Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .memory/aiden-cli-standalone.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,3 +38,5 @@
- Merging #71 (Linux desktop) took main's native C ports and `native-c-build-core.mjs` build scripts. The PR's OpenSSL/renameat2 shims were dropped because `native/shared/aiden-platform.h` carries its own SHA-256. `nativeHelperSourceHash` now also hashes `native/shared/*.h`, so a shared-header edit marks prebuilts stale. The PR's speech core carries main's "desktop" wording.
- Merging #246 (root pi 0.87.1) bumped the CLI to `@earendil-works/pi-coding-agent` 0.87.1 and added a direct `@earendil-works/chord` 0.87.1 dependency. btw wraps its context in `normalizeContext`, and the child beforeTool context drops `systemPrompt`. The re-vendored advisor uses `normalizeContext`. The build's external check falls back to ESM resolution for chord's import-only subpaths and allowlists the optional `kerberos`. Session import accepts both `v: 4` (storage v1) and `version: 4` (0.84.4) journal headers.
- Merging #251 (main's Remote contract revision 14) renumbered this PR's `GET /scheduled-tasks/notifications` addition to contract revision 15. The shared fixture and the Android copy are byte-identical at 15. The TS, iOS and Android fixture assertions expect 15, and the iOS fixture CodingKeys keep both main's streamInput/question/chatSkills and this PR's scheduleRunNotification.

- 2026-09-27 review: plan index now describes Phase 6 as implemented; physical iPhone acceptance remains pending.
4 changes: 3 additions & 1 deletion .memory/chat-pull-requests.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ Work continues on existing PR #184 (`devin/1789864248-chat-pull-requests`), isol

Never normalize a supplied malformed expectedHeadSha to omission. Unknown creates remain pending even after an empty lookup; absence from a list does not establish that a mutation failed. Save link + settle intent atomically. Recovery uses the durable host/repository, independent of chat workspace changes. Same-target pending intents block repeat creates. Post-push identity comes from the frozen endpoint used by Git, never gh's inferred default repository. Unlink dismissal is durable and suppresses current-PR rediscovery until explicit relink.

Two requested Sol medium reviews identified empty-list retries, split link/intent publication, selected-remote routing, and source IPC mismatch; all remediated with focused coverage. Final verification tracked in docs/plans/chat-pull-requests-plan.md and PR #184.
Two requested Sol medium reviews identified empty-list retries, split link/intent publication, selected-remote routing, and source IPC mismatch; all remediated with focused coverage. Final verification tracked in docs/plans/completed/chat-pull-requests-plan.md and PR #184.

Follow-up review fixes: store settlement checks that the operation is still pending inside the serialized write, preventing stale completions from undoing unlink. Unknown/retargeted/advanced-head attempts can be explicitly cleared only after a confirmation to check GitHub first. Within-repository create destination is named in the dialog; cross-fork upstream creation remains manual.

Expand All @@ -19,3 +19,5 @@ Failed-recovery deletion follow-up: after fencing admission and draining loads/w
Dotted-ID recovery isolation follow-up: DataStore recovery and PR deletion share a complete-basename matcher with the fixed hash/operation/suffix fields, preventing chat-1 from consuming chat-1.json recovery files. Cached and cold deletion regressions cover both directions and both artifact suffixes; startup recovery also preserves sibling bytes. Validation: 98 focused PR tests, 255 portable-config/storage tests, 103 service-boundary tests, TypeScript and Electron build pass. Both independent Sol reviews are clean; current-head hosted checks remain pending.

Recovery-token follow-up: artifact ownership also requires the lowercase UUIDv4 operation token emitted by randomUUID. Non-UUID, wrong-version and wrong-variant lookalikes remain untouched during recovery and deletion. Existing recovery fixtures now use generated-format UUIDs. Validation: 99 focused PR tests, 255 portable-config/storage tests, TypeScript and Electron build pass.

Status (2026-09-27 plan refresh): PR #184 merged 2026-09-23 and shipped in 0.43.0; plan moved to docs/plans/completed/.
4 changes: 3 additions & 1 deletion .memory/dictation-parakeet-modes.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Dictation Parakeet lifecycle, modes, and dictionary — 2026-09-27

- Branch `feature/dictation-parakeet-modes`. Plan: `docs/plans/dictation-parakeet-modes-plan.md`.
- Branch `feature/dictation-parakeet-modes`. Plan: `docs/plans/completed/dictation-parakeet-modes-plan.md`.
- **Shared, pure modules:**
- `renderer/shared/dictation-preferences.ts` holds the mode resolution, idle-minute validation, and `parseDictationPreferencePatch`, which `settings:set` uses.
- `renderer/shared/dictation-dictionary.ts` holds parse, apply, and add-entry.
Expand Down Expand Up @@ -34,3 +34,5 @@
- Added shortcut/dictionary regressions; 44 focused tests, CI policy suite, desktop typecheck, and CLI build/typecheck pass. New suites are assigned to CI lanes.

Independent review corrected the dictionary settings row keys to use the same locale-independent lowercase identity as parser deduplication; a Turkish-casing regression verifies distinct I/dotless-ı entries keep distinct React keys.

Status (2026-10-01): merged in PR #279 (on main after 0.51.0); plan moved to `docs/plans/completed/`.
4 changes: 3 additions & 1 deletion .memory/dictation-secure-input.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Dictation Secure Input warning — 2026-09-27

Branch `feature/dictation-secure-input`; plan `docs/plans/dictation-secure-input-plan.md`.
Branch `feature/dictation-secure-input`; plan `docs/plans/completed/dictation-secure-input-plan.md`.

- `pasteTranscript` (main/services/dictation-paste.ts) takes an injectable
`isSecureInputActive`. Order: Accessibility check → Secure Input probe → atomic
Expand All @@ -23,3 +23,5 @@ Review validation: 15 focused paste/pill tests pass, including a process-owned e
The JXA probe explicitly binds `IsSecureEventInputEnabled` as a no-argument boolean function, avoiding reliance on OS BridgeSupport metadata. The plan index and PR description now match the Carbon detector and conservative copy fallback.

Independent review: reading the original AXValue is optional, so text controls without an accessible value still receive a guarded paste attempt. An unconfirmed result or transport error says “Check the field — transcript copied.” It never instructs a second paste after a possibly successful attempt; the prior clipboard is restored only after confirmed delivery.

Status (2026-10-01): merged in PR #267 (on main after 0.51.0); plan moved to `docs/plans/completed/`.
4 changes: 3 additions & 1 deletion .memory/durable-tool-outputs.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Durable tool output / file provenance — September 22, 2026

Active implementation: `feature/durable-produced-tool-output`, baseline `c8c09e0d`.
Plan: `docs/plans/durable-tool-output-plan.md`. MCP was already bounded on current
Plan: `docs/plans/completed/durable-tool-output-plan.md`. MCP was already bounded on current
main, despite the September 15 Notion audit. Adapt the successful-mutation principle
from verified `deepseek-ai/deepseek-harness` deliverables documentation; no code copied.

Expand All @@ -20,3 +20,5 @@ Validation: 125 focused tests and 10 inventory-fence tests pass; TypeScript and
PR #219 at 58abfb02 passed hosted CI/Android/Electron gates. Pullfrog follow-up fixes include all three encrypted credential stores even in no-MCP workspaces, POSIX colon path parity, 240 Unicode code-point limits across clients, ASCII-only drive prefixes, and AJV-tested normative path/tool/status constraints. Follow-up validation: 128/128 focused tests, TypeScript, lint, Android chat/contract tests, and unsigned generic iOS test build pass; both independent reviewers clear. Follow-up hosted CI remains pending; physical XCTest remains blocked by device lock.

Pullfrog incremental follow-up: ProducedFile schema lookaheads now scan all characters, including U+2028/U+2029; parity vectors cover valid paths, traversal, dot/empty segments and trailing separators for both. Protocol suite passes via node --import tsx (CLI IPC blocked by sandbox). Runtime/native validators unchanged. Hosted validation pending; physical device still locked.

Status (2026-09-27 plan refresh): PR #219 merged 2026-09-23 and shipped in 0.43.0; plan moved to docs/plans/completed/. Physical iOS execution is still unverified.
4 changes: 3 additions & 1 deletion .memory/live-activity-freshness-bot-deeplinks.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Live Activity freshness chips and Bot deep links (2026-09-27)

Branch: `feature/live-activity-freshness`. Plan: `docs/plans/live-activity-freshness-bot-deeplinks-plan.md`.
Branch: `feature/live-activity-freshness`. Plan: `docs/plans/completed/live-activity-freshness-bot-deeplinks-plan.md`.

## Live Activity state and chips

Expand All @@ -24,3 +24,5 @@ Branch: `feature/live-activity-freshness`. Plan: `docs/plans/live-activity-fresh
## Coordination

PR #119 adds `AidenBotLiveActivityStateTests.swift` and edits the pbxproj. This branch adds no new iOS files, to avoid conflicting with it.

Status (2026-10-01): merged in PR #276 (on main after 0.51.0); plan moved to `docs/plans/completed/`.
4 changes: 3 additions & 1 deletion .memory/mcp-advertised-status.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,4 +8,6 @@ Shared TypeScript status definition is desktop-only. Confirmed no McpStatus/mcp:

Validation: registered `test:mcp` includes six new status tests; 88 total pass. Real in-memory SDK servers cover success, discovery failure, opaque extension metadata, empty/resource-only capability sets and independent clients. Controlled barriers cover document/connection revocation and generation-bound replacement. Full type-check, ESLint and whitespace checks pass. Independent GPT-5.6 Sol medium blast-radius/adversarial reviews requested.

Original assignment completion remains partial: docs/plans/mcp-session-context-audit.md classifies every item. Resources, scoped server instructions and per-model-request AGENTS refresh are concrete remaining deliverables, not external blockers. Pi compaction owner confirms no live AGENTS/MCP hook overlap. No native test blocker is claimed for this desktop-only diagnostic slice; the prior #214 physical iOS lock remains that slice's limitation.
Original assignment completion remains partial: docs/plans/completed/mcp-session-context-audit.md classifies every item. Resources, scoped server instructions and per-model-request AGENTS refresh are concrete remaining deliverables, not external blockers. Pi compaction owner confirms no live AGENTS/MCP hook overlap. No native test blocker is claimed for this desktop-only diagnostic slice; the prior #214 physical iOS lock remains that slice's limitation.

Status (2026-09-27 plan refresh): PR #226 merged 2026-09-23 (0.43.0). Resources (#230), server instructions (#229) and trusted AGENTS refresh (#232) merged the same day, so the audit is complete.
2 changes: 2 additions & 0 deletions .memory/mcp-numeric-schema-formats.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,5 @@ Tests: `main/services/mcp-tool-schema.test.ts` (in `test:mcp`) uses realistic sc
Draft-07 schema-valued dependencies now normalize too; property-name dependency lists remain unchanged. Added strict-Ajv regression and registered the suite in the core-git CI lane. Focused schema tests (7) and CI policy tests (46) pass.

Independent review identified a silent 64-level cutoff that could leave numeric formats unnormalized. Traversal now uses an iterative worklist and weak object-copy map, preserving raw identity and schema-keyword boundaries while normalizing deep schemas fully; a 2,000-level regression covers this case.

Status (2026-10-01): merged in PR #264 (on main after 0.51.0); plan moved to `docs/plans/completed/`.
2 changes: 2 additions & 0 deletions .memory/mcp-scoped-resources.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,3 +9,5 @@ Pullfrog identified that pinned SDK1.30.0 concatenates multi-variable expression

## Constrained template syntax correction
A follow-up review found SDK1.30 also misinterprets single-variable operators/modifiers. Discovery now rejects every form except plain {name} expressions with ASCII identifier names, before any inventory handles are published. Operators, prefix/explode modifiers, comma-separated names, dotted/percent-encoded names and malformed braces fail closed. Accepted plain scalar values use strict RFC6570 percent encoding (including !'()*), without SDK expansion. Repeated separate expressions still work. An unsupported template makes that inventory fail closed; no partial inventory is presented as complete. MCP97 covers the requested single-variable forms, unpublished-handle denial and Unicode/reserved encoding.

Status (2026-09-27 plan refresh): PR #230 merged 2026-09-23 and shipped in 0.43.0; plan moved to docs/plans/completed/.
2 changes: 2 additions & 0 deletions .memory/mcp-scoped-server-instructions.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,3 +11,5 @@ Onboarding's existing MCP tile now discloses service-provided tool guidance with
Validation: MCP90, onboarding56, Bot447, scheduled151 passed. Full type-check, ESLint and whitespace checks passed after test-fixture fixes. New mcp-server-instructions.test.ts is registered in test:mcp. Both requested independent GPT-5.6 Sol medium reviews (blast radius; adversarial/edge cases) clear. Reviewers confirmed exact tool/server identity, final filtering, immutable lifetime, context budget and fail-closed bounds. Hosted checks and review remain PR follow-through gates.

Original scope remains partial: scoped MCP resource operations and trusted AGENTS loading/request-boundary prompt refresh remain concrete deliverables. Capability status is separate #226, skill policy #214, result spills another owner's work. This change claims no resource access, provider upgrade or native acceptance.

Status (2026-09-27 plan refresh): PR #229 merged 2026-09-23 (0.43.0). The resources and trusted AGENTS deliverables listed above as remaining also merged (#230, #232), so the original assignment is complete; plan and audit are in docs/plans/completed/.
4 changes: 3 additions & 1 deletion .memory/mobile-transcript-polish.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Mobile transcript polish (Hermex Tier 1)

Branch `feature/mobile-transcript-polish`. Plan: `docs/plans/mobile-transcript-polish-plan.md`.
Branch `feature/mobile-transcript-polish`. Plan: `docs/plans/completed/mobile-transcript-polish-plan.md`.

- There was no protocol change. "Worked for" reads `Message.timeline`, but only when the status is completed and `finishedAt >= startedAt`. The live timer uses the running timeline's `startedAt` and otherwise falls back to the newest user message's `createdAt`. Timestamps use `createdAt`.
- iOS code lives in `Features/Chat/AidenTranscriptPolish.swift`. It is a new file because `AidenChatFeature.swift` is far over the 500-line Swift warning, and it is registered manually in the pbxproj with IDs `A714739233F64F4FA4C2B700` and `...710`. The footer replaced the old safeAreaInset copy/read-aloud row. `AidenSettledMessageRows` computes `showsFooter`, so Bot clusters show it only on the last joined bubble.
Expand All @@ -9,3 +9,5 @@ Branch `feature/mobile-transcript-polish`. Plan: `docs/plans/mobile-transcript-p
- SwiftUI `.textSelection` and Compose `SelectionContainer` cannot add custom menu items, so selection uses a native select-text sheet/dialog. On iOS this is a `UITextView` with `editMenuForTextIn`; on Android it is a `TextView` with `customSelectionActionModeCallback`.
- User messages are now copyable on iOS. `copyText` returns nil only for empty text.
- Open items: flatten Markdown in the Android select-text dialog, and focus the Android composer after Ask.

Status (2026-10-01): merged in PR #277 and shipped in 0.51.0; plan moved to `docs/plans/completed/`. Physical-device visual acceptance remains.
4 changes: 3 additions & 1 deletion .memory/pr187-context-meter.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,4 +18,6 @@
- Pi 0.87.1 merge (#246): the prompt now lives in transcript system messages and the AGENTS refresher appends a section patch (`apply(AgentContext)`). `withAgentsInstructionsEstimate` builds a one-message transcript (`createInitialSystemMessage`), applies the refresher and reads `getCurrentSystemPrompt`. `withoutAgentsInstructions` also strips a block rendered with no base prompt. llm-client registers the generation profile after the initial AGENTS apply, so the captured prompt and the tracker baseline agree. The harness emits projections from `installCompactedMessages`' result. Journal system messages count zero in `messageTokens`, so static context is counted once. Pullfrog on 5186fe54 pointed out that Pi sends later system messages in place for `supportsMidConvoSystemMessages` models, including superseded AGENTS revisions. `GenerationContextOptions.retainsSystemUpdates` (from `modelRetainsSystemUpdates(model)`; set in llm-client, the harness projection options, and `nextRequestContextOptions`, which defaults it to false) makes whole-transcript estimates (`projectNextContextUsage` and compaction) add the rendered updates beyond the replayed prompt. Compaction's replay into one head removes that extra.
- Retained updates and usage anchors (Pullfrog on 8f06c37e): provider usage covers everything up to its anchor, but Pi's `estimateContextTokens` and `messageTokens` price system messages at 0, so for a retaining model each system message after the latest valid anchor is added in full (rendered with `renderSystemMessageUpdate`) through `retainedTailSystemTokens`. The same helper serves the projection's anchored tail and provider term, compaction's provider-aware total and candidate tails, and `PiCompactionCoordinator` (the direct previous-assistant usage in `checkContextPressure`, the stale-anchor estimate in both post-turn checks, and the whole-transcript fallback after a model switch, which adds later updates but not the leading head). A zero-usage response does not move the anchor, so revisions before and after it both count.
- Static-inclusive totals (Pullfrog on de658be1): content and still-active sections set after the anchor are already in `options.systemPrompt`. Totals that add `staticTokens` next to the anchored tail (the projection's usage+static+trailing term and the compaction candidates) use `retainedTailSystemTokensBeyondPrompt` (rendered updates minus `postAnchorPromptChars`). Compaction's prefix ratio subtracts the anchor-time static (static minus the post-anchor share), so `static + prefix*ratio + tail` equals usage plus the full tail, and a replayed head prices the active revision. Totals without static (Pi's `estimate.tokens`, direct usage, every pi-compaction-core path) keep the full render.
- Plan: `docs/plans/composer-context-meter-plan.md`.
- Plan: `docs/plans/completed/composer-context-meter-plan.md`.

Status (2026-09-27 plan refresh): PR #187 merged 2026-09-26 and shipped in 0.50.0; plan moved to docs/plans/completed/composer-context-meter-plan.md.
4 changes: 3 additions & 1 deletion .memory/queue-while-compacting.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Queue messages while compaction runs — 2026-09-27

Branch: `feature/queue-while-compacting`. Plan: `docs/plans/queue-while-compacting-plan.md`.
Branch: `feature/queue-while-compacting`. Plan: `docs/plans/completed/queue-while-compacting-plan.md`.

Manual compaction keeps the composer editable and holds queued messages until compaction succeeds. `ChatMessageQueue.holdReason` is the durable per-chat state; the composer must derive its active compaction affordance, status text and Cancel action from the queue snapshot as well as its local start state, because the chat-keyed composer remounts when navigating away and back.

Expand All @@ -9,3 +9,5 @@ The `/compact` slash token is consumed immediately after the asynchronous comman
Relevant validation: `npm run test:slash-commands`; `npm run type-check:e2e`; focused `chat-message-queue.spec.ts` compaction scenario.

Follow-up review: attachment and skill removal now use `composerInputLocked`, preserving draft editing while manual compaction holds queued sends. The compaction E2E removes a pasted image before navigation while the original command is still pending.

Status (2026-10-01): merged in PR #272 (on main after 0.51.0); plan moved to `docs/plans/completed/`.
2 changes: 2 additions & 0 deletions .memory/rich-link-previews.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,3 +9,5 @@
- Escape fences both the open card and Radix's delayed focus-open callback until the next pointer-enter or focus interaction, without moving focus.
- No network, IPC, connector, persistence, schema, transcript, Bot runtime, main-process, iOS, or Android contract changed.
- Validation: focused rich-link/transcript suite 42/42; Bot suite 451/451; Chat/slash-command suite passed; TypeScript, ESLint, CI policy, production build, and `git diff --check` passed. Packaged-app, pointer/keyboard visual, assistive-technology, and physical-device acceptance remain separate.

Status (2026-09-27 plan refresh): PR #253 merged 2026-09-26 and shipped in 0.50.0; plan moved to docs/plans/completed/rich-link-previews-plan.md. The optional authenticated metadata phase is unstarted.
Loading
Loading