Commit Graph

75 Commits

Author SHA1 Message Date
程序员阿江-Relakkes fd42b0ca05 fix(agent-teams): keep long-running teams recoverable (#1426)
Long Agent Teams runs lost members for good: a truncated provider stream
ended a member's turn with nobody to wake it, the desktop Stop button and
every lead restart killed all members and marked the plan interrupted,
mail sent to a stopped member landed in an inbox nothing read, and a lead
kept inside one long turn never saw member reports. Aligned with the
official CLI 2.1.284 and verified with DeepSeek Flash through a
fault-injecting proxy.

Stream recovery
- Re-send a stream that breaks before any tool ran (proxy truncation,
  transport errors), with the existing retry budget and backoff; the
  desktop drops the discarded attempt's tool cards and todo update.

Desktop team runtime (teamPlanRuntime)
- The server supervises members: a stopped member restarts from its own
  transcript when messaged; transient failures continue automatically
  (15s/45s/2m/5m/10m) and only exhausted retries reach the lead; ready
  dependent tasks wake their owner; a crash-loop guard ignores user stops.
- Stop pauses the team instead of ending it; the lead's next user message
  is followed by a notice listing the stopped members and their open
  tasks. Lead restarts (model/permission switch, crash) keep members;
  server restarts re-own the team. Teams end on /clear or session delete.
- Approving a plan no longer races a concurrent plan read into
  "Launch ownership was lost".

Mailbox and messaging
- Atomic inbox writes, identity-based read marking, read history files,
  idle notifications with result/failureReason, and write failures
  reported instead of "Message sent". External builds keep the official
  between-turn delivery to the lead.
- SendMessage resumes non-running in-process teammates from their
  transcript, notes restarting desktop members, queues mail for members
  of a plan awaiting approval, and rejects unknown names.

CLI in-process teammates
- Compaction uses the teammate's own controller and real history and no
  longer kills it on error; failed turns are classified and continued;
  the turn-end mailbox drains as one batch; one durable transcript per
  teammate.

Lead behaviour
- An unmet /goal ends the lead turn while members work, so member reports
  arrive; WaitSessions on own team members returns immediately.

Desktop UI
- Member states for stopped, auto-retrying and failed, with reason,
  countdown and recovery hint in all five locales.

Tests and tooling
- Regression tests for every behaviour above; module mocks in four test
  files are restored after use so the single-process coverage run is not
  polluted; the desktop smoke asserts the new Stop semantics.
2026-10-03 17:07:30 +08:00
程序员阿江(Relakkes) 6bab6fbe97 feat(desktop): preview documents in the workspace and images in chat
Documents the agent writes open in the workspace panel instead of another
application, and local images the agent mentions show up in the conversation.

Workspace preview
- PDF (pdf.js with its own layout and text layer), Word (docx-preview inside a
  scripts-disabled sandboxed iframe) and Excel (SheetJS; .xlsx, .xlsm, .xls) open
  in the side panel with zoom and fit, per-file scroll/zoom/sheet memory, and a
  refresh when the agent rewrites the file. The engines load lazily.
- Bytes come from a new GET /api/sessions/:id/workspace/raw route, with an
  extension allowlist, size caps, the workspace boundary and canonical-path
  checks. The file endpoint returns metadata and a version for documents. The
  client fetches with the bearer credential, so it works in Electron, LAN H5 and
  remote access alike.
- Chat links, output cards and the change card open pdf/docx/xlsx in the
  workspace; documents outside the workdir still go to the system application.
- Image viewer with fit, zoom and pan, and "open in system app".

Chat images
- Markdown images outside the workdir, at ~/, C:\ and file:// paths render, open
  in the viewer, and offer "open original" (pictures only).
- Images returned by tools such as Read appear as thumbnails under the call.

Hardening found in review
- previewFsUrl escapes each path segment; a double-escaped %2e%2e used to leave
  /preview-fs/<session>/.
- The CORS, API timing and remote-access header decorators set headers in place.
  Rebuilding the response buffered whole files in memory and dropped
  Content-Length.
- The engine owns the pdf.js worker, so closing one document no longer fails the
  next open.
- Office archives are inflated in steps to check their real sizes, not the sizes
  they declare.
- A viewer that fails to load stays in its panel instead of taking the window down.

Adds pdfjs-dist, docx-preview, xlsx (SheetJS 0.20.3 tarball) and fflate as
renderer dev dependencies; Vite bundles them.

Refs #1397
2026-09-30 01:53:47 +08:00
程序员阿江(Relakkes) c5892b5353 feat: add contextual side chats in desktop workspace 2026-09-25 15:55:13 +08:00
程序员阿江(Relakkes) 0258ff7f96 fix(desktop): diagnose and reduce session loading stalls 2026-09-22 07:29:50 +08:00
程序员阿江(Relakkes) cd0d2a1d7b fix(desktop): mount the whole transcript so large sessions scroll smoothly
The bounded history window stitched pages behind the scrollbar and dropped
rows from the far end, which made big sessions flicker and lag. Load the
transcript in one byte-bounded response, keep it as a single mounted array,
and remember disclosure choices across virtualized row remounts.
2026-09-22 01:51:55 +08:00
程序员阿江(Relakkes) 27f660fe5c fix(perf): bound large session history and tracing resource usage
Page transcript and trace reads, bound UI caches and retained task records,
and replace full-file background polling with incremental projections.
Preserve recovery and ownership semantics across pages and cancel stale work.
2026-09-19 20:29:20 +08:00
程序员阿江(Relakkes) 4aca1d98c0 feat(desktop): search and create projects from the composer picker
The composer directory picker only showed ten recent projects with no
search and no way to name one. Load the full project list with a deep
session-history scan, filter it client-side with a fuzzy scorer, and
offer a "new project" entry that names a folder through the existing
ProjectEditorModal and selects it as the working directory.

Also key the recent-projects response cache by scan depth so a shallow
request can no longer truncate a deeper one.
2026-09-19 09:27:16 +08:00
程序员阿江(Relakkes) 451621a58a fix(desktop): serve trace views from the index instead of rereading JSONL
Opening or polling a trace used to read and parse the whole session JSONL
on every request, so a live multi-hundred-MB trace stalled the shared
server for seconds at a time and the trace list could trigger full
rebuilds for every file on the page.

The trace detail now serves the SQLite projection: summaries and call
locators come from the index, calls ship as body-less shells, and the
detail pane keeps fetching one full call at a time through the existing
byte-range endpoint. The list answers from stored summaries and defers
projection of missing or stale sources to a serialized background queue,
so no request path performs a full file read. A schema v5 migration adds
the body facts the tree header shows (request/response bytes, response
status, event title/message) and marks old projections for rebuild,
since shells built from them would look permanently pending.

Also fixes the model-count bookkeeping that violated the call_count
CHECK constraint when a rewritten call dropped a model to zero, which
used to degrade the projection and force a full-rescan fallback.
2026-09-19 01:13:25 +08:00
程序员阿江(Relakkes) af2872a50f fix(desktop): stop inlining subagent transcripts in the session timeline
A session with 44 linked subagent transcripts returned a 541,817,705-byte /
539,323,608-character /messages body — past V8's 536,870,888-character string
limit, where Chromium hands the renderer an empty string. The session opened to
"Unexpected end of JSON input" instead of its history.

HTTP now serves the root transcript only; an Agent card fetches its run's tool
stream from /subagents/by-tool when expanded, reusing the truncation the server
already applies to oversized runs. Rewind checkpoints, team task anchors and
workspace change attribution keep the merged view they depend on.

Measured on the session that failed: /messages 542 MB -> 40 MB; one run payload
45.8 MB -> 22.9 MB (the Activity projection is no longer sent twice when it is
the same array).
2026-09-17 22:34:18 +08:00
程序员阿江(Relakkes) 16e58b92c0 feat(usage): show session token totals and generation speed in the context panel
The context panel could say what was in the window but nothing about what the
session had spent: no total token count, no cache hit rate, no generation speed.
The numbers were already on the wire — translateCliUsage picked four token
buckets out of the CLI's result message and dropped duration_ms, duration_api_ms
and num_turns with them — and nothing anywhere accumulated how long the model
spent emitting tokens rather than waiting on prefill.

Measure that span where it happens: a decode span opens at the first generated
delta and closes at message_stop, rides the stream_event up to QueryEngine, and
accumulates in cost-tracker beside totalAPIDuration, including the project
config restore path so it survives a CLI restart. Tokens/sec is output over that
span, never over wall clock, which would divide by tool execution time.

The totals needed fixing before they were worth showing. Claude Code persists one
JSONL line per content block of a reply and repeats the whole usage object on
every one, so summing lines overstated real transcripts by 2.2x — and
chooseRicherUsage prefers the larger of two snapshots, so the inspector actively
selected the inflated one. The transcript readers and the renderer's history
summary now deduplicate on usageAccounting's key, the rule stats.ts and the
activity index already use.

The panel polls a usageOnly inspection mode while it is open and stops when it
closes: one get_session_usage control, no skills-directory scan, no transcript
re-read, and no request stacked behind one that has not answered.
2026-09-15 17:24:29 +08:00
程序员阿江(Relakkes) 6f0650c5cb fix(workspace): align resource panels and complete backend state flows
Unify workspace controls and resource tabs, refine browser, file and diff
interactions, and remove superseded panels. Preserve resource lifecycles,
refresh Git comparisons after external changes, and correlate terminal
startup events across IPC.
2026-09-13 16:02:58 +08:00
程序员阿江(Relakkes) dbc1e483ca feat(desktop): rebuild the workspace as a unified tab controller
Replaces the two-mode right-side panel (files ↔ browser) with one controller
that owns layout, navigation and resource lifetime for four content kinds:
files, browser pages, Git review and terminals. Follows the Codex desktop
reference captured in the workspace-refactor plan.

The old panel conflated three things that have different lifetimes: a UI tab,
the content it shows, and the process behind it. That is why switching modes
destroyed a live page, why a second link overwrote the first, and why the
toolbar button reported "show workspace" while the workspace was already open.
Splitting them is the whole change:

- workspaceStore    layout, docks, tab order, preview/pinned, focus
- workspaceContentStore / workspaceReviewStore   file and diff data
- host services     webContents and PTYs, keyed by resource id, never by tab id

Consequences that fall out of the split:

- Hiding the panel, switching tabs and switching tasks keep every page and PTY
  alive; only closing a tab releases them.
- A terminal moves between the side and bottom docks without restarting.
- Pages live in a shared persistent partition with native navigation history;
  popups become sibling tabs in the task that opened them.
- Review names both sides of every comparison and performs real index and
  working-tree writes, guarded by a snapshot token and a backup-first revert.

Also adds versioned workspace persistence with a forward migration: terminals
come back stopped and restartable, pages reload lazily, and nothing holding
content, cookies or handles is written to storage.

The previous implementation is no longer reachable but is left in place: the new
file tab does not yet reproduce workspace search, quick-open or the changed-file
view, so removing it now would lose those. Real three-platform Electron
acceptance (plan item A10) has not been performed; all evidence here is
deterministic tests, type checks and a packaging smoke.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-12 17:17:39 +08:00
程序员阿江(Relakkes) 8546f43ec3 fix(desktop): load older sessions while scrolling within projects 2026-09-08 16:05:48 +08:00
程序员阿江(Relakkes) 0d8a1a11fa fix(desktop): add bounded full session history browsing
Keep historical conversations reachable beyond the recent sidebar limit, hydrate only opened sessions, and restore old tabs through metadata-only lookups. Preserve newer metadata across history and restore races. Refs #1287.
2026-09-08 15:32:36 +08:00
程序员阿江(Relakkes) dd4edc0efe merge: bring main into the computer-use worktree
main is 87 commits ahead and carries a large amount of fixed behaviour this
branch should not be re-deciding. The rule applied throughout: this worktree
owns Computer Use, main owns everything else.

Only 12 files were touched on both sides, and Git merged all of them without
reporting a conflict — but two of those silent merges were wrong, and neither
was visible until the checks ran.

`desktop/src/api/client.ts` ended up with two `apiGetBlob` implementations.
Both sides had independently hit the same problem (an `<img src>` pointed at an
API endpoint is a cross-origin subresource, so it carries no Authorization
header and the server's fetch-metadata policy refuses it) and both had written
the same fix. Git saw two additions in different places and kept both, which
does not even compile. main's version survives: it builds its headers through
the shared `buildHeaders()` rather than assembling them inline, so it inherits
whatever main adds there later.

`src/server/api/computer-use.ts` still imported `runtime/mac_helper.py` and
`runtime/requirements.txt` as compile-time text, both deleted on this branch.
Nothing at runtime referenced them, which is why the deletion looked clean; the
bundler resolves those imports when the server module is loaded, so the failure
surfaced only when the tests actually imported it. That path is now Windows-only
in the same sense the rest of the Python bridge is, and it also ships
`win_cursor_badge.py`, which the badge needs because it runs as its own process.

`computer-use-requirements.test.ts` drops its darwin half for the same reason —
the pins it guards still matter, but only one requirements file is left.

Verified: server 3869 tests / 331 files, desktop 4612 tests / 319 files
(lint + tsc + build), Swift 272 XCTest + 14 Swift Testing, Python 25.

Claude-Session: https://claude.ai/code/session_015j1yxxaoonyAS2iZ7qGnTS
2026-08-23 18:39:47 +08:00
程序员阿江(Relakkes) e72c55264f fix(rewind): prevent long-session checkpoint stalls 2026-08-15 23:59:18 +08:00
程序员阿江(Relakkes) 0b13dc6f71 fix(sessions): keep worktree paths authoritative 2026-08-10 16:23:44 +08:00
程序员阿江(Relakkes) 3ce7c67822 feat(workflows): dynamic workflow orchestration end to end
A workflow is a JS script the model writes in the moment and hands to the
Workflow tool, which runs it in a locked-down `node:vm` and orchestrates
subagents through `agent()`/`parallel()`/`pipeline()`/`phase()`. Saving one
as a `/name` command is the secondary path; the inline script is the point.

Runtime: cross-realm value marshalling so a script cannot reach the host
`Function`, determinism guards on `Date.now()`/`Math.random()` (they would
make a resume replay diverge), a FIFO concurrency gate, and a journal that
lets an interrupted run resume from its longest unchanged prefix.

Desktop: the run shows up as a `workflow` section in the existing activity
panel — phases as headings, their agents beneath. A workflow agent is an
ordinary subagent run by the same runner, so its row opens the existing
subagent page rather than a parallel viewer of its own; that needed a
`by-agent` lookup, because these agents have no parent `Agent` tool call to
key off. Finished runs are rebuilt from the per-agent sidecars when a
session is reopened, since the live progress stream does not outlive the
process.
2026-08-10 00:17:03 +08:00
程序员阿江(Relakkes) 4fbbafa0b6 feat(agent-teams): add collaborative workbench 2026-08-08 22:48:51 +08:00
程序员阿江(Relakkes) 38e2f11253 fix(rewind): stop blocking undo on unrecognized tools (#1192)
restoreAvailable conflated two questions: whether the files this checkpoint
reports can be put back, and whether the checkpoint saw every file the turn
touched. Any tool outside an 18-name allowlist — Bash, PowerShell, TaskCreate,
every MCP tool — forced the second to false, and one such call anywhere from
the target turn onward disabled undo for the whole range. In practice that is
every real turn, so v0.5.3 shipped with undo effectively dead.

Split the two. restoreAvailable now answers only the first question.
The second becomes unverifiedChangeSources: tool names whose file effects the
checkpoint could not capture. Undo stays available and restores exactly the
files it lists, and the card, the confirmation, and the completion toast each
name what it is leaving behind. An unrecognized tool now costs a warning
instead of the feature. A transcript that cannot be read still blocks, because
then even the reported file list may be wrong.

Bash calls are classified against the existing read-only allowlist via a new
recordedCommandIsReadOnly, which drops the sandbox/cwd checks that describe the
live process rather than the replayed session. `git status` no longer warns at
all, so the warning means something when it appears.

Rewind also takes a mode. `conversation` skips the file restore entirely, so a
turn whose files cannot be restored no longer costs the user the ability to
back out of the prompt — matching how upstream keeps Restore conversation
independent of Restore code.

Files written by shell commands were never recoverable here; the checkpoint
only ever covered the structured file tools. Reporting that is honest, and
docs now say so.
2026-08-06 00:27:51 +08:00
程序员阿江(Relakkes) 3538b30b97 feat(desktop): create git branches from the launch picker (#1190)
Switching branches from the composer's launch pill has always been
possible; creating one meant leaving for a terminal. A "Create branch…"
row now sits under the branch list, in the dropdown and pinned to the
mobile sheet's footer, leading to a small form seeded with whatever was
typed into the branch filter.

The branch is created and selected, but HEAD is not moved. That matches
what every other pick in this menu already does: the real `git switch`
(or the isolated worktree) happens at session launch, which is where the
dirty-tree and already-checked-out guards live. Creating the ref is the
one part that has to be eager, since a branch cannot be selected before
it exists.

Server-side `createRepositoryBranch` refuses names git or this app
cannot honour: a leading dash (which `git branch` would read as a flag,
and which `check-ref-format` accepts once prefixed with refs/heads/),
the `worktree-desktop-` prefix that `listBranches` filters out and would
leave invisible on disk, a name already in the list — including a
remote-only one, where a second local branch would win the name and make
the launch run on the wrong content — and an empty repository, which
previously failed with untranslated `fatal:` text. Everything runs in
the picked directory rather than `repoRoot`, which resolves a linked
worktree back to the main checkout and branches off a different commit
than the reported HEAD.

Branch rows now carry their commit, and the context its HEAD, so the
"uncommitted changes may block switching" warning can stay quiet for a
branch that points where HEAD already points — the common case right
after creating one, where git only moves the ref and rewrites nothing.

(cherry picked from commit 7392a48b8cd5d83827d4e4656b8114a68edc9765)
2026-08-06 00:27:51 +08:00
程序员阿江(Relakkes) b8a90626ce feat(computer-use): native macOS engine, on top of main and nothing else
Rebuilt against main so the branch carries the Computer Use work and no other
divergence. Three unrelated efforts had been sitting uncommitted in this
worktree and were swept into an earlier commit; they are preserved on
cu-worktree-full-backup and belong on their own branches — adapter control
credentials, Electron asar sealing, and the sidecar code-loading audit. Every
file outside Computer Use now matches main exactly.

The engine
  A Swift helper drives apps through the accessibility tree, with coordinate
  actuation for the Chromium and Electron apps whose tree is a bare window
  frame. Ten primitives matching the shape Codex uses, so an app's guidance and
  the model's habits transfer.

  Coordinate actions resolve their target window once and refuse when none can
  be named. The unbound event they used to fall back to is discarded by custom
  renderers, so a minimized target produced a whole session of "Action
  completed" with nothing behind it.

  Input acceptance is established for typing and key presses as well as clicks:
  each MCP call is seconds apart, so the keyboard cannot inherit the focus a
  click established. The synthetic focus notification is gated on the target
  not already being active — sent unconditionally it names window 0 at an app
  that already owns a key window, and nine window-bound clicks were discarded
  with the traffic lights fully lit.

State the model can trust
  An off-screen target says so, and says which tools still reach it: element
  actions need no on-screen geometry, so an app with a real tree can still be
  driven from the Dock. A fully covered window is recovered once, then left
  alone — burying it again is the user wanting their screen back. A repeated
  capture is reported with the cause that actually applies rather than both,
  because coverage is something we compute.

Signing
  The helper is signed under a stable identity before electron-builder sees it,
  and excluded from re-signing: macOS ties Accessibility and Screen Recording
  grants to the signing identity, so rotating it drops both on every update.

Discoverability
  The desktop slash menu falls back to a directory scan while a session's CLI
  has not started, which is when the menu is first opened. Built-ins and
  bundled skills live in the binary, so /computer-use was absent until after
  the first message.
2026-08-05 22:06:23 +08:00
程序员阿江(Relakkes) bd44d0a17d fix(desktop): refine slash menu and launch warnings 2026-07-29 14:30:07 +08:00
Relakkes Yang a07e68839c fix: harden desktop runtime and pet interactions 2026-07-22 20:46:34 +08:00
程序员阿江(Relakkes) 6b725a0b6f fix(desktop): show live SubAgent run details #1077 2026-07-20 20:30:33 +08:00
程序员阿江(Relakkes) 36560c09d5 feat(pets): add interactive desktop companions 2026-07-20 19:20:18 +08:00
程序员阿江(Relakkes) 53a15098c0 perf(desktop): add SQLite-backed local data index #1016
Project sessions, activity, scheduled runs, traces, and searchable content into rebuildable managed databases while preserving canonical-file fallbacks. Add diagnostics, recovery, parity coverage, and performance acceptance checks.
2026-07-16 04:16:02 +08:00
程序员阿江(Relakkes) 86393ac179 fix(desktop): search unopened workspace files #1023 2026-07-14 21:31:39 +08:00
程序员阿江(Relakkes) ad2a504bba feat(permission): add Auto mode #978 2026-07-11 20:06:36 +08:00
程序员阿江(Relakkes) 56a4be3d14 feat(desktop): add session activity panel
Move session tasks, background tasks, subagents, and team activity into a floating right-side activity panel with capped section scrolling.

Add subagent run detail tabs backed by the existing session run data so member activity can be inspected from the main chat.

Tested: cd desktop && bun run test -- src/components/activity/SessionActivityPanel.test.tsx

Tested: bun run check:desktop
2026-07-03 23:24:22 +08:00
程序员阿江(Relakkes) 35f43e8289 fix: resolve post-release semantic conflicts
Fix cross-issue regressions found during post-0.4.4 merge review:\n\n- preserve permission mode across clear and empty-session replacement flows\n- keep provider effort passthrough and context-window estimates aligned with runtime metadata\n- invalidate recent project caches and trace message signatures when sessions change\n- recognize Windows ARM64 unpacked package-smoke output\n\nTested: bun test scripts/quality-gate/package-smoke/index.test.ts scripts/quality-gate/runner.test.ts\nTested: bun run check:desktop\nTested: bun run check:server\nConfidence: high\nScope-risk: moderate
2026-07-02 22:11:43 +08:00
程序员阿江(Relakkes) c324aee51d fix: bound git-info git probes (#908)
Tested: bun test src/server/__tests__/sessions.test.ts -t "git-info"

Tested: bun run check:server

Confidence: high

Scope-risk: narrow
2026-07-02 21:01:16 +08:00
程序员阿江(Relakkes) 2228524462 fix: reduce sidecar transcript memory pressure (#933)
Stream inspection transcript aggregation and avoid trace/message polling paths that repeatedly hydrate large session files.

Tested: bun run check:server
Tested: bun run check:desktop
Confidence: high
Scope-risk: moderate
2026-07-02 21:00:48 +08:00
程序员阿江-Relakkes 705f34b535 Merge pull request #919 from zhbdesign/patch-14
修复非git项目在新会话执行git命令导致加载慢
2026-07-02 15:42:57 +08:00
zhb 4e59c2feb5 优化会话中最近项目列表加载慢
优化会话中最近项目列表加载慢
2026-06-26 10:05:35 +08:00
zhb 78a9e26476 修复非git项目在新会话执行git命令导致加载慢
修复非git项目在新会话执行git命令导致加载慢
2026-06-26 08:48:53 +08:00
程序员阿江(Relakkes) fc27397205 fix(desktop): anchor output chips and previews on real changed files
Fix four root causes in the desktop preview pipeline, surfaced when the
model writes the files the user pointed it at:

- Output chips guessed paths from prose and could point at a missing file.
  They are now reconciled against the turn's real changed files: a bare
  `index.html` resolves to the `todo-app/index.html` actually written, and
  mentions the turn never changed are dropped.
- A standalone single-page index.html got no browser preview (mistaken for a
  Vite template). It is now only routed to the source view when a
  package.json/vite.config ships in the same change-set.
- Files written outside the session workdir (another folder, or another drive
  on Windows) failed to preview with 'Path is outside workspace'. The turn's
  changed-file directories are registered as filesystem access roots; html
  serves via /local-file and other files via a workdir-relaxed read.
- The visual-selection prompt leaked as a raw bubble on Windows because the
  server-appended '[Image source: ...]' line broke replay dedupe. Replay text
  is now metadata-normalized before comparison (affects any image message).

Adds unit tests for each: htmlPreviewPolicy, assistantOutputTargets
reconciliation, replay dedupe + stripGeneratedImageMetadataLines, filesystem
access roots, and workspace outside-workdir reads.
2026-06-13 11:01:46 +08:00
程序员阿江(Relakkes) d3d7566f0c refactor(trace): redesign trace UI with LangSmith-style two-pane layout
UI rebuild (desktop):
- TraceSession: replace 3-column layout with two panes — turn-grouped
  timeline tree (draggable splitter, search/filter, keyboard nav) and a
  section-flow detail panel (Response / Messages / System Prompt /
  Tools / Parameters / Raw), collapse state persists across spans
- Render LLM requests/responses semantically: messages as role-colored
  conversation with tool_use/tool_result pairing instead of raw JSON
  dumps; Raw fallback via CodeViewer for legacy truncated records
- TraceList: row-style list with model chips, mono metrics, hover
  actions; content-visibility rows (no virtualization, WebKit-safe)
- i18n synced across zh/en/jp/kr/zh-TW (+25/-55 keys)

Data & capture (server):
- Capture full bodies: preview cap 2048 -> 240k chars, stream cap
  256KB -> 1MB; list API trims previews to keep polling light; new
  GET /api/sessions/:id/trace/calls/:callId returns the full record
- Extract per-call token usage at read time (SSE + JSON + proxy
  wrapped); mtime-keyed read cache for the polling path
- Fix sensitive-key regex redacting *_tokens count fields, which made
  token stats always report 0

Frontend data layer:
- SSE stream reassembly (Anthropic + OpenAI chat) adapted from
  claude-tap (MIT, attribution in THIRD_PARTY_LICENSES.md), request/
  response body parsers, shared formatters, on-demand call detail
  cache; traceViewModel gains tokenUsage/isLifecycleNoise, drops
  fullRaw

Tested:
- bun run check:server (1201 pass)
- bun run check:desktop (lint + 1358 tests + build)
- Chromium walkthrough against real local traces: list, session tree,
  LLM semantic detail (new format), legacy fallback, tool detail
2026-06-11 01:02:51 +08:00
程序员阿江(Relakkes) 0d45439fbe feat(trace): add session trace monitoring (#606)
Tested:
- cd desktop && bun run test -- --run src/pages/TraceList.test.tsx
- bun test src/server/__tests__/trace-capture.test.ts
- bun run check:desktop
- bun run check:server

Scope-risk: broad
2026-06-10 17:13:27 +08:00
程序员阿江(Relakkes) f559ed31dc fix: keep MCP and history navigation responsive (#648)
MCP settings could remount into a full-page spinner even when cached server data was available, and overlapping refreshes could let stale responses replace newer state. Historical chat sessions also had no explicit history-loading state, so slow transcript reads looked like a blank session.

This keeps cached MCP/session lists visible during refresh, ignores stale list responses, clears the selected MCP server when returning to the list, and gives historical sessions explicit loading/error states with de-duped history loads.

Constraint: Fix must stay local-state focused and avoid changing MCP config persistence.
Rejected: Add a broad transcript/session indexing layer | too large for the issue-level stall fix.
Confidence: high
Scope-risk: moderate
Directive: Do not remove the stale-response guards without re-testing rapid settings navigation and session switching.
Tested: cd desktop && bun run test -- mcpSettings.test.tsx
Tested: cd desktop && bun run test -- sessionStore.test.ts
Tested: cd desktop && bun run test -- chatStore.test.ts
Tested: cd desktop && bun run test -- ActiveSession.test.tsx
Tested: bun test src/server/__tests__/sessions.test.ts src/server/__tests__/mcp.test.ts
Tested: cd desktop && bun run lint
Tested: cd desktop && bun run check:desktop
Tested: bun run check:server
Not-tested: Manual Windows desktop reproduction for issue #648.
2026-05-31 17:42:09 +08:00
程序员阿江(Relakkes) 3f4d731cc7 fix: scope permission mode to sessions
Permission mode is a per-session runtime choice, while scheduled tasks cannot rely on a human approval loop. This removes the General settings permission surface, persists session permission metadata, and forces scheduled tasks to run with bypass permissions. Runtime permission changes now handle both directions across bypass boundaries, including startup/prewarm races, by persisting first and restarting only when the CLI launch mode must change.

Constraint: Scheduled tasks must be able to execute without a human standing by for authorization.

Constraint: The CLI only honors bypass permissions when launched with the skip-permissions flag, so switching to or from bypass requires a restart.

Rejected: Keep a global General permission default | it can leak across sessions and scheduled runs in ways the user cannot reason about.

Confidence: high

Scope-risk: broad

Directive: Do not reintroduce a global UI permission selector without proving it cannot affect unrelated sessions or automations.

Tested: bun test src/server/__tests__/conversations.test.ts -t "permission" --timeout 30000 (10 pass, 0 fail)

Tested: bun run check:server (858 pass, 0 fail)

Tested: cd desktop && bun run check:desktop (760 tests plus production build passed)

Tested: desktop/scripts/build-macos-arm64.sh and codesign verification passed

Tested: Real DeepSeek smoke validated plan, bypass, and scheduled task permission behavior

Not-tested: Did not repeat the full DeepSeek smoke after the final startup-race hardening; mock WebSocket permission regression and full server gate were rerun after that change.

Fixes #632
2026-05-31 17:40:45 +08:00
程序员阿江(Relakkes) 89ec7d66c9 fix: hide internal worktree branch labels
Desktop worktree sessions should show the source project and worktree marker without surfacing implementation refs like worktree-desktop-* as user-facing branch state. The git-info response now keeps launch branch metadata separate from worktree identity, and the desktop chip hides branch and slug labels in isolated worktree mode.

Constraint: Git worktrees need an internal branch for isolated execution, but that ref is product plumbing rather than useful UI context
Rejected: Show both launch branch and worktree slug | duplicated noisy identifiers and confused the session location
Confidence: high
Scope-risk: narrow
Tested: bun test src/server/__tests__/sessions.test.ts -t "git-info"; cd desktop && bun run test src/components/shared/ProjectContextChip.test.tsx; bun run check:server; bun run check:desktop; git diff --check
Not-tested: Live desktop screenshot smoke
2026-05-23 16:16:30 +08:00
程序员阿江(Relakkes) 4dc705db3c fix: allow selected workspaces in filesystem browser
Desktop file mentions should follow the workspace the user opened, but
the filesystem browser only trusted the home and temp roots. Register
workspace roots after repository context, session creation, and session
git-info resolution so Windows projects on another drive can be searched
without turning the browse API into arbitrary disk access.

Constraint: Windows users can open repositories outside C:\\Users, such as D:\\workspace\\code\\cc-haha
Constraint: Filesystem browse must not become an unbounded local disk reader
Rejected: Add a global user-configurable filesystem whitelist | broader product and persistence surface than this bug needs
Rejected: Allow every requested browse path | would bypass the intended filesystem boundary
Confidence: high
Scope-risk: moderate
Directive: Register only workspace roots that the server has already resolved through session or repository flows
Tested: bun test src/server/__tests__/filesystem.test.ts
Tested: bun run check:server
Not-tested: Windows packaged desktop smoke
2026-05-22 19:48:05 +08:00
程序员阿江(Relakkes) 09c7167a49 fix: prevent worktree sessions showing source branch
Desktop git-info preserved the launch branch before checking the active worktree cwd, so materialized isolated worktree sessions could keep showing the source branch instead of the branch Git had checked out in the worktree. The API now switches to the real cwd branch only once the session has actually entered its planned worktree, while direct branch launches still keep their stable launch branch.

Constraint: Direct branch launches still need stable launch metadata when the source checkout later changes.
Rejected: Always prefer git rev-parse output | would regress direct launch sessions that intentionally show the selected branch.
Confidence: high
Scope-risk: narrow
Tested: bun test src/server/__tests__/sessions.test.ts -t "git-info"
Tested: /tmp/cc-haha-issue-539-verify API reproduction returned the worktree branch
Tested: bun run check:server
2026-05-21 17:21:02 +08:00
程序员阿江(Relakkes) 73e915ac6b Enable desktop branching from transcript messages
Desktop users need the same branch-from-here workflow that the CLI already exposed, so the branch creation logic now lives in a shared transcript utility and the desktop app routes completed message actions through the server API. The UI hydrates transcript ids after live completions so newly generated turns can be branched immediately without a refresh.

Constraint: Source sessions must remain unmodified while branch sessions inherit the active transcript chain and persistence metadata.
Rejected: Keep a desktop-only branch implementation | it would drift from CLI /branch semantics and duplicate transcript filtering rules
Confidence: high
Scope-risk: moderate
Directive: Do not remove the post-completion transcript hydration without a real-model desktop E2E for just-finished messages
Tested: bun run verify; Chrome Web UI E2E with real gpt-5.5 provider on ports 45678/45679
Not-tested: Provider-specific behavior beyond the configured Sub2API-ChatGPT route
2026-05-19 18:31:24 +08:00
程序员阿江(Relakkes) 8a5b3467c5 Merge origin/main into local post-0.2.7 main
Remote main carries portable-mode, legacy Windows workdir recovery, and Feishu path-safety fixes while local main carries terminal shell, update proxy, slash-command, prompt-draft, AskUserQuestion, background-work, and shell-env changes. This merge keeps both lines by layering portable Bash-path defaults underneath the desktop terminal shell preference and preserving both update-proxy and app-mode settings state.

Constraint: Local main and origin/main diverged after v0.2.7 and both lines contain release-relevant desktop/runtime fixes

Rejected: Prefer either side's terminal settings wholesale | would drop either Windows portable Bash support or explicit desktop startup-shell support

Confidence: medium

Scope-risk: moderate

Directive: Keep portable Bash path as the system-default terminal fallback; explicit desktop startup-shell settings should continue to override it

Tested: cd desktop && bun run test -- --run src/pages/TerminalSettings.test.tsx src/stores/settingsStore.test.ts

Tested: cd desktop/src-tauri && cargo test terminal -- --nocapture

Tested: bun test src/server/__tests__/sessions.test.ts -t stale worktree

Tested: bun run check:desktop

Tested: bun run check:server

Tested: bun run check:native

Not-tested: Manual Windows packaged-app terminal/portable smoke
2026-05-18 20:05:24 +08:00
程序员阿江(Relakkes) 010a4bf9d8 fix: preserve custom slash commands after live updates
The desktop command list could be replaced by a partial live CLI update after a turn, and the server fallback only knew about skills. Keep the client list stable while refreshing from the authoritative session endpoint, and include legacy .claude/commands entries in that endpoint.

Constraint: Claude Code custom slash commands still use .claude/commands/*.md alongside newer skill commands.
Rejected: Only union client-side updates | would still miss custom commands before CLI init and lose argument hints from the authoritative API.
Confidence: high
Scope-risk: moderate
Directive: Keep session slash command fallback aware of both skills and legacy command directories.
Tested: bun test src/server/__tests__/sessions.test.ts -t "slash-commands"
Tested: cd desktop && bun run test -- --run src/stores/chatStore.test.ts
Tested: bun run check:desktop
Tested: bun run check:server
Tested: bun run check:native
Not-tested: bun run verify remains red due unrelated/flaky coverage lane failures outside this change.
Related: https://github.com/NanmiCoder/cc-haha/issues/495
2026-05-18 14:38:40 +08:00
Relakkes Yang 3c3030fddf fix: recover legacy Windows session workdirs 2026-05-18 13:13:12 +08:00
程序员阿江(Relakkes) b4a5c09b11 fix: expose plugin skills in new session slash commands
New desktop sessions populated slash suggestions from the session endpoint before the CLI had emitted init metadata. That endpoint only scanned user and project skill directories, while the plugin settings view and global skills API already saw enabled plugin skills such as superpowers. The session endpoint now reuses the global skill listing and merges it with any cached CLI slash commands, and both composer surfaces rank command-name matches before broad description matches so /su surfaces superpowers first.

Constraint: New sessions need plugin skills before the first real user turn starts the CLI.

Rejected: Start or restart a hidden CLI process on plugin enable | heavier than needed and still misses the REST slash-command fallback path.

Confidence: high

Scope-risk: moderate

Directive: Keep session slash commands and /api/skills on the same skill discovery path when changing plugin skill loading.

Tested: bun test src/server/__tests__/skills.test.ts src/server/__tests__/plugins.test.ts src/server/__tests__/sessions.test.ts

Tested: cd desktop && bun run test --run src/components/chat/composerUtils.test.ts src/pages/EmptySession.test.tsx src/components/chat/ChatInput.test.tsx

Tested: bun run check:server

Tested: cd desktop && bun run lint

Not-tested: Manual desktop click-through in the packaged app.
2026-05-16 00:03:44 +08:00
程序员阿江(Relakkes) 0e78439f9d Group desktop sessions by project root
The desktop sidebar needed a project-first navigation model that keeps worktree sessions attached to their source project instead of scattering them as separate paths. The UI now renders sessions under project groups with project-level actions and persisted ordering, while the server exposes a logical project root for worktree transcripts.

Constraint: Existing memory directory tree work must remain separate from the session sidebar behavior.

Rejected: Group by raw transcript projectPath | worktree paths fragment the same repository into multiple sidebar projects.

Confidence: high

Scope-risk: moderate

Directive: Keep future sidebar grouping keyed by projectRoot before projectPath so isolated worktrees stay under their source repository.

Tested: cd desktop && bun run test -- src/components/layout/Sidebar.test.tsx

Tested: bun test src/server/__tests__/sessions.test.ts

Tested: git diff --check
2026-05-15 16:01:36 +08:00