGENT_NOTIFY_SUMMARY chat display (default hide)

Add hub setting sibling to emit (#1376): show compact NotifySummaryText
when on; strip footer from chat/copy when off. Store/parse/FCM unchanged.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): address #1477 Majors for display setting

Allow any namespace to GET hub-settings (PUT stays owner-only) so
sessionSummaryInChat applies hub-wide. Reject whitespace-delimited
AGENT_NOTIFY_SUMMARY examples so default-hide does not eat prose.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(shared): allow indented AGENT_NOTIFY_SUMMARY footers

Keep rejecting whitespace-delimited prose examples, but accept a
standalone footer whose only prefix is leading indentation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): poll hub display setting; hide empty notify footers

Refetch sessionSummaryInChat so open clients pick up owner toggles.
When display is on, recognized footers without status/summary/action
still strip raw JSON instead of falling back to MarkdownText.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): poll notify display once in chat shell

Move hub-settings refetchInterval off per-message hooks into HappyThread
context. Strip well-formed footers while streaming when display is off.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web,hub): QueryClient for HappyThread tests; atomic hub-settings

Wrap HappyThread mobile-scroll tests in QueryClientProvider after the
chat-shell hub-settings poll. Read/write both hub setting flags in one
settings.json snapshot under the shared lock.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Ananovo <78636812+techotaku39@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-12 10:10:36 +08:00
c1ceb83ec2 fix(web): fail-closed scheme-less markdown file links (#1519)
* fix(web): fail-closed scheme-less markdown file links

Never paint a blue SPA dead-end for path-like hrefs after #1142.
Route workspace file targets (relative, abs, ~/ when expandable) through
FilePathAnchor; keep real app routes navigable; render everything else
path-like as inert text. Defense in <A> plus expanded remark rewrite.

Refs #1452

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(web): fixture for fail-closed markdown file-link dogfood

Visual cases for #1452: preview blues vs inert dead paths vs SPA routes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): harden fail-closed markdown href policy for review findings

Stop rewriting POSIX abs in remark so <A> can workspace-check; tighten SPA allowlist; resolve .. before containment.

* fix(web): fail-closed Windows absolute markdown file links

Drive paths looked scheme-bearing and skipped containment; leave them for <A> with workspace checks.

* fix(web): autolink Windows paths as raw hrefs for containment

Bare/inline Windows abs become anchors without hapi-file rewrite so <A> can classify; compare containment case-insensitively.

* fix(web): encode Windows file links as hapi-file-candidate

Backslash paths were URI-normalized to %5C before <A>; candidate encoding preserves the path for workspace classification.

* fix(web): satisfy InertMarkdownHref href type for candidate paths

* fix(web): resolve ~/ against /root workspaces in markdown hrefs

* fix(web): reject non-Windows hapi-file-candidate payloads

* fix(web): decode percent-encoded markdown paths before containment

* fix(web): fail-closed empty hapi-file-candidate hrefs

* fix(web): honor Vite BASE_URL and normalize candidate scheme detection

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-12 09:30:37 +08:00
SSU-WEI HUANGandGitHub d396e9d6d4 feat(voice): curate dictation credential presets to ElevenLabs, OpenAI, Groq (#1474)
* feat(voice): curate dictation credential presets to ElevenLabs, OpenAI, Groq

Groq transcription was already wired end-to-end (GROQ_API_KEY,
whisper-large-v3, standard mode), but the credential onboarding panel
listed five providers with no hint that Groq is supported, so mobile
users could not discover it.

- Curate Settings > Voice > Dictation credential presets to ElevenLabs,
  OpenAI, and Groq (Deepgram / OpenAI-compatible remain fully supported
  via env and stay listed when configured)
- Name the three presets in the empty-state and manage hints (en + zh-CN)
- Lock the curated list in with a web preset test, a hub route test for
  the Groq whisper-large-v3 proxy, and shared provider-listing coverage
- Note the presets and no-restart save behavior in voice-assistant.md

Verified: bun typecheck (cli+web+hub) and targeted suites pass; full
test gate green except pre-existing load-sensitive runner stress tests.

* fix(voice): keep legacy dictation providers manageable when configured

HAPI Bot review finding (Major): curating the onboard panel to the three
presets made settings-managed Deepgram / OpenAI-compatible credentials
impossible to rotate or clear from the UI.

- Re-add deepgram / openai-compatible to the onboard provider list
  conditionally when credentials exist, restoring update/clear controls
- Fall back to the first preset if the selected provider leaves the list
- Cover the conditional list in the preset test

* fix(voice): surface partial OpenAI-compatible credentials in onboard panel

HAPI Bot follow-up finding (Major): hub marks openaiCompatible.configured
only when both base URL and model exist, so api-key-only or endpoint-only
stored settings lost the UI path to rotate or clear them.

- Gate the openai-compatible onboard entry on any stored field (base URL,
  model, or API key) via hasOpenAICompatibleCredentials()
- Cover api-key-only / base-url-only / model-only cases in tests
2026-08-11 22:27:44 +08:00
SSU-WEI HUANGandGitHub e6b9fd68e6 feat(pi): queue mid-turn messages by default; steer only via explicit per-message Steer button (#1480)
* feat(pi): queue mid-turn messages by default; steer only via explicit per-message Steer button

Pi (PyAgent) was the only flavor whose ordinary composer submission while
streaming bypassed the queue: the web resolved it to deliveryMode 'steer'
and the CLI dispatched a native steer into the running turn immediately,
with no waiting state. This makes Pi match Codex/Claude behavior (issue
#1466): mid-turn messages wait in the queue by default, and the operator
delivers one into the running turn with the new per-queued-message Steer
button.

- web: resolveMessageDeliveryMode now queues for every flavor; QueuedMessagesBar
  gains a Steer button (pi + thinking + remote-controlled + immediate rows)
  backed by a new useSteerQueuedMessage hook + api.steerMessage.
- hub: POST /sessions/:id/messages/:messageId/steer -> syncEngine.steerQueuedMessage
  (pi-only gate, remote-only, scheduled/absent/invoked rejection) -> RPC.
- cli: pi runner registers 'steer-queued-message'; a queued message is promoted
  into the active turn via the existing PiSteerDispatcher (target generation
  captured at promote time; turn-ended steers fall back to the prompt FIFO).
  Steers requested while the message is still preparing are deferred and
  promoted right after preparation completes.
- Removed the now-dead Alt+Enter / touch-hold queue gesture (its only purpose
  was opting out of the removed automatic steer).

Verified: bun typecheck; cli/hub/web/shared suites (env-dependent runner
integration + kimi wire-locator flakes reproduce on pristine upstream and
are unrelated to this diff).

* fix(pi): preserve queued messages on rejected steers and pin the steering generation

Addresses both Major findings from the HAPI Bot review of PR #1480.

- steerDispatcher: a deterministic native rejection (Pi responded error) now
  degrades the message to the ordinary prompt FIFO instead of emitting
  messages-consumed. A promoted queued message must not be lost just because
  the steer was rejected; the hub row stays queued until the FIFO delivers it.
  The indeterminate-timeout path keeps its fail-closed consume + escalate
  behavior (a duplicate delivery would be worse).
- runPi: the deferred-steer path now captures the streaming generation at RPC
  request time (Map<localId, generation>) instead of reading it after
  preparation completes, so a steer requested against turn G1 can never be
  injected into a turn G2 that started while the message was preparing — the
  dispatcher's generation-mismatch check degrades it to the FIFO.

Regression coverage: negative steer response preserves the entry via the FIFO
(no consume); generation rollover while preparing delivers as a normal prompt
at the next settle (no steer into the new turn).

Verified: bun typecheck; cli pi suites (48 tests), hub 1041, web 2301, shared
240 — all green; only the pre-existing environment-dependent runner
integration test fails locally (reproduces on pristine upstream).

* fix(pi): reject all scheduled steers and always clear deferred-steer bookkeeping

Addresses the two Minor findings from the HAPI Bot follow-up review.

- hub: steerQueuedMessage rejects every scheduled row — mature ones included —
  aligning the endpoint with the web UI (Steer is never offered on scheduled
  rows) and preserving scheduled-FIFO delivery semantics.
- cli: the deferred-steer bookkeeping map is now cleared in a finally on the
  preparation chain, covering the early exits (cancellation before/after
  attachment I/O, empty prepared message, preparation failure) that previously
  could leave a stale generation entry behind for the session lifetime.

Regression coverage: hub steer gate tests (mature scheduled row stays queued,
non-pi flavor rejected) and a runPi test proving cancellation wins over a
deferred steer (no steer/prompt/consume after preparation completes).

Verified: bun typecheck; hub 1043 pass, cli 2421 pass (only the pre-existing
environment-dependent runner integration suite fails locally), web 2301 and
shared 240 unchanged since their green runs.

* fix(web): reconcile stale queued rows when a steer returns invoked

Addresses the remaining Minor finding from the HAPI Bot follow-up review:
when the steer endpoint reports the message was already invoked and the
messages-consumed SSE was missed while the row was still queued, the hook
now marks the row consumed locally (mirroring useCancelQueuedMessage) so
the queued bar cannot keep a stale actionable row until the next sync.

Regression coverage: steer returning status 'invoked' reconciles the row
via markMessagesConsumed and shows no toast.

Verified: bun typecheck; web 2302 pass (hub/cli/shared unchanged since
their green runs).
2026-08-11 22:27:14 +08:00
AnanovoandGitHub eb7a762984 fix(web): clarify session list status hints (#1504) 2026-08-11 22:26:07 +08:00
AnanovoandGitHub 173da49c84 fix(web): remove duplicate queued composer gap (#1505) 2026-08-11 22:25:25 +08:00
AnanovoandGitHub c2aa4bf171 fix(web): align generated share watermark to bottom right (#1513) 2026-08-11 22:25:07 +08:00
1cd4d1137a feat(hub,cli,web): fleet runner version governance (skew, self-upgrade, soft-fail reopen) (#1108)
* fix(hub): govern runner capabilities so Cursor reopen soft-fails on skew

Hub↔runner protocol drift was reported as missing Cursor chat data when
cursor-chat-store-status was unregistered. Soft-fail reopen on probe errors,
advertise required machine capabilities, surface an unmissable upgrade banner,
and stop-runner when a newer CLI binary is already on disk.

Fixes #1084

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web,hub): make runner skew banner dismissible; gate auto-upgrade

Compact the out-of-date banner (minimize + 1h snooze + per-host Restart)
so it no longer blocks the session list. Auto stop-runner on skew stays
opt-in via HAPI_AUTO_UPGRADE_RUNNERS / autoUpgradeRunners (default off).

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): tolerate full sessionStorage on skew banner minimize

QuotaExceededError from setItem aborted minimize before React state
updated, leaving the banner stuck over the session list. Persist to
memory when storage fails; only enable Restart when a newer CLI is
already on disk; clarify opt-in is stop-runner only, not package push.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(hub): drop redundant autoUpgradeRunners; runners already self-restart

CLI version handoff already reloads the runner when the on-disk binary
mtime changes. Hub-driven stop-runner on skew duplicated that. Keep the
skew banner and manual Restart only as a stuck/disabled-handoff escape.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(cli,hub,web): runner-only caps ads; gate Restart on supervisor

Address #1108 bot Majors on the thin tip: terminal/lazy bootstraps no
longer merge CURRENT_MACHINE_CAPABILITIES into the machine row (only
asRunner registration does). Banner Restart refuses unsupervised hosts
so stop-runner cannot leave a detached laptop offline; supervised
runners advertise supervisedRestart via HAPI_RUNNER_SUPERVISED=1.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(hub,cli,web): clear sticky runner ads; docs SUPERVISED; i18n skew label

Omit-means-clear on runner registration so rollback cannot leave
supervisedRestart/capabilities sticky; always advertise boolean
supervisedRestart from asRunner. Document HAPI_RUNNER_SUPERVISED=1
and localize MachineSelector UPDATE REQUIRED.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Debian <heavygee@oos-linux.in.lockhouse>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-11 22:24:39 +08:00
0d12035674 feat(web): searchable session picker on Android share target (#986)
* feat(web): searchable session picker on share target (#980)

Add search to the Android share-target picker so operators can attach
shared content to inactive or older sessions, not just recent actives.
Reuses sidebar search helpers; caps default active list with a search hint.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): defer share pending consume until session is active

ShareSeedConsumer was consuming the sessionStorage transfer id on first
mount even when the target session was inactive. Reopening into a new
session id remounted the chat with the key already gone, dropping the
shared payload. Consume and seed only after sessionActive is true.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): bind share pending transfer to target session id

Deferring consume until active left a global pending slot that the next
unrelated active SessionChat could claim. Bind the pending transfer to
the picked session id, retarget on reopen/spawn id-swap, and only
consume when the mounting session matches.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): wire SessionListSearch date-range props on share picker

Upstream added required customStart/customEnd/onDateRangeChange to
SessionListSearch; share /share must pass them and honor the range when
filtering sessions after rebase onto v0.23.1.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): pass sessionActivityDates to share SessionListSearch

Upstream SessionListSearch now requires activity dates for the date
picker; without them CI typecheck fails and the PR chip stays needs_work.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): use cached machine labels in share picker search

Share picker now uses useMachineLabels like SessionList so stale
machine ids still match search by display name.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): align share picker with sidebar session prep and preview limit

Snapshot via prepareSidebarSessions and pass useSessionPreviewLimit
so search targets and fold cap match the main session list.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): wire SessionListSearch expanded props on share picker

Upstream search now requires expanded/onExpandedChange; default open
on the share picker so the field is available immediately.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): unblock typecheck after SessionSummary and RawSendError fields

Fill new required SessionSummary watermarks in the share picker test
helper, and set deliveryMode on abort-restore send errors.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): mock machines hooks in share page missing-state test

SharePage now calls useMachines for picker search labels; the missing-
share unit test needs those hooks stubbed without a QueryClient.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): retarget pending share on automatic session supersession

When SessionDetailRoute follows supersededBySessionId A→B, rewrite the
share pending target so ShareSeedConsumer on B can still claim it.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Debian <heavygee@oos-linux.in.lockhouse>
2026-08-11 14:25:00 +01:00
5d8cd9b8fa fix(web): exclude path-only husks from @ session mentions (#1507)
* fix(web): exclude path-only husks from @ session mentions

Mention autocomplete required a real title signal (metadata.name or
summary text) so sidebar-hidden stubs and path-basename husks cannot
win @ queries over live named sessions (#1506).

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): mention @ pool uses sidebar dedup before title filter

Titled stale duplicates hidden by prepareSidebarSessions were still
@-able and could outrank the live row. Align mention candidates with
the visible list, then keep the #1506 title-signal exclusion.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-11 12:38:46 +01:00
SSU-WEI HUANGandGitHub d147ae00aa fix(web): rename storageUsagePie helper to storageUsageSlices to avoid macOS case-collision with StorageUsagePie.tsx (#1483)
Since #1383 renamed the helper to storageUsagePie.ts, the same directory
contained both StorageUsagePie.tsx and storageUsagePie.ts. On case-insensitive
filesystems (macOS), extensionless imports of the component resolve to the
helper because '.ts' is tried before '.tsx' and 'StorageUsagePie.ts' matches
'storageUsagePie.ts' case-insensitively, breaking typecheck and component
tests on macOS. Linux CI is unaffected.

Renames the helper (and its test) to storageUsageSlices.ts, which cannot
collide, and updates the two importers. Fixes #1482.
2026-08-11 10:04:18 +08:00
AnanovoandGitHub db46b4e08f fix(web): hide unavailable history actions and reorder message actions (#1494)
* fix(web): reorder and hide history actions

* test(web): cover locked history actions
2026-08-11 10:03:09 +08:00
AnanovoandGitHub f63d4bb83b fix(web): remove trailing ellipses from search placeholders (#1449) 2026-08-10 10:50:50 +08:00
AnanovoandGitHub a36df44221 fix(web): left-align confirmation dialog descriptions (#1434) 2026-08-10 10:50:36 +08:00
AnanovoandGitHub ffd0c752ca fix(web): align and remember Codex-family permission mode (#1410)
* fix(web): align and remember Codex-family permission mode

* fix(web): restore family permission preferences for all agents

* fix(web): scope legacy yolo migration to Codex
2026-08-10 10:48:26 +08:00
AnanovoandGitHub ad7f2a4084 fix(web): keep shared-image titles in sync with renamed sessions (#1411)
* fix(web): use renamed session title in share images

* ci: rerun failed checks
2026-08-10 10:47:46 +08:00
AnanovoandGitHub ac5e959045 fix(web): return chat file previews to conversation (#1415)
* fix(web): return chat file previews to conversation

* chore: retrigger pull request checks
2026-08-10 10:47:34 +08:00
SSU-WEI HUANGandGitHub 1dd7a49f42 fix(web): keep Pi controls available during message send (#1442) 2026-08-10 10:47:19 +08:00
b8a765d4ef fix(web): keep project pin inside groups below In progress (#1458)
* fix(web): keep project pin inside groups below In progress

Revert #1432's section lift: Pin in project stays first inside its
folder and among directory groups, but must not promote whole folders
above In progress. Restore Settings copy to match.

Fixes #1457

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): align pin-in-progress Settings copy with exclusions

Describe unpinned floaters only, keep global pins above In progress,
and avoid implying every working session or project-pin folders float.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-09 12:45:01 +01:00
00b6e44869 fix(web): keep project-pin groups above In progress (#1432)
Durable project pins were losing to unpinned In progress floaters.
Render pin-containing directory groups between the global pinned band
and the In progress section; leave project-pinned rows inside groups.

Closes #1431

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-09 09:50:54 +01:00
weishu cde0507bad fix(codex): harden model discovery fallback 2026-08-09 09:04:28 +08:00
3da9f7780a feat(web): support project and global pinned sessions (#1115)
* feat(web): support persistent pinned sessions

* fix(web): preserve project hierarchy for pinned sessions

* fix(web): preserve pins during session deduplication

* fix(hub): preserve pins when merging sessions

* fix(hub): migrate session pins from schema v15

* chore: retrigger PR review

* chore: retrigger PR review

* chore: retrigger PR review

* chore: retrigger PR review

* fix: align pinning with schema and sidebar filters

* fix(web): expose pinning in session header menu

* test(hub): expect schema v17 after pin migration

* fix(web): report pin action failures

* chore: retrigger PR review

* chore: retrigger PR review

* chore: retrigger PR review

* chore: retrigger PR review

* fix: address pinning review regressions

* fix(web): scope pin error toast to session rows

* test(hub): expect schema v20 after migration

* fix(hub): preserve latest source pin during merge

* test(hub): expect schema v22 after pin migration

* feat(web): add project and global session pin modes

Support mutually exclusive project vs global pins, surface both in the
session action menu, and render globally pinned sessions in a top-level
sidebar group with project path labels.

* fix(web): polish pinned section icon and divider alignment

* fix(web): tighten pinned section title icon alignment

* fix(web): restore original pinned section pin icon shape

* fix(web): rename pinned section to pinned sessions

* fix(hub): prefer stronger pin mode when merging sessions

Keep global pins over project pins during consolidation so a project-pinned source cannot downgrade an already or concurrently global-pinned target.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): keep inactive project-pinned groups expanded

Pinned sessions should stay easy to find after reload; do not hide them behind the default inactive-group collapse.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): keep project pins in directory groups

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-08 16:07:21 +01:00
17d1ea0c75 fix(web): close composer settings on outside click (#1354)
* fix(web): close composer settings on outside click

Co-Authored-By: Codex <noreply@anthropic.com>

* fix(web): capture composer outside clicks

Co-Authored-By: Codex <noreply@anthropic.com>

---------

Co-authored-by: Codex <noreply@anthropic.com>
2026-08-08 13:53:48 +08:00