T3 Code audit: issues, volume 4

pingdotgg/t3code. All authors. Drafts included. Default branch main. 570 issue assessments and 925 PR assessments. Initial inventory: 570 open issues and 924 open PRs. Current assessed open inventory: 570 issues and 924 PRs. Final reconciliation: 2026-09-01T11:57:41.491617+00:00.

Source baseline: e86604d3372acccd9f6a33a2c4ae46f4e2685541. A fix in this commit is not necessarily in a stable release.

Issues, volume 4

24 items. Each GitHub number links to its item. Recommendations and GitHub metadata are shown separately.

Issue #8896. Colliding migration IDs silently skip migrations; one undecodable event row bricks startup

Request. Foreign migration IDs and undecodable event rows can prevent startup after switching builds.

Audit finding. Main still decodes every event after the projector cursor without an event-generation filter, and a decode failure aborts replay. Its migration wrapper does not compare recorded names with the manifest before the underlying migrator skips earlier IDs. There is now a debug-level no-op migration log, but that does not address either failure, and the related origin-enum report does not cover migration identity.

Recommendation. Keep open: work remains. Add migration-identity validation and a defined incompatible-event recovery path before projection startup.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author hackel. Updated 2026-08-31T14:59:19Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8789, #7537, #4374.

Limits. The fork-to-stable database scenario was not reproduced during this read-only audit.

Issue #8899. [Bug]: File preview breadcrumb folders do not open their contents

Request. File breadcrumb folders should open an inline child picker instead of remaining static labels.

Audit finding. Current breadcrumbs are still tooltip-wrapped spans with no navigation handler. Two open proposals take different paths: reveal the folder in Files or browse its children in a popover. Neither is landed, and choosing between those behaviors is still a product decision rather than closure as fixed.

Recommendation. Keep open: decision needed. Choose the child-picker or reveal-in-Files behavior before finishing one of the competing implementations.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author 404khai. Updated 2026-08-31T15:06:01Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7145, #8910.

Issue #8900. [Bug]: zoom works poorly in the preview panel

Request. The normal full-panel browser mode is hard to find, making device-preview zoom look broken.

Audit finding. The reporter confirms that closing the device toolbar restores the expected browser behavior. Current Close device toolbar sets fill mode, while agent-created tabs still change an unstated fill default to a fixed 1280 by 800 viewport. The remaining request concerns the device-mode default and how clearly the exit control explains normal browser mode, not a missing fill capability.

Recommendation. Keep open: decision needed. Decide whether agent-opened previews should enter device mode automatically or make it opt-in.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author mo. Updated 2026-08-31T15:29:41Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Issue #8915. [Bug]: Envirornment filter works in Android, but does not appear in windows desktop client

Request. Desktop users cannot filter grouped project threads by environment as mobile users can.

Audit finding. The web sidebar still offers projectScopeKey and project search, but has no environment-scope filter. Mobile explicitly builds an Environment submenu and applies selectedEnvironmentId before grouping projects. The searchable desktop project picker does not add this separate environment filter.

Recommendation. Keep open: work remains. Add an environment filter to the shared web and desktop thread list.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author CCLabs-Fleet. Updated 2026-08-31T16:39:10Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5931.

Issue #8916. [Bug]: On Android, no rename thread option exists

Request. Android needs a manual thread rename action.

Audit finding. The current mobile row menu exposes title regeneration, pinning, lifecycle actions, and deletion, but no manual title editor. Searching the native client also finds no rename-thread command path. Regenerating a provider-written title is not equivalent to entering a chosen title.

Recommendation. Keep open: work remains. Add a manual rename action and text editor to the native mobile thread menu.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author CCLabs-Fleet. Updated 2026-08-31T16:44:13Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Issue #8924. [Bug]: Threads from an offline T3 Connect environment cannot be settled or dismissed

Request. Offline T3 Connect threads retain Working and cannot be settled or dismissed locally.

Audit finding. The older open issue describes the same cached Working state and every cleanup action failing because the owning environment is unavailable. Both require a local dismissal path that does not claim to stop a process on the offline machine. Current settle and delete actions still use environment RPC, and the newer unreachable-state proposal is still open.

Recommendation. Close: duplicate. Close as a duplicate of issue 4852 and retain this reproduction and its linked implementation there.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author lukemavdynamics. Updated 2026-08-31T17:49:43Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #4852, #8935, #8618.

Independent closure check. Both complete reports describe cached Working threads on an unreachable environment, RPC-dependent cleanup failing, and the need for local dismissal plus an honest unavailable state. Open issue 4852 already covers the missing local recovery path and has a later unreachable-machine reproduction. The new T3 Connect power-loss reproduction adds useful detail, not a different failing mechanism. Preserve it and the explicit warning that local dismissal does not stop the remote process on the retained issue. Main cleanup still uses remote commands.

Issue #8927. High-contrast user message bubbles

Request. Add a persistent high-contrast user-message style without changing the rest of the theme.

Audit finding. User bubbles still use only the theme's message surface and foreground roles. Custom themes can change those roles, but main has no dedicated subtle/high-contrast appearance choice. The proposed preference remains open, so existing theme controls do not satisfy the requested first-class setting.

Recommendation. Keep open: decision needed. Review the high-contrast preference proposal and its light/dark readability coverage.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author coygeek. Updated 2026-08-31T18:00:05Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8937, #4441, #5226.

Issue #8938. [Feature]: Support "Open in Zed" for remote (SSH) environments

Request. Remote Open in Zed needs Zed-specific SSH links, including correct Windows project paths.

Audit finding. Zed still has no remote entry, and both the link builder and Electron validator accept only the VS Code SSH shape. Two open PRs add Zed routes, but both inspected builders retain and encode the Windows drive prefix, unlike the working system-drive form in this report. Neither proposal is a landed fix or proof of the Windows remote case.

Recommendation. Keep open: work remains. Consolidate the Zed proposals and verify system-drive, other-drive, user, and port forms on the reported remote setup.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author HighBeamCapital. Updated 2026-08-31T19:19:07Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7900, #8866, #7899, #4361, #4362.

Limits. Non-system-drive Zed paths and host encoding remain unverified.

Issue #8944. Versioned AppImage filename breaks desktop entries and symlinks on every update

Request. AppImage updates change the binary filename and leave stable launcher symlinks pointing to the removed version.

Audit finding. The desktop build still sets artifactName to T3-Code-${version}-${arch}.${ext}, including for AppImage. No Linux-specific stable-name override is present, so the packaging condition reported across the stable update remains. The launcher-path fix is open.

Recommendation. Keep open: work remains. Complete the stable AppImage launch-path fix and test an update through a desktop entry pointing at a symlink.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author hamishnorton. Updated 2026-08-31T20:15:23Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8983, #5174.

Issue #8945. [Bug]: A response that pauses and resumes is folded as several separate responses

Request. One answer that pauses for background work is split into several completed-response folds.

Audit finding. The current fold builder still groups entries in a Map keyed by turn ID. Provider continuations with new turn IDs therefore become separate folds even if no new user message starts another answer. The two response-segment proposals remain open, and recent activity-label changes do not alter this grouping.

Recommendation. Keep open: work remains. Group completed answer segments across continuation turns until the next user-message boundary.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author orbitingflea. Updated 2026-08-31T20:22:43Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8973, #8974.

Issue #8946. [Bug]: Plan progress, background task rows, and "Ran N subagents" rows are never folded away

Request. Completed response folds leave plan progress, background work, and subagent summary rows visible.

Audit finding. The unified activity change removed the historical turn-plan row, and composer plan progress now disappears when the latest turn settles. Background work without a turn ID is still excluded from fold groups, and agentSpawn rows are explicitly kept outside every fold. The complete response-segment proposal is open, so the remaining two row classes are not fixed.

Recommendation. Keep open: partial fix. Review response-segment folding while keeping live background work reachable.

Confidence high. Release: In nightly source.

Observed GitHub metadata. GitHub state OPEN. Author orbitingflea. Updated 2026-08-31T20:22:46Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8734, #8828, #8973, #8945. Merged PRs that cover all or part: #8734.

Issue #8948. [Feature]: Add Remote environments filtering to desktop clients

Request. Desktop needs a sidebar filter for one or more remote environments.

Audit finding. The current sidebar builds its filter from All projects and project groups only. It has no independent environment selection, so a repository group can still mix projects from multiple environments. The merged searchable project combobox does not provide the requested environment filter.

Recommendation. Keep open: work remains. Add an environment filter that supports All and multiple selected environments.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author andyxxchen. Updated 2026-08-31T23:35:27Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5931, #3523.

Issue #8949. [Bug]: Repository identity and VCS detection spawn git per project on every read, stalling shellSnapshot

Request. Repository identity and VCS detection repeatedly spawn Git during snapshot and status reads.

Audit finding. The merged performance change now caches positive repository-root resolution, fixing the uncached rev-parse step. VcsDriverRegistry still expires positive detection after two seconds, and identity caches still use a one-minute default. That leaves the second reported source of repeated Git work open despite the new root cache.

Recommendation. Keep open: partial fix. Finish positive VCS detection caching while preserving immediate detection after repository creation.

Confidence high. Release: In nightly source.

Observed GitHub metadata. GitHub state OPEN. Author willsheldon. Updated 2026-08-31T20:38:40Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8187, #8950, #8951. Merged PRs that cover all or part: #8187.

Issue #8955. [Bug]: Codex provider probe times out on WSL when server cwd is on /mnt/c drvfs

Request. Codex provider checks time out when the WSL server starts on a Windows-mounted directory.

Audit finding. checkCodexProviderStatus still passes process.cwd into the probe, and skills/list uses that same directory. The full probe retains the 10-second timeout. No mounted-drive fallback is present, so the reported WSL path remains unchanged.

Recommendation. Keep open: work remains. Finish the WSL probe-directory fallback and test native and mounted-drive working directories.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author mznouira. Updated 2026-08-31T21:13:50Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8956, #7513.

Issue #8958. [Bug]: Codex paginated thread revert fails after restoring workspace files

Request. A rejected Codex rollback can leave restored files paired with an unchanged conversation.

Audit finding. CheckpointReactor still restores the workspace and refreshes its file index before calling rollbackConversation. CodexSessionRuntime still sends thread/rollback without checking whether the thread supports it. If a paginated thread rejects that call, the file restore has already happened and no compensation is visible in this path.

Recommendation. Keep open: work remains. Check rollback support before changing files and make failed reverts preserve a consistent workspace and conversation.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author LunarRed. Updated 2026-08-31T21:13:33Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Issue #8961. [Bug]: T3 Connect relay provisioning fails because api.t3.codes serves an expired TLS certificate

Request. A new headless installation remains unlinked after authorization and server startup.

Audit finding. The maintainer corrected the endpoint to relay.t3.codes, and the reporter withdrew the expired api.t3.codes diagnosis. The checked-in public config agrees with the maintainer, while the remaining log excerpt stops before a reconciliation result. Pending startup is a real unresolved symptom, but it is not evidence that the configured relay certificate expired.

Recommendation. Keep open: evidence needed. Attach the final link-reconciliation error from a fresh start with the configured relay URL redacted only if private.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author physk. Updated 2026-09-01T00:01:28Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #5612, #5729.

Limits. No certificate check was performed and no final provisioning error is present.

Issue #8963. [Bug]: Typed composer text is lost when clicking Stop during a pending approval prompt

Request. Text typed while a question is pending disappears from the composer when Stop cancels the question.

Audit finding. Pending custom answers are stored in component-local maps instead of the persisted composer draft. The editor shows that answer while a question is active, then switches back to the ordinary prompt after the question disappears. Stop only dispatches interruption and does not transfer the answer text into the draft, which leaves this data-preservation gap on local and remote threads.

Recommendation. Keep open: work remains. Preserve pending custom-answer text in the thread draft when interruption dismisses the question.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author michaelgrafwebdev. Updated 2026-08-31T22:39:41Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #7805, #7820.

Limits. No runtime reproduction was run against the reporter's remote environment.

Issue #8985. feat: support Oh My Pi (omp) as an ACP provider

Request. Add Oh My Pi as a first-class provider through its ACP runtime.

Audit finding. The shipped driver registry has no omp driver, although the ACP runtime used by Cursor and Grok provides reusable transport code. No current source or merged history adds its authentication, cancellation, permissions, catalog, or client controls. The issue asks for agreement on a new supported provider before implementation.

Recommendation. Keep open: decision needed. Decide whether to support omp as a built-in provider and define required ACP capabilities before accepting a PR.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Neon-Wang. Updated 2026-09-01T01:34:24Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Limits. The external omp ACP implementation and CLI compatibility were not verified.

Issue #8998. [Bug]: unable to stop opencode agent

Request. Stop does not visibly stop an OpenCode turn after a skill is invoked.

Audit finding. The new merged stop implementation aborts descendant sessions, but it is only on main at the audit snapshot. This report does not show whether native child work continues or only the saved T3 status remains running. Unknown skill permissions and durable abort state still have confirmed gaps, so the child-stop change alone is not enough to close it.

Recommendation. Keep open: retest. Retest Stop in a build containing the child-session fix and capture the native abort events if it still fails.

Confidence medium. Release: Main only.

Observed GitHub metadata. GitHub state OPEN. Author jagrat7. Updated 2026-09-01T03:31:20Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #9005, #8895, #4795, #8813. Merged PRs that cover all or part: #9005.

Limits. The report gives no exact nightly build or native provider trace. The attached recording was not inspected during this no-browser audit.

Issue #9002. [Bug]: Periodic Claude provider refresh still leaves suspended orphan git.exe processes on Windows

Request. Periodic Claude probes can leave suspended Windows descendants after the probe process exits.

Audit finding. The report reproduces on a nightly after #8634, which disables IDE discovery but does not own or stop the entire probe process tree. probeClaudeCapabilities still only aborts its controller in the finalizer, with no explicit Windows descendant cleanup. The remaining git.exe case cannot be closed as the earlier tasklist/findstr fix.

Recommendation. Keep open: work remains. Capture and test the full Windows probe process tree through success, timeout, and cancellation.

Confidence medium. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author HMBSbige. Updated 2026-09-01T04:59:41Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8575, #8634, #1757.

Limits. No Windows runtime or process-tree reproduction was available.

Issue #9004. [Bug]: "View PR" in Git action success toasts always opens the system browser

Request. The View PR action in success toasts opens externally instead of using the in-app pull request panel.

Audit finding. The normal View PR action calls onOpenPullRequest, but the shared success-toast branch still calls shell.openExternal directly. The same open_pr CTA handles both PR creation and pushes to an existing PR, so both reported flows remain affected in web and desktop. Two competing fixes are open.

Recommendation. Keep open: work remains. Use the normal in-app PR routing for plain toast clicks and retain an explicit external-open path.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author eimexdev. Updated 2026-09-01T05:03:35Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #9006, #9007, #7250, #7099.

Issue #9026. [Bug]: Sending a picked preview element hangs on "Capturing..." forever and locks the composer

Request. Submitting a picked preview element can remain in Capturing indefinitely and block annotation submission.

Audit finding. The Capturing label is in the annotation preload, which sets pendingCapture before waiting for getElementContext on every selected element. That wait has no timeout, and the later desktop capturePage call has no timeout either. No failure path restores the annotation submit control when either promise never settles, which matches the missing capture traces without proving which stage stalled.

Recommendation. Keep open: work remains. Bound the entire annotation capture sequence and restore the submit control with an error when it times out.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author KarstenKreh. Updated 2026-09-01T09:27:27Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #3713, #6242.

Limits. The Windows traces do not identify the unresolved promise, and the main composer itself has no Capturing label in current source.

Issue #9029. [Bug]: Plan sidebar stays empty on Claude 5 models , Claude Code no longer exposes the Task tools by default

Request. The plan sidebar receives no task updates when new Claude models omit task tools unless the host opts in.

Audit finding. The adapter already maps TodoWrite and TaskCreate/TaskUpdate/TaskList to plan updates. makeClaudeEnvironment does not set CLAUDE_CODE_ENABLE_TODO_TOOLS, so the reported CLI model gate leaves those mappings with no events to consume. The environment change in the linked fix is not in main.

Recommendation. Keep open: work remains. Review #9031 with a Claude 5 task-list session and an unaffected model.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author Daeroni. Updated 2026-09-01T10:41:35Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #9031, #1541.

Limits. The CLI model gate was reported upstream and was not exercised in this source audit.

Issue #9034. [Bug]: Bitbucket PR comments fail because permission preflight returns HTTP 404

Request. Bitbucket PR comments fail before posting because the permissions preflight returns 404.

Audit finding. This is the same removed-endpoint 404 already tracked by the open Bitbucket write-action report. Merge and comment both call viewerPermissionsOf, which reaches the same getRepositoryPermission helper that only tolerates 410. Keep the new workspace-endpoint proposal with the older issue rather than maintaining separate reports for two actions blocked by one gate.

Recommendation. Close: duplicate. Preserve the workspace-endpoint proposal on issue 8328 and close this as its duplicate.

Confidence high. Release: Not applicable.

Observed GitHub metadata. GitHub state OPEN. Author OliStarCooke. Updated 2026-09-01T11:05:06Z. Metadata snapshot 2026-09-01T11:57:41.491617+00:00.

Evidence read. body yes, discussion yes, current source yes, history yes.

Related work: #8328, #9035, #8557, #6525, #6341.

Independent closure check. Full issue bodies identify the identical Bitbucket HTTP 404 from the retired repository-permission endpoint. The retained issue 8328 explicitly covers every write action, not only merge, and a new comment on its linked PR also reproduces comment posting. Comment and merge share viewerPermissionsOf and the same 410-only helper. Preserve the new supported-endpoint proposal and link 9035 on issue 8328 before closing this duplicate. The defect is not fixed in main.