Skip to content

fix: connection and server runtime fixes (upstream G6) - #998

Merged
rynfar merged 12 commits into
pylonfrom
upstream/2026-10-03-g6-connection-runtime
Oct 3, 2026
Merged

rynfar merged 12 commits into
pylonfrom
upstream/2026-10-03-g6-connection-runtime

Conversation

@rynfar

@rynfar rynfar commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Ports upstream group G6 (connection and server runtime) from T3 Code. It covers relay tombstone noise, idle shell metadata reloads, how reconnects back off, analytics retries, Codex API-key identity warnings, slow editor discovery, and updating a server too old for the client to connect to. Part of upstream cycle #996.

Sources

Upstream SHA Outcome How
d668ffcd64d74daba16520cbbfb0fdb431983eac subagent threads stop publishing tombstones to the relay Adopted Clean cherry-pick -x into Pylon's AgentAwarenessRelay. The relay identity and publish path are unchanged. A subagent thread only skips publishing when this relay has never published state for it.
8bc40b4e07bb7b4b0f71876d59520360c9bf958c idle shells stop reloading every project once a minute Adopted + adapted Clean cherry-pick. A follow-up commit moves the mapping into projectsWithResolvedRepositoryIdentities in ShellStream.ts and adds regression tests, because upstream shipped no test. repositoryIdentity is the only enriched field in Pylon, so the refresh frames carry the same data as before.
a7b3ce8c0896d123a7c3f02c586ff8193841cc09 Pi and ACP Registry drop the Early Access badge Adopted, Pylon semantics kept The badge comes off Pi and ACP Registry only. Prime Agent keeps its Pylon-owned "Early Access" badge, and its tests (ProviderSettingsForm.test.ts, providerIconUtils.test.ts) still pass.
22e9d35613305a04a28e96f83abc10c1bcf4aa8a outdated servers can be updated when the client can't connect Adapted Conflicts were resolved for Pylon. (1) User-facing copy says "Update Pylon on …" and "compatible Pylon version" instead of "T3 Code". (2) registry.ts keeps Pylon's Equal.equals(target/profile) matching and its expectedRelayTarget race guard, and gains unsupportedState(...). (3) Pylon's SavedBackendListRow has a different layout, so the OutdatedServerUpdateAction button sits next to "Check again" in Pylon's action column. The installer and self-update boundaries are unchanged. The client only drives an update when the host descriptor advertises serverSelfUpdate. For a desktop-managed host it also requires desktopAppUpdate === true, so desktop-managed updates stay with the desktop app. The t3@<version> toast copy matches Pylon's existing ServerUpdateAction.
9333509c918083cbfb7e66759ddbcbfa71a3a452 reconnects back off with jitter and keep healthy sockets Adopted + adapted The supervisor and wakeups changes applied cleanly, and span/telemetry names are unchanged (EXC-10). In AnalyticsService the retry, backoff, uuid and flush-lock change was merged on top of Pylon's no-baked-in-key gating: there is still no default PostHog key, and nothing is sent without one. Both Pylon's no-key test and upstream's retry/drop test are kept. In connection-runtime.md, Pylon's "retry policy" wording was merged with the new backoff paragraph.
bf7121d7a25fe84d76561c3142b9433615a703a1 API-key Codex installs no longer warn on every start Adopted The doc-comment conflict was resolved to keep Pylon's ~/.pylon-code/telemetry/anonymous-id path.
a8927712f8b3338fa3c47a0c657b6e11d7e9aaec Codex auth tokens are an omitted key Adopted Clean cherry-pick.
0080e80c00a3e333e3dcafd85b2615d56f84e3b8 editors appear once a slow discovery scan finishes Adopted Only conflict was an import (Pylon no longer imports Stream in externalLauncher.ts). Pylon's ServerConfigStreamEvent union matches upstream's, so withLateEditorConfig folds every live event type.

No upstream hunks were skipped. G1-owned services (RunExecutionService, ProviderSessionManager, EventSink, EffectOutbox) were not touched.

Pylon additions

  • test: projectsWithResolvedRepositoryIdentities regression tests. A refresh carries only the changed roots, the latest change for a root wins, and unknown roots are ignored.

  • test: relay-target supervisor tests:

    • A relay session that answers a probe survives an offline report and an explicit retry.
    • A relay credential change during a stalled probe still ends and replaces the session.

    Together with the upstream tests these cover primary (local), relay, and multi-environment registry reconnects. The new registry test is "keeps one session per environment across concurrent registrations and retries".

  • Lint cleanup in adopted tests: the analytics decoder is hoisted to module scope, and the editor test uses Effect.undefined.

Review follow-up (fix(web): confirm before updating a host too old to connect)

  • Confirmation before any restart. updateOutdatedHost now reads the host descriptor, then asks a confirm(plan) callback before opening the socket or reporting progress, and interrupts with nothing sent if declined. Web shows requestConfirmDialog with outdatedHostUpdateConfirmation(plan):
    • Desktop-managed: "Update the Pylon desktop app on X to V? It will close and relaunch on that machine, and agent sessions running there will stop."
    • Other methods: "Update Pylon on X to V? The server will restart, and agent sessions running there will stop."
    • A declined confirmation leaves an earlier failed-update state visible. The progress fromVersion now comes from the fresh descriptor.
  • The success toast says "Desktop app relaunched on V." when the result method is desktop-app.
  • The block message for self-updatable outdated hosts names desktop/web as the place to start the update (mobile has no action).
  • Fixed the stacked doc comments in ShellStream.ts.
  • Tests:
    • Confirm runs before any stage or socket, in order.
    • A declined desktop-managed update is interrupted with no socket, no stage and no registry writes.
    • Confirmation copy for each method.
    • Block-message copy.

Verification

  • vp test run on 13 files: AgentAwarenessRelay, ShellStream, AnalyticsService, Identify, externalLauncher, ws, the client-runtime connection tests (compatibility, onboarding, outdatedHostUpdate, registry, supervisor), ProviderSettingsForm, providerIconUtils. 13 files and 218 tests pass, 1 skipped (already skipped before this change). After the follow-up tests: supervisor and ShellStream 70/70 pass, AnalyticsService and ws 13/13 pass.
  • Typechecks pass (exit 0) for vp run -F t3 typecheck, @t3tools/client-runtime, @t3tools/web, @t3tools/contracts and @t3tools/mobile. No new diagnostics or suggestions in changed lines; the remaining suggestions are on lines that predate this branch. Desktop and shared were not touched.
  • vp lint on changed files: the remaining warnings were already there before this branch (an unused layerTest in AnalyticsService, React Compiler memoization in ConnectionsSettings). vp fmt --check: clean.

Not verified / notes

  • No UI screenshots. The new "Update" button for outdated saved backends in Settings → Connections was not checked in a browser, because browser use was out of scope for this port. Only type and unit coverage exists.
  • Not tested end to end against a real v1 Pylon host. The update runs over a bare socket using the self-update RPCs (serverUpdateServer, serverUpdateServerWithProgress, serverCommitDesktopUpdate), whose wire shape upstream says has not changed across protocol versions. The outdated-host path polls the descriptor for up to 4 minutes and does not reuse Pylon's desktop commit-retry loop (waitForDesktopUpdateTarget); a desktop host that relaunches without installing fails after the timeout. This is now documented in docs/internals/connection-runtime.md.
  • Mobile shows no update button. Pairing an outdated host from mobile now saves it as an unsupported connection instead of rejecting it, because the onboarding change is shared (mobile pairing calls the same preparePairingRegistration, covered by onboarding.test.ts). For a host that can update itself, the block message now adds "Pylon on desktop or web can start the update from Settings → Connections."

Part of upstream cycle #996.

🤖 Generated with Claude Code

juliusmarminge and others added 10 commits October 3, 2026 13:28
… (#15016)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
(cherry picked from commit d668ffcd64d74daba16520cbbfb0fdb431983eac)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…#14893)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 8bc40b4e07bb7b4b0f71876d59520360c9bf958c)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ge (#14915)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
(cherry picked from commit a7b3ce8c0896d123a7c3f02c586ff8193841cc09)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…connect (#15002)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 22e9d35613305a04a28e96f83abc10c1bcf4aa8a)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… sockets (#14897)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 9333509c918083cbfb7e66759ddbcbfa71a3a452)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…4903)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>
(cherry picked from commit bf7121d7a25fe84d76561c3142b9433615a703a1)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…14908)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>
(cherry picked from commit a8927712f8b3338fa3c47a0c657b6e11d7e9aaec)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 0080e80c00a3e333e3dcafd85b2615d56f84e3b8)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Extract the upstream 8bc40b4e07 refresh mapping into ShellStream so the
no-re-enrichment behavior has focused regression coverage.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Add relay-target supervisor coverage for probe-instead-of-replace and
credential changes during a probe, hoist the analytics test decoder, and
use Effect.undefined in the late editor config test.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Oct 3, 2026
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire 4.9 KiB 4.9 KiB −40 B (−0.8%) 6.8 KiB ✅
Codex Thread snapshot wire 3.7 KiB 3.7 KiB 0 B (0.0%) 4.9 KiB ✅
Codex Live turn WebSocket wire 1.2 KiB 1.1 KiB −40 B (−3.3%) 2.0 KiB ✅
Codex Live turn WebSocket decoded 20.4 KiB 20.4 KiB −41 B (−0.2%) 29.3 KiB ✅
Codex Live turn messages 2 1 −1 (−50.0%) 8 ✅
Claude Total thread wire 4.9 KiB 4.9 KiB 0 B (0.0%) 6.8 KiB ✅
Claude Thread snapshot wire 3.7 KiB 3.7 KiB 0 B (0.0%) 4.9 KiB ✅
Claude Live turn WebSocket wire 1.2 KiB 1.2 KiB 0 B (0.0%) 2.0 KiB ✅
Claude Live turn WebSocket decoded 20.8 KiB 20.8 KiB 0 B (0.0%) 29.3 KiB ✅
Claude Live turn messages 2 2 0 (0.0%) 8 ✅

Baseline: 30ec43a · PR result: 8df76f3 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 106.1 KiB
  • Claude decoded thread snapshot: 106.4 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

rynfar and others added 2 commits October 3, 2026 13:44
The outdated-host update restarted the remote server, or relaunched a
desktop-managed app, on a single click. The runtime now reads the host
descriptor, asks for confirmation naming the method and the agent sessions
that will stop, and sends nothing when declined. The success toast reports
a desktop relaunch, the block message tells clients without an update
action that desktop or web can start it, and the connection-runtime doc
records the bare-socket path and its four-minute no-recommit timeout.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Replace the EnvironmentRegistry service casts with a helper that builds the
full service and dies on unexpected calls.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants