diff --git a/.memory/aiden-cli-standalone.md b/.memory/aiden-cli-standalone.md index 1b86d7b8e..d536373eb 100644 --- a/.memory/aiden-cli-standalone.md +++ b/.memory/aiden-cli-standalone.md @@ -38,3 +38,5 @@ - Merging #71 (Linux desktop) took main's native C ports and `native-c-build-core.mjs` build scripts. The PR's OpenSSL/renameat2 shims were dropped because `native/shared/aiden-platform.h` carries its own SHA-256. `nativeHelperSourceHash` now also hashes `native/shared/*.h`, so a shared-header edit marks prebuilts stale. The PR's speech core carries main's "desktop" wording. - Merging #246 (root pi 0.87.1) bumped the CLI to `@earendil-works/pi-coding-agent` 0.87.1 and added a direct `@earendil-works/chord` 0.87.1 dependency. btw wraps its context in `normalizeContext`, and the child beforeTool context drops `systemPrompt`. The re-vendored advisor uses `normalizeContext`. The build's external check falls back to ESM resolution for chord's import-only subpaths and allowlists the optional `kerberos`. Session import accepts both `v: 4` (storage v1) and `version: 4` (0.84.4) journal headers. - Merging #251 (main's Remote contract revision 14) renumbered this PR's `GET /scheduled-tasks/notifications` addition to contract revision 15. The shared fixture and the Android copy are byte-identical at 15. The TS, iOS and Android fixture assertions expect 15, and the iOS fixture CodingKeys keep both main's streamInput/question/chatSkills and this PR's scheduleRunNotification. + +- 2026-09-27 review: plan index now describes Phase 6 as implemented; physical iPhone acceptance remains pending. diff --git a/.memory/chat-pull-requests.md b/.memory/chat-pull-requests.md index 29334450f..1102a16b8 100644 --- a/.memory/chat-pull-requests.md +++ b/.memory/chat-pull-requests.md @@ -4,7 +4,7 @@ Work continues on existing PR #184 (`devin/1789864248-chat-pull-requests`), isol Never normalize a supplied malformed expectedHeadSha to omission. Unknown creates remain pending even after an empty lookup; absence from a list does not establish that a mutation failed. Save link + settle intent atomically. Recovery uses the durable host/repository, independent of chat workspace changes. Same-target pending intents block repeat creates. Post-push identity comes from the frozen endpoint used by Git, never gh's inferred default repository. Unlink dismissal is durable and suppresses current-PR rediscovery until explicit relink. -Two requested Sol medium reviews identified empty-list retries, split link/intent publication, selected-remote routing, and source IPC mismatch; all remediated with focused coverage. Final verification tracked in docs/plans/chat-pull-requests-plan.md and PR #184. +Two requested Sol medium reviews identified empty-list retries, split link/intent publication, selected-remote routing, and source IPC mismatch; all remediated with focused coverage. Final verification tracked in docs/plans/completed/chat-pull-requests-plan.md and PR #184. Follow-up review fixes: store settlement checks that the operation is still pending inside the serialized write, preventing stale completions from undoing unlink. Unknown/retargeted/advanced-head attempts can be explicitly cleared only after a confirmation to check GitHub first. Within-repository create destination is named in the dialog; cross-fork upstream creation remains manual. @@ -19,3 +19,5 @@ Failed-recovery deletion follow-up: after fencing admission and draining loads/w Dotted-ID recovery isolation follow-up: DataStore recovery and PR deletion share a complete-basename matcher with the fixed hash/operation/suffix fields, preventing chat-1 from consuming chat-1.json recovery files. Cached and cold deletion regressions cover both directions and both artifact suffixes; startup recovery also preserves sibling bytes. Validation: 98 focused PR tests, 255 portable-config/storage tests, 103 service-boundary tests, TypeScript and Electron build pass. Both independent Sol reviews are clean; current-head hosted checks remain pending. Recovery-token follow-up: artifact ownership also requires the lowercase UUIDv4 operation token emitted by randomUUID. Non-UUID, wrong-version and wrong-variant lookalikes remain untouched during recovery and deletion. Existing recovery fixtures now use generated-format UUIDs. Validation: 99 focused PR tests, 255 portable-config/storage tests, TypeScript and Electron build pass. + +Status (2026-09-27 plan refresh): PR #184 merged 2026-09-23 and shipped in 0.43.0; plan moved to docs/plans/completed/. diff --git a/.memory/dictation-parakeet-modes.md b/.memory/dictation-parakeet-modes.md index c18216392..6359efdac 100644 --- a/.memory/dictation-parakeet-modes.md +++ b/.memory/dictation-parakeet-modes.md @@ -1,6 +1,6 @@ # Dictation Parakeet lifecycle, modes, and dictionary — 2026-09-27 -- Branch `feature/dictation-parakeet-modes`. Plan: `docs/plans/dictation-parakeet-modes-plan.md`. +- Branch `feature/dictation-parakeet-modes`. Plan: `docs/plans/completed/dictation-parakeet-modes-plan.md`. - **Shared, pure modules:** - `renderer/shared/dictation-preferences.ts` holds the mode resolution, idle-minute validation, and `parseDictationPreferencePatch`, which `settings:set` uses. - `renderer/shared/dictation-dictionary.ts` holds parse, apply, and add-entry. @@ -34,3 +34,5 @@ - Added shortcut/dictionary regressions; 44 focused tests, CI policy suite, desktop typecheck, and CLI build/typecheck pass. New suites are assigned to CI lanes. Independent review corrected the dictionary settings row keys to use the same locale-independent lowercase identity as parser deduplication; a Turkish-casing regression verifies distinct I/dotless-ı entries keep distinct React keys. + +Status (2026-10-01): merged in PR #279 (on main after 0.51.0); plan moved to `docs/plans/completed/`. diff --git a/.memory/dictation-secure-input.md b/.memory/dictation-secure-input.md index 452a0cc80..828dca5aa 100644 --- a/.memory/dictation-secure-input.md +++ b/.memory/dictation-secure-input.md @@ -1,6 +1,6 @@ # Dictation Secure Input warning — 2026-09-27 -Branch `feature/dictation-secure-input`; plan `docs/plans/dictation-secure-input-plan.md`. +Branch `feature/dictation-secure-input`; plan `docs/plans/completed/dictation-secure-input-plan.md`. - `pasteTranscript` (main/services/dictation-paste.ts) takes an injectable `isSecureInputActive`. Order: Accessibility check → Secure Input probe → atomic @@ -23,3 +23,5 @@ Review validation: 15 focused paste/pill tests pass, including a process-owned e The JXA probe explicitly binds `IsSecureEventInputEnabled` as a no-argument boolean function, avoiding reliance on OS BridgeSupport metadata. The plan index and PR description now match the Carbon detector and conservative copy fallback. Independent review: reading the original AXValue is optional, so text controls without an accessible value still receive a guarded paste attempt. An unconfirmed result or transport error says “Check the field — transcript copied.” It never instructs a second paste after a possibly successful attempt; the prior clipboard is restored only after confirmed delivery. + +Status (2026-10-01): merged in PR #267 (on main after 0.51.0); plan moved to `docs/plans/completed/`. diff --git a/.memory/durable-tool-outputs.md b/.memory/durable-tool-outputs.md index fdc691730..782819ebf 100644 --- a/.memory/durable-tool-outputs.md +++ b/.memory/durable-tool-outputs.md @@ -1,7 +1,7 @@ # Durable tool output / file provenance — September 22, 2026 Active implementation: `feature/durable-produced-tool-output`, baseline `c8c09e0d`. -Plan: `docs/plans/durable-tool-output-plan.md`. MCP was already bounded on current +Plan: `docs/plans/completed/durable-tool-output-plan.md`. MCP was already bounded on current main, despite the September 15 Notion audit. Adapt the successful-mutation principle from verified `deepseek-ai/deepseek-harness` deliverables documentation; no code copied. @@ -20,3 +20,5 @@ Validation: 125 focused tests and 10 inventory-fence tests pass; TypeScript and PR #219 at 58abfb02 passed hosted CI/Android/Electron gates. Pullfrog follow-up fixes include all three encrypted credential stores even in no-MCP workspaces, POSIX colon path parity, 240 Unicode code-point limits across clients, ASCII-only drive prefixes, and AJV-tested normative path/tool/status constraints. Follow-up validation: 128/128 focused tests, TypeScript, lint, Android chat/contract tests, and unsigned generic iOS test build pass; both independent reviewers clear. Follow-up hosted CI remains pending; physical XCTest remains blocked by device lock. Pullfrog incremental follow-up: ProducedFile schema lookaheads now scan all characters, including U+2028/U+2029; parity vectors cover valid paths, traversal, dot/empty segments and trailing separators for both. Protocol suite passes via node --import tsx (CLI IPC blocked by sandbox). Runtime/native validators unchanged. Hosted validation pending; physical device still locked. + +Status (2026-09-27 plan refresh): PR #219 merged 2026-09-23 and shipped in 0.43.0; plan moved to docs/plans/completed/. Physical iOS execution is still unverified. diff --git a/.memory/live-activity-freshness-bot-deeplinks.md b/.memory/live-activity-freshness-bot-deeplinks.md index 4639914da..50992013a 100644 --- a/.memory/live-activity-freshness-bot-deeplinks.md +++ b/.memory/live-activity-freshness-bot-deeplinks.md @@ -1,6 +1,6 @@ # Live Activity freshness chips and Bot deep links (2026-09-27) -Branch: `feature/live-activity-freshness`. Plan: `docs/plans/live-activity-freshness-bot-deeplinks-plan.md`. +Branch: `feature/live-activity-freshness`. Plan: `docs/plans/completed/live-activity-freshness-bot-deeplinks-plan.md`. ## Live Activity state and chips @@ -24,3 +24,5 @@ Branch: `feature/live-activity-freshness`. Plan: `docs/plans/live-activity-fresh ## Coordination PR #119 adds `AidenBotLiveActivityStateTests.swift` and edits the pbxproj. This branch adds no new iOS files, to avoid conflicting with it. + +Status (2026-10-01): merged in PR #276 (on main after 0.51.0); plan moved to `docs/plans/completed/`. diff --git a/.memory/mcp-advertised-status.md b/.memory/mcp-advertised-status.md index 6e62d049b..2e40484ac 100644 --- a/.memory/mcp-advertised-status.md +++ b/.memory/mcp-advertised-status.md @@ -8,4 +8,6 @@ Shared TypeScript status definition is desktop-only. Confirmed no McpStatus/mcp: Validation: registered `test:mcp` includes six new status tests; 88 total pass. Real in-memory SDK servers cover success, discovery failure, opaque extension metadata, empty/resource-only capability sets and independent clients. Controlled barriers cover document/connection revocation and generation-bound replacement. Full type-check, ESLint and whitespace checks pass. Independent GPT-5.6 Sol medium blast-radius/adversarial reviews requested. -Original assignment completion remains partial: docs/plans/mcp-session-context-audit.md classifies every item. Resources, scoped server instructions and per-model-request AGENTS refresh are concrete remaining deliverables, not external blockers. Pi compaction owner confirms no live AGENTS/MCP hook overlap. No native test blocker is claimed for this desktop-only diagnostic slice; the prior #214 physical iOS lock remains that slice's limitation. +Original assignment completion remains partial: docs/plans/completed/mcp-session-context-audit.md classifies every item. Resources, scoped server instructions and per-model-request AGENTS refresh are concrete remaining deliverables, not external blockers. Pi compaction owner confirms no live AGENTS/MCP hook overlap. No native test blocker is claimed for this desktop-only diagnostic slice; the prior #214 physical iOS lock remains that slice's limitation. + +Status (2026-09-27 plan refresh): PR #226 merged 2026-09-23 (0.43.0). Resources (#230), server instructions (#229) and trusted AGENTS refresh (#232) merged the same day, so the audit is complete. diff --git a/.memory/mcp-numeric-schema-formats.md b/.memory/mcp-numeric-schema-formats.md index b6a6bf23d..bd164e405 100644 --- a/.memory/mcp-numeric-schema-formats.md +++ b/.memory/mcp-numeric-schema-formats.md @@ -17,3 +17,5 @@ Tests: `main/services/mcp-tool-schema.test.ts` (in `test:mcp`) uses realistic sc Draft-07 schema-valued dependencies now normalize too; property-name dependency lists remain unchanged. Added strict-Ajv regression and registered the suite in the core-git CI lane. Focused schema tests (7) and CI policy tests (46) pass. Independent review identified a silent 64-level cutoff that could leave numeric formats unnormalized. Traversal now uses an iterative worklist and weak object-copy map, preserving raw identity and schema-keyword boundaries while normalizing deep schemas fully; a 2,000-level regression covers this case. + +Status (2026-10-01): merged in PR #264 (on main after 0.51.0); plan moved to `docs/plans/completed/`. diff --git a/.memory/mcp-scoped-resources.md b/.memory/mcp-scoped-resources.md index 70c1880ff..d3a75d1e3 100644 --- a/.memory/mcp-scoped-resources.md +++ b/.memory/mcp-scoped-resources.md @@ -9,3 +9,5 @@ Pullfrog identified that pinned SDK1.30.0 concatenates multi-variable expression ## Constrained template syntax correction A follow-up review found SDK1.30 also misinterprets single-variable operators/modifiers. Discovery now rejects every form except plain {name} expressions with ASCII identifier names, before any inventory handles are published. Operators, prefix/explode modifiers, comma-separated names, dotted/percent-encoded names and malformed braces fail closed. Accepted plain scalar values use strict RFC6570 percent encoding (including !'()*), without SDK expansion. Repeated separate expressions still work. An unsupported template makes that inventory fail closed; no partial inventory is presented as complete. MCP97 covers the requested single-variable forms, unpublished-handle denial and Unicode/reserved encoding. + +Status (2026-09-27 plan refresh): PR #230 merged 2026-09-23 and shipped in 0.43.0; plan moved to docs/plans/completed/. diff --git a/.memory/mcp-scoped-server-instructions.md b/.memory/mcp-scoped-server-instructions.md index 509733af8..8b7f3b13b 100644 --- a/.memory/mcp-scoped-server-instructions.md +++ b/.memory/mcp-scoped-server-instructions.md @@ -11,3 +11,5 @@ Onboarding's existing MCP tile now discloses service-provided tool guidance with Validation: MCP90, onboarding56, Bot447, scheduled151 passed. Full type-check, ESLint and whitespace checks passed after test-fixture fixes. New mcp-server-instructions.test.ts is registered in test:mcp. Both requested independent GPT-5.6 Sol medium reviews (blast radius; adversarial/edge cases) clear. Reviewers confirmed exact tool/server identity, final filtering, immutable lifetime, context budget and fail-closed bounds. Hosted checks and review remain PR follow-through gates. Original scope remains partial: scoped MCP resource operations and trusted AGENTS loading/request-boundary prompt refresh remain concrete deliverables. Capability status is separate #226, skill policy #214, result spills another owner's work. This change claims no resource access, provider upgrade or native acceptance. + +Status (2026-09-27 plan refresh): PR #229 merged 2026-09-23 (0.43.0). The resources and trusted AGENTS deliverables listed above as remaining also merged (#230, #232), so the original assignment is complete; plan and audit are in docs/plans/completed/. diff --git a/.memory/mobile-transcript-polish.md b/.memory/mobile-transcript-polish.md index 8a3bf29fb..d117d4e48 100644 --- a/.memory/mobile-transcript-polish.md +++ b/.memory/mobile-transcript-polish.md @@ -1,6 +1,6 @@ # Mobile transcript polish (Hermex Tier 1) -Branch `feature/mobile-transcript-polish`. Plan: `docs/plans/mobile-transcript-polish-plan.md`. +Branch `feature/mobile-transcript-polish`. Plan: `docs/plans/completed/mobile-transcript-polish-plan.md`. - There was no protocol change. "Worked for" reads `Message.timeline`, but only when the status is completed and `finishedAt >= startedAt`. The live timer uses the running timeline's `startedAt` and otherwise falls back to the newest user message's `createdAt`. Timestamps use `createdAt`. - iOS code lives in `Features/Chat/AidenTranscriptPolish.swift`. It is a new file because `AidenChatFeature.swift` is far over the 500-line Swift warning, and it is registered manually in the pbxproj with IDs `A714739233F64F4FA4C2B700` and `...710`. The footer replaced the old safeAreaInset copy/read-aloud row. `AidenSettledMessageRows` computes `showsFooter`, so Bot clusters show it only on the last joined bubble. @@ -9,3 +9,5 @@ Branch `feature/mobile-transcript-polish`. Plan: `docs/plans/mobile-transcript-p - SwiftUI `.textSelection` and Compose `SelectionContainer` cannot add custom menu items, so selection uses a native select-text sheet/dialog. On iOS this is a `UITextView` with `editMenuForTextIn`; on Android it is a `TextView` with `customSelectionActionModeCallback`. - User messages are now copyable on iOS. `copyText` returns nil only for empty text. - Open items: flatten Markdown in the Android select-text dialog, and focus the Android composer after Ask. + +Status (2026-10-01): merged in PR #277 and shipped in 0.51.0; plan moved to `docs/plans/completed/`. Physical-device visual acceptance remains. diff --git a/.memory/pr187-context-meter.md b/.memory/pr187-context-meter.md index e20c61d68..963012d5c 100644 --- a/.memory/pr187-context-meter.md +++ b/.memory/pr187-context-meter.md @@ -18,4 +18,6 @@ - Pi 0.87.1 merge (#246): the prompt now lives in transcript system messages and the AGENTS refresher appends a section patch (`apply(AgentContext)`). `withAgentsInstructionsEstimate` builds a one-message transcript (`createInitialSystemMessage`), applies the refresher and reads `getCurrentSystemPrompt`. `withoutAgentsInstructions` also strips a block rendered with no base prompt. llm-client registers the generation profile after the initial AGENTS apply, so the captured prompt and the tracker baseline agree. The harness emits projections from `installCompactedMessages`' result. Journal system messages count zero in `messageTokens`, so static context is counted once. Pullfrog on 5186fe54 pointed out that Pi sends later system messages in place for `supportsMidConvoSystemMessages` models, including superseded AGENTS revisions. `GenerationContextOptions.retainsSystemUpdates` (from `modelRetainsSystemUpdates(model)`; set in llm-client, the harness projection options, and `nextRequestContextOptions`, which defaults it to false) makes whole-transcript estimates (`projectNextContextUsage` and compaction) add the rendered updates beyond the replayed prompt. Compaction's replay into one head removes that extra. - Retained updates and usage anchors (Pullfrog on 8f06c37e): provider usage covers everything up to its anchor, but Pi's `estimateContextTokens` and `messageTokens` price system messages at 0, so for a retaining model each system message after the latest valid anchor is added in full (rendered with `renderSystemMessageUpdate`) through `retainedTailSystemTokens`. The same helper serves the projection's anchored tail and provider term, compaction's provider-aware total and candidate tails, and `PiCompactionCoordinator` (the direct previous-assistant usage in `checkContextPressure`, the stale-anchor estimate in both post-turn checks, and the whole-transcript fallback after a model switch, which adds later updates but not the leading head). A zero-usage response does not move the anchor, so revisions before and after it both count. - Static-inclusive totals (Pullfrog on de658be1): content and still-active sections set after the anchor are already in `options.systemPrompt`. Totals that add `staticTokens` next to the anchored tail (the projection's usage+static+trailing term and the compaction candidates) use `retainedTailSystemTokensBeyondPrompt` (rendered updates minus `postAnchorPromptChars`). Compaction's prefix ratio subtracts the anchor-time static (static minus the post-anchor share), so `static + prefix*ratio + tail` equals usage plus the full tail, and a replayed head prices the active revision. Totals without static (Pi's `estimate.tokens`, direct usage, every pi-compaction-core path) keep the full render. -- Plan: `docs/plans/composer-context-meter-plan.md`. +- Plan: `docs/plans/completed/composer-context-meter-plan.md`. + +Status (2026-09-27 plan refresh): PR #187 merged 2026-09-26 and shipped in 0.50.0; plan moved to docs/plans/completed/composer-context-meter-plan.md. diff --git a/.memory/queue-while-compacting.md b/.memory/queue-while-compacting.md index 7396f4608..20959f0f7 100644 --- a/.memory/queue-while-compacting.md +++ b/.memory/queue-while-compacting.md @@ -1,6 +1,6 @@ # Queue messages while compaction runs — 2026-09-27 -Branch: `feature/queue-while-compacting`. Plan: `docs/plans/queue-while-compacting-plan.md`. +Branch: `feature/queue-while-compacting`. Plan: `docs/plans/completed/queue-while-compacting-plan.md`. Manual compaction keeps the composer editable and holds queued messages until compaction succeeds. `ChatMessageQueue.holdReason` is the durable per-chat state; the composer must derive its active compaction affordance, status text and Cancel action from the queue snapshot as well as its local start state, because the chat-keyed composer remounts when navigating away and back. @@ -9,3 +9,5 @@ The `/compact` slash token is consumed immediately after the asynchronous comman Relevant validation: `npm run test:slash-commands`; `npm run type-check:e2e`; focused `chat-message-queue.spec.ts` compaction scenario. Follow-up review: attachment and skill removal now use `composerInputLocked`, preserving draft editing while manual compaction holds queued sends. The compaction E2E removes a pasted image before navigation while the original command is still pending. + +Status (2026-10-01): merged in PR #272 (on main after 0.51.0); plan moved to `docs/plans/completed/`. diff --git a/.memory/rich-link-previews.md b/.memory/rich-link-previews.md index cb1893882..d62ce175f 100644 --- a/.memory/rich-link-previews.md +++ b/.memory/rich-link-previews.md @@ -9,3 +9,5 @@ - Escape fences both the open card and Radix's delayed focus-open callback until the next pointer-enter or focus interaction, without moving focus. - No network, IPC, connector, persistence, schema, transcript, Bot runtime, main-process, iOS, or Android contract changed. - Validation: focused rich-link/transcript suite 42/42; Bot suite 451/451; Chat/slash-command suite passed; TypeScript, ESLint, CI policy, production build, and `git diff --check` passed. Packaged-app, pointer/keyboard visual, assistive-technology, and physical-device acceptance remain separate. + +Status (2026-09-27 plan refresh): PR #253 merged 2026-09-26 and shipped in 0.50.0; plan moved to docs/plans/completed/rich-link-previews-plan.md. The optional authenticated metadata phase is unstarted. diff --git a/.memory/skill-invocation-policy.md b/.memory/skill-invocation-policy.md index 13f7de66e..54059d320 100644 --- a/.memory/skill-invocation-policy.md +++ b/.memory/skill-invocation-policy.md @@ -6,7 +6,7 @@ Implemented independent `modelInvocable`/`userInvocable` policies for discovered Bot automatic skill eligibility uses model policy through existing available flags. Eligible entries sort ahead of unavailable entries before the 256 limit. iOS/Android use the existing availability field for catalog validation and tools/editor selections; no native wire changes. Onboarding Skills copy explains automatic/explicit use using the existing artwork. -Research checked: dated Notion DeepSeek→Aiden and September 11/15 digests against current Aiden and primary `deepseek-ai/deepseek-harness` docs/subsystems/skills.md and packages/skill/skill/src/index.ts (HEAD observed c36a83ff6bb95e3f82cf79f9be7c724270a8aa61). Original implementation, no source copied. Bodies already load lazily into model context; bounded disk reads retained for validation/fingerprints. MCP advertised capabilities, scoped resources, server instructions and safe request-boundary refresh remain deferred in docs/plans/skill-mcp-session-context-plan.md. MCP spills and provider upgrades outside scope. +Research checked: dated Notion DeepSeek→Aiden and September 11/15 digests against current Aiden and primary `deepseek-ai/deepseek-harness` docs/subsystems/skills.md and packages/skill/skill/src/index.ts (HEAD observed c36a83ff6bb95e3f82cf79f9be7c724270a8aa61). Original implementation, no source copied. Bodies already load lazily into model context; bounded disk reads retained for validation/fingerprints. MCP advertised capabilities, scoped resources, server instructions and safe request-boundary refresh remain deferred in docs/plans/completed/skill-mcp-session-context-plan.md. MCP spills and provider upgrades outside scope. ## Validation diff --git a/.memory/subagent-live-context-window.md b/.memory/subagent-live-context-window.md index d62b0baed..905d46584 100644 --- a/.memory/subagent-live-context-window.md +++ b/.memory/subagent-live-context-window.md @@ -8,4 +8,6 @@ This is an ephemeral desktop side channel. It adds no durable snapshot fields, r Coverage lives in the projector, context-usage-store and subagents-panel suites. The new store test is registered in the package scripts and CI registry. Recovery review found this memory note missing from the original commit and added it to match the plan and PR description; no implementation changed in that follow-up. -Follow-ups recorded in `docs/plans/subagent-live-context-window-plan.md`: Remote/iOS/Android need a separate live event and contract revision; message-list chips do not yet show the reading; percentages use the full context window rather than the usable input budget; notifications emitted before the first panel mounts are not replayed. +Follow-ups recorded in `docs/plans/completed/subagent-live-context-window-plan.md`: Remote/iOS/Android need a separate live event and contract revision; message-list chips do not yet show the reading; percentages use the full context window rather than the usable input budget; notifications emitted before the first panel mounts are not replayed. + +Status (2026-10-01): merged in PR #271 and shipped in 0.51.0; plan moved to `docs/plans/completed/`. diff --git a/.memory/timed-ask-user.md b/.memory/timed-ask-user.md index f81efadac..2f94ec6d0 100644 --- a/.memory/timed-ask-user.md +++ b/.memory/timed-ask-user.md @@ -1,9 +1,11 @@ # Timed ask-user waits — 2026-09-27 -Branch: `feature/timed-ask-user`. Plan: `docs/plans/timed-ask-user-plan.md`. +Branch: `feature/timed-ask-user`. Plan: `docs/plans/completed/timed-ask-user-plan.md`. The desktop coordinator owns optional deadlines, `expiresAt`, explicit expired responses, and a bounded recent-prompt set. Attended desktop requests without a timeout continue waiting; unattended requests use the Remote-aligned cap. Timed-out prompts now remain in the desktop composer after generation settles, letting a late answer become a follow-up or queued follow-up. The CLI adapter must forward the tool's `timeoutSeconds` to the terminal selection UI. The CLI uses one absolute deadline across the complete questionnaire and multi-select steps, passing each `select` only the remaining milliseconds plus the tool-call abort signal. Pi `ExtensionUIContext.select` supports both options. If multi-select exhausts every option, preserve the accumulated choices before leaving the loop. Relevant validation: `npm run test:ask-user-question`; `npm run test:cli`; `npm --prefix packages/cli run type-check`. + +Status (2026-10-01): merged in PR #270 and shipped in 0.51.0; plan moved to `docs/plans/completed/`. diff --git a/.memory/tool-approval-scopes.md b/.memory/tool-approval-scopes.md index aa494992b..b82a50c58 100644 --- a/.memory/tool-approval-scopes.md +++ b/.memory/tool-approval-scopes.md @@ -1,6 +1,6 @@ # Tool approval scopes — 2026-09-27 -- Branch `feature/approval-scopes`, based on `origin/main` at `a9baa4aa3`. Plan: `docs/plans/tool-approval-scopes-plan.md`. +- Branch `feature/approval-scopes`, based on `origin/main` at `a9baa4aa3`. Plan: `docs/plans/completed/tool-approval-scopes-plan.md`. - Shared types and helpers live in `renderer/shared/tool-approval-scope.ts`. The rule book and its persistence are in `main/services/tool-approval-rules.ts` (a DataStore `tool-approval-rules.json`), and the singleton is in `tool-approval-rules-main.ts`. - `llm-client.ts` computes `toolApprovalRuleTarget(...)` for non-Bot `APPROVAL_TOOL_NAMES` calls in Ask workspaces. - A remembered match (chat or always) skips the prompt. @@ -33,3 +33,5 @@ Remembered file targets preserve leading/trailing whitespace, so distinct filesy - Follow-up review: reject raw parent-path segments before normalization; command rules permit tab/newline/carriage-return whitespace but reject other ASCII controls before trimming. Regression covers leading and embedded control characters and parent segments. Independent review also identified Windows backslash parent segments; raw parent validation now covers both separator forms and mixed separators, with regression coverage. + +Status (2026-10-01): merged in PR #273 as contract revision 17 (on main after 0.51.0); plan moved to `docs/plans/completed/`. diff --git a/.memory/transcript-sticky-headers-turn-footers.md b/.memory/transcript-sticky-headers-turn-footers.md index 1aa3bd9ee..407faa1e6 100644 --- a/.memory/transcript-sticky-headers-turn-footers.md +++ b/.memory/transcript-sticky-headers-turn-footers.md @@ -1,6 +1,6 @@ # Transcript sticky headers, preparing stage, turn footers -Branch `feature/sticky-think-turn-footers`; plan `docs/plans/transcript-polish-sticky-headers-plan.md`. +Branch `feature/sticky-think-turn-footers`; plan `docs/plans/completed/transcript-polish-sticky-headers-plan.md`. - `ScrollArea` root sets `--scroll-area-sticky-top` = measured toolbar height. The var sits on the root, not the viewport or content div, because `renderer/main/chat-transition.test.tsx` source-greps the viewport `style={{...}}` and `data-scroll-content className="min-h-full"` verbatim. - `.transcript-sticky-header` paints an opaque layered background (state var over surface var over `--color-background`). Hover and focus fills come from the CSS vars `--transcript-sticky-state`, not Tailwind `hover:bg-*`, since a Tailwind bg would replace the opaque base. @@ -10,3 +10,5 @@ Branch `feature/sticky-think-turn-footers`; plan `docs/plans/transcript-polish-s - Android unit tests here need `ANDROID_HOME=~/Library/Android/sdk JAVA_HOME=/opt/homebrew/opt/openjdk@17`. No iOS simulator was available, so iOS XCTest runs in hosted CI. - Review recovery: sticky-section and assistant-turn-stats regressions now run from pretest through test:transcript-polish, with explicit renderer-other CI lane assignments. Previously they appeared only in test:preflight and were absent from the CI source union. + +Status (2026-10-01): merged in PR #269 and shipped in 0.51.0; plan moved to `docs/plans/completed/`. diff --git a/.memory/trusted-agents-refresh.md b/.memory/trusted-agents-refresh.md index 104d8987e..826618b79 100644 --- a/.memory/trusted-agents-refresh.md +++ b/.memory/trusted-agents-refresh.md @@ -7,3 +7,5 @@ Loader7 including native UTF-8/provider-scope fence, runtime/context81, Bots447, PR232 review hardening: trusted AGENTS metadata preflight requires exactly one link. Native read-html enforces exclusive regular-file identity at open and after reading, rejecting hard-linked content and concurrent link changes. Regression coverage exercises preexisting links, a pre-open hard-link swap and post-open link creation. This also makes shared HTML reads fail closed for multiply-linked files; no protocol or native-client DTO changes. Hard-link correction validation: AGENTS7, native file-mutator27, shared reader IO14, generative UI42 plus artifact2 and browser containment5 pass; type-check and lint pass. No mobile DTO or transcript changes; physical iOS remains untouched. + +Status (2026-09-27 plan refresh): PR #232 merged 2026-09-23 and shipped in 0.43.0; plan moved to docs/plans/completed/. diff --git a/.memory/upgrade-pi-small-context-budgets.md b/.memory/upgrade-pi-small-context-budgets.md index 9963de4d7..dadbf825b 100644 --- a/.memory/upgrade-pi-small-context-budgets.md +++ b/.memory/upgrade-pi-small-context-budgets.md @@ -30,3 +30,5 @@ See `pi-compaction-scope-reconciliation-20260922.md`. Configurable per-provider/ Pullfrog identified that lowering the retained tail can expose an oversized hidden summary request. The coordinator now fences both Models completion entry points around Pi's fully assembled prompt, before provider transport/accounting. It rejects estimated input + requested output + 5% window safety (minimum 64 tokens) over capacity, with no checkpoint, retry, or automatic replay. Non-ASCII text gets a conservative UTF-8-byte allowance; ASCII uses the existing Pi content heuristic. This is an estimated-capacity preflight, not a provider-tokenizer guarantee. Oversized histories require a larger-context model; this patch does not silently truncate summary input. Manual/automatic long-history, output-reservation/no-retry/event, and Unicode regressions cover the boundary. Existing fake-provider fixtures previously accepted histories larger than their declared windows; their payloads or windows now fit. The executable semantic replay uses a 64k window with synthetic usage recalibrated around its threshold, preserving the original replay objectives; those synthetic metrics are not installed/provider acceptance evidence. The bot replay has an 8k window. Rollout stages and receipt schemas remain unchanged. + +Status (2026-09-27 plan refresh): PR #228 merged 2026-09-23 (0.43.0). Pi has since moved from 0.84.4 to 0.87.1 in PR #246 (see pi-0871-transcript-pin.md). diff --git a/.memory/web-search-key-pool.md b/.memory/web-search-key-pool.md index 42a4cae23..92c91bfae 100644 --- a/.memory/web-search-key-pool.md +++ b/.memory/web-search-key-pool.md @@ -1,6 +1,6 @@ # Web Search API key pool — 2026-09-27 -- Plan: `docs/plans/web-search-key-pool-plan.md`. Source idea: pi-web-access #453. No code was copied. +- Plan: `docs/plans/completed/web-search-key-pool-plan.md`. Source idea: pi-web-access #453. No code was copied. - Pool-capable providers are listed in `WEB_SEARCH_KEY_POOL_PROVIDER_IDS` in `renderer/shared/web-search-key-pool.ts`. Only `tavily` is listed today. - Add a provider only after its adapter maps 401/403 to `auth` and its quota statuses to `quota`. - Storage lives in `main/services/web-search-credential-core.ts`: @@ -30,3 +30,5 @@ - `npm run test:settings-design`: 60 tests pass. - `npm run type-check` and scoped ESLint pass. - No live provider requests were made. + +Status (2026-10-01): merged in PR #278 and shipped in 0.51.0; plan moved to `docs/plans/completed/`. diff --git a/docs/plans/README.md b/docs/plans/README.md index 0f0487c0f..ab90e33e5 100644 --- a/docs/plans/README.md +++ b/docs/plans/README.md @@ -2,55 +2,32 @@ This directory is the source of truth for Aiden's implementation plans. The engineer changing a plan owns its status row and should update it in the same change when a meaningful milestone lands. -## Active and partial +Last refreshed 2026-10-01 against `main` at `d2197dfef` (0.51.0 plus later merges). "On main" means merged after 0.51.0 and not yet in a release. -- [Linux macOS parity reconciliation](linux-macos-parity-plan.md) — Active; main@0.43.0 merged and review-gated (42 conflicts resolved by ownership, two independent review passes, full local suite green). Linux runtime smoke, Linux CI burn-in, Gemini Live orb and managed-worktree checks on real Linux remain before the main merge. Enforcing Fedora GNOME VM validated the SELinux file-descriptor probes, Electron role transitions, protected-socket transfer, payload inventory, root-managed generation staging, and fail-closed security-label preservation. Release provenance and cross-platform installer delivery are implemented. Real portal testing exposed modifier-release loss; GNOME safely retains toggle dictation. Computer Use remains disabled on Linux. -- [Durable Bot and chat runs](durable-jobs-leases-plan.md) — Foundation implemented for review (P0): SQLite admission/leases/controls and conservative runtime recovery port; 56 focused tests pass. Production Bot runtime, desktop and Remote/native rollout remain pending. No Comfy/Design integration. +## Active and partial -[MCP session context audit](mcp-session-context-audit.md) — Partial: advertised-capability status implemented for review; resources, server instructions and request-boundary instruction refresh remain explicit deliverables. Skill invocation is separately green in PR #214. -[Skill and MCP session context](skill-mcp-session-context-plan.md) — Partial: skill invocation policy implemented in PR #214; implementation CI/review passed, physical iOS launch blocked by device lock. MCP metadata/resources/instructions and boundary refresh deferred. -[Scoped MCP server instructions](mcp-server-instructions-plan.md) — Implemented for review: bounded generation-owned service guidance filtered by final tool admission. Resource operations and trusted AGENTS request-boundary refresh remain open. Related slices: #214 and #226. +- [Linux macOS parity reconciliation](linux-macos-parity-plan.md) — Active; the Linux branch merged to main in PR #71 (2026-09-26) and shipped in 0.50.0. Linux runtime smoke, Linux CI burn-in, Gemini Live orb and managed-worktree checks on real Linux remain. Enforcing Fedora GNOME VM validated the SELinux file-descriptor probes, Electron role transitions, protected-socket transfer, payload inventory, root-managed generation staging, and fail-closed security-label preservation. Release provenance and cross-platform installer delivery are implemented. Real portal testing exposed modifier-release loss; GNOME safely retains toggle dictation. Computer Use remains disabled on Linux. +- [Durable Bot and chat runs](durable-jobs-leases-plan.md) — Foundation (P0) merged in PR #243 and shipped in 0.50.0: SQLite admission/leases/controls and conservative runtime recovery port. Production Bot runtime, desktop and Remote/native rollout remain pending. No Comfy/Design integration. | Plan | Status | Current state | | -------------------------------------------------------------------------------------------------- | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| [Tool approval scopes](tool-approval-scopes-plan.md) | Implemented for review | Allow once / Allow for this chat / Always allow for exact parent workspace commands and file writes; persisted rules revocable in Settings → Tool approvals; Aiden Remote contract revision 17 with iOS and Android menus. Assistant dock, subagent and Bot scopes are out of scope. | -| [Aiden CLI](aiden-cli-plan.md) | Active | Phases 0–5 implementation complete; macOS/Linux CLI (57 tests each), Linux native helpers, complete shared subagent suites, root TypeScript/lint, and Android client checks pass. Physical iPhone acceptance is pending an unlocked device. Phase 6 adds QR remote pairing, scheduled-run notifications (mobile push + desktop), shared desktop memory, daemon autostart, and prebuilt binaries; see the [checklist](aiden-cli-parity-checklist.md). | -| [Dictation: Parakeet lifecycle, modes, dictionary](dictation-parakeet-modes-plan.md) | Implemented for review | Handy P1 slice: configurable Parakeet idle unload with warm-up on hotkey/mic start, toggle/hold/tap-or-hold shortcut modes, and a custom dictionary applied to every transcript. VAD, history, and mute remain later; real-hardware acceptance pending. | -| Chat width setting (T3 #11594) | Implemented for review | Appearance → **Chat width** (Narrow 44rem / Default 52rem / Wide 64rem / Full) persists as `AppearanceConfig.chatWidth` and drives `--chat-content-max-width`, so the transcript, approvals, and composer resize together. The main chat footer matches the scrollport's usable width when a classic scrollbar reserves space, so Full remains aligned without horizontal overflow. Desktop only; older settings migrate to Default. No plan doc. | -| [Web Search API key pool](web-search-key-pool-plan.md) | Implemented for review | Tavily accepts up to 8 encrypted keys with ordered or round-robin use. Rejected keys (401/403) and quota-limited keys (429/432/433) cool down in memory with backoff and fail over to the next key. When every key is cooling, no request is sent and automatic routing falls back. Settings can add, remove, reorder and retry keys, and the renderer never sees a key. Other providers and CLI parity remain. | -| [Timed ask-user waits](timed-ask-user-plan.md) | Implemented for review | Optional `timeoutSeconds` on `ask_user_question`; unattended (Remote) runs always expire within 5 min and resolve with an explicit best-judgement result. Late desktop answers become a Send/Queue follow-up offer; Remote `expiresAt` carries the real deadline; iOS/Android say when a question expired. PR CI pending. | -| [Rich link previews for Chats and Bots](rich-link-previews-plan.md) | Implemented for review | Shared regular Chat and Bot transcripts now show provider-aware inline icons and bounded hover/focus cards. User HTTP(S) text is autolinked, assistant streaming and persisted Markdown share the opt-in renderer, and URL-derived previews perform no network requests. | -| [Simulator Devices](simulator-devices-plan.md) | Partial | Environment **Simulator** tab plus `device_*` agent tools, ported from T3 Code (MIT, `1c127066`). iOS only; consent-gated pinned `expo-device-hub@0.12.0` + `agent-device@0.21.12`; token-authenticated loopback proxy. Phases 0–3 done (spike, flagged tab shell, main-process toolchain/host/proxy/service/IPC, live stream viewer with controls and screenshot-to-chat; `test:devices` 96 pass; fake-hub Electron E2E; real-Mac acceptance passed). Phase 4 (agent `device_*` tools), Phase 5 (simulators on paired Macs over Aiden Remote; [plan](simulator-devices-phase-5-peers.md)) and Phase 6 (procedural 3D device frames; [plan](simulator-devices-phase-6-3d.md)) done. Phase 7 done: Settings → **Simulator** (consent switches, pinned/installed helper versions, prune, remove installed tools) and [`docs/devices.md`](../devices.md); onboarding skipped while the flag is off. Agent guidance now prefers `device_*`/`agent-device` for the watched device but allows shell `xcrun simctl`/`xcodebuild`/`adb` for builds, installs, logs, port forwarding, and diagnostics (T3 #13908). Remaining: real-Mac acceptance for Phases 4–6 before the flag defaults on; SSH hosts are a later follow-up. | -| [Dictation Secure Input warning](dictation-secure-input-plan.md) | Implemented for review | Before pasting, dictation probes macOS Secure Event Input through the documented Carbon API; when active it keeps the transcript on the clipboard and the pill explains why with a ⌘V hint. PR CI pending. | -| [MCP numeric schema formats](mcp-numeric-schema-formats-plan.md) | Implemented for review | Desktop and CLI MCP tool schemas drop schemars numeric formats (`uint32`, `int8`, `double`, ...) at every nested position and keep exact width ranges as `minimum`/`maximum`. Raw schemas remain the drift/grant identity. Source: pi-mcp-adapter #651. | -| [Scoped MCP resources](mcp-scoped-resources-plan.md) | Implemented | Per-server resource inventory/templates/read; MCP93/Bots448/scheduled151/onboarding56 and both independent reviews pass. PR CI pending. | -| [Transcript polish: sticky headers, preparing stage, turn footers](transcript-polish-sticky-headers-plan.md) | Implemented for review | Opened Thinking disclosures and activity/compaction trails keep a sticky header under the toolbar and flow at full height; pending tool calls read `Preparing ` on desktop, iOS and Android; settled responses show a duration/model/token footer from new content-free `turnStats`. Mobile footer and live streaming footer are follow-ups. | -| [Chronological Chat Motion](chronological-chat-motion-plan.md) | In review | Readable Thinking stretches, tool rows, and prose project in sequence across desktop and regular native chats. [PR #224](https://github.com/sambitcreate/aiden-agent/pull/224) and visual acceptance remain. | -| [Queue while compacting](queue-while-compacting-plan.md) | Implemented for review | Manual `/compact` keeps the desktop composer editable. Messages queue behind a per-chat compaction hold and deliver in order on success. Failure, cancellation or an error pauses the queue with every message kept until the user resumes. Remote and native clients are unchanged, since Remote has no manual compaction. Relates to #182 and #220. | -| [Composer Context Meter](composer-context-meter-plan.md) | In review | Composer gauge and popover driven by `projectNextContextUsage` (the runtime compaction projection) with live `chat:context-pressure` pushes; PR #187 kept only this part after PR #224 shipped ordered thinking traces. Visual acceptance pending. | -| [Live subagent context window](subagent-live-context-window-plan.md) | In review | Each running child shows its latest provider-reported context use (percent in the roster row, `used / window` in detail, warning tone at 80%) through a non-durable `chat:subagent-context` side channel; snapshots, revisions and Remote are unchanged. Desktop only; Remote/iOS/Android live context is a follow-up. | -| [Managed Worktree Lifecycle](managed-worktree-lifecycle-plan.md) | Partial | P0 lifecycle merged in #185; admission hardening and [old-stack disposition](managed-worktree-stack-disposition.md) under review: hook-free managed creation, free-space admission, `.worktreeinclude` provisioning, durable snapshot records + synthetic `refs/aiden/snapshots/*` commits, byte-exact provisioned-ignored blob restore, journal v4 snapshot-aware quarantine deletion with force semantics, and first-class restore. GC/owner-kind/setup-script/UI phases remain open. | -| [Durable chat pull requests](chat-pull-requests-plan.md) | Implemented | PR #184 hardens durable multi-link identities, exact create intent, selected push repository, atomic recovery and persistent unlink dismissal; local full suite and two independent final reviews pass; hosted acceptance tracked on PR #184. | -| [Trusted AGENTS refresh](trusted-agents-refresh-plan.md) | Implemented | Bounded global/workspace instruction refresh and per-dispatch scope fence; local loader/runtime/Bot/scheduled/onboarding checks and both reviews pass. PR CI pending. | -| [Mobile Task Progress and Subagents](mobile-task-progress-and-subagents-plan.md) | Active | Read-only task/agent projections, durable Mac-owned progress, explicit Workspace/Bot eligibility, and native controls/sheets implemented. Automated server/native validation passed; PR review and physical UI acceptance remain. See the linked evidence report. | -| [Remote subagent interrupt](../aiden-remote-api-v1.md) | In review | Hermex P1 (Hermes subpage 6) follow-on to Mobile Task Progress: `POST /chats/{chatId}/agents/{agentId}/interrupt` (contract revision 16, `chat-agent-interrupt-v1`) reuses the desktop subagent stop path and returns the refreshed roster; iOS and Android agent sheets offer a confirmed Stop. Desktop, iOS simulator, and Android unit suites pass; physical-device acceptance and the revision-16 claim against concurrent PRs remain. | -| [Scheduled-Task Provider and Pi Rollout Recovery](scheduled-provider-and-pi-rollout-recovery-plan.md) | Implemented | Attended chat starts seed the scheduler's provider fallback, tasks pin providers explicitly (editor picker + prefilled drafts + honest `schedule_task` gating), Pi-rollout-ineligible chats generate journalless over in-memory sessions with the fail-closed contract preserved, and remote request journal events carry method/route evidence — green in the recovery worktree; release-owner stage advance (B1) and machine remediation remain. | -| [Durable tool output and produced files](durable-tool-output-plan.md) | Implemented | Bounded command/MCP recovery and shared file provenance pass local tests and independent reviews; physical iOS execution and hosted PR checks pending. | +| [Aiden CLI](aiden-cli-plan.md) | Active | Merged to main in PR #121 (2026-09-26) and shipped in 0.50.0 on pinned Pi 0.87.1. Phases 0–6 implementation complete; macOS/Linux CLI (57 tests each), Linux native helpers, complete shared subagent suites, root TypeScript/lint, and Android client checks pass. Physical iPhone acceptance is pending an unlocked device. Phase 6 delivered QR remote pairing, scheduled-run notifications (mobile push + desktop), shared desktop memory, daemon autostart, and prebuilt binaries; see the [checklist](aiden-cli-parity-checklist.md). | +| [Simulator Devices](simulator-devices-plan.md) | Partial | Phases 0–7 merged in PR #252 (2026-09-26) and shipped in 0.50.0 behind `AIDEN_EXPERIMENTAL_DEVICES`. Environment **Simulator** tab plus `device_*` agent tools, ported from T3 Code (MIT, `1c127066`). iOS only; consent-gated pinned `expo-device-hub@0.12.0` + `agent-device@0.21.12`; token-authenticated loopback proxy. Phases 0–3 done (spike, flagged tab shell, main-process toolchain/host/proxy/service/IPC, live stream viewer with controls and screenshot-to-chat; `test:devices` 96 pass; fake-hub Electron E2E; real-Mac acceptance passed). Phase 4 (agent `device_*` tools), Phase 5 (simulators on paired Macs over Aiden Remote; [plan](simulator-devices-phase-5-peers.md)) and Phase 6 (procedural 3D device frames; [plan](simulator-devices-phase-6-3d.md)) done. Phase 7 done: Settings → **Simulator** (consent switches, pinned/installed helper versions, prune, remove installed tools) and [`docs/devices.md`](../devices.md); onboarding skipped while the flag is off. Agent guidance prefers `device_*`/`agent-device` for the watched device but allows shell `xcrun simctl`/`xcodebuild`/`adb` for builds, installs, logs, port forwarding, and diagnostics (T3 #13908; PR #263, 0.51.0). Remaining: real-Mac acceptance for Phases 4–6 before the flag defaults on; SSH hosts are a later follow-up. | +| [Managed Worktree Lifecycle](managed-worktree-lifecycle-plan.md) | Partial | P0 lifecycle merged in #185; admission hardening merged in #221 (0.43.0), with the superseded stack recorded in the [old-stack disposition](managed-worktree-stack-disposition.md): hook-free managed creation, free-space admission, `.worktreeinclude` provisioning, durable snapshot records + synthetic `refs/aiden/snapshots/*` commits, byte-exact provisioned-ignored blob restore, journal v4 snapshot-aware quarantine deletion with force semantics, and first-class restore. GC/owner-kind/setup-script/UI phases remain open. | +| [Mobile Task Progress and Subagents](mobile-task-progress-and-subagents-plan.md) | Active | Read-only task/agent projections, durable Mac-owned progress, explicit Workspace/Bot eligibility, and native controls/sheets implemented. Merged in PR #123; physical UI acceptance remains. The first mutation control, a confirmed single-agent Stop on iOS and Android (`POST /chats/{chatId}/agents/{agentId}/interrupt`, `chat-agent-interrupt-v1`, contract revision 16), merged in PR #275 and is on main. See the linked evidence report. | +| [Scheduled-Task Provider and Pi Rollout Recovery](scheduled-provider-and-pi-rollout-recovery-plan.md) | Implemented | Attended chat starts seed the scheduler's provider fallback, tasks pin providers explicitly (editor picker + prefilled drafts + honest `schedule_task` gating), Pi-rollout-ineligible chats generate journalless over in-memory sessions with the fail-closed contract preserved, and remote request journal events carry method/route evidence — merged in PR #105; release-owner stage advance (B1) and machine remediation remain. | | [Desktop multi-host control](desktop-multi-host-control-plan.md) | Active | Outbound connection foundation and regression coverage implemented. Full sidebar/chat/runtime integration remains incomplete; interactive UI proposal approved on 2026-09-09. | -| [Form Fill Specialist](form-fill-specialist-plan.md) | Blocked — pinned driver lacks document-bound mutation | Local scoring and artifact groundwork verified. Specialist admission and execution disabled; cleanup-only Settings. Requires upstream document-lifetime identity and atomic conditional writes, new supported-driver regressions, and signed live-window acceptance before enablement. | -| [Draft Agent Chats](draft-agent-chats-plan.md) | Implemented | Transient desktop drafts, atomic first-message creation, and the one-time legacy empty-chat migration are implemented with Electron regression coverage; PR CI and merge pending. | -| [Nontechnical User Journey UX](nontechnical-user-journey-ux-plan.md) | Active | Approved ten-journey UX pass implemented for review: guided phone setup, four AI choices, two-step Create a bot, setup acknowledgements, recovery, and native pairing copy. Broader audit backlog and physical-device acceptance remain open. | -| [Gemini 3.8 Read Aloud](gemini-tts-read-aloud-plan.md) | Partial | Desktop unary-WAV slice hardened: source/owner fencing, managed Google credentials, whole-soundbite session replay without regeneration, bounded ordered playback and audible settings previews. Desktop-owned iOS/Android playback and read-only settings implemented; Android 101 tests/debug APK and iOS test build pass. Physical iOS XCTest now passes: 224 passed, 5 skipped, 0 failures on Smbt16ProMax. Live Google acceptance, native audible verification, streaming, Voice Studio, desktop audio focus and final independent sign-off remain. Review fixes add production usage accounting, strict WAV, progress-based native waiting, reclaimable sessions and failed-outcome eligibility; Preflight retry follow-up preserves concurrency-safe billing fences; TTS 131, Android chat/client 70 and simulator 227 passed (5 skipped). | +| [Form Fill Specialist](form-fill-specialist-plan.md) | Blocked — pinned driver lacks document-bound mutation | Local scoring and artifact groundwork merged in PR #195. Specialist admission and execution disabled; cleanup-only Settings. Requires upstream document-lifetime identity and atomic conditional writes, new supported-driver regressions, and signed live-window acceptance before enablement. | +| [Nontechnical User Journey UX](nontechnical-user-journey-ux-plan.md) | Active | Approved ten-journey UX pass merged in PR #96: guided phone setup, four AI choices, two-step Create a bot, setup acknowledgements, recovery, and native pairing copy. Broader audit backlog and physical-device acceptance remain open. | +| [Gemini 3.8 Read Aloud](gemini-tts-read-aloud-plan.md) | Partial | Merged in PR #245 and shipped in 0.50.0. Desktop unary-WAV slice hardened: source/owner fencing, managed Google credentials, whole-soundbite session replay without regeneration, bounded ordered playback and audible settings previews. Desktop-owned iOS/Android playback and read-only settings implemented; Android 101 tests/debug APK and iOS test build pass. Physical iOS XCTest now passes: 224 passed, 5 skipped, 0 failures on Smbt16ProMax. Live Google acceptance, native audible verification, streaming, Voice Studio, desktop audio focus and final independent sign-off remain. Review fixes add production usage accounting, strict WAV, progress-based native waiting, reclaimable sessions and failed-outcome eligibility; Preflight retry follow-up preserves concurrency-safe billing fences; TTS 131, Android chat/client 70 and simulator 227 passed (5 skipped). | | [Aiden Assistant](aiden-assistant-plan.md) | Partial | Markdown parity and confirmed provider-connection/model-pinned project-or-MCP automation creation/editing ship. The user-facing dock/panel/composer was superseded and removed by [Aiden Live Assistant](gemini-live-assistant-plan.md) Phase 4.5; settings tools and proactivity remain planned and need an Aiden Live/main-chat UX before implementation. | -| [Aiden On The Go](aiden-on-the-go-plan.md) | Active | Version 0.1.0 build 22 is `VALID` and `IN_BETA_TESTING` for Internal Testers. Native lazy workspace file pages and bounded source previews are implemented for PR/physical-device review. Native cold/warm replay and optimistic-send recovery are hardened; physical-device recovery acceptance remains pending. Android matches iOS's app-icon switcher, Workspace hierarchy, warm scoped Bots/Usage/SSE lifecycle, Usage dashboard, image showcase/gallery, and keyboard-safe elevated composer. Both clients provide separate native photo and file intake; iOS adds an anchored Files/Camera/Photos surface with an embedded recoverable camera and ordered PhotoKit selection. Both clients remember the last explicitly chosen Workspace-chat provider, model and thinking level per paired Mac, restore it on relaunch after validating it against the host's current inventory (falling back to the chat's pair, then host defaults), and purge it on unpair; Android's composer model/thinking picker is now wired. Preference snapshots stay within the loaders' 256 KiB limit, iOS writes are fenced by the captured pairing generation, and Android seeds resolution from the current chat before host defaults. Both clients support native in-process dictation or bounded no-retention transcription by the paired Mac's local Parakeet model. iOS also ships progressive onboarding, bidirectional media, reliable mobile approvals, typed activity timelines, semantic haptics, and one-chat-per-Bot conversations with companion vision for text-only models. Physical iPad/manual permission-system-UI acceptance, privacy publication, final store assets, and external/public-release decisions remain open. | -| [Mobile transcript polish](mobile-transcript-polish-plan.md) | Implemented for review | Hermex Tier 1 on iOS and Android: "Worked for" on completed turns plus a live "Working for" timer, a per-message timestamp and copy footer, and native Select Text with an "Ask about this" action that quotes into the composer. Uses the existing timeline and createdAt fields, so no protocol revision. Hosted CI and physical-device visual acceptance remain. | -| [Unified Workspace Sidebar](unified-workspace-sidebar-plan.md) | Active | Phases 1 and 2 ship the unified workspace/chat outline plus a feature-negotiated, transcript-free paginated summary read on Electron, iOS/iPadOS, and Android; physical-device performance acceptance remains open. | -| Chat row states and honest unread (no plan doc; see `.memory/chat-row-states.md`) | Implemented for review | Hermex-inspired list rows: Needs approval / Needs input / Working / Idle plus a durable unread marker (new assistant output after the last view, with an install baseline so history never lights up). Desktop sidebar, Remote `/chat-summaries` `rowState`/`unread`, `POST /chats/{chatId}/read` under `chat-read-state-v1` (contract revision 18), and iOS/Android rows with soft semantic fills. Desktop, iOS simulator and Android unit suites pass; PR CI and physical-device acceptance pending. | -| [Bot-First Aiden On The Go](bot-first-aiden-on-the-go-plan.md) | Active | Phases 0–9 are implemented. Native approval/Stop hardening is in review; Hermex Queue/Steer admission and consumers remain unfinished follow-on work. Every Bot has one persistent chat and one contact row; Favorites are a pinned placement, Bot chat reuses the shared runtime with Messages-inspired identity/bubbles and Aiden's existing composer, and New/Edit Bot exclusively own its durable model. Remote open-or-create, immediate exact-cache chat entry, optimistic favorites, shaped skeleton loading, stable photos, atomic desktop creation, fresh-inventory save retries, conflict-safe Mac/iOS draft rebasing, final-only Bot replies with expandable progress, native-or-companion image handling, and internal TestFlight build 22 are green. Eligible Apple Intelligence hardware, physical iPad, multi-device/Mac, packaged rollback, live Telegram, wider staged TestFlight, Xcode 27, accessibility, and App Store owner gates remain open. | +| [Aiden On The Go](aiden-on-the-go-plan.md) | Active | Version 0.1.0 build 22 is `VALID` and `IN_BETA_TESTING` for Internal Testers. Native lazy workspace file pages and bounded source previews merged in PR #222; physical-device review remains. Native cold/warm replay and optimistic-send recovery are hardened; physical-device recovery acceptance remains pending. Android matches iOS's app-icon switcher, Workspace hierarchy, warm scoped Bots/Usage/SSE lifecycle, Usage dashboard, image showcase/gallery, and keyboard-safe elevated composer. Both clients provide separate native photo and file intake; iOS adds an anchored Files/Camera/Photos surface with an embedded recoverable camera and ordered PhotoKit selection. Both clients remember the last explicitly chosen Workspace-chat provider, model and thinking level per paired Mac (PR #268, 0.51.0), restore it on relaunch after validating it against the host's current inventory (falling back to the chat's pair, then host defaults), and purge it on unpair; Android's composer model/thinking picker is now wired. Preference snapshots stay within the loaders' 256 KiB limit, iOS writes are fenced by the captured pairing generation, and Android seeds resolution from the current chat before host defaults. Both clients support native in-process dictation or bounded no-retention transcription by the paired Mac's local Parakeet model. iOS also ships progressive onboarding, bidirectional media, reliable mobile approvals, typed activity timelines, semantic haptics, and one-chat-per-Bot conversations with companion vision for text-only models. Physical iPad/manual permission-system-UI acceptance, privacy publication, final store assets, and external/public-release decisions remain open. | +| [Unified Workspace Sidebar](unified-workspace-sidebar-plan.md) | Active | Phases 1 and 2 ship the unified workspace/chat outline plus a feature-negotiated, transcript-free paginated summary read on Electron, iOS/iPadOS, and Android; physical-device performance acceptance remains open. Summary rows gained additive `rowState`/`unread` hints in contract revision 18 (PR #280, on main). | +| [Bot-First Aiden On The Go](bot-first-aiden-on-the-go-plan.md) | Active | Phases 0–9 are implemented. Native approval/Stop hardening merged in PR #218, and mid-flight Steer/Queue, question prompts and quiet chat merged in PR #251. Bot chat deep links (`aiden-otg://bot/{id}/chat`) merged in PR #276 and are on main. Every Bot has one persistent chat and one contact row; Favorites are a pinned placement, Bot chat reuses the shared runtime with Messages-inspired identity/bubbles and Aiden's existing composer, and New/Edit Bot exclusively own its durable model. Remote open-or-create, immediate exact-cache chat entry, optimistic favorites, shaped skeleton loading, stable photos, atomic desktop creation, fresh-inventory save retries, conflict-safe Mac/iOS draft rebasing, final-only Bot replies with expandable progress, native-or-companion image handling, and internal TestFlight build 22 are green. Eligible Apple Intelligence hardware, physical iPad, multi-device/Mac, packaged rollback, live Telegram, wider staged TestFlight, Xcode 27, accessibility, and App Store owner gates remain open. | | [Aiden Manual Pairing](aiden-manual-pairing-plan.md) | Implemented | The reviewed 100-bit setup-code path, shared one-use QR window, staged iOS activation, and adversarial coverage ship; hands-on LAN/Tailscale UI and physical-iPad acceptance remain open. | | [Compaction](compaction-plan.md) | Partial | Pi-native checkpoints, lifecycle/crash recovery, and exact audited-upstream compatibility ship; durable memory and provider-native paths remain open. | | [Designer Mode](designer-mode-plan.md) | Planned | Phase 0 validation has not started in the runtime. | -| [Dynamic Model Catalog](dynamic-model-catalog-plan.md) | Implemented | Validated pi.dev overlays, offline `0600` cache hydration, scoped setup refresh, four-hour launch refresh, force refresh, Pi metadata fallback, and Mac/iOS projection ship on pinned Pi 0.84.4. | +| [Dynamic Model Catalog](dynamic-model-catalog-plan.md) | Implemented | Validated pi.dev overlays, offline `0600` cache hydration, scoped setup refresh, four-hour launch refresh, force refresh, Pi metadata fallback, and Mac/iOS projection ship; Pi is now pinned to 0.87.1 (PR #246). | | [Generative UI Artifacts](generative-ui-artifacts-plan.md) | Active | Phases 0–6 shipped: chat-scoped `render_artifact`, strict sandboxed preview/export hosts, verified vendored Chart.js/Plotly/KaTeX, permission-aware `/visualize`, crash-recoverable authoritative storage/copies, descriptor-relative workspace reads, one-iframe handoff/expansion, visible failure states, and route-stable Responding/Visualizing activity. Three-agent PR review findings are remediated with focused regression coverage. | | [Generation Progress Notes](generation-progress-notes-plan.md) | Planned | No implementation yet. | | [Aiden Live Assistant](gemini-live-assistant-plan.md) | Partial | Voice-only Aiden Live ships enabled by default in 0.41.5 with Extended Thinking, the blue duplex orb, device selection, connection sounds, session threads, and session-authorized direct actions. Screen capture remains independently gated pending native-picker acceptance. | @@ -59,25 +36,45 @@ This directory is the source of truth for Aiden's implementation plans. The engi | [Long-thread payload upgrades](long-thread-payload-upgrade-plan.md) | Partial | Investigation complete: T3’s O(N²) stdout store does not exist here. No-op `toolRunning` timeline republish is skipped; Remote gzip, stream-journal debounce, chat JSON/attachments, and transcript windowing remain planned. | | [Model Insights](model-insights-plan.md) | Partial | A dedicated benchmark-only OpenRouter key, manual fetch, exact source-aware offline cache, metric-selectable collision-free capability suggestions, progressive canvas-first Pad UX, axis provenance, attribution, and direct-AA retirement ship; device-local pace signals remain. | | [Onboarding Authentication and Provider Validation](onboarding-auth-and-provider-validation-plan.md) | Active | Codex uses its dedicated auth surface, every interactive Pi provider can be configured during onboarding, OpenAI/Anthropic keys receive stronger catalog validation, completion is main-owned, and provider deferral stays explicit. | -| [Performance, Stability, Battery, and Efficiency](performance-stability-efficiency-plan.md) | Planned | Whole-app source audit is complete; implementation starts with instrumentation, durable state, and hard memory bounds. | +| [Performance, Stability, Battery, and Efficiency](performance-stability-efficiency-plan.md) | Planned | Whole-app source audit is complete; phased implementation has not started. Targeted bounded-work fixes (#282–#287 in 0.51.0, #288 on main; evidence in `docs/performance/`) landed independently and do not complete a phase. | | [Pi Provider Integration](pi-provider-integration-plan.md) | Partial | Pi built-ins, stores, auth, native routing, custom provider composition, canonical assistant provenance, voice credential lookup, and attended structured questions ship; scalable UX and rollout cleanup remain. | -| [Pi Compaction and Durable Memory Upgrade](pi-compaction-memory-upgrade-plan.md) | Active | Phases 0–7 are implemented and accepted after two reviews each. Executable replays, staged per-chat rollout, crash-safe receipts, and provider-native defer policy ship; a bounded small-context semantic-budget fix is implemented for PR review. Persisted budget overrides and installed/signed/credentialed operator evidence remain pending. | +| [Pi Compaction and Durable Memory Upgrade](pi-compaction-memory-upgrade-plan.md) | Active | Phases 0–7 are implemented and accepted after two reviews each. Executable replays, staged per-chat rollout, crash-safe receipts, and provider-native defer policy ship; the bounded small-context semantic-budget fix merged in PR #228, and Pi moved to 0.87.1 in PR #246. Persisted budget overrides and installed/signed/credentialed operator evidence remain pending. | | [Quick View and Non-Modal Environment Tools](quick-view-environment-tools-plan.md) | Implemented | Quick View and Environment now have independent persisted state; both render side by side when measured space permits and the background surface auto-hides on smaller allocations. Focus, compact-sidebar priority, compatibility routes, dock placement, focused suites, and production build pass; unlocked visual acceptance is pending. | -| [rpiv-advisor integration](rpiv-advisor-integration-plan.md) | Implemented | A bounded, tool-free, provider/auth-aware second opinion now uses an ephemeral per-consultation Ask User Question choice when the prompt does not name a reviewer, with no persistent Advisor settings or IPC. | | [rpiv-todo Integration](rpiv-todo-integration-plan.md) | Partial | Attended desktop chats have a journal-replayed native todo tool, strict fail-closed snapshots, owner-fenced IPC, and a self-hiding floating progress chip with portal details; packaged visual/accessibility acceptance remains open. | | [rpiv-btw Integration](rpiv-btw-integration-plan.md) | Partial | Attended desktop chats have bounded read-only side questions, ephemeral fingerprinted follow-ups, foreground-safe admission, exact provider dispatch, content-free usage accounting, and a native slash/card surface; packaged visual/accessibility acceptance remains open. | -| [Subagent Orchestration Expansion](subagent-orchestration-expansion-plan.md) | Active | Foreground implementer role and Full/Ask run grants are in progress; per-task child model override remains P1. Phases 0–6, Phase 7A durable lifecycle, Phase 7B1 storage, migration and foreground recovery are complete; `needs_attention` children now surface their pending question on desktop (Remote stays closed-vocabulary). App-lifetime coordinator activation remains next. | +| [Subagent Orchestration Expansion](subagent-orchestration-expansion-plan.md) | Active | Foreground implementer role and Full/Ask run grants merged in PR #247 (0.50.0); per-task child model override remains P1. Phases 0–6, Phase 7A durable lifecycle, Phase 7B1 storage, migration and foreground recovery are complete. `needs_attention` children surface their pending question on desktop (PR #266, 0.51.0; Remote stays closed-vocabulary). App-lifetime coordinator activation remains next. | | [Taracodlab Learnings](taracodlab-learnings-plan.md) | Partial | Phases A–B and D, plus core Phase E, are implemented; the remaining roadmap is open. | -| [Live Activity freshness chips and Bot deep links](live-activity-freshness-bot-deeplinks-plan.md) | Implemented for review | iOS Live Activities show a bounded tool-call chip and a self-updating "Updated Xs ago" / "Stale" chip; `aiden-otg://bot/{id}/chat` opens the Bot's canonical chat on iOS and Android without creating chats. Android notification chips and physical-device acceptance remain. | -| [Hermes-inspired Bot run control](hermes-bot-run-control-plan.md) | Active | Telegram bounded queue, cancellation and canonical-chat shipped; shared foreground input admission (`chat-run-input-v1`) shipped on `feature/on-the-go-midflight-ops`; busy-composer Steer/Queue/Redirect and pending `ask_user_question` prompts (`chat-question-prompts-v1`) shipped on iOS + Android. | +| [Hermes-inspired Bot run control](hermes-bot-run-control-plan.md) | Active | Telegram bounded queue, cancellation and canonical-chat shipped; shared foreground input admission (`chat-run-input-v1`) merged in PR #251; busy-composer Steer/Queue/Redirect and pending `ask_user_question` prompts (`chat-question-prompts-v1`) shipped on iOS + Android. PRs #220 and #223 were closed as superseded by #251; their desktop and Telegram Steer parts shipped in #298 (desktop composer and queued-row Steer plus Telegram `/steer` through the shared admission; on main, no Remote contract change). | | [Telegram First-Class Agent Parity](telegram-first-class-agent-parity-plan.md) | Active | Controls, compaction, skills, rich inbound, drafts/activity, buttons, documents, Settings, and onboarding are green; Threaded Mode/profiles/extensions/TTS/live smoke remain. | | [Update, Microphone, and Computer Use Hardening](update-microphone-computer-use-hardening-plan.md) | Partial | Installed acceptance found a silent stalled download; observable full-download recovery is implemented, while repaired-build → next-release and clean-TCC acceptance remain. | -| [Web Access Rehaul](web-access-rehaul-plan.md) | Partial | Implementation is complete through Phase 5: fresh profiles stay default-on with anonymous Exa, onboarding no longer shows a Web Search toggle, Settings exposes 17 reviewed shipped providers with fenced Fixed/Automatic routing, autonomous authority remains explicit, and a startup-bound Exa-only rollback preserves hidden state. Focused suites, Settings E2E, build, development packaging, and hardened package verification pass; the credential-backed live installed matrix remains a release-owner acceptance gate. | +| [Web Access Rehaul](web-access-rehaul-plan.md) | Partial | Implementation is complete through Phase 5: fresh profiles stay default-on with anonymous Exa, onboarding no longer shows a Web Search toggle, Settings exposes 17 reviewed shipped providers with fenced Fixed/Automatic routing, autonomous authority remains explicit, and a startup-bound Exa-only rollback preserves hidden state. Tavily now accepts a pooled set of keys with failover ([key pool](completed/web-search-key-pool-plan.md), PR #278, 0.51.0). Focused suites, Settings E2E, build, development packaging, and hardened package verification pass; the credential-backed live installed matrix remains a release-owner acceptance gate. | ## Completed | Plan | Status | Completion note | | ---------------------------------------------------------------------------------------------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | +| [Dictation: Parakeet lifecycle, modes, dictionary](completed/dictation-parakeet-modes-plan.md) | Complete | Configurable Parakeet idle unload with warm-up, toggle/hold/tap-or-hold shortcut modes, and a custom dictionary; merged in PR #279, on main. VAD, history and mute are later work; real-hardware acceptance pending. | +| [Dictation Secure Input warning](completed/dictation-secure-input-plan.md) | Complete | Dictation probes macOS Secure Event Input before pasting and keeps the transcript on the clipboard with a ⌘V hint when blocked; merged in PR #267, on main. | +| [Tool approval scopes](completed/tool-approval-scopes-plan.md) | Complete | Allow once / Allow for this chat / Always allow for exact parent workspace commands and file writes, revocable in Settings → Tool approvals, with iOS and Android menus; merged in PR #273 as Aiden Remote contract revision 17, on main. | +| [Live Activity freshness chips and Bot deep links](completed/live-activity-freshness-bot-deeplinks-plan.md) | Complete | iOS Live Activity tool-call and freshness chips plus `aiden-otg://bot/{id}/chat` on iOS and Android; merged in PR #276, on main. Android notification chips and physical-device acceptance remain follow-ups. | +| [Queue while compacting](completed/queue-while-compacting-plan.md) | Complete | Manual `/compact` keeps the desktop composer editable; messages queue behind a per-chat hold and pause on failure; merged in PR #272, on main. | +| [MCP numeric schema formats](completed/mcp-numeric-schema-formats-plan.md) | Complete | Desktop and CLI MCP tool schemas drop schemars numeric formats and keep exact width ranges as bounds; merged in PR #264, on main. | +| [Web Search API key pool](completed/web-search-key-pool-plan.md) | Complete | Tavily holds up to 8 encrypted keys with ordered or round-robin use, cooldowns and failover; merged in PR #278 and shipped in 0.51.0. Other providers and CLI parity remain follow-ups. | +| [Timed ask-user waits](completed/timed-ask-user-plan.md) | Complete | Optional `timeoutSeconds`, bounded unattended waits, late-answer follow-up offers on desktop and expiry notices on iOS/Android; merged in PR #270 and shipped in 0.51.0. | +| [Live subagent context window](completed/subagent-live-context-window-plan.md) | Complete | Desktop roster and detail show each running child's provider-reported context use; merged in PR #271 and shipped in 0.51.0. Remote/iOS/Android live context is a follow-up. | +| [Mobile transcript polish](completed/mobile-transcript-polish-plan.md) | Complete | Worked-for timers, timestamps, copy and Ask about this on iOS and Android with no protocol revision; merged in PR #277 and shipped in 0.51.0. Physical-device visual acceptance remains. | +| [Transcript polish: sticky headers, preparing stage, turn footers](completed/transcript-polish-sticky-headers-plan.md) | Complete | Sticky Thinking/activity headers, `Preparing ` on desktop, iOS and Android, and settled-turn footers; merged in PR #269 and shipped in 0.51.0. Mobile and live-streaming footers are follow-ups. | +| [Composer Context Meter](completed/composer-context-meter-plan.md) | Complete | Composer gauge and popover driven by `projectNextContextUsage` with live `chat:context-pressure` pushes; merged in PR #187 and shipped in 0.50.0. Hands-on visual acceptance is a release follow-up. | +| [Rich link previews for Chats and Bots](completed/rich-link-previews-plan.md) | Complete | URL-derived provider icons and bounded hover/focus cards in Chat and Bot transcripts, with no network requests; merged in PR #253 and shipped in 0.50.0. The optional authenticated metadata phase needs its own plan. | +| [Chronological Chat Motion](completed/chronological-chat-motion-plan.md) | Complete | Readable Thinking, tool rows and prose project in order across desktop and native chats; merged in PR #224 and shipped in 0.43.0. | +| [Durable chat pull requests](completed/chat-pull-requests-plan.md) | Complete | Durable multi-link PR identities, exact create intent, selected push repository and atomic recovery; merged in PR #184 and shipped in 0.43.0. | +| [Trusted AGENTS refresh](completed/trusted-agents-refresh-plan.md) | Complete | Bounded global/workspace instruction refresh at model-turn boundaries with a per-dispatch scope fence; merged in PR #232 and shipped in 0.43.0. | +| [Scoped MCP resources](completed/mcp-scoped-resources-plan.md) | Complete | Per-server resource inventory, templates and handle-bound reads; merged in PR #230 and shipped in 0.43.0. | +| [Scoped MCP server instructions](completed/mcp-server-instructions-plan.md) | Complete | Bounded generation-owned service guidance filtered by final tool admission; merged in PR #229 and shipped in 0.43.0. | +| [Skill and MCP session context](completed/skill-mcp-session-context-plan.md) | Complete | Skill model/user invocation policy merged in PR #214; its [audit](completed/mcp-session-context-audit.md) deliverables shipped in #226, #229, #230 and #232 (0.43.0). Physical iOS execution remains a device follow-up. | +| [Durable tool output and produced files](completed/durable-tool-output-plan.md) | Complete | Bounded command/MCP output recovery and shared produced-file provenance; merged in PR #219 and shipped in 0.43.0. Physical iOS execution remains a device follow-up. | +| [Draft Agent Chats](completed/draft-agent-chats-plan.md) | Complete | Transient desktop drafts, atomic first-message creation and the one-time legacy empty-chat migration; merged in PR #103. | +| [rpiv-advisor integration](completed/rpiv-advisor-integration-plan.md) | Complete | A bounded, tool-free, provider/auth-aware second opinion uses an ephemeral per-consultation Ask User Question choice when the prompt does not name a reviewer, with no persistent Advisor settings or IPC. | | [CLI Appearance Playground](completed/cli-appearance-playground.md) | Complete | Separate React/DialKit studio with ten directions, live controls, comparison, saved looks and proposal exports; build and browser tests pass. Applying a chosen CLI design remains user-directed. | | [Unified settings and workspace presentation](completed/settings-unification-plan.md) | Complete | Workspace path preferences, responsive Model Pad, global Skills enforcement, unified Settings, native Bot catalog routing/cache isolation, tests, and adversarial reviews delivered in PR #97; final CI tracked by the PR. | | [LLM and pi-vcc Compaction](completed/pi-vcc-compaction-plan.md) | Complete | Prepared for 0.38.1: LLM default, experimental local compiler/recall, per-run inheritance, desktop controls, native activity, and signed packaged Settings/compaction/restart checks pass. | @@ -104,4 +101,12 @@ This directory is the source of truth for Aiden's implementation plans. The engi | [Pi Thinking Disclosure](completed/pi-thinking-disclosure-plan.md) | Complete | Provider-neutral readable Pi thinking, a one-second inspectable preview, and a durable local presentation toggle now match the audited Pi contract. | | [Linux Desktop Support](completed/linux-desktop-support-plan.md) | Complete | Linux x64/arm64 AppImage, DEB, and RPM packages, explicit platform capability tradeoffs, native helpers, and hosted Ubuntu/Fedora package and E2E acceptance all pass. | +### Shipped without a plan doc + +| Change | Status | Note | +| ------ | ------ | ---- | +| Chat row states and honest unread (see `.memory/chat-row-states.md`) | Complete | Needs approval / Needs input / Working / Idle rows plus a durable unread marker on the desktop sidebar, Remote `/chat-summaries` and iOS/Android, with `POST /chats/{chatId}/read` under `chat-read-state-v1` (contract revision 18); merged in PR #280, on main. Bot rows and physical-device acceptance are follow-ups. | +| Remote subagent interrupt ([API](../aiden-remote-api-v1.md)) | Complete | `POST /chats/{chatId}/agents/{agentId}/interrupt` (`chat-agent-interrupt-v1`, contract revision 16) reuses the desktop subagent stop path; iOS and Android agent sheets offer a confirmed Stop. Merged in PR #275, on main; physical-device acceptance remains. | +| Chat width setting (T3 #11594) | Complete | Appearance → **Chat width** (Narrow 44rem / Default 52rem / Wide 64rem / Full) persists as `AppearanceConfig.chatWidth` and drives `--chat-content-max-width`, so the transcript, approvals and composer resize together. Desktop only; merged in PR #265, on main. | + Move a plan to `completed/` only when its original delivery scope is complete. Keep the original plan as historical documentation; follow-on work belongs in a new active plan. diff --git a/docs/plans/aiden-cli-plan.md b/docs/plans/aiden-cli-plan.md index 8607a44ca..a67c00ba1 100644 --- a/docs/plans/aiden-cli-plan.md +++ b/docs/plans/aiden-cli-plan.md @@ -1,6 +1,6 @@ # Aiden CLI — pi-based headless Aiden Agent -Build `aiden`, a standalone CLI/TUI inside this repo (`packages/cli/`) that runs the Aiden feature set on any machine — including headless Linux servers — on top of the pi coding agent (`@earendil-works/pi-coding-agent`, MIT, pinned to the same 0.84.4 line as the desktop app's `pi-agent-core`/`pi-ai`). +Build `aiden`, a standalone CLI/TUI inside this repo (`packages/cli/`) that runs the Aiden feature set on any machine — including headless Linux servers — on top of the pi coding agent (`@earendil-works/pi-coding-agent`, MIT, pinned to the same 0.87.1 line as the desktop app's `pi-agent-core`/`pi-ai` since #246). The TUI is pi's own interactive TUI customized with Aiden themes and (later) extension UI; headless use rides pi's print/JSON/RPC modes. Interop with Aiden Desktop is phased in later (shared stores/formats, then live coordination). diff --git a/docs/plans/chat-pull-requests-plan.md b/docs/plans/completed/chat-pull-requests-plan.md similarity index 97% rename from docs/plans/chat-pull-requests-plan.md rename to docs/plans/completed/chat-pull-requests-plan.md index 3da731213..708ebd62a 100644 --- a/docs/plans/chat-pull-requests-plan.md +++ b/docs/plans/completed/chat-pull-requests-plan.md @@ -1,6 +1,6 @@ # Durable chat pull requests -Status: Implemented and independently reviewed; hosted CI acceptance is tracked on PR #184. +Status: Complete — merged in [PR #184](https://github.com/sambitcreate/aiden-agent/pull/184) on 2026-09-23 and shipped in 0.43.0. ## Scope diff --git a/docs/plans/chronological-chat-motion-plan.md b/docs/plans/completed/chronological-chat-motion-plan.md similarity index 91% rename from docs/plans/chronological-chat-motion-plan.md rename to docs/plans/completed/chronological-chat-motion-plan.md index 49f2d31d4..44d0571dc 100644 --- a/docs/plans/chronological-chat-motion-plan.md +++ b/docs/plans/completed/chronological-chat-motion-plan.md @@ -1,6 +1,6 @@ # Chronological Chat Motion -Status: Implemented in [PR #224](https://github.com/sambitcreate/aiden-agent/pull/224); review and visual acceptance pending. +Status: Complete — merged in [PR #224](https://github.com/sambitcreate/aiden-agent/pull/224) on 2026-09-23 and shipped in 0.43.0. Hands-on visual acceptance is a release follow-up, not open plan scope. ## Objective diff --git a/docs/plans/composer-context-meter-plan.md b/docs/plans/completed/composer-context-meter-plan.md similarity index 93% rename from docs/plans/composer-context-meter-plan.md rename to docs/plans/completed/composer-context-meter-plan.md index 86197f57a..ccbc086a6 100644 --- a/docs/plans/composer-context-meter-plan.md +++ b/docs/plans/completed/composer-context-meter-plan.md @@ -1,6 +1,6 @@ # Composer Context Meter -Status: Implemented in [PR #187](https://github.com/sambitcreate/aiden-agent/pull/187); review and visual acceptance pending. +Status: Complete — merged in [PR #187](https://github.com/sambitcreate/aiden-agent/pull/187) on 2026-09-26 and shipped in 0.50.0. Hands-on visual acceptance is a release follow-up, not open plan scope. ## Objective diff --git a/docs/plans/dictation-parakeet-modes-plan.md b/docs/plans/completed/dictation-parakeet-modes-plan.md similarity index 94% rename from docs/plans/dictation-parakeet-modes-plan.md rename to docs/plans/completed/dictation-parakeet-modes-plan.md index 30d436a50..b4292d41f 100644 --- a/docs/plans/dictation-parakeet-modes-plan.md +++ b/docs/plans/completed/dictation-parakeet-modes-plan.md @@ -1,6 +1,6 @@ # Dictation: Parakeet lifecycle, activation modes, and custom dictionary -Status: Implemented for review (branch `feature/dictation-parakeet-modes`). +Status: Complete — merged in [PR #279](https://github.com/sambitcreate/aiden-agent/pull/279) on 2026-09-30; on main after 0.51.0, not yet released. VAD, history and mute remain later work; real-hardware acceptance is still pending. This is the first slice of the Handy-inspired P1 dictation work. VAD, dictation history, and mute-while-recording come later. diff --git a/docs/plans/dictation-secure-input-plan.md b/docs/plans/completed/dictation-secure-input-plan.md similarity index 94% rename from docs/plans/dictation-secure-input-plan.md rename to docs/plans/completed/dictation-secure-input-plan.md index a93d2e975..d4fbfb938 100644 --- a/docs/plans/dictation-secure-input-plan.md +++ b/docs/plans/completed/dictation-secure-input-plan.md @@ -1,6 +1,6 @@ # Dictation Secure Input Warning -Status: Implemented for review (`feature/dictation-secure-input`). +Status: Complete — merged in [PR #267](https://github.com/sambitcreate/aiden-agent/pull/267) on 2026-09-30; on main after 0.51.0, not yet released. Source: Handy parity tracker, P0 — "dictation paste silently fails while macOS Secure Event Input is active". diff --git a/docs/plans/draft-agent-chats-plan.md b/docs/plans/completed/draft-agent-chats-plan.md similarity index 97% rename from docs/plans/draft-agent-chats-plan.md rename to docs/plans/completed/draft-agent-chats-plan.md index f854570b0..b4ff78549 100644 --- a/docs/plans/draft-agent-chats-plan.md +++ b/docs/plans/completed/draft-agent-chats-plan.md @@ -1,6 +1,6 @@ # Draft agent chats -Status: Implemented; pull-request CI and merge pending. +Status: Complete — merged in [PR #103](https://github.com/sambitcreate/aiden-agent/pull/103) on 2026-09-11. Ordinary desktop workspace chats stay transient until the first user message is durably saved. Opening New Agent, entering an empty workspace, or opening a fresh worktree must not install an empty chat or sidebar history entry. Leaving an unsent draft discards it. A committed message remains saved even if generation fails. diff --git a/docs/plans/durable-tool-output-plan.md b/docs/plans/completed/durable-tool-output-plan.md similarity index 94% rename from docs/plans/durable-tool-output-plan.md rename to docs/plans/completed/durable-tool-output-plan.md index 6d1532e85..7f1ebbf31 100644 --- a/docs/plans/durable-tool-output-plan.md +++ b/docs/plans/completed/durable-tool-output-plan.md @@ -1,6 +1,6 @@ # Durable tool output and produced files -Status: Implemented — local checks and independent reviews passed; physical iOS execution and hosted PR checks pending. +Status: Complete — merged in [PR #219](https://github.com/sambitcreate/aiden-agent/pull/219) on 2026-09-23 and shipped in 0.43.0. Physical iOS execution remains a device-acceptance follow-up. ## Confirmed scope diff --git a/docs/plans/live-activity-freshness-bot-deeplinks-plan.md b/docs/plans/completed/live-activity-freshness-bot-deeplinks-plan.md similarity index 90% rename from docs/plans/live-activity-freshness-bot-deeplinks-plan.md rename to docs/plans/completed/live-activity-freshness-bot-deeplinks-plan.md index 64c983d88..678792272 100644 --- a/docs/plans/live-activity-freshness-bot-deeplinks-plan.md +++ b/docs/plans/completed/live-activity-freshness-bot-deeplinks-plan.md @@ -1,6 +1,6 @@ # Live Activity freshness chips and Bot deep links -Status: Implemented for review. This is the Hermex 1.7 parity slice for Aiden On The Go. +Status: Complete — merged in [PR #276](https://github.com/sambitcreate/aiden-agent/pull/276) on 2026-09-30; on main after 0.51.0, not yet released. Android notification chips and physical-device acceptance remain follow-ups. This is the Hermex 1.7 parity slice for Aiden On The Go. ## Goal diff --git a/docs/plans/mcp-numeric-schema-formats-plan.md b/docs/plans/completed/mcp-numeric-schema-formats-plan.md similarity index 88% rename from docs/plans/mcp-numeric-schema-formats-plan.md rename to docs/plans/completed/mcp-numeric-schema-formats-plan.md index 23e60aebe..b7b6ca9d9 100644 --- a/docs/plans/mcp-numeric-schema-formats-plan.md +++ b/docs/plans/completed/mcp-numeric-schema-formats-plan.md @@ -1,6 +1,6 @@ # MCP numeric schema formats -Status: Implemented for review. +Status: Complete — merged in [PR #264](https://github.com/sambitcreate/aiden-agent/pull/264) on 2026-09-30; on main after 0.51.0, not yet released. ## Problem diff --git a/docs/plans/mcp-scoped-resources-plan.md b/docs/plans/completed/mcp-scoped-resources-plan.md similarity index 97% rename from docs/plans/mcp-scoped-resources-plan.md rename to docs/plans/completed/mcp-scoped-resources-plan.md index 7d999e0da..abe0b45dc 100644 --- a/docs/plans/mcp-scoped-resources-plan.md +++ b/docs/plans/completed/mcp-scoped-resources-plan.md @@ -1,6 +1,6 @@ # Scoped MCP resources -Status: Implemented for PR review; local validation and both independent Sol reviews clear. +Status: Complete — merged in [PR #230](https://github.com/sambitcreate/aiden-agent/pull/230) on 2026-09-23 and shipped in 0.43.0. Separate branch from origin/main; PR214/226/229 remain untouched. No SDK/dependency or MCP tool-result spill changes. diff --git a/docs/plans/mcp-server-instructions-plan.md b/docs/plans/completed/mcp-server-instructions-plan.md similarity index 92% rename from docs/plans/mcp-server-instructions-plan.md rename to docs/plans/completed/mcp-server-instructions-plan.md index 3d2472027..f7bb0550a 100644 --- a/docs/plans/mcp-server-instructions-plan.md +++ b/docs/plans/completed/mcp-server-instructions-plan.md @@ -1,6 +1,6 @@ # Scoped MCP server instructions -Status: Implemented for review, 2026-09-22. Baseline origin/main `c8c09e0d2`. This is a separate slice from green skill-policy PR #214 and capability-status PR #226. +Status: Complete — merged in [PR #229](https://github.com/sambitcreate/aiden-agent/pull/229) on 2026-09-23 and shipped in 0.43.0, alongside skill-policy PR #214 and capability-status PR #226. Original baseline: origin/main `c8c09e0d2`. ## Behavior and authority diff --git a/docs/plans/mcp-session-context-audit.md b/docs/plans/completed/mcp-session-context-audit.md similarity index 88% rename from docs/plans/mcp-session-context-audit.md rename to docs/plans/completed/mcp-session-context-audit.md index 97b4c2352..bce3d7063 100644 --- a/docs/plans/mcp-session-context-audit.md +++ b/docs/plans/completed/mcp-session-context-audit.md @@ -1,7 +1,7 @@ # Skill and MCP session context — remaining-scope audit Date: 2026-09-22. Baseline: origin/main `c8c09e0d239dd596a68b7a5d5719d543399d077b`. -Status: Partial. This audit accounts for the original assignment; it does not claim the whole program is complete. +Status: Complete (updated 2026-09-27). Every deliverable this audit classified merged to main on 2026-09-23 and shipped in 0.43.0: skill invocation policy ([#214](https://github.com/sambitcreate/aiden-agent/pull/214)), advertised capability status ([#226](https://github.com/sambitcreate/aiden-agent/pull/226)), scoped server instructions ([#229](https://github.com/sambitcreate/aiden-agent/pull/229)), scoped resources ([#230](https://github.com/sambitcreate/aiden-agent/pull/230)) and trusted AGENTS refresh ([#232](https://github.com/sambitcreate/aiden-agent/pull/232)). The table below is the original 2026-09-22 classification. | Item | Classification | Evidence and completion boundary | | --- | --- | --- | diff --git a/docs/plans/mobile-transcript-polish-plan.md b/docs/plans/completed/mobile-transcript-polish-plan.md similarity index 94% rename from docs/plans/mobile-transcript-polish-plan.md rename to docs/plans/completed/mobile-transcript-polish-plan.md index 46bfdedd0..9de1b5134 100644 --- a/docs/plans/mobile-transcript-polish-plan.md +++ b/docs/plans/completed/mobile-transcript-polish-plan.md @@ -1,6 +1,6 @@ # Mobile transcript polish (Hermex Tier 1) -Status: Implemented for review. Hosted CI and physical-device visual acceptance are still open. +Status: Complete — merged in [PR #277](https://github.com/sambitcreate/aiden-agent/pull/277) on 2026-09-29 and shipped in 0.51.0. Physical-device visual acceptance remains a follow-up. ## Goal diff --git a/docs/plans/queue-while-compacting-plan.md b/docs/plans/completed/queue-while-compacting-plan.md similarity index 95% rename from docs/plans/queue-while-compacting-plan.md rename to docs/plans/completed/queue-while-compacting-plan.md index 7c0d84f38..edd8b8f7e 100644 --- a/docs/plans/queue-while-compacting-plan.md +++ b/docs/plans/completed/queue-while-compacting-plan.md @@ -1,6 +1,6 @@ # Queue Messages While Compaction Runs -Status: Implemented for review (desktop first slice). +Status: Complete (desktop first slice) — merged in [PR #272](https://github.com/sambitcreate/aiden-agent/pull/272) on 2026-09-30; on main after 0.51.0, not yet released. ## Problem diff --git a/docs/plans/rich-link-previews-plan.md b/docs/plans/completed/rich-link-previews-plan.md similarity index 98% rename from docs/plans/rich-link-previews-plan.md rename to docs/plans/completed/rich-link-previews-plan.md index bf3c3167d..2cff9445e 100644 --- a/docs/plans/rich-link-previews-plan.md +++ b/docs/plans/completed/rich-link-previews-plan.md @@ -1,6 +1,6 @@ # Rich link previews for Chats and Bots -Status: Implemented for review +Status: Complete — the renderer-only slice merged in [PR #253](https://github.com/sambitcreate/aiden-agent/pull/253) on 2026-09-26 and shipped in 0.50.0. The optional authenticated metadata phase below has not started and needs its own plan. Baseline: `origin/main` at `7a4d9d0bde09d9dbe81b38d2611ac29dc848ee62` on 2026-09-25. diff --git a/docs/plans/skill-mcp-session-context-plan.md b/docs/plans/completed/skill-mcp-session-context-plan.md similarity index 87% rename from docs/plans/skill-mcp-session-context-plan.md rename to docs/plans/completed/skill-mcp-session-context-plan.md index 01d4cc3f9..3942d07b1 100644 --- a/docs/plans/skill-mcp-session-context-plan.md +++ b/docs/plans/completed/skill-mcp-session-context-plan.md @@ -1,6 +1,6 @@ # Skill and MCP session context -Status: Partial — invocation-policy slice implemented in PR #214, with hosted CI and review passed on implementation head 5ab368c1. Physical iOS execution remains blocked by a locked device; broader MCP scope remains deferred. +Status: Complete — the invocation-policy slice merged in [PR #214](https://github.com/sambitcreate/aiden-agent/pull/214) on 2026-09-23 and shipped in 0.43.0. The broader MCP scope shipped in separate slices (#226, #229, #230, #232; see the [audit](mcp-session-context-audit.md)). Physical iOS execution remains a device-acceptance follow-up. ## Bounded implementation diff --git a/docs/plans/subagent-live-context-window-plan.md b/docs/plans/completed/subagent-live-context-window-plan.md similarity index 86% rename from docs/plans/subagent-live-context-window-plan.md rename to docs/plans/completed/subagent-live-context-window-plan.md index 892c79cf7..b4c65e40e 100644 --- a/docs/plans/subagent-live-context-window-plan.md +++ b/docs/plans/completed/subagent-live-context-window-plan.md @@ -1,6 +1,6 @@ # Live subagent context window -Status: In review (desktop). Source: pi-subagents #2448, reusing the #187 context meter's formatting and 80% warning threshold. +Status: Complete (desktop) — merged in [PR #271](https://github.com/sambitcreate/aiden-agent/pull/271) on 2026-09-29 and shipped in 0.51.0. Remote, iOS and Android live context remain a follow-up. Source: pi-subagents #2448, reusing the #187 context meter's formatting and 80% warning threshold. ## Goal diff --git a/docs/plans/timed-ask-user-plan.md b/docs/plans/completed/timed-ask-user-plan.md similarity index 93% rename from docs/plans/timed-ask-user-plan.md rename to docs/plans/completed/timed-ask-user-plan.md index 280e25ded..f4784c3c7 100644 --- a/docs/plans/timed-ask-user-plan.md +++ b/docs/plans/completed/timed-ask-user-plan.md @@ -1,6 +1,6 @@ # Timed ask-user waits with late-reply handling -Status: Implemented for review. +Status: Complete — merged in [PR #270](https://github.com/sambitcreate/aiden-agent/pull/270) on 2026-09-29 and shipped in 0.51.0. CLI timeout policy and native late-answer prefill remain follow-ups. Source: the DeepSeek harness comparison page and the 2026-09-24..27 digests. They point out that an `ask_user_question` wait can block an unattended run forever, and that an answer arriving after the agent has moved on is silently dropped. diff --git a/docs/plans/tool-approval-scopes-plan.md b/docs/plans/completed/tool-approval-scopes-plan.md similarity index 94% rename from docs/plans/tool-approval-scopes-plan.md rename to docs/plans/completed/tool-approval-scopes-plan.md index 4750a03b8..9a46a4ef1 100644 --- a/docs/plans/tool-approval-scopes-plan.md +++ b/docs/plans/completed/tool-approval-scopes-plan.md @@ -1,6 +1,6 @@ # Tool approval scopes: once, this chat, always -Status: Implemented for review (branch `feature/approval-scopes`). +Status: Complete — merged in [PR #273](https://github.com/sambitcreate/aiden-agent/pull/273) on 2026-09-30 as Aiden Remote contract revision 17; on main after 0.51.0, not yet released. ## Goal diff --git a/docs/plans/transcript-polish-sticky-headers-plan.md b/docs/plans/completed/transcript-polish-sticky-headers-plan.md similarity index 92% rename from docs/plans/transcript-polish-sticky-headers-plan.md rename to docs/plans/completed/transcript-polish-sticky-headers-plan.md index e7928c60f..fd0a6de45 100644 --- a/docs/plans/transcript-polish-sticky-headers-plan.md +++ b/docs/plans/completed/transcript-polish-sticky-headers-plan.md @@ -1,6 +1,6 @@ # Transcript polish: sticky section headers, preparing tool stage, turn footers -Status: Implemented for review (desktop). Source: the DeepSeek transcript research page, items on sticky reasoning headers, tool-call staging and per-turn metadata. +Status: Complete — merged in [PR #269](https://github.com/sambitcreate/aiden-agent/pull/269) on 2026-09-28 and shipped in 0.51.0. The mobile and live-streaming footers remain follow-ups. Source: the DeepSeek transcript research page, items on sticky reasoning headers, tool-call staging and per-turn metadata. ## Goals diff --git a/docs/plans/trusted-agents-refresh-plan.md b/docs/plans/completed/trusted-agents-refresh-plan.md similarity index 96% rename from docs/plans/trusted-agents-refresh-plan.md rename to docs/plans/completed/trusted-agents-refresh-plan.md index 62220b618..7ecb0c862 100644 --- a/docs/plans/trusted-agents-refresh-plan.md +++ b/docs/plans/completed/trusted-agents-refresh-plan.md @@ -1,6 +1,6 @@ # Trusted AGENTS instruction refresh -Status: Implemented for PR review; local validation and both independent Sol reviews clear. +Status: Complete — merged in [PR #232](https://github.com/sambitcreate/aiden-agent/pull/232) on 2026-09-23 and shipped in 0.43.0. Ordinary generations load user-authored instructions from the portable config root AGENTS.md (normally ~/.aiden/AGENTS.md), then the authorized workspace root AGENTS.md. Workspace files are withheld when either effective or persisted workspace permission is none. Bot and Assistant lanes keep their explicitly granted prompt sources and do not acquire ambient instruction access. The global Skills enable switch continues to govern skills independently; AGENTS files do not enable any skill or tool. diff --git a/docs/plans/web-search-key-pool-plan.md b/docs/plans/completed/web-search-key-pool-plan.md similarity index 95% rename from docs/plans/web-search-key-pool-plan.md rename to docs/plans/completed/web-search-key-pool-plan.md index 36e1ab2da..15ab4d079 100644 --- a/docs/plans/web-search-key-pool-plan.md +++ b/docs/plans/completed/web-search-key-pool-plan.md @@ -1,6 +1,6 @@ # Web Search API key pool -Status: Implemented for review (Tavily). +Status: Complete (Tavily) — merged in [PR #278](https://github.com/sambitcreate/aiden-agent/pull/278) on 2026-09-29 and shipped in 0.51.0. Other keyed providers and CLI parity remain follow-ups. ## Goal diff --git a/docs/plans/durable-jobs-leases-plan.md b/docs/plans/durable-jobs-leases-plan.md index 1857cafb7..cf31f3e2c 100644 --- a/docs/plans/durable-jobs-leases-plan.md +++ b/docs/plans/durable-jobs-leases-plan.md @@ -1,6 +1,6 @@ # Durable Bot and chat runs — OpenMuse adoption -Status: PR 1 foundation implemented for review; production Bot runtime, desktop controls and Remote/native rollout remain pending. Implementation authorized in the follow-up request. +Status: PR 1 foundation merged in [PR #243](https://github.com/sambitcreate/aiden-agent/pull/243) on 2026-09-26 and shipped in 0.50.0; production Bot runtime, desktop controls and Remote/native rollout remain pending. Implementation authorized in the follow-up request. Verified: 2026-09-23. Priority: P0. Adopt OpenMuse's SQL ownership leases and durable controls for **Mac-owned Bot/chat runs**, using SQLite around Aiden's existing Pi runtime. Start with accepted Bot chat turns, then regular workspace chats. Do not add Comfy, image-generation workflows, or Design integration in this scope. diff --git a/docs/plans/gemini-tts-read-aloud-plan.md b/docs/plans/gemini-tts-read-aloud-plan.md index d24719150..e2be7d89e 100644 --- a/docs/plans/gemini-tts-read-aloud-plan.md +++ b/docs/plans/gemini-tts-read-aloud-plan.md @@ -1,7 +1,7 @@ # Gemini 3.8 Read Aloud and Voice Studio — Implementation Status **Status:** Partial implementation (desktop unary-WAV and desktop-configured native playback implemented; live acceptance, streaming, Voice Studio, and physical playback verification pending). -**Branch:** `feature/gemini-3-8-tts`. +**Branch:** `feature/gemini-3-8-tts`, merged in [PR #245](https://github.com/sambitcreate/aiden-agent/pull/245) on 2026-09-26 and shipped in 0.50.0. **Full plan:** the delivered `plan.md` document (September 23, 2026 audit of `7a4d9d0b`). This document tracks the repository's implementation state against the audited diff --git a/docs/plans/hermes-bot-run-control-plan.md b/docs/plans/hermes-bot-run-control-plan.md index 0a4c44fbe..1bc2f3472 100644 --- a/docs/plans/hermes-bot-run-control-plan.md +++ b/docs/plans/hermes-bot-run-control-plan.md @@ -1,6 +1,6 @@ # Hermes-inspired Bot run control -Status: Active (Telegram slice under review; shared foreground admission next) +Status: Active — Telegram slice merged in [PR #216](https://github.com/sambitcreate/aiden-agent/pull/216) (0.43.0); shared foreground admission (`chat-run-input-v1`), native Steer/Queue/Redirect and pending-question prompts merged in [PR #251](https://github.com/sambitcreate/aiden-agent/pull/251) (0.50.0). Earlier stacked PRs #220 and #223 are still open. September 23 desktop composer slice: Steer is exposed through exact-stream, document-owned IPC to Pi's existing queue, with text-only validation and a diff --git a/docs/plans/linux-macos-parity-plan.md b/docs/plans/linux-macos-parity-plan.md index 1f624a47b..3232da536 100644 --- a/docs/plans/linux-macos-parity-plan.md +++ b/docs/plans/linux-macos-parity-plan.md @@ -1,6 +1,6 @@ # Linux macOS parity reconciliation -Status: Active — phases 1–3c implemented and reviewed; phase 4 hosted validation running; main 0.43.0 reconciliation merge in progress; Fedora Computer Use prerequisites in progress. +Status: Active — phases 1–3c implemented and reviewed; the main reconciliation merged to main in [PR #71](https://github.com/sambitcreate/aiden-agent/pull/71) on 2026-09-26 and shipped in 0.50.0; Fedora Computer Use prerequisites in progress. Baseline: Linux `4747cf95`, macOS main `origin/main` (0.43.0). diff --git a/docs/plans/mobile-task-progress-and-subagents-plan.md b/docs/plans/mobile-task-progress-and-subagents-plan.md index 29bf95cd0..0b81b1354 100644 --- a/docs/plans/mobile-task-progress-and-subagents-plan.md +++ b/docs/plans/mobile-task-progress-and-subagents-plan.md @@ -1,6 +1,6 @@ # Mobile task progress and subagents -Status: Active — read-only task progress and agent inspection implemented and automated validation passed; PR review and physical UI acceptance remain. Optional mutation controls remain separate. +Status: Active — read-only task progress and agent inspection merged in [PR #123](https://github.com/sambitcreate/aiden-agent/pull/123) on 2026-09-15; physical UI acceptance remains. Optional mutation controls remain separate; the first one, a confirmed single-agent Stop from the iOS and Android agent sheets, merged in [PR #275](https://github.com/sambitcreate/aiden-agent/pull/275) on 2026-09-30 (Aiden Remote contract revision 16). Date: 2026-09-14 ## Outcome and scope diff --git a/docs/plans/nontechnical-user-journey-ux-plan.md b/docs/plans/nontechnical-user-journey-ux-plan.md index 276f7cc7a..845c93fcc 100644 --- a/docs/plans/nontechnical-user-journey-ux-plan.md +++ b/docs/plans/nontechnical-user-journey-ux-plan.md @@ -1,7 +1,7 @@ # Make Aiden easier to start, understand, and recover Date: 2026-09-04 -Status: **Active — approved UX implementation in review; broader journey backlog and physical-device usability validation remain open.** +Status: **Active — approved UX implementation merged in [PR #96](https://github.com/sambitcreate/aiden-agent/pull/96) on 2026-09-11; broader journey backlog and physical-device usability validation remain open.** Baseline: `d40d00f1d` Deliverable: UX audit, journey chart, remote-setup proposal, and implementation handoff. diff --git a/docs/plans/performance-stability-efficiency-plan.md b/docs/plans/performance-stability-efficiency-plan.md index 1ab6358be..af07dc794 100644 --- a/docs/plans/performance-stability-efficiency-plan.md +++ b/docs/plans/performance-stability-efficiency-plan.md @@ -1,6 +1,6 @@ # Performance, Stability, Battery, and Efficiency Master Plan -Status: planned; source audit complete, implementation not started +Status: planned; source audit complete, phased implementation not started. Separate targeted performance fixes landed outside this phase sequence (#282–#288; 0.51.0 and later, evidence in `docs/performance/`) and do not complete any phase here. Date: 2026-07-27 Audit snapshot: dirty working tree on `feature/aiden-assistant-plan-777723` at `7299340282f84fb816f1615f54a27bf97390f6fe`; findings refer to the current filesystem, not only `HEAD` Scope: Electron main/preload, React renderer, native helpers, storage, IPC, networking, background services, packaging, and macOS lifecycle diff --git a/docs/plans/scheduled-provider-and-pi-rollout-recovery-plan.md b/docs/plans/scheduled-provider-and-pi-rollout-recovery-plan.md index 550ad4931..41af0bdb1 100644 --- a/docs/plans/scheduled-provider-and-pi-rollout-recovery-plan.md +++ b/docs/plans/scheduled-provider-and-pi-rollout-recovery-plan.md @@ -1,7 +1,7 @@ # Scheduled-Task Provider Recovery and Pi Rollout Generation Fix -Status: Implemented (2026-09-09) — Phases A, B2, and C are coded and green in -worktree `.worktrees/prod-error-recovery` (branch `fix/scheduled-provider-and-pi-rollout`); +Status: Implemented (2026-09-09) — Phases A, B2, and C merged in +[PR #105](https://github.com/sambitcreate/aiden-agent/pull/105) on 2026-09-11 (branch `fix/scheduled-provider-and-pi-rollout`); B1 (operator stage advance) and machine remediation remain release-owner steps. Originated from installed production diagnostics on 2026-09-09 (app v0.39.0, `~/Library/Application Support/Aiden Agent`). diff --git a/docs/plans/simulator-devices-plan.md b/docs/plans/simulator-devices-plan.md index 463f047f4..7ef2d8891 100644 --- a/docs/plans/simulator-devices-plan.md +++ b/docs/plans/simulator-devices-plan.md @@ -14,6 +14,10 @@ - **Platforms:** iOS Simulator only for v1. Keep `platform` in every contract so Android can slot in later behind the same `DeviceHost` seam. - **Also in scope:** SSH device hosts (Phase 5) and 3D device frames (Phase 6). The mobile companion preview is out of scope. +## Status (2026-10-01) + +Phases 0–7 merged to main in [PR #252](https://github.com/sambitcreate/aiden-agent/pull/252) on 2026-09-26 and shipped in 0.50.0 behind the `AIDEN_EXPERIMENTAL_DEVICES` flag. The softened shell-tooling guidance (T3 Code #13908) merged in [PR #263](https://github.com/sambitcreate/aiden-agent/pull/263) and shipped in 0.51.0. Real-Mac acceptance for Phases 4–6 remains before the flag defaults on; SSH hosts are a later follow-up. + ## Status (2026-09-25) Phases 0–3 and 3.5 are implemented and uncommitted on `worktree-main-20260925`. The spike results are in [simulator-devices-spike.md](simulator-devices-spike.md). The Phase 2 acceptance script passed on a real Mac with Xcode. Phase 3 has its own task plan, [simulator-devices-phase-3.md](simulator-devices-phase-3.md), and an Electron E2E against a fake hub. Phase 4 is implemented except its manual real-simulator exit gate; 5–7 remain. See "Phase 2 as built" and "Phase 3 as built" below for where the code differs from the task text. diff --git a/docs/plans/subagent-orchestration-expansion-plan.md b/docs/plans/subagent-orchestration-expansion-plan.md index 757e990c0..ac5867135 100644 --- a/docs/plans/subagent-orchestration-expansion-plan.md +++ b/docs/plans/subagent-orchestration-expansion-plan.md @@ -8,6 +8,10 @@ complete. The 2026-09-01 foreground failure remediation is also complete. The 2026-09-01 V1-to-V2 checkpoint repair makes persisted migration verification content-addressed across macOS volume remounts while retaining native generation checks for same-process writes. Phase 7B coordinator activation is next. +Implementer run grants merged in PR #247 (0.50.0). Desktop pending-question +display for `needs_attention` children (#266) and the live child context window +(#271) shipped in 0.51.0; Remote stop of a single child agent (#275, contract +revision 16) is on main after 0.51.0. Spec date: 2026-08-05. diff --git a/docs/plans/web-access-rehaul-plan.md b/docs/plans/web-access-rehaul-plan.md index 431aee06a..9b99823b4 100644 --- a/docs/plans/web-access-rehaul-plan.md +++ b/docs/plans/web-access-rehaul-plan.md @@ -389,7 +389,7 @@ route and requires a user choice rather than silently changing recipients. Pool-capable providers (Tavily first) add the `webSearch:keyPool:*` channels (`get`, `add`, `remove`, `reorder`, `setStrategy`, `resetCooldown`). They return only the redacted pool projection. See the -[Web Search API key pool plan](web-search-key-pool-plan.md). +[Web Search API key pool plan](completed/web-search-key-pool-plan.md). ## UI plan