Skip to content

fix(desktop): prevent browser screenshot filename collisions - #14784

Merged
Yash-Singh1 merged 1 commit into
pingdotgg:mainfrom
saphid:upstream-browser-screenshot-identity
Oct 6, 2026
Merged

Yash-Singh1 merged 1 commit into
pingdotgg:mainfrom
saphid:upstream-browser-screenshot-identity

Conversation

@saphid

@saphid saphid commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Problem

If you take two desktop Browser screenshots of the same site in the same millisecond, both get the same filename. The second save silently overwrites the first image.

Why this qualifies

This is a small, obvious data-loss bug fix under CONTRIBUTING: every successful capture should keep its own file. There is no linked issue or prior maintainer discussion. The change is one expression in the desktop screenshot ID, plus one regression test. Capture, save, reveal, copy-path and copy-image behaviour are all unchanged.

Fix

PreviewManager.captureScreenshot now adds an eight-character UUID suffix to the screenshot ID, and so to the filename. Agent MCP screenshots already use exactly this format, in apps/server/src/mcp/McpHttpServer.ts.

Evidence

Environment: macOS 26.5.2 (arm64), a locally built Electron 44.4.2 desktop client and a disposable local page with isolated state. The window is 1280 × 850 CSS px, the Browser page is 539 × 758 CSS px, and DPR is 2.

Versions verified:

  • Focused tests and builds were re-run on upstream main f870c419fc.
  • The desktop media below was captured on main 43bd667739 and on the previous head of this PR (53488e872b). The images carry those labels.
  • The capture is still valid for the rebased head:
    • The production change is byte-identical.
    • Main changed none of the files on the capture path between those commits: preview/Manager.ts, preload.ts, the desktop IPC channel and method, PreviewView.tsx and the contracts IPC type.

Reproduction. Both runs use the same Browser panel, page and viewport, and start with an empty screenshot directory:

  1. Capture the page in state A with the Browser panel's Capture screenshot button. This goes through the real desktop:preview-capture-screenshot IPC handler.
  2. Change the page to state B and capture again.
  3. Compare the returned IDs and paths with the files on disk and their SHA-256 hashes.

How the collision is forced. A hook at the capture boundary pins only the artifact naming timestamp, to 2026-10-03T00:00:00.000Z. Everything else is real: Electron capturePage, PNG conversion, file writes and rendering. The two requests started 62 ms apart on main and 72 ms apart with the fix. This reproduces the equal-timestamp collision deterministically. It does not claim the captures were naturally simultaneous.

Before (main).

  • Both requests return browser-screenshot-127-0-0-1-murml1c0 and the same path.
  • Only one file is left on disk. Its hash matches capture B, so capture A was overwritten.
browser-screenshot-127-0-0-1-murml1c0.png  77592 bytes
SHA-256 67c367e55d1d592da40fb8b3ea154bf752c2bef8c87ee30b5ff7c7f28111f0d3

Before: real desktop Browser screenshot flow leaves one overwritten artifact

Before: desktop Browser panel and overwritten screenshot artifact

Before: directory listing transcript shows one file containing capture B

After (this PR).

  • The timestamps still match.
  • The two IDs and paths differ.
  • Both files are on disk, and each matches its own captured image.
browser-screenshot-127-0-0-1-murml1c0-9a74238e.png  75187 bytes (A)
SHA-256 49041333cbd4269294c6c75b2fb31b7b99387271231a22014f7273e08fa18d2d
browser-screenshot-127-0-0-1-murml1c0-42b8ba4f.png  77592 bytes (B)
SHA-256 910818ea9939730fd350ce7aaabbec3082dbf9fcc3e6cfa46ecf529256c7d2dc

After: real desktop Browser screenshot flow preserves both distinct artifacts

After: desktop Browser panel and two preserved screenshot artifacts

After: directory listing transcript shows two files matching captures A and B

Recordings: before, after.

  • They are timestamped real page screenshots sampled at about 10 fps. The 62–72 ms gap between the two requests is shorter than that sampling interval. So the recordings show the state change and the final result, and the request receipts establish that two requests were made. They say nothing about frame-rate performance.
  • The "Harness disk check" text on the page is a test-harness annotation filled in from the actual directory listing. It is not product UI.
  • The directory images are labelled transcripts of the actual disk listings, with the full hashes split across lines for readability.

Focused commands run at this head, on main f870c41:

Command Result
vp test run src/preview/Manager.test.ts (from apps/desktop), with main's Manager.ts 1 failed, 95 passed. The new test fails with expected 'browser-screenshot-example-com-0' not to be 'browser-screenshot-example-com-0'
Same command with this PR 96 passed
vp run --filter @t3tools/desktop typecheck pass
vp lint --report-unused-disable-directives and vp fmt --check on both changed files pass
vp run build:desktop pass
node scripts/release-smoke.ts pass
node apps/desktop/scripts/verify-preload-bundle.mjs pass when run with process.platform set to linux, which is how CI's Linux host runs it

On macOS, the preload verifier fails with window is not defined at a darwin-only listener. That failure is not caused by this PR:

  • main fails the same way.
  • The built preload.cjs has the same SHA-256 on main and on this branch.
  • This PR changes no preload source, verifier or bundler config.

Surfaces

  • Desktop: fixed. PreviewManager.captureScreenshot is the only place Browser panel screenshots get their name. Its only caller is the Browser panel's Capture screenshot control, through the desktop:preview-capture-screenshot IPC handler.
  • Web (app.t3.codes and npx t3): not affected. Only the desktop Browser panel writes these files. The server's MCP screenshot path already uses this suffix.
  • Mobile: not affected. Mobile has no desktop Browser panel capture.
  • Local / remote-relay / tunnel: not affected. Screenshots are captured and written on the desktop machine, whatever environment it is connected to. The ID format is not part of any wire contract, and the artifact type is unchanged.
  • Providers (Codex, Claude, Cursor, Grok, OpenCode, Antigravity): not affected. This is not provider-shaped behaviour.

Not checked

  • Naturally occurring same-millisecond collisions. The demo pins the naming timestamp instead.
  • Windows and Linux desktop runtimes.
  • Remote/relay/tunnel sessions, and multi-environment sessions.
  • The desktop media was not recaptured after the rebase. It is reused because the capture path and the production change are byte-identical, as explained above.

GPT-6.1 Sol, GPT-6 Astra and Claude Opus 5.5 via T3 Code
🤖 Generated with Claude Code

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Oct 2, 2026
macroscopeapp[bot]
macroscopeapp Bot previously approved these changes Oct 2, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at fa56909

Macroscope's review found this PR approvable — This is a small, self-contained desktop bug fix that adds a UUID suffix to screenshot filenames to prevent overwrites. Capture behavior, artifact structure, and the IPC contract remain unchanged, with focused regression coverage added.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge juliusmarminge added the macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews label Oct 2, 2026 — with ChatGPT Codex Connector
@macroscopeapp
macroscopeapp Bot dismissed their stale review October 2, 2026 09:49

Dismissing prior approval to re-evaluate 47a86a7

macroscopeapp[bot]
macroscopeapp Bot previously approved these changes Oct 2, 2026
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: pingdotgg/t3code/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 56292b60-f017-4987-ac32-ebf3d9f23e98
📥 Commits

Reviewing files that changed from the base of the PR and between 53488e8 and fa56909.

📒 Files selected for processing (1)
  • apps/desktop/src/preview/Manager.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

Screenshot artifact IDs now include an eight-character UUID suffix. A regression test checks that same-site captures with the same timestamp receive distinct IDs and paths.

Changes

Screenshot artifact ID uniqueness

Layer / File(s) Summary
Generate and verify unique screenshot IDs
apps/desktop/src/preview/Manager.ts, apps/desktop/src/preview/Manager.test.ts
The ID generator appends an eight-character UUID suffix. The test checks distinct IDs and paths, matching timestamps, and PNG data written to each path.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Suggested reviewers: juliusmarminge

Merge Risk: ⚪ Minimal · up to fa569

The UUID suffix distinguishes same-time screenshot filenames, and inspected desktop consumers do not depend on the old ID format. No known workflow issue remains before merge.

Security Architecture Review

Security architecture risk: ⚪ Minimal · up to fa569

The change reduces accidental screenshot overwrites without expanding access or changing the storage destination. No material security risk was identified in the reviewed change.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The change affects filenames within the existing screenshot directory. The inspected comparison shows no additional caller, storage destination, tenant scope or privilege introduced by the suffix.

Trust Boundaries and Controls

  • observed — The URL-derived filename component is restricted to a sanitized hostname slug. The suffix is generated by Node crypto rather than page content. Existing capture retries check that the web contents still belong to the tab before capture and before accepting the image; these checks are unchanged.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the fix for desktop Browser screenshot filename collisions.
Description check ✅ Passed The description explains the problem, the fix, why the focused change qualifies without prior approval, and the verification performed. It also reports limitations and untested cases.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@saphid
saphid force-pushed the upstream-browser-screenshot-identity branch 2 times, most recently from aa7e93c to 53488e8 Compare October 3, 2026 04:10
@saphid
saphid force-pushed the upstream-browser-screenshot-identity branch from 53488e8 to fa56909 Compare October 4, 2026 06:55
@saphid

saphid commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Rebased onto current main with no production change. On CodeRabbit's note that distinct filenames are probabilistic: a collision now needs the same site, the same millisecond and the same 32-bit UUID prefix, about 1 in 4 billion for each same-millisecond pair. The server's MCP screenshot path already uses this exact format (apps/server/src/mcp/McpHttpServer.ts), so both screenshot writers now behave the same. A counter or exclusive-create write would add more machinery than this flow needs.

@macroscopeapp
macroscopeapp Bot dismissed their stale review October 4, 2026 06:55

Dismissing prior approval to re-evaluate fa56909

@saphid

saphid commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Review requested

Date (UTC) Reviewer Where
2026-10-03 Julius Discord DM

Logged so this PR shows when a maintainer was asked to review it.

@Yash-Singh1
Yash-Singh1 merged commit 411cef0 into pingdotgg:main Oct 6, 2026
30 checks passed
github-actions Bot added a commit to omarcresp/t3code-flake that referenced this pull request Oct 6, 2026
## What's Changed
* refactor(server,relay): webhook capabilities live in services, not handlers by @juliusmarminge in pingdotgg/t3code#16232
* fix(server): a T3 Connect preferences save finishes even if the client disconnects by @juliusmarminge in pingdotgg/t3code#16266
* refactor(server): import service modules as namespaces, not aliased layers by @juliusmarminge in pingdotgg/t3code#16267
* feat(server): log how long PR watches stay quiet before they end by @t3dotgg in pingdotgg/t3code#16262
* feat(server,web): choose where new worktrees are created by @juliusmarminge in pingdotgg/t3code#16231
* perf(server): idle status polls and PR sweeps start fewer git processes by @t3dotgg in pingdotgg/t3code#16272
* perf(server): PR watches spend ~90% fewer GitHub points by checking a 1-point fingerprint first by @t3dotgg in pingdotgg/t3code#16270
* fix(pull-requests): PR detail reads no longer drain the GitHub quota by @t3dotgg in pingdotgg/t3code#16280
* refactor: layer variables are named layer or layerXyz by @juliusmarminge in pingdotgg/t3code#16282
* refactor(server): T3 Connect link capabilities live in a CloudLink service by @juliusmarminge in pingdotgg/t3code#16265
* fix(web): sidebar drag and drop no longer snaps back by @t3dotgg in pingdotgg/t3code#16291
* fix(web): inline HTML renders no longer trap the thread's scroll by @t3dotgg in pingdotgg/t3code#16283
* refactor(server): one module per service instead of Services/ and Layers/ folders by @juliusmarminge in pingdotgg/t3code#16295
* chore(review): configure CodeRabbit in TypeScript by @esthor in pingdotgg/t3code#16281
* docs: put the Effect and web UI review rules in the docs by @esthor in pingdotgg/t3code#16286
* chore(lint): require a reason on every lint and type-checker suppression by @esthor in pingdotgg/t3code#16294
* refactor(relay): import HookInboxObject once, as a namespace by @juliusmarminge in pingdotgg/t3code#16307
* fix(web): a rejected desktop-local credential is not retried every poll by @juliusmarminge in pingdotgg/t3code#16273
* feat(desktop): the renderer's bootstrap token rotates every 12 hours by @juliusmarminge in pingdotgg/t3code#16275
* fix(web): recover from a closed IndexedDB connection by @juliusmarminge in pingdotgg/t3code#16311
* fix(relay): stop forcing manual relay deploys by default by @juliusmarminge in pingdotgg/t3code#13563
* feat(relay): measure the managed tunnel backlog by @juliusmarminge in pingdotgg/t3code#13564
* feat(relay): clean up tunnels of hosts that never registered recovery by @juliusmarminge in pingdotgg/t3code#13565
* perf(relay): delete expired tunnels four at a time within a time budget by @juliusmarminge in pingdotgg/t3code#13566
* feat(connect): tell users when an idle tunnel was removed by @juliusmarminge in pingdotgg/t3code#13567
* docs(relay): add the legacy tunnel cleanup rollout runbook by @juliusmarminge in pingdotgg/t3code#13568
* chore(review): point CodeRabbit at the web UI conventions by @esthor in pingdotgg/t3code#16324
* chore(review): turn off CodeRabbit's docstring coverage check by @esthor in pingdotgg/t3code#16328
* refactor(server): CloudLink keeps only the link lifecycle; pure checks live beside it by @juliusmarminge in pingdotgg/t3code#16340
* refactor(server): CloudLink fails with its own errors; the connect routes map them to HTTP by @juliusmarminge in pingdotgg/t3code#16341
* refactor(server): replay guards stay in CloudLink by @juliusmarminge in pingdotgg/t3code#16349
* fix(server): forks no longer merge into their upstream repo's project group by @t3dotgg in pingdotgg/t3code#16353
* fix(server): stop the startup project sync from delaying the app window by @Mnigos in pingdotgg/t3code#14912
* fix(web): avoid blocking image preparation conversions by @Bil0000 in pingdotgg/t3code#13342
* fix(server): return partial workspace index on timeout by @Michel-Liao in pingdotgg/t3code#11500
* fix(server): probe project favicon candidates concurrently by @ishaanko in pingdotgg/t3code#12543
* fix(observability): a failing trace disk no longer stalls the server by @t3dotgg in pingdotgg/t3code#13758
* fix(server): status polling no longer locks the git index by @ahalekelly in pingdotgg/t3code#14718
* perf(shared): scan PATH once per command before spawning, not on every spawn by @SkiTee3000 in pingdotgg/t3code#12600
* fix(server): main's startup auto-pull test compiles again by @t3dotgg in pingdotgg/t3code#16357
* fix(server): project favicons stop being rescanned every minute by @t3dotgg in pingdotgg/t3code#16206
* fix(server): Claude limits load again for users with large transcript histories by @t3dotgg in pingdotgg/t3code#16358
* fix(server): caches and ids are written atomically by @juliusmarminge in pingdotgg/t3code#16242
* fix(server): one-shot initializers no longer race by @juliusmarminge in pingdotgg/t3code#16260
* fix(server): the PR cache sweep only removes real entry files by @juliusmarminge in pingdotgg/t3code#16285
* chore: keep one copy each of undici 8 and ws 8 by @juliusmarminge in pingdotgg/t3code#16211
* fix(shared): DrainableWorker keeps running after a failed item by @juliusmarminge in pingdotgg/t3code#16223
* fix(server): metrics count interrupted work on the monotonic clock by @juliusmarminge in pingdotgg/t3code#16207
* refactor(web): import connection storage as a namespace in its test by @juliusmarminge in pingdotgg/t3code#16315
* fix(contracts): trimmed IDs round-trip by @juliusmarminge in pingdotgg/t3code#16300
* fix(server): main's settings, keybindings and session tests compile again by @juliusmarminge in pingdotgg/t3code#16363
* chore(lint): catch known tags with Effect.catchTags by @esthor in pingdotgg/t3code#16361
* fix(observability): T3 Connect tracing stops at the relay boundary by @juliusmarminge in pingdotgg/t3code#16314
* fix(relay): error and deadline responses carry CORS headers by @juliusmarminge in pingdotgg/t3code#16253
* fix(web): bring back the live shimmer on work log rows by @juliusmarminge in pingdotgg/t3code#16372
* refactor: Effect code gets UUIDs and SHA-256 from Effect's Crypto by @esthor in pingdotgg/t3code#16377
* fix(relay): export traces through one tracer, one request span each by @juliusmarminge in pingdotgg/t3code#16382
* fix(server): Pi thread titles use linked PR context by @juliusmarminge in pingdotgg/t3code#16210
* fix(desktop): retry transient bearer bootstrap and degrade on session fetch failure by @jamesvillarrubia in pingdotgg/t3code#12919
* fix(server): avoid scanning completed history for pending secrets by @Yash-Singh1 in pingdotgg/t3code#16409
* fix(orchestration-v2): let Stop recover stalled runs by @Yash-Singh1 in pingdotgg/t3code#15442
* fix(release): resolve version-qualified catalog overrides by @Yash-Singh1 in pingdotgg/t3code#16411
* fix(web): type in front of bold that starts a composer line by @saphid in pingdotgg/t3code#13217
* fix(desktop): prevent browser screenshot filename collisions by @saphid in pingdotgg/t3code#14784
* fix(server): end clone options before the repository URL by @saphid in pingdotgg/t3code#14781
* fix(web): queued messages no longer split the composer notice stack by @tristanmanchester in pingdotgg/t3code#16400
* fix(server): reject invalid explicit Bitbucket repositories by @aravhawk in pingdotgg/t3code#15876
* fix: restore desktop and server typechecks on main by @Yash-Singh1 in pingdotgg/t3code#16415
* fix(shared): find versioned JetBrains macOS app bundles by @Sypher760-gif in pingdotgg/t3code#16246
* fix(server): OpenCode 2 threads get T3 Code's MCP tools by @nkoynov in pingdotgg/t3code#16142
* feat(preview): run the browser on the environment server by @maria-rcks in pingdotgg/t3code#15328
* fix: restore service references breaking ci by @maria-rcks in pingdotgg/t3code#16495
* fix(mcp): mark declared tool failures as errors by @maria-rcks in pingdotgg/t3code#15617
* fix(release): unblock nightly browser tests and cli builds by @maria-rcks in pingdotgg/t3code#16515

## New Contributors
* @esthor made their first contribution in pingdotgg/t3code#16281
* @ahalekelly made their first contribution in pingdotgg/t3code#14718
* @SkiTee3000 made their first contribution in pingdotgg/t3code#12600
* @jamesvillarrubia made their first contribution in pingdotgg/t3code#12919
* @Sypher760-gif made their first contribution in pingdotgg/t3code#16246
* @nkoynov made their first contribution in pingdotgg/t3code#16142

**Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261005.2702...v0.0.46-nightly.20261006.2735

Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261006.2735
github-actions Bot added a commit to davidvanderklay/t3code-flake that referenced this pull request Oct 6, 2026
## What's Changed
* refactor(server,relay): webhook capabilities live in services, not handlers by @juliusmarminge in pingdotgg/t3code#16232
* fix(server): a T3 Connect preferences save finishes even if the client disconnects by @juliusmarminge in pingdotgg/t3code#16266
* refactor(server): import service modules as namespaces, not aliased layers by @juliusmarminge in pingdotgg/t3code#16267
* feat(server): log how long PR watches stay quiet before they end by @t3dotgg in pingdotgg/t3code#16262
* feat(server,web): choose where new worktrees are created by @juliusmarminge in pingdotgg/t3code#16231
* perf(server): idle status polls and PR sweeps start fewer git processes by @t3dotgg in pingdotgg/t3code#16272
* perf(server): PR watches spend ~90% fewer GitHub points by checking a 1-point fingerprint first by @t3dotgg in pingdotgg/t3code#16270
* fix(pull-requests): PR detail reads no longer drain the GitHub quota by @t3dotgg in pingdotgg/t3code#16280
* refactor: layer variables are named layer or layerXyz by @juliusmarminge in pingdotgg/t3code#16282
* refactor(server): T3 Connect link capabilities live in a CloudLink service by @juliusmarminge in pingdotgg/t3code#16265
* fix(web): sidebar drag and drop no longer snaps back by @t3dotgg in pingdotgg/t3code#16291
* fix(web): inline HTML renders no longer trap the thread's scroll by @t3dotgg in pingdotgg/t3code#16283
* refactor(server): one module per service instead of Services/ and Layers/ folders by @juliusmarminge in pingdotgg/t3code#16295
* chore(review): configure CodeRabbit in TypeScript by @esthor in pingdotgg/t3code#16281
* docs: put the Effect and web UI review rules in the docs by @esthor in pingdotgg/t3code#16286
* chore(lint): require a reason on every lint and type-checker suppression by @esthor in pingdotgg/t3code#16294
* refactor(relay): import HookInboxObject once, as a namespace by @juliusmarminge in pingdotgg/t3code#16307
* fix(web): a rejected desktop-local credential is not retried every poll by @juliusmarminge in pingdotgg/t3code#16273
* feat(desktop): the renderer's bootstrap token rotates every 12 hours by @juliusmarminge in pingdotgg/t3code#16275
* fix(web): recover from a closed IndexedDB connection by @juliusmarminge in pingdotgg/t3code#16311
* fix(relay): stop forcing manual relay deploys by default by @juliusmarminge in pingdotgg/t3code#13563
* feat(relay): measure the managed tunnel backlog by @juliusmarminge in pingdotgg/t3code#13564
* feat(relay): clean up tunnels of hosts that never registered recovery by @juliusmarminge in pingdotgg/t3code#13565
* perf(relay): delete expired tunnels four at a time within a time budget by @juliusmarminge in pingdotgg/t3code#13566
* feat(connect): tell users when an idle tunnel was removed by @juliusmarminge in pingdotgg/t3code#13567
* docs(relay): add the legacy tunnel cleanup rollout runbook by @juliusmarminge in pingdotgg/t3code#13568
* chore(review): point CodeRabbit at the web UI conventions by @esthor in pingdotgg/t3code#16324
* chore(review): turn off CodeRabbit's docstring coverage check by @esthor in pingdotgg/t3code#16328
* refactor(server): CloudLink keeps only the link lifecycle; pure checks live beside it by @juliusmarminge in pingdotgg/t3code#16340
* refactor(server): CloudLink fails with its own errors; the connect routes map them to HTTP by @juliusmarminge in pingdotgg/t3code#16341
* refactor(server): replay guards stay in CloudLink by @juliusmarminge in pingdotgg/t3code#16349
* fix(server): forks no longer merge into their upstream repo's project group by @t3dotgg in pingdotgg/t3code#16353
* fix(server): stop the startup project sync from delaying the app window by @Mnigos in pingdotgg/t3code#14912
* fix(web): avoid blocking image preparation conversions by @Bil0000 in pingdotgg/t3code#13342
* fix(server): return partial workspace index on timeout by @Michel-Liao in pingdotgg/t3code#11500
* fix(server): probe project favicon candidates concurrently by @ishaanko in pingdotgg/t3code#12543
* fix(observability): a failing trace disk no longer stalls the server by @t3dotgg in pingdotgg/t3code#13758
* fix(server): status polling no longer locks the git index by @ahalekelly in pingdotgg/t3code#14718
* perf(shared): scan PATH once per command before spawning, not on every spawn by @SkiTee3000 in pingdotgg/t3code#12600
* fix(server): main's startup auto-pull test compiles again by @t3dotgg in pingdotgg/t3code#16357
* fix(server): project favicons stop being rescanned every minute by @t3dotgg in pingdotgg/t3code#16206
* fix(server): Claude limits load again for users with large transcript histories by @t3dotgg in pingdotgg/t3code#16358
* fix(server): caches and ids are written atomically by @juliusmarminge in pingdotgg/t3code#16242
* fix(server): one-shot initializers no longer race by @juliusmarminge in pingdotgg/t3code#16260
* fix(server): the PR cache sweep only removes real entry files by @juliusmarminge in pingdotgg/t3code#16285
* chore: keep one copy each of undici 8 and ws 8 by @juliusmarminge in pingdotgg/t3code#16211
* fix(shared): DrainableWorker keeps running after a failed item by @juliusmarminge in pingdotgg/t3code#16223
* fix(server): metrics count interrupted work on the monotonic clock by @juliusmarminge in pingdotgg/t3code#16207
* refactor(web): import connection storage as a namespace in its test by @juliusmarminge in pingdotgg/t3code#16315
* fix(contracts): trimmed IDs round-trip by @juliusmarminge in pingdotgg/t3code#16300
* fix(server): main's settings, keybindings and session tests compile again by @juliusmarminge in pingdotgg/t3code#16363
* chore(lint): catch known tags with Effect.catchTags by @esthor in pingdotgg/t3code#16361
* fix(observability): T3 Connect tracing stops at the relay boundary by @juliusmarminge in pingdotgg/t3code#16314
* fix(relay): error and deadline responses carry CORS headers by @juliusmarminge in pingdotgg/t3code#16253
* fix(web): bring back the live shimmer on work log rows by @juliusmarminge in pingdotgg/t3code#16372
* refactor: Effect code gets UUIDs and SHA-256 from Effect's Crypto by @esthor in pingdotgg/t3code#16377
* fix(relay): export traces through one tracer, one request span each by @juliusmarminge in pingdotgg/t3code#16382
* fix(server): Pi thread titles use linked PR context by @juliusmarminge in pingdotgg/t3code#16210
* fix(desktop): retry transient bearer bootstrap and degrade on session fetch failure by @jamesvillarrubia in pingdotgg/t3code#12919
* fix(server): avoid scanning completed history for pending secrets by @Yash-Singh1 in pingdotgg/t3code#16409
* fix(orchestration-v2): let Stop recover stalled runs by @Yash-Singh1 in pingdotgg/t3code#15442
* fix(release): resolve version-qualified catalog overrides by @Yash-Singh1 in pingdotgg/t3code#16411
* fix(web): type in front of bold that starts a composer line by @saphid in pingdotgg/t3code#13217
* fix(desktop): prevent browser screenshot filename collisions by @saphid in pingdotgg/t3code#14784
* fix(server): end clone options before the repository URL by @saphid in pingdotgg/t3code#14781
* fix(web): queued messages no longer split the composer notice stack by @tristanmanchester in pingdotgg/t3code#16400
* fix(server): reject invalid explicit Bitbucket repositories by @aravhawk in pingdotgg/t3code#15876
* fix: restore desktop and server typechecks on main by @Yash-Singh1 in pingdotgg/t3code#16415
* fix(shared): find versioned JetBrains macOS app bundles by @Sypher760-gif in pingdotgg/t3code#16246
* fix(server): OpenCode 2 threads get T3 Code's MCP tools by @nkoynov in pingdotgg/t3code#16142
* feat(preview): run the browser on the environment server by @maria-rcks in pingdotgg/t3code#15328
* fix: restore service references breaking ci by @maria-rcks in pingdotgg/t3code#16495
* fix(mcp): mark declared tool failures as errors by @maria-rcks in pingdotgg/t3code#15617
* fix(release): unblock nightly browser tests and cli builds by @maria-rcks in pingdotgg/t3code#16515

## New Contributors
* @esthor made their first contribution in pingdotgg/t3code#16281
* @ahalekelly made their first contribution in pingdotgg/t3code#14718
* @SkiTee3000 made their first contribution in pingdotgg/t3code#12600
* @jamesvillarrubia made their first contribution in pingdotgg/t3code#12919
* @Sypher760-gif made their first contribution in pingdotgg/t3code#16246
* @nkoynov made their first contribution in pingdotgg/t3code#16142

**Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261005.2702...v0.0.46-nightly.20261006.2735

Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261006.2735
aorwall added a commit to aorwall/t3code that referenced this pull request Oct 7, 2026
Merges `pingdotgg/t3code` `cd41c4ada0` into the fork: 81 upstream
commits since `442735897f`, the base pingdotgg#207 landed.

> [!IMPORTANT]
> **Merge with "Create a merge commit", not squash.** Squashing pingdotgg#207
broke the merge base and `main` had to be force-pushed back to a real
merge commit. A squash here would do the same.

## What changed in the merge

- **Counts:** 853 files landed against 853 in the upstream range. The
fork delta is 765 files. The [tracker
entry](docs/fork/upstream-merge-log.md) explains the three files on each
side that differ.
- **Conflicts:** 36 files, resolved by the verdicts `preflight.mjs`
printed. The ones that needed more than a mechanical resolution:
- **Preview:** upstream now runs the browser on the environment server
(pingdotgg#15328). The fork's iframe preview is kept beside it in `PreviewView`,
`ThreadPreviewMiniPlayer` and `PreviewPanel`. The frame picker now uses
upstream's per-pick token for `pickActiveRef`.
- **Permissions:** upstream split its coarse scopes into granular ones
(pingdotgg#9786–pingdotgg#9791). Upstream's new gates are combined with the fork's
`FEATURES` gates in Sidebar, ProviderSettingsPanel, ChatMarkdown,
ProjectSettingsPanel, GitActionsControl and others.
- **`ws.ts` instrumentation:** upstream replaced `observeRpcEffect` with
an `RpcInstrumentation` middleware. The fork's 15 stub handlers for
Moatless-only methods are unwrapped, and those methods are added to
`RPC_AGGREGATES`.
- **`ChatView.tsx`:** the woke, parked and resume-compaction banners are
dropped, because upstream deleted them. The fork's sandbox-commands
banner and the path that runs a script from a draft thread are kept.
- **`runOnSettle`** (pingdotgg#16290): carried on the script. The editor has no
switch for it because Moatless runs no script on settle.
- **Unsupported methods:** `preview.adjust`, `preview.clearProfile` and
`terminal.observe` now declare `UnsupportedMethodError`.
- **Fork tests:** five upstream tests were adapted to the fork's deltas,
each with a `Fork:` comment.
- **Docs:**
- [`gaps.md`](docs/fork/gaps.md) adds entries for the granular scopes
and for MCP sign-in, and extends the scripts, methods and settlement
entries.
- The auth bootstrap suite entry is struck, because that file now passes
36 of 36.
- [`upstream-merge-log.md`](docs/fork/upstream-merge-log.md) has the
2026-10-07 entry.

## Usable as-is

- Upstream's granular permission gates work today. Moatless sends no
`permissions` record, so `sessionGrantsScope` falls back to
`legacyParents`, which grant every new scope (pingdotgg#10298).
- File preview errors show the path that was attempted (pingdotgg#15628).
- The diff panel keeps the chosen scope while a turn runs (pingdotgg#16571).
- The desktop browser no longer gives two screenshots the same filename
(pingdotgg#14784).
- Assorted MCP fixes on upstream's server have no effect here.

## Unsupported in Moatless / needs implementation

- **Server-hosted browser** (pingdotgg#15328): `preview.adjust` and
`preview.clearProfile`, and the `serverBrowser` capability. Moatless
doesn't report the capability, so the web client keeps its frame
runtime.
- **Passive terminal observation** (pingdotgg#9791): `terminal.observe`. A client
sends it only to a session with `terminal:read` and without
`terminal:operate`. Moatless grants operate to every session.
- **Granular scopes:** Moatless can't grant less than everything. It
needs to send a `permissions` record from `session_state` in
`crates/t3code/src/rpc/config.rs`.
- **MCP OAuth for outside agents** (pingdotgg#16336, pingdotgg#16718, pingdotgg#16335): the
`/connect-agent` consent page and "Copy MCP URL" (pingdotgg#16337). The copy
button is already hidden by `FEATURES.connections`. The route is
reachable only by a typed URL.
- **Run a project action when a worktree thread settles** (pingdotgg#16290):
needs `runOnSettle` stored on the script in
`crates/t3code/src/projection/project.rs`, and a backend that runs the
script on settle.

## Backend behavior to consider reproducing in Moatless

- **pingdotgg#16761:** a thread settles as soon as a client sees its PR merge,
without waiting for the server's poll.
- **pingdotgg#16762:** settled threads stop polling their pull requests. Moatless
polls linked PRs and would save the same requests.
- **pingdotgg#16290:** running a designated script when a worktree thread
settles, such as a teardown.

## Verification

`verify.mjs --sequential` passed every check except `test`:
duplicate-adds, tripwires, resolution-check, unsupported-methods,
lockfile, fmt, lint, typecheck and build.

- **web:** five tests failed because upstream's new tests don't know the
fork's deltas. After the fixes, `--only test --package @t3tools/web`
passes all 496 files and 6,523 tests.
- **server:** four files fail because of the sandbox, not the code:
- `OpenCodeServerLedger`, `AcpAdapterV2` and
`OrchestratorReplayFixtures` fail as they did in the 2026-10-06 merge.
The sandbox doesn't reap detached process groups, and its
`CLAUDE_CONFIG_DIR` leaks into an auth error message.
- The new `ServerBrowserPage.test.ts` needs Playwright's
`chromium_headless_shell-1223`, which the sandbox lacks.
- The fork's only changes to the server areas these tests cover are 12
lines in `Orchestrator.ts` and its testkit, which none of the failing
tests touch.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---
Moatless task:
https://moatless.soaplabstest.com/tasks/b9b339cd-86dd-464d-8b37-1dd4a0ff4be7
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:XS 0-9 changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants