Skip to content

Approve installed Codex hooks after dogfood - #4075

Merged
lawrencecchen merged 7 commits into
mainfrom
feat-codex-hook-approvals-dogfood
May 13, 2026
Merged

lawrencecchen merged 7 commits into
mainfrom
feat-codex-hook-approvals-dogfood

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented May 13, 2026 •

Copy link
Copy Markdown
Contributor

Reapplies the Codex hook approval work from #4035 after it was reverted by #4074. Kept draft so it can be dogfooded before relanding.


Summary by cubic

Reapplies Codex hook approval/trust and config migration, adds “needs input” notifications from both event messages and function-call transcripts, and repairs malformed Codex trust blocks in config.toml. cmux-owned hooks are trusted by default, and the UI shows clear “Codex needs input” prompts.

  • New Features

    • Notify when Codex asks a question from event_msg request_user_input and response_item function calls; dedupe by call_id; include question text; localized “Waiting”/“Codex needs input”.
    • Centralize cmux-owned hook detection/builders for event/feed hooks; match legacy command forms; preserve hook order on reinstall and avoid duplicate consecutive reinserts.
    • Write deterministic trust entries in config.toml under [hooks.state."<key>"] with a trusted_hash; escape keys and normalize paths.
  • Migration

    • Install: migrate from codex_hooks to hooks, replace legacy cmux codex-hook/cmux feed-hook, write/repair cmux trust blocks (recover malformed or partially written entries), and skip trust write if an existing cmux trust marker is unclosed; preserve other feature settings.
    • Uninstall: remove only cmux-owned hooks and trust, restore prior hooks settings (true/false, dotted/table), keep unowned trust, and surface config.toml read/encoding errors instead of overwriting unreadable files.

Written for commit fe2b5b9. Summary will update on new commits.


Note

Medium Risk
Moderate risk because it changes Codex hook install/uninstall behavior and rewrites config.toml (feature flag migration + trust blocks), which could affect user configs if edge cases are missed; adds new monitor notifications based on transcript parsing.

Overview
Adds Codex “needs input” detection to the hook monitor by parsing transcripts for request_user_input (both event_msg and response_item function calls), deduping by call_id, and publishing a notification + high-priority set_status using new localized strings.

Refactors hook installation/uninstallation to identify cmux-owned hook commands by exact command generation (including legacy Codex cmux codex-hook / cmux feed-hook forms), and preserves prior hook ordering on reinstall by reinserting cmux entries at their original positions.

Updates Codex hook post-install to migrate config.toml from deprecated codex_hooks to hooks, and to write/remove a cmux-managed hook trust block ([hooks.state."…"] trusted_hash = "sha256:…") computed deterministically from installed cmux hook handlers (with path normalization + TOML key escaping) while handling malformed/unclosed trust markers more safely.

Expands integration/regression coverage with new Swift monitor tests and extensive Python tests covering trust hashing/escaping, legacy migration, order preservation, and error handling for unreadable/invalid config.toml.

Reviewed by Cursor Bugbot for commit fe2b5b9. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

Release Notes

New Features

  • Codex now automatically detects when user input is required and displays notifications with corresponding status indicators, continuing to monitor for input requests.

Localization

  • Added Japanese and English localized strings for Codex input state messages, including "waiting" and "needs input" status indicators.

Review Change Stack

@coderabbitai

coderabbitai Bot commented May 13, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

This PR adds Codex hook command ownership detection, a SHA256-based trust system for validating installed hooks in config.toml, transcript-based user input detection and notifications, and comprehensive test coverage. The changes enable cmux to identify which hook commands it owns, compute and verify per-hook trust hashes, monitor Codex transcripts for user input events, and publish high-priority notifications when user input is needed.

Changes

Codex Hook Command Ownership, Trust System, and User Input Monitoring

Layer / File(s) Summary
Hook command generation and ownership detection
CLI/CMUXCLI+AgentHookDefinitions.swift, CLI/cmux.swift
CMUXCLI adds hookCommandString and feedHookCommandString helpers to generate shell commands for agent hooks, and isCmuxOwnedHookCommand to classify whether a command matches current or legacy hook patterns. Existing hookCommand/feedHookCommand builders delegate to these helpers.
Codex user input detection and publishing
CLI/cmux.swift
Transcript tail-reading and JSONL parsing detect request_user_input events (both direct and function_call forms), extract question text and stable call IDs, deduplicate via published call-id set, and publish user questions via notify_target and set_status socket commands with localized UI strings.
Hook installation with trust entry management
CLI/cmux.swift
Hook installation refactored to compute insertion indexes for cmux-owned hooks, prune existing cmux-owned entries while preserving user-provided ones, re-insert newly provided hooks at captured positions, and compute trust entries for Codex hooks destined for config.toml.
TOML trust block structures and manipulation
CLI/cmux.swift
Implements CodexHookTrustEntry structures, computes per-hook SHA256 hashes from event labels, matchers, commands, timeouts, and status messages, adds TOML table/key matching helpers, and provides block removal/detection logic for cmux-codex-hook-trust markers and trust state entries.
Localization strings for Codex input states
Resources/Localizable.xcstrings
Adds agent.codex.input.body.needsInput, agent.codex.input.status.needsInput, and agent.codex.input.subtitle.waiting with English and Japanese translations.
Swift test helpers and Codex monitor tests
cmuxTests/WorkspaceRemoteConnectionTests.swift
Adds MockSocketServerState.snapshot() for safe concurrent command inspection, waitForSocketCommand polling helper, and two integration tests verifying Codex monitor detects user input events and publishes expected notifications and status updates.
Python test constants, helpers, and environment updates
tests/test_codex_feed_hooks.py
Introduces shared constants for fake surface/workspace IDs and Codex hook event mappings; adds deterministic helpers to compute trust hashes, generate cmux hook commands, parse TOML trust blocks, and unescape TOML strings; updates existing tests to use shared constants.
Python test cases for hook installation, uninstall, and robustness
tests/test_codex_feed_hooks.py
Extends installation tests to validate trust hashes and insertion ordering; adds uninstall robustness tests for restoring disabled states, handling unclosed trust blocks, and managing invalid UTF-8; updates main() test list.

Sequence Diagram

sequenceDiagram
  participant Client as User/App
  participant Monitor as cmux codex monitor
  participant Transcript as Codex Transcript File
  participant Parser as Event Parser
  participant Socket as cmux Socket
  Client->>Transcript: write request_user_input event
  Monitor->>Transcript: tail-read JSONL
  Transcript->>Parser: provide lines
  Parser->>Parser: recognize request_user_input<br/>extract callId, question
  Parser-->>Monitor: CodexHookUserInputCandidate
  Monitor->>Socket: notify_target Codex|Waiting|<question>
  Monitor->>Socket: set_status codex Codex needs input
  Socket-->>Client: notification received
  Monitor->>Transcript: continue watching
Loading

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

  • manaflow-ai/cmux#3298: Modifies hook command string generation and legacy marker handling so installed hooks use the cmux hooks <agent> ... syntax with backward compatibility.
  • manaflow-ai/cmux#2717: Introduces generalized agent hook framework that overlaps with the new hook command generation and Codex hook dispatch/install-uninstall logic.
  • manaflow-ai/cmux#4035: Modifies Codex hook install/uninstall to manage the same config.toml hook-trust block and deterministic hash entry computation/cleanup.

Poem

A rabbit hops through trust and hooks, 🐰
Parsing transcripts like trusty books,
User input now gets a voice,
With hashes and notifications—rejoice!
Codex waits, and we listen well,
A tale of monitoring to tell. ✨

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 2.04% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Description check ❓ Inconclusive The PR description provides comprehensive context about the changes and their purpose but does not follow the required template structure with explicit Testing, Demo Video, Review Trigger, and Checklist sections. Add the missing template sections: Testing (how tested and manual verification), Demo Video (link if applicable), Review Trigger (copy-paste bot review commands), and Checklist (mark items as complete).
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title 'Approve installed Codex hooks after dogfood' is specific and directly related to the main objective of reapplying Codex hook approval work and validating it before relanding.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat-codex-hook-approvals-dogfood

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@vercel

vercel Bot commented May 13, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview, Comment May 13, 2026 11:47am
cmux-staging Building Building Preview, Comment May 13, 2026 11:47am

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@greptile-apps

greptile-apps Bot commented May 13, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR re-lands Codex hook approval work (reverted in #4074): it writes deterministic SHA-256 trusted_hash entries in config.toml, migrates codex_hooks to hooks = true, preserves third-party hook ordering on reinstall, and adds Codex needs-input notifications from request_user_input transcript events.

  • Trust-block management: codexConfigTomlInstallingHookTrust writes a cmux-fenced trust block on install and removes it on uninstall; a new stripMalformedCmuxCodexHookTrustMarker removes orphaned begin markers to unblock re-installation.
  • Hook ordering: A new insertion-index tracking mechanism preserves original hook positions relative to third-party entries during reinstall.
  • User-input notifications: readCodexTranscriptUserInput scans the JSONL transcript, deduplicates by call_id, and publishes a notify_target + high-priority set_status codex command with new en/ja localized strings.

Confidence Score: 3/5

Install and uninstall flows handle most config.toml states correctly, but a malformed trust block leaves stale trust entries for removed hooks permanently in config.toml.

When stripMalformedCmuxCodexHookTrustMarker removes only the begin marker, orphaned trust table lines for old hooks remain. Subsequent installs clean up only tables matching current hook keys, so trust entries for removed hooks persist and continue telling Codex to treat no-longer-installed commands as pre-approved.

CLI/cmux.swift — the install and uninstall paths through codexConfigTomlInstallingHooksFeature and codexConfigTomlInstallingHookTrust when a malformed trust block is present.

Important Files Changed

Filename Overview
CLI/CMUXCLI+AgentHookDefinitions.swift Centralizes cmux hook command string generation as static helpers; adds isCmuxOwnedHookCommand with legacy-command detection. Logic is clean and well-isolated.
CLI/cmux.swift Adds ~896 production lines across four responsibilities. The malformed-trust-block recovery path leaves stale orphaned trust entries for old hook keys in config.toml.
Resources/Localizable.xcstrings Adds three new localized strings (en + ja) for Codex user-input notifications. Translations look correct.
cmuxTests/WorkspaceRemoteConnectionTests.swift Adds two integration tests for request_user_input notification paths. Upgrades MockSocketServerState to a semaphore-signaled waitForCommand.
tests/test_codex_feed_hooks.py Adds 15 new Python integration tests covering trust-state hashing, key escaping, hook ordering, legacy migration, encoding errors, and malformed-marker recovery.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[hooks codex install] --> B[Write hooks.json]
    B --> C{config.toml exists?}
    C -- No --> D[existingContent = empty]
    C -- Yes --> E[try read config.toml]
    D & E --> F[codexConfigTomlInstallingHooksFeature]
    F --> G{trust block malformed?}
    G -- Yes --> H[strip begin marker only - stale tables remain]
    G -- No --> I[trust block cleanly removed]
    H & I --> J[codexConfigTomlInstallingHookTrust - remove current keys - append new block]
    J --> K[write config.toml]
    L[hooks codex uninstall] --> M[Remove cmux hooks from hooks.json]
    M --> N{config.toml exists?}
    N -- No --> O[done]
    N -- Yes --> P[try read config.toml]
    P --> Q[codexConfigTomlUninstallingHooksFeature]
    Q --> R{trust block malformed?}
    R -- Yes --> S[strip begin marker only - stale tables remain]
    R -- No --> T[trust block cleanly removed]
    S & T --> U[write config.toml]
    style H fill:#ffcccc
    style S fill:#ffcccc
Loading

Comments Outside Diff (1)

  1. CLI/cmux.swift, line 18217-18232 (link)

    P1 Orphaned stale trust entries survive a malformed-block recover on install

    When codexConfigTomlInstallingHooksFeature encounters a malformed trust block (begin marker with no end), it strips only the begin marker via stripMalformedCmuxCodexHookTrustMarker, leaving every [hooks.state."key"] / trusted_hash = … line in place. The featureContent passed to codexConfigTomlInstallingHookTrust then contains those orphaned table sections. removeCodexHookTrustTables removes only tables whose keys match the current hooks, so trust entries for any hook that was removed or renamed since the malformed write persist indefinitely in config.toml. Codex would continue treating those stale, no-longer-installed commands as pre-approved.

Reviews (4): Last reviewed commit: "Avoid duplicate consecutive cmux hook re..." | Re-trigger Greptile

Comment on lines +1721 to +1733
return false
}

private func waitForSocketCommand(
state: MockSocketServerState,
timeout: TimeInterval,
matching predicate: (String) -> Bool
) -> Bool {
let deadline = Date().addingTimeInterval(timeout)
while Date() < deadline {
if state.snapshot().contains(where: predicate) {
return true
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Blocking poll-sleep in new test helper

waitForSocketCommand uses DispatchSemaphore(value: 0).wait(timeout: .now() + 0.05) as a fixed-interval poll sleep — the same pattern cmux-swift-blocking-runtime asks to avoid. The pre-existing waitForProcess helper in this file already uses the same idiom, so this is consistent with local test convention; however, it adds another instance of the pattern. A callback-based approach (e.g., notifying via a DispatchSemaphore that is signalled from MockSocketServerState.snapshot on write) would eliminate the poll loop entirely and make the assertion fire as soon as the command arrives rather than after up to 50 ms lag per check.

Comment thread CLI/cmux.swift Outdated
isOwnedCommand(command) else {
continue
}
let timeoutSec = max(intValue(hook["timeout"]) ?? 600, 1)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Misleading variable name: timeoutSec holds a milliseconds value

hook["timeout"] is written by buildHooksDict as timeoutMs (e.g., 5000 for Codex's .nested(timeoutMs: 5000) format). The variable is therefore storing milliseconds, not seconds. Both sides of the hash computation use the same raw value so the hashes agree, but calling it timeoutSec is likely to mislead someone who later tries to convert units or add a seconds-based fallback.

Suggested change
let timeoutSec = max(intValue(hook["timeout"]) ?? 600, 1)
let timeoutMs = max(intValue(hook["timeout"]) ?? 600, 1)

Comment thread CLI/cmux.swift
Comment on lines +18499 to +18505
let trustedHash = codexCommandHookHash(
eventLabel: eventLabel,
matcher: matcher,
command: command,
timeoutSec: timeoutSec,
statusMessage: statusMessage
)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 timeoutMs must be threaded through to codexCommandHookHash

Follow-up to the rename: the timeoutSec argument label in the call below must also be updated once the local variable is renamed to timeoutMs.

Suggested change
let trustedHash = codexCommandHookHash(
eventLabel: eventLabel,
matcher: matcher,
command: command,
timeoutSec: timeoutSec,
statusMessage: statusMessage
)
let trustedHash = codexCommandHookHash(
eventLabel: eventLabel,
matcher: matcher,
command: command,
timeoutSec: timeoutMs,
statusMessage: statusMessage
)

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
CLI/cmux.swift (1)

16216-16941: 🛠️ Refactor suggestion | 🟠 Major | 🏗️ Heavy lift

Extract the new Codex parsing/trust work out of CLI/cmux.swift.

This file is already over 18k lines, and this patch adds several hundred more lines of transcript parsing, socket publishing, TOML mutation, path normalization, and hashing. Please split the Codex transcript/user-input logic and the config/trust/TOML logic into focused types before merging.

As per coding guidelines, do not accept more than 250 lines added to an existing production Swift file that is already over 800 lines, and flag Swift files that mix persistence, parsing, networking/subprocess protocol, and platform code in one place.

Also applies to: 18355-18831

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@CLI/cmux.swift` around lines 16216 - 16941, The CLi/cmux.swift addition
bundles parsing, persistence, lease/monitoring and notification logic into a
huge file; extract these responsibilities into focused types and files: create a
CodexTranscriptParser (move readCodexTranscriptUserInput,
codexUserInputEventCandidate, codexUserInputFunctionCallCandidate,
codexFunctionCallArgumentsObject, codexUserInputCandidate,
codexUserInputQuestionText, codexHookStopPayloadHasAssistantMessage,
codexTranscriptLineHasAssistantMessage, codexHookFailureCandidate,
summarizeCodexHookFailureCandidate, codexHookStringValue, readTextFileTail), a
CodexMonitorLeaseManager (move codexMonitorLeaseDirectory,
codexMonitorLeasePath, writeCodexMonitorLease, readCodexMonitorLease,
createCodexMonitorLease, retireCodexMonitorLeases,
pruneExpiredCodexMonitorLeases, isCodexMonitorLeaseRetired,
removeCodexMonitorLease), and a CodexMonitorRunner/Publisher (move
findCodexTranscriptPath, recentCodexSessionDirectories, codexMonitorOwnerState,
startCodexTranscriptMonitor, runCodexTranscriptMonitor,
publishCodexMonitorUserInput and any helpers like codexMonitor constants); keep
the public call sites (startCodexTranscriptMonitor/runCodexTranscriptMonitor
invocation points) but delegate to the new types and move any
config/TOML/trust-related helpers into a separate Config/Trust module; ensure
all moved methods keep signatures or are adapted to dependency-inject
FileManager/SocketClient/telemetry so tests and callers remain unchanged.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@CLI/cmux.swift`:
- Around line 18331-18335: Update the thrown CLIError in the catch block where
you attempt to read the hook file (String(contentsOfFile:encoding:)) so it
includes the underlying error string; modify the message created for CLIError to
append String(describing: error) (referencing configPath, def.displayName, and
the local variable content) so the exception surfaces the real failure
(permissions, encoding, etc.) instead of the generic "could not be read" text.
- Around line 18242-18246: The message prints claim approval whenever
codexHookTrustEntries is non-empty even if codexConfigTomlInstallingHookTrust
did not actually install trust; update codexConfigTomlInstallingHookTrust to
return an outcome (enum or bool) indicating whether the trust block was written,
propagate that return value to the caller, and change the conditional around the
print (the branch that checks def.name == "codex") to require both
codexHookTrustEntries.isEmpty == false and the new outcome == .installed (or
true) before printing "Enabled hooks and approved cmux hooks..."; apply the same
change to the other similar block referenced (the second occurrence around the
18446-18469 range).
- Around line 18095-18110: The code only records a single insertion index per
event in cmuxInsertionIndexes, collapsing multiple cmux-owned spans into one;
change cmuxInsertionIndexes from [String: Int] to [String: [Int]] and, inside
the loop where you detect isCmuxOwnedCommand(...), append the current
rewrittenEntries.count to cmuxInsertionIndexes[event] every time (do not guard
with == nil), so every cmux span position is recorded; later reinsert cmux
blocks using the sequence of indexes to preserve each original interleaved span
and apply the same change to the duplicated logic in the other block (the
section at the later range referenced).

In `@CLI/CMUXCLI`+AgentHookDefinitions.swift:
- Around line 265-266: Add a brief explanatory comment in the
isLegacyCmuxOwnedHookCommand function next to the guard that checks def.name ==
"codex" to document why legacy detection is limited to Codex hooks (legacy `cmux
codex-hook` and `cmux feed-hook` were Codex-specific), mentioning that other
agents were never affected and should therefore be excluded from legacy
handling; reference the function name isLegacyCmuxOwnedHookCommand and the guard
condition def.name == "codex" so maintainers understand the historical
rationale.
- Line 286: The function legacyCmuxCommandTokens(from:for:) currently returns an
optional [Substring]? but callers treat nil same as empty; change its signature
to return a non-optional [Substring] and return an empty array when parsing
fails (e.g., on shell metacharacters). Update any callers (the guard binding
that currently does `guard let tokens = legacyCmuxCommandTokens(...),
!tokens.isEmpty`) to drop the optional unwrap and just check `!tokens.isEmpty`
(or handle the empty array), ensuring all call sites compile with the new
non-optional return type.

---

Outside diff comments:
In `@CLI/cmux.swift`:
- Around line 16216-16941: The CLi/cmux.swift addition bundles parsing,
persistence, lease/monitoring and notification logic into a huge file; extract
these responsibilities into focused types and files: create a
CodexTranscriptParser (move readCodexTranscriptUserInput,
codexUserInputEventCandidate, codexUserInputFunctionCallCandidate,
codexFunctionCallArgumentsObject, codexUserInputCandidate,
codexUserInputQuestionText, codexHookStopPayloadHasAssistantMessage,
codexTranscriptLineHasAssistantMessage, codexHookFailureCandidate,
summarizeCodexHookFailureCandidate, codexHookStringValue, readTextFileTail), a
CodexMonitorLeaseManager (move codexMonitorLeaseDirectory,
codexMonitorLeasePath, writeCodexMonitorLease, readCodexMonitorLease,
createCodexMonitorLease, retireCodexMonitorLeases,
pruneExpiredCodexMonitorLeases, isCodexMonitorLeaseRetired,
removeCodexMonitorLease), and a CodexMonitorRunner/Publisher (move
findCodexTranscriptPath, recentCodexSessionDirectories, codexMonitorOwnerState,
startCodexTranscriptMonitor, runCodexTranscriptMonitor,
publishCodexMonitorUserInput and any helpers like codexMonitor constants); keep
the public call sites (startCodexTranscriptMonitor/runCodexTranscriptMonitor
invocation points) but delegate to the new types and move any
config/TOML/trust-related helpers into a separate Config/Trust module; ensure
all moved methods keep signatures or are adapted to dependency-inject
FileManager/SocketClient/telemetry so tests and callers remain unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: ec1968c5-3371-47c2-aa38-fd4943b9e797

📥 Commits

Reviewing files that changed from the base of the PR and between 1ac63a3 and 2a01d1e.

📒 Files selected for processing (5)
  • CLI/CMUXCLI+AgentHookDefinitions.swift
  • CLI/cmux.swift
  • Resources/Localizable.xcstrings
  • cmuxTests/WorkspaceRemoteConnectionTests.swift
  • tests/test_codex_feed_hooks.py

Comment thread CLI/cmux.swift Outdated
Comment thread CLI/cmux.swift Outdated
Comment thread CLI/cmux.swift
Comment thread CLI/CMUXCLI+AgentHookDefinitions.swift Outdated
Comment thread CLI/CMUXCLI+AgentHookDefinitions.swift Outdated
Comment thread CLI/cmux.swift
Comment on lines +18385 to +18390
removeCmuxCodexHooksFeatureBlock(from: &lines)
removeCmuxCodexHookTrustBlock(from: &lines)
lines.removeAll { tomlLineDefinesKey("codex_hooks", line: $0) }
lines.removeAll { tomlLineDefinesDottedFeaturesKey("codex_hooks", line: $0) }

let insertedLines = [

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Malformed trust block is silently preserved, creating an unrecoverable stuck state. removeCmuxCodexHookTrustBlock returns .malformed early without modifying lines when it finds a begin marker with no matching end. Because the result is @discardableResult-ignored here, the orphaned begin marker survives into featureContent. When codexConfigTomlInstallingHookTrust then calls removeCmuxCodexHookTrustBlock on that same content it finds the orphaned marker again, returns .malformed, and skips trust installation — so reinstalling never repairs the broken config. The fix is to consume the return value and strip the orphaned marker explicitly when .malformed is returned.

Suggested change
removeCmuxCodexHooksFeatureBlock(from: &lines)
removeCmuxCodexHookTrustBlock(from: &lines)
lines.removeAll { tomlLineDefinesKey("codex_hooks", line: $0) }
lines.removeAll { tomlLineDefinesDottedFeaturesKey("codex_hooks", line: $0) }
let insertedLines = [
removeCmuxCodexHooksFeatureBlock(from: &lines)
let trustBlockResult = removeCmuxCodexHookTrustBlock(from: &lines)
if trustBlockResult == .malformed {
// Orphaned begin marker (no matching end): strip it so reinstall can recover.
lines.removeAll { $0 == cmuxCodexHookTrustBegin }
}
lines.removeAll { tomlLineDefinesKey("codex_hooks", line: $0) }
lines.removeAll { tomlLineDefinesDottedFeaturesKey("codex_hooks", line: $0) }
let insertedLines = [

Comment thread CLI/cmux.swift
Comment on lines +18448 to +18452
static func codexConfigTomlUninstallingHooksFeature(from existingContent: String) -> String {
var lines = tomlLines(from: existingContent)
removeLegacyCodexHooksFeatureBlock(from: &lines)
var filteredLines: [String] = []
var currentTable: String?
for line in lines {
if let tableName = tomlTableName(in: line) {
currentTable = tableName
filteredLines.append(line)
continue
}
if (currentTable == nil || currentTable == "features"),
tomlLineDefinesCodexHooksKey(line) {
removeCmuxCodexHooksFeatureBlock(from: &lines)
removeCmuxCodexHookTrustBlock(from: &lines)
lines.removeAll { tomlLineDefinesKey("codex_hooks", line: $0) }

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Same orphaned-begin-marker issue on the uninstall path. If a user runs hooks codex uninstall with a malformed trust block, removeCmuxCodexHookTrustBlock silently returns .malformed without removing anything, and the orphaned begin marker is written back to config.toml. Apply the same defensive strip here.

Suggested change
static func codexConfigTomlUninstallingHooksFeature(from existingContent: String) -> String {
var lines = tomlLines(from: existingContent)
removeLegacyCodexHooksFeatureBlock(from: &lines)
var filteredLines: [String] = []
var currentTable: String?
for line in lines {
if let tableName = tomlTableName(in: line) {
currentTable = tableName
filteredLines.append(line)
continue
}
if (currentTable == nil || currentTable == "features"),
tomlLineDefinesCodexHooksKey(line) {
removeCmuxCodexHooksFeatureBlock(from: &lines)
removeCmuxCodexHookTrustBlock(from: &lines)
lines.removeAll { tomlLineDefinesKey("codex_hooks", line: $0) }
static func codexConfigTomlUninstallingHooksFeature(from existingContent: String) -> String {
var lines = tomlLines(from: existingContent)
removeCmuxCodexHooksFeatureBlock(from: &lines)
let trustBlockResult = removeCmuxCodexHookTrustBlock(from: &lines)
if trustBlockResult == .malformed {
lines.removeAll { $0 == cmuxCodexHookTrustBegin }
}
lines.removeAll { tomlLineDefinesKey("codex_hooks", line: $0) }

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit c52380f. Configure here.

Comment thread CLI/cmux.swift
@lawrencecchen
lawrencecchen merged commit 6c9e913 into main May 13, 2026
25 checks passed
@lawrencecchen
lawrencecchen deleted the feat-codex-hook-approvals-dogfood branch May 13, 2026 11:57
lawrencecchen added a commit that referenced this pull request May 14, 2026
* feat: improve markdown viewer

* fix: address markdown review feedback

* fix: clean up markdown review issues

* fix: address markdown review feedback

* fix: address latest markdown review

* Fix #3807: bring notification CLI to panel parity (#3811)

* Prove notification CLI parity is missing

Add behavior-level coverage for the missing notification socket and CLI actions before implementing them. The tests drive V2 notification action methods, CLI subcommands, extended list fields, and the UI open-notification flow so CI can show the pre-fix gap.

Constraint: Regression tests must be committed before the implementation for issue #3807

Constraint: Local Swift tests are not run in this repo; verification is through CI

Confidence: high

Scope-risk: narrow

Tested: git diff --check

Not-tested: Swift/XCUITest execution; intentionally deferred to CI

* Make notification actions scriptable from the CLI

The notifications panel already owned the behavior for dismissing, marking read, opening, and jumping to unread rows. This wires the socket and CLI to those existing store/AppDelegate paths, extends list output with panel metadata, and documents the new command surface without introducing a second notification action model.

Constraint: Existing Notifications page behavior must remain the source of truth

Constraint: Direct xcodebuild and local Swift/XCUITest runs are forbidden in this workspace

Rejected: Duplicate CLI-side focus or read-state logic | would diverge from AppDelegate.openNotification and TerminalNotificationStore semantics

Confidence: medium

Scope-risk: moderate

Tested: git diff --check

Tested: jq empty Resources/Localizable.xcstrings

Tested: python3 -m json.tool Resources/Localizable.xcstrings

Not-tested: Swift unit/UI execution; deferred to CI per repo policy

* Make notification CI compile under strict concurrency

The notification parity implementation introduced a shared formatter on a main-actor type and a test helper that crossed actor boundaries through escaping closures. This keeps the socket behavior unchanged while making date formatting local to the main-actor call path and keeping the XCTest socket request helper from capturing actor-isolated state in the background request closure.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace

Rejected: Run xcodebuild locally to confirm | user explicitly warned direct xcodebuild can deadlock the machine

Confidence: medium

Scope-risk: narrow

Tested: git diff --check

Tested: jq empty Resources/Localizable.xcstrings

Not-tested: Swift compilation and XCTest execution; deferred to CI

* Make notification parity actions atomic and exact

Review feedback exposed two behavior risks in the notification parity path: bulk dismissal was implemented as client-side list-and-loop work, and jump-to-unread could report one unread notification while opening a later valid one. The server now owns already-read dismissal as a single V2 action, the jump helper returns the notification it actually opened, and event/list parsing details match those server semantics.

Constraint: Notification action logic must reuse the existing store and AppDelegate paths

Rejected: Split TerminalController into new controllers in this PR | broad refactor is unrelated to issue #3807 and would obscure the parity fix

Confidence: medium

Scope-risk: moderate

Tested: git diff --check

Tested: jq empty Resources/Localizable.xcstrings

Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace instructions

* Expose app test symbols to CLI notification coverage

The integration regression exercises real app-backed notification state through the CLI harness, so the test target must import the built app module the same way the socket action tests do.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace
Rejected: Verify with xcodebuild locally | user explicitly forbids direct xcodebuild
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI

* Make notification list and dismiss payloads stable

Review caught two small contract hazards in the new notification RPC surface: the dismiss result used mixed JSON types, and a pipe in the appended tab title could shift the legacy list parser. The server now reports dismissals as counts consistently and escapes only the new trailing list field, with the CLI decoding it after structural parsing.

Constraint: The V1 list response remains pipe-delimited for backward compatibility, so only newly appended trailing fields can be encoded without changing old parser behavior
Rejected: Replace list_notifications with JSON-only output | existing V1 parsers depend on the line format
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace policy

* Return async notification socket responses from tests

CircleCI caught a compile-only issue in the async V2 test helper: the continuation result was awaited but not returned from the method that promises a response dictionary. Returning the continuation value restores the helper contract without changing the exercised socket behavior.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace
Rejected: Verify with local xcodebuild | user explicitly forbids direct xcodebuild
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI

* Avoid blocking notification CLI integration sockets

The integration regression has to create AppKit-backed notification state on the main actor, but running the CLI subprocess synchronously there can block the socket handler's main-actor store mutations. The test now awaits subprocess work on a background queue and verifies read state through the same CLI list path.

Constraint: Socket notification handlers intentionally hop to the main actor for store and AppDelegate work
Rejected: Run the CLI synchronously from the main actor | it can deadlock the in-process socket server during tests
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace policy

* Harden notification CLI response contracts

The notification parity path now distinguishes new list-notification trailer fields from old pipe-heavy bodies, rejects surface-only mark-read selectors, and returns post-open read state by marking through the shared store path after a successful focus action.

Constraint: list_notifications remains a legacy pipe-delimited protocol, so the new trailer needs its own discriminator while older body parsing keeps joining payload[6...]
Rejected: Add a third list_notifications sentinel field | the issue asked for exactly the two appended fields
Rejected: Rely on AppDelegate delayed mark-read for socket JSON | CLI callers need the open response and subsequent list output to reflect the explicit action
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace policy

* Make CLI integration helper capture explicit self

CircleCI's Swift compile step requires explicit self when the background subprocess closure calls the test helper method. This keeps the deadlock fix intact while satisfying Swift capture rules.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace
Rejected: Verify with local xcodebuild | user explicitly forbids direct xcodebuild
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI

* Make CLI presentation flags order-independent

Users naturally put presentation flags next to the command they are inspecting. Normalize --json and --id-format after command selection so docs examples such as cmux list-notifications --json produce JSON while still preserving literal flag-looking values for command options.

Constraint: Do not run reload.sh before CI is green; never run bare xcodebuild.

Rejected: Documentation-only correction | leaves copy-pasted command behavior surprising.

Rejected: Notification-only --json handling | repeats the same parser split for future JSON-capable commands.

Confidence: medium

Scope-risk: moderate

Directive: Keep presentation flag parsing centralized; update commandOptionsWithValues when adding value-taking command options.

Tested: git diff --check

Not-tested: Local XCTest/build per repo policy; CI will verify.

* Fix notification surface selector error message

* Make notification open mark read synchronously

* Fix CLI presentation flag parsing

* Test notification mark-read missing id

* Reject missing notification mark-read ids

* fix: polish markdown viewer dogfood

* Fix shared WebView task manager attribution

Fixes shared WebContent resource attribution in task manager rows and adds regression coverage.

* Prevent display-link crash from terminal portal layout reentry (#3885)

* Pin portal sync deferral during SwiftUI host callbacks

The silent-exit crash path points at SwiftUI/AppKit layout recursion reaching a CATransaction display-link flush. This test locks the intended invariant: geometry callbacks originating from the SwiftUI NSViewRepresentable host must defer portal reconciliation instead of forcing immediate AppKit layout, even while an interactive resize is active.

Constraint: Local tests are intentionally not run in this repository; CI owns regression proof.\nRejected: Assert on source text or unified-log contents | timing-dependent and not executable through the policy seam.\nConfidence: medium\nScope-risk: narrow\nDirective: Keep immediate portal flushing owned by external AppKit resize observers, not SwiftUI host callbacks.\nTested: Not run locally per repository policy and user instruction.\nNot-tested: Full multi-session crash reproduction is timing-dependent and not deterministic.

* Prevent portal layout reentry from terminal host callbacks

The terminal NSViewRepresentable host was allowed to bind into the window portal and synchronously flush AppKit layout from update/layout callbacks. That made SwiftUI's own host layout and the external terminal portal both believe they could drive geometry in the same render turn, matching the NSHostingView reentrant-layout warnings reported before the CATransaction display-link abort.\n\nThe portal now treats SwiftUI host callbacks as state capture only: they register the binding and schedule the portal owner to reconcile geometry after the current render turn. Immediate geometry flushing remains available to the portal's external AppKit resize observers, which are outside SwiftUI body/layout evaluation. The launch path also records clean exits and posts a one-time TerminalNotificationStore breadcrumb when a newer ghostty Breakpad envelope is found after an unclean exit.

Constraint: Local tests and app builds are not run before CI for this branch; verification is delegated to CI, then the required tagged reload.\nRejected: Wrap the CATransaction/display-link exception in @try/@catch | it would hide AppKit's abort symptom without removing the reentrant layout owner split.\nRejected: Keep immediate sync during interactive SwiftUI host callbacks | still allows layoutSubtreeIfNeeded inside the representable layout/update path.\nConfidence: medium\nScope-risk: moderate\nDirective: SwiftUI/AppKit host callbacks must not force terminal portal layout synchronously; add external observer paths for any future immediate resize flushing.\nTested: git diff --check; jq empty Resources/Localizable.xcstrings\nNot-tested: Local XCTest/build/repro per repository and user instructions; 75-minute multi-session crash reproduction is not deterministic.

* Record clean-exit breadcrumb after teardown

The crash breadcrumb should compare Breakpad envelopes against the last successfully completed termination path. Recording the timestamp after teardown avoids marking an exit clean before session persistence, process cleanup, and notification cleanup have finished.

Constraint: This is a follow-up correctness tweak before CI settled.\nRejected: Keep the timestamp at the start of applicationWillTerminate | a crash during termination cleanup could suppress the next-launch breadcrumb.\nConfidence: high\nScope-risk: narrow\nDirective: Only update the clean-exit timestamp after teardown work that must complete for a clean quit.\nTested: git diff --check; jq empty Resources/Localizable.xcstrings\nNot-tested: Local tests/builds per repository and user instructions.

* Defer first portal install from SwiftUI callbacks

A deferred SwiftUI host bind could still create the WindowTerminalPortal for the first time, and the initializer previously installed the host with an immediate layout flush. Threading the same deferral flag through portal creation keeps the invariant complete: representable update/layout callbacks never synchronously flush terminal portal layout, even on first bind.

Constraint: Must preserve immediate install behavior for non-SwiftUI external portal callers
Rejected: Assume portals already exist before host callbacks | first terminal bind in a new window can create one
Confidence: high
Scope-risk: narrow
Directive: Any future portal creation path from SwiftUI callbacks must carry deferred synchronization through initialization
Tested: git diff --check; jq empty Resources/Localizable.xcstrings
Not-tested: Local tests/builds per repository and user instructions

* Move crash breadcrumb work out of launch hot path

The crash breadcrumb scanner is pure Foundation logic, so it now lives in its own source file and performs the crash-directory scan from a detached utility task. App launch only schedules the check once, then posts the existing localized notification after the background scan returns to the main actor. The terminal host geometry policy is also simplified to make the always-deferred invariant explicit at the call site.

Constraint: Local build/tests are intentionally skipped until CI completes per issue instructions
Rejected: Keep synchronous directory enumeration in AppDelegate.configure | startup should not block on crash artifact I/O
Rejected: Preserve the dead immediate portal sync branch | host callbacks are never allowed to force layout synchronously
Confidence: high
Scope-risk: narrow
Directive: Do not reintroduce synchronous crash-directory scans or immediate portal layout flushes from SwiftUI host callbacks
Tested: git diff --check; jq empty Resources/Localizable.xcstrings; plutil -lint GhosttyTabs.xcodeproj/project.pbxproj
Not-tested: Local build/tests per repository and user instructions

* Tighten portal geometry regression seam

* Fix crash breadcrumb actor isolation

* Mark crash breadcrumb async helper nonisolated

* Make crash breadcrumb scan concurrent

* fix: remove inert crash breadcrumb cooldown key

* fix: use renamed crash breadcrumb annotation

* fix: own crash breadcrumb scan task

* Hide sidebar descriptions in title-only mode (#4040)

* Hide sidebar descriptions in title-only mode

* Add sidebar description visibility toggle

* Let sidebar titles use trailing slack

* Float sidebar shortcut hints over rows

* Remove unused sidebar width helper

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add Pi agent icon

PR: https://github.com/manaflow-ai/cmux/pull/4057

* Keep Claude Running after clear (#3631)

* Prove Claude clear hook loses running status

The regression exercises the Claude hook handler directly with a SessionStart payload whose source is clear, then sends a late Stop for the previous session. The current handler does not promote the clear boundary to Running or reject stale Stop mutations, so this test is expected to fail before the lifecycle fix.

Constraint: Tests must exercise the hook handler directly rather than driving the full app.

Confidence: high

Scope-risk: narrow

Directive: Keep this regression on the direct CLI hook path; do not replace it with source-text assertions.

Tested: Not run locally per repository policy.

Not-tested: CI red/green proof pending on GitHub Actions.

* Prove Claude clear should own running status

Add hook-level regression coverage for Claude Code /clear. The tests drive the bundled CLI against a mock cmux socket so CI proves SessionStart(source=clear) must set the visible Running status and a prior session Stop must not clobber that fresh lifecycle.

Constraint: Local tests are intentionally not run; CI owns test execution for this task.
Confidence: high
Scope-risk: narrow
Tested: Not run locally per instruction
Not-tested: Full app UI repro under CI

* Ignore stale Claude hook events after clear

Claude /clear starts a fresh hook lifecycle but the sidebar status key is shared at the workspace level. Persist the active Claude session per workspace, promote clear SessionStart to a visible Running state, and ignore teardown or notification mutations from sessions that are no longer current.

Constraint: Claude Code emits /clear as SessionStart(source=clear).
Rejected: Only set Running on clear SessionStart | late Stop from the previous lifecycle could still clobber the new status.
Confidence: high
Scope-risk: narrow
Directive: Future Claude hook status mutations must respect the active workspace session before touching claude_code.
Tested: Not run locally per instruction
Not-tested: Full app UI after CI

* Prove Claude clear hook loses running status

The regression exercises the Claude hook handler directly with a SessionStart payload whose source is clear, then sends a late Stop for the previous session. The current handler does not promote the clear boundary to Running or reject stale Stop mutations, so this test is expected to fail before the lifecycle fix.

Constraint: Tests must exercise the hook handler directly rather than driving the full app.

Confidence: high

Scope-risk: narrow

Directive: Keep this regression on the direct CLI hook path; do not replace it with source-text assertions.

Tested: Not run locally per repository policy.

Not-tested: CI red/green proof pending on GitHub Actions.

* Keep Claude clear sessions authoritative

Claude /clear arrives as a SessionStart source=clear event, but the hook store only remembered routing data. This change makes the store also own the active session for each workspace, promotes clear starts to Running, and ignores visible Stop/Notification/SessionEnd mutations when their session no longer matches the active workspace session.

Constraint: Claude Code documents SessionStart source=clear for /clear lifecycle boundaries.

Rejected: Only set Running on source=clear | old Stop and SessionEnd events could still clobber the new session afterward.

Confidence: high

Scope-risk: narrow

Directive: Visible Claude hook mutations must pass active-session ownership checks before changing sidebar status or notifications.

Tested: Not run locally per repository policy.

Not-tested: CI red/green proof pending on GitHub Actions.

* Allow Claude sessions to advance turns

A visible hook mutation can only be rejected as stale after the active session boundary is known. Keeping a completed turn id active after Stop made the next prompt in the same Claude session look stale before it could promote its own turn.

The Stop path now refreshes the active session with no turn id once the completed turn has been accepted, preserving stale-session protection across /clear while allowing normal multi-turn prompts to re-enter Running. The regression now exercises that two-turn path before the clear boundary.

Constraint: Do not run local tests; CI owns verification for this branch.
Rejected: Ignore turn id in all current-session checks | would weaken stale turn filtering for late Stop and Notification events.
Confidence: high
Scope-risk: narrow
Directive: Do not persist a completed turn id past Stop without proving the next prompt-submit can promote a new turn.
Tested: git diff --check
Not-tested: Local unit/regression tests per project policy

* Remove duplicate Claude clear helper

The branch integration accidentally kept two isClaudeClearSessionStart definitions in CLI/cmux.swift. The duplicate version referenced a non-existent parsedInput.source property, so Swift would reject the file before CI could exercise the hook lifecycle tests.

Keep the existing implementation that reads source from the parsed hook object and delete only the duplicate helper.

Constraint: Fix review-reported compile blocker without changing lifecycle behavior.
Rejected: Add source to ClaudeHookParsedInput | unnecessary for this compile fix and broader than the failing duplicate.
Confidence: high
Scope-risk: narrow
Directive: Keep exactly one Claude clear source helper unless the parsed input model is intentionally extended.
Tested: git diff --check; rg confirms a single isClaudeClearSessionStart definition and no parsedInput.source reference.
Not-tested: Local tests per project policy

* Restore Claude hook compileability after lifecycle merge

The active-session merge left behind the old source-property helper alongside the newer compact-payload helper. Removing the duplicate keeps source=clear detection on the JSON payload and avoids both the redeclaration and missing-property errors.

Constraint: Do not run local tests; CI owns verification for this branch
Rejected: Reintroduce ClaudeHookParsedInput.source | duplicates state already retained in the compact hook payload
Confidence: high
Scope-risk: narrow
Tested: git diff --check; rg verified a single isClaudeClearSessionStart definition and no parsedInput.source references
Not-tested: Local compile/test execution per task policy

* Normalize Claude active-session cleanup keys

The active-session map is keyed by normalized workspace id, so cleanup after consuming a session must use the same normalized key. Otherwise a record containing incidental whitespace could leave a stale active-session entry behind.

Constraint: Address reviewer-reported lifecycle cleanup edge case without changing visible hook behavior.
Rejected: Store raw workspace ids as active map keys | inconsistent with existing upsert normalization and lookup guards.
Confidence: high
Scope-risk: narrow
Directive: Any activeSessionsByWorkspace lookup should use the normalized workspace key, matching insertion.
Tested: git diff --check
Not-tested: Local tests per project policy

* Harden CI Zig downloads against transient upstream failures

CircleCI and the activation workflow both depend on ziglang.org tarballs during remote macOS setup. A transient 500 from that host failed the debug build before any project code compiled, so the install path now retries downloads and avoids unnecessary Homebrew update/cleanup churn on CircleCI.

Constraint: CI must be made green remotely without running local tests or local xcodebuild.

Rejected: Push an empty commit to rerun CI | would leave the same upstream download flake unchanged.

Confidence: high

Scope-risk: narrow

Directive: Keep Zig installer retries in remote CI setup paths; failures here happen before project build logic runs.

Tested: git diff --check

Not-tested: Local tests and local builds not run per repository/user policy.

* Cover stale Claude session-end lifecycle

Greptile identified that stale SessionEnd exercises a different clear-state path than stale Stop. The existing active-session guard already blocks the mutation, so the regression now drives that hook directly and asserts the active /clear session keeps its status, PID, and notifications intact.

Constraint: Do not run local tests; CI is the verification source for this branch.

Rejected: Add another Swift integration test | the existing Python hook harness already executes the CLI handler through the socket path used by CI.

Confidence: high

Scope-risk: narrow

Tested: Not run locally per repo policy.

Not-tested: Local test execution.

* Stop activation CI from stalling on Zig downloads

The activation workflow was cancelled before build because repeated ziglang.org transfers crawled for the full job timeout. Prefer Homebrew's pinned zig@0.15 bottle on macOS runners, then keep the direct tarball path as a bounded fallback with connection, total-time, and minimum-speed limits.

Constraint: The failed check never reached project build or tests; the only failing surface was CI tool bootstrap.

Rejected: Increase the job timeout | it would hide the bootstrap failure and delay feedback.

Confidence: medium

Scope-risk: narrow

Directive: Keep activation workflow tool bootstrap bounded so performance CI reaches the benchmark or fails quickly.

Tested: git diff --check

Not-tested: Local workflow execution, per repository and user instruction.

* Gate Claude session-end cleanup on the consumed workspace

Greptile noted that session-end computed the current-session guard from the fallback workspace while clearing the consumed session's workspace. Move the guard next to the mutation target so stale cleanup and visible cleanup always evaluate the same workspace identity.

Constraint: This is follow-up review hardening on the existing active-session model.

Rejected: Collapse activeSessionsByWorkspace into sessions in this PR | per-workspace current-session lookup is the intended lifecycle boundary for stale event gating.

Confidence: high

Scope-risk: narrow

Directive: SessionEnd visible cleanup must be gated against the workspace being cleared, not an earlier fallback lookup.

Tested: git diff --check

Not-tested: Local test execution, per repository and user instruction.

* Gate Claude session-end cleanup on consumed workspace

A late SessionEnd can be resolved through fallback surface lookup, so the workspace used to find a record is not always the workspace whose visible state would be cleared. Move the staleness check after consume() and evaluate it against the consumed session's workspace, where the clear_status and notification cleanup actually run.

Constraint: Hook events are delivered by short-lived CLI processes and must tolerate stale or partial Claude payloads

Rejected: Keep the pre-consume fallback workspace guard | it can validate one workspace while clearing another

Confidence: high

Scope-risk: narrow

Tested: Added Swift integration regression for stale SessionEnd fallback cleanup

Not-tested: Local tests not run per repository policy

* Make stale Claude session-end test consume the seeded session

Greptile caught that the Swift regression used an unknown session id, so the hook returned before reaching the intended consumed-session visibility guard. Use the seeded stale session id in the SessionEnd payload so the test exercises consume(), then verifies that stale visible cleanup is blocked.

Constraint: Address high-priority review feedback without running local tests.

Rejected: Leave Python-only coverage | the Swift regression would continue passing for the wrong reason.

Confidence: high

Scope-risk: narrow

Directive: Stale session-end regressions should consume a known stale session before asserting visible cleanup is skipped.

Tested: git diff --check

Not-tested: Local tests per repository and user instruction

* Cover fallback Claude session-end consumption

The stale SessionEnd regression should prove the handler consumed the stale session through fallback lookup before deciding whether visible state may be cleared. Use an unknown late session id and assert the seeded stale session is removed from the store, so the test cannot pass without exercising the consumed-workspace guard.

Constraint: Review feedback flagged the prior Swift regression as able to pass without covering the intended guard

Rejected: Use the stored stale session id directly | that only covers the ordinary mapped-session stale path

Confidence: high

Scope-risk: narrow

Tested: Not run locally per repository policy; CI will run the Swift regression

Not-tested: Local XCTest execution

* Keep Claude clear ownership panel-scoped

The clear SessionStart path now owns the active Claude boundary only for explicit clear events, so late startup/resume SessionStart events from the previous session cannot reclaim the workspace before their stale Stop or SessionEnd arrives. The same clear path now passes the resolved surface id into status updates so split panels receive the Running state in the intended pane.

Constraint: Local test execution is disallowed by repository policy; CI remains the behavioral gate.

Rejected: Let every SessionStart mark active | late non-clear events can overwrite the clear boundary.

Rejected: Drop fail-open isCurrent behavior | transient store errors should not hide legitimate current status updates.

Confidence: medium

Scope-risk: moderate

Directive: Do not let non-clear Claude SessionStart events replace an explicit /clear active boundary without adding event ordering metadata.

Tested: python3 -m py_compile tests/test_claude_hook_clear_running_status.py; git diff --check; conflict marker scan.

Not-tested: Local Swift/unit/UI test execution per repo policy.

* Protect Claude clear state from stale session cleanup

Late hook events can arrive after an explicit /clear boundary. The SessionStart handler now skips PID registration when the event is stale against the active session, and SessionEnd consumption preserves the active session when the incoming turn id is older than the stored active turn.

Constraint: Local test execution is disallowed by repository policy; CI remains the behavioral gate.

Rejected: Clear active ownership before checking currentness | same-session stale SessionEnd would fail open and apply cleanup.

Rejected: Keep prefix-only command assertions | option ordering changes would make the regression test brittle.

Confidence: medium

Scope-risk: moderate

Directive: Do not consume a Claude session or replace its PID from a hook event that is stale relative to active session/turn state.

Tested: python3 -m py_compile tests/test_claude_hook_clear_running_status.py; git diff --check; conflict marker scan.

Not-tested: Local Swift/unit/UI test execution per repo policy.

* Allow new Claude sessions to replace stopped owners

A stopped Claude turn must keep the same session eligible for the next turn, but it must not strand the workspace if that process exits before session-end. Mark stopped ownership as replaceable and let only session activation paths use that escape hatch; clear-session ownership remains non-replaceable so stale pre-clear events stay blocked. Session-end fallback cleanup now checks the consumed session id so missing input session ids do not fail open.\n\nConstraint: /clear SessionStart must continue to suppress stale pre-clear startup, stop, and session-end events\nRejected: Clear active ownership on Stop | breaks same-session multi-turn prompt-submit currentness\nConfidence: medium\nScope-risk: narrow\nTested: git diff --check; conflict-marker scan\nNot-tested: local XCTest per repo policy; CI will run cmux unit regressions

* test: cover codex hooks TOML features section

* fix: harden hook config and auth token cache

* test: cover sign-out browser auth loading cleanup

* fix: cancel browser auth on sign-out

* test: cover codex config read failures

* fix: fail closed on codex config read errors

* test: cover auth sign-out callback race

* fix: discard auth callback after sign-out

* fix: keep claude subcommands out of hook injection

* fix: dismiss stale sparkle update replies

* fix: redact auth logs while preserving observability

* fix: reset update checks and guard sign-out races

* fix: preserve update metadata from driver state

* fix: await auth token assertions before comparing

* fix: address wrapper and auth review feedback

* fix: address session and config review feedback

* ci: retrigger pending checks

* fix: clear stale ime and auth token state

* fix: clean legacy codex hooks config

* test: cover legacy codex hooks markers

* fix: clean empty codex features table

* fix: preserve browser key reentry dispatch

* Fix new-workspace caller window routing (#4042)

* test: cover new workspace caller routing

* fix: route new workspace to caller context

* Add iMessage workspace insertion regression test

* Reset Kitty keyboard mode at shell prompt boundaries (#3870)

* Prove stale Kitty keyboard state leaks CSI-u key bytes

The regression exercises a hosted Ghostty terminal, leaves Kitty keyboard protocol enabled as a crashed TUI would, mirrors the clear-history socket handler clear_screen path, and captures raw PTY stdin bytes for a plain c key. Current behavior should encode CSI-u instead of a single ASCII byte, making the test fail until the protocol state is reset at the shell prompt boundary.

Constraint: Regression must cover PTY input bytes, not source text shape
Confidence: high
Scope-risk: narrow
Directive: Keep this test on the real ghostty_surface_key path; sendText alone bypasses the keyboard encoder
Tested: Manual current-main repro captured c9;1:3uc9;1:3uc9;1:3u after Kitty enable plus clear-history
Not-tested: Local unit execution deferred to CI per requested red/green workflow

* Reset stale Kitty keyboard mode at prompt boundaries

A crashed TUI can leave Ghostty's Kitty keyboard protocol stack pushed after clear-history, causing normal shell input to be encoded as CSI-u. Resetting the stack from the shell prompt hook makes the prompt boundary the ownership point for returning interactive shells to plain byte input.

Constraint: Fix must run through shell integration because Ghostty keeps protocol state inside the terminal surface

Rejected: Reset only in clear-history socket path | stale state also leaks after any crashed TUI returns to prompt

Confidence: high

Scope-risk: narrow

Directive: Keep prompt-boundary reset paired across bash and zsh integrations

Tested: Not run locally per repository testing policy; regression added in prior commit

Not-tested: CI not yet completed

* Clarify Kitty reset fixture failures

The stale keyboard regression now fails at the fixture boundary if the zsh integration does not emit the expected reset bytes, instead of falling through to a misleading PTY byte mismatch.

Constraint: Repository policy forbids local test execution for this PR loop

Confidence: high

Scope-risk: narrow

Tested: Not run locally per repository policy; CI will run the affected XCTest

Not-tested: Local XCTest execution

* chore: retrigger Vercel checks

* Add Kitty reset shell hook coverage

* Reset all terminal keyboard protocols at prompt

* Fix terminal keyboard reset test expectations

* Clarify disabling agent session auto-resume for #3640 (#3991)

* docs: explain disabling agent auto resume

* docs: name auto resume config path

* Fix stale restored agent resume state

* Harden restored agent hook liveness

* refactor: share restored agent normalization

* Honor iMessage workspace ordering and previews

* Add workspace cwd inheritance setting (#3921)

* feat: add workspace cwd inheritance setting

* fix: align workspace cwd setting key naming

* fix: apply workspace cwd setting to detached creation

* fix: expose workspace cwd inheritance setting

* fix: route pane break through detached workspace creation

* fix: keep pane break response pane ids non-null

* fix: distinguish pane break resolution errors

* Approve installed Codex hooks (#4035)

* Approve installed Codex hooks

* Address Codex hook trust review feedback

* Avoid tomllib in Codex hook tests

* Align Codex hook trust test mirror

* Harden Codex hook trust ownership

* Preserve legacy Codex hook cleanup

* Fix workspace unit test after merge

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Revert "Approve installed Codex hooks (#4035)" (#4074)

This reverts commit e4546b7675a4ffa5a41a5429218b60f4e7644e21.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Fix workspace unit test transfer resume state (#4076)

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Clarify in cmux --help that reload-config covers Ghostty config too (#4060)

* Clarify cmux help that reload-config covers Ghostty config too

`cmux reload-config` reloads BOTH ~/.config/cmux/cmux.json and Ghostty
config (~/.config/ghostty/config) and refreshes terminals in place, but
the help/docs only mentioned cmux.json. Agents (and humans) reading the
help would think they had to restart cmux after editing Ghostty config.

- cmux --help "Agent Help" now tells agents where Ghostty config lives
  and that reload-config picks it up live.
- cmux docs settings, cmux settings path, cmux config --help now list
  ~/.config/ghostty/config as a related (not cmux-owned) location and
  describe reload-config's actual scope.
- cmux schema sidebarAppearance.tintOpacity description now notes it's
  sidebar-only, and points to Ghostty background-opacity / blur for
  terminal transparency.
- skills/cmux/SKILL.md mirrors the wording.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Align ghostty_config JSON shape across CLI surfaces

Cursor Bugbot and Greptile both flagged that `cmux settings path --json`
emitted `ghostty_config` as a string while `cmux docs settings --json`
emitted it as an object {path, note}. An agent reading both outputs with
the same key expectation would have to special-case the type.

Standardize on the object shape with `path` and `note` in both, matching
docsPayload. This is the agent-discoverability path the PR is trying to
make reliable, so making the shape consistent is on-purpose.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Use canonical Ghostty config key background-blur (not background-blur-radius)

CodeRabbit flagged that `background-blur-radius` is outdated. Verified
against the Ghostty submodule at ghostty/src/config/Config.zig: line 70
declares `background-blur-radius` as a compatibilityRenamed alias for
`background-blur`. The current canonical key is `background-blur` and it
accepts the same integer value (e.g. `background-blur = 20`).

Update the two docs that introduced the alias name:
- skills/cmux/SKILL.md
- web/data/cmux.schema.json (sidebarAppearance.tintOpacity description)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Add nucleo FFI command palette benchmark

* Open right sidebar tools as panes (#4065)

* Open right sidebar tools as panes

* Remove unreachable sidebar pane commands

* Fix sidebar pane unit test build

* Address sidebar pane review feedback

* Fix vault pane focus tracking

* Address right sidebar pane review followups

* Use modern sidebar pane flash observer

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Save crash diagnostics under cmux state (#4077)

* Save crash diagnostics under cmux state

* fix: key GhosttyKit artifacts by crash path

* fix: pin cmux crash GhosttyKit archive

* fix: mark crash breadcrumb scan concurrent

* fix: keep crash scan compatible with Xcode 16

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Menubar global search P1 (#3908)

* Ship local global search as a remappable menubar flow

Phase 1 needs browser and markdown value without terminal scrollback, so the index owns durable FTS5 upserts while AppDelegate keeps one navigation path from palette rows to focused panels. The global shortcut is wired through the existing shortcut settings instead of a standalone Carbon shim so Settings and cmux.json remain authoritative.

Constraint: Phase 1 excludes Ghostty terminal scrollback capture

Constraint: User required no local test execution and no reload before CI is green

Rejected: Hardcoded GlobalSearchHotkey shim | violates KeyboardShortcutSettings policy

Confidence: medium

Scope-risk: broad

Directive: Keep future terminal capture feeding SearchIndex documents through GlobalSearchCoordinator rather than adding another palette/navigation path

Tested: git diff --check; python3 -m json.tool Resources/Localizable.xcstrings; python3 -m json.tool web/data/cmux.schema.json; plutil -lint GhosttyTabs.xcodeproj/project.pbxproj

Not-tested: Local unit/UI tests and tagged app launch per task constraints

* Remove duplicate search refresh work

Cursor review pointed out that the menubar toggle and palette onAppear both refreshed the live index. Keeping the refresh in the palette lifecycle avoids resetting browser debounce tasks while still indexing each time the palette opens, and removing the unused workspace delete API keeps the storage surface honest.

Constraint: Review feedback came from PR #3908 after the first CI pass started

Rejected: Keep both refresh calls | causes avoidable debounce cancellation and slower browser result availability

Confidence: high

Scope-risk: narrow

Directive: Add workspace-level deletion only when a real workspace teardown caller is wired

Tested: git diff --check; python3 -m json.tool Resources/Localizable.xcstrings; python3 -m json.tool web/data/cmux.schema.json; plutil -lint GhosttyTabs.xcodeproj/project.pbxproj

Not-tested: Local tests/build per task constraints

* Fix global search stale index entries

* Address global search review feedback

* Fix search query token mapping compile error

* Fix global search CI failures

* Fix stale unavailable markdown search entries

* Cancel stale markdown search captures

* Cancel global search refresh on dismiss

* Fix global search review followups

* Address global search post-CI feedback

* Preserve markdown panel title search on read failure

* Address global search lifecycle feedback

* Address global search review lifecycle feedback

* Refine global search capture ownership

* fix: address global search review blockers

* feat: show open panels in global search

* fix: cover right sidebar tool panel in search

* Fix cmuxTests: rename restorableAgentAutoResumePending to restorableAgentResumeState (#4068)

* fix: handle repeated assistant imessage completions

* Open supported files in cmux on cmd-click (#4041)

* Open supported files in cmux on cmd-click

* Add cmd-click file preview verification script

* Reuse right pane for cmd-click file previews

* Keep cmd-click UI test terminal after preview focus

* Accept numeric cmd-click test payload values

* Capture cmd-click UI test window snapshots

* Add file-type-aware external open actions

* Address supported file routing review feedback

* Fix external open menu sendability warnings

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Suppress native proxy icon on cmux main windows (#3973)

* Add proxy icon regression test

* Suppress native proxy icon on cmux windows

* chore: retrigger preview deployments

* Refine native proxy icon suppression

* fix: keep titlebar folder icon aligned

* fix: restore titlebar folder icon leading offset

* test: cover folder icon frame replacement

* fix: resync folder icon on frame replacement

* test: cover folder icon ancestor movement

* fix: track folder icon ancestor movement

* fix: address folder icon review feedback

* test: stabilize folder icon ancestor sync

* fix: handle sidebar tool panels in global search

---------

Co-authored-by: austinpower1258 <austinwang115@gmail.com>

* Close browser panels when pages request window close (#4070)

* Add browser self-close restore regression test

* Close browser panels from WebKit close callbacks

* fix: index right sidebar tool panels as titles

* fix: keep web close callback synchronous

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add notification policy hooks

Merged https://github.com/manaflow-ai/cmux/pull/4054

* Fix sidebar unread badge after re-marking notifications (#4084)

* Add sidebar unread notification regression test

* Keep sidebar notification badge live during menu freeze

* Cover sidebar presentation fallback cases

* Limit Cloud VMs by active provider state (#4046)

* test: cover active vm limit with paused freestyle vms

* fix: enforce cloud vm limits by active state

* fix: parallelize cloud vm status refresh

* chore: update web security dependencies

* fix: handle right sidebar tools in global search

* fix: guard cloud vm status refresh races

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Fix Settings search synonyms (#4082)

* Add settings search synonym regressions

* Fix settings search synonyms

* Add shortcut bindings anchor regression

* Cover clickable PR settings search alias

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add tagged debug CLI helper (#4092)

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add unread defer shortcut (#4086)

* Add unread defer shortcut

* fix: address unread defer feedback

* fix: keep manual unread jump explicit

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Document notification hooks default off

Document that notification hooks are off by default and style the config key in localized docs.

* Approve installed Codex hooks after dogfood (#4075)

* Reapply Codex hook approval changes for dogfood

* Notify on Codex plan input requests

* Handle Codex plan question transcript items

* Address Codex hook review feedback

* Recover malformed Codex hook trust blocks

* Avoid duplicate consecutive cmux hook reinserts

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Document session restore behavior

Adds session restore docs, blog, README updates, and review cleanup.

* Use nucleo for command palette search

* Skip unrestorable Claude startup sessions

PR: https://github.com/manaflow-ai/cmux/pull/4079

* Revert "Suppress native proxy icon on cmux main windows" (#4099)

* Revert "Suppress native proxy icon on cmux main windows (#3973)"

This reverts commit 5048440ff44b4edbe328b65403724ff79476b2e6.

* Fix titlebar proxy icon without detached panel sync

* Apply proxy icon override to fallback config

* Restore key regain redraw invariant

* Tune nucleo palette initialism ranking

* Fix terminal portal resize lag (#4102)

* Fix Korean 2-Set terminal arrows (#4095)

* Add Korean 2-Set arrow IME regression

* Restore Korean 2-Set arrow forwarding

* Restore Zhuyin IME command routing

* Address IME review feedback

* Fix Korean IME regression test compile

* Address IME review follow-ups

* Address Bopomofo preedit review feedback

* Avoid idle Zhuyin key suppression

* Remove dead text input wrapper

* Address IME suppression review feedback

* Fix palette stitched highlight precedence

* Add Codex Teams subagent panes

* Open markdown files in preview panels from cmux open (#4085)

* fix: open markdown files in preview panels

* fix: preserve markdown viewer transparency

* fix: mute markdown open-with header button

* fix: align markdown header controls

* fix: align file header controls

* fix: address markdown review feedback

* test: cover opaque text editor alpha

* fix: align header open fallback

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add task manager sorting and program aggregates (#4066)

* Add task manager sorting and program aggregates

* Add sorting to cmux top output

* Add flat TSV cmux top output

* Add coding agent task manager totals

* Make task manager program totals payload-backed

* Recognize agent launcher process names in task manager

* Fix task manager test build helpers

* Recognize Claude versioned launcher processes

* Show loading state before task manager sample

* Recognize versioned agent process names

* Use agent totals for task manager hierarchy icons

* fix: address task manager review feedback

* fix: address follow-up task manager review

* fix: address final task manager review

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Keep manual unread sticky until terminal interaction (#4104)

* test: cover sticky manual unread state

* fix: keep manual unread sticky until terminal input

* fix: show workspace manual unread pane ring

* fix: sync manual unread badge on focus changes

* fix: stabilize manual unread representative fallback

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: austinpower1258 <austinwang115@gmail.com>

* Bump version to 0.64.5 (#4107)

* Fix Pi Vault icon and JSONL titles (#4120)

* test: cover Pi JSONL content block titles

* fix: parse Pi JSONL text blocks for Vault titles

* fix: align Pi JSONL title role handling

* fix: require typed text blocks for Pi titles

* Improve Cloud VM error guidance (#4094)

* Improve Cloud VM error guidance

* Address final Cloud VM review feedback

* Narrow Cloud VM sanitizer env var block

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Keep selected workspace visible after sidebar reorders

* Add sidebar scroll regression for workspace move to top

* Reveal selected workspace after sidebar reorders

* Handle right sidebar tool panels in global search

* Test workspace move to top visibility only

* Refine sidebar reorder scroll trigger

* Add move-to-top notification regression

* Skip no-op move-to-top notifications

* Assert no-op move-to-top keeps order

* Require matching manager for reorder scroll

* Scroll selected workspace on index shifts

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Use transparent backgrounds for file preview panels (#4088)

* Handle right sidebar tools in global search browse hits

* Use transparent backgrounds for file preview panels

* Cover panel theme background preservation

* Fix PDF file preview open menu

* Make file open menu button compact

* Fix PDF open menu chrome button

* Fix PDF open-with chrome click target

* Address file preview chrome review feedback

* Fix PDF background cache invalidation

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Inherit stdin in backgrounded ssh inside startup wrapper (#4135)

* Add regression test for SSH startup wrapper dropping stdin

After PR #3786 backgrounded the ssh invocation inside the startup
wrapper for signal/reconnect handling, `cmux ssh <host>` sessions
stopped forwarding keystrokes from the surface PTY to the remote
shell. Output flowed back (the remote prompt rendered in cmux UI),
but anything typed never reached zsh on the other side, which sat
blocked in `do_poll` on the remote pts.

Root cause: POSIX sh redirects stdin of an async command (`&`) to
/dev/null when job control is off — the default for the `/bin/sh -c …`
that runs the startup wrapper. Without an explicit `<&0` on the
`&`'d ssh line, the local PTY stdin is silently dropped.

This commit adds the failing regression test. The fix follows in
the next commit so CI can prove the test catches the bug.

* Inherit stdin in backgrounded ssh inside startup wrapper

PR #3786 wrapped the ssh invocation in `while :; do … & wait` to enable
SIGHUP/INT/TERM trap handling and reconnect-on-exit-255. Backgrounding
ssh, however, drops its stdin: POSIX sh redirects fd 0 of any async
command to /dev/null when job control is off, which is the default for
the `/bin/sh -c …` host that runs this wrapper.

As a result, output from the remote still flowed back to the surface
PTY (ssh's stdout/stderr stayed wired) but the user's keystrokes never
reached the remote — they hit ttysNNN on the Mac side, kernel echoed
them locally, but ssh's stdin was /dev/null so nothing was forwarded.
zsh on the far side sat in `do_poll` forever.

Explicit `<&0` on both the `command` line and the `( … )` shell-snippet
form overrides the POSIX default and re-attaches the wrapper's own
stdin to the backgrounded ssh process.

Verified with the regression test added in the previous commit, plus
manual repro on Darwin:

    /bin/sh -c 'cat &  wait'           # cat's fd 0 → /dev/null (bug)
    /bin/sh -c 'cat <&0 &  wait'       # cat's fd 0 → parent stdin (fix)

* Add docs search

Adds localized Pagefind docs search with heading anchors and section-aware results.

* Fix Swift interpolation escape in SSH stdin regression test (#4154)

`testSSHStartupForwardsStdinToBackgroundedSSH` used `\"<empty>\"` inside a
`\(...)` string interpolation. Swift parses `\"` as the end of the outer
literal, breaking compilation of cmuxTests on main:

    Cannot find ')' to match opening '(' in string interpolation
    Unterminated string literal

That kept `ci/circleci: macos-unit-tests` red on main after #4135 even
though `macos-debug-build` and `macos-release-build` still passed (the
test target was the only thing affected). The runtime fix (`<&0` on the
backgrounded ssh) is unchanged and was verified end-to-end on a cloud Mac.

Inside an interpolation, the string is already a Swift expression and
literal quotes are unescaped; drop the four backslashes.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Add command palette settings toggles

Adds command palette toggles for boolean Settings rows, including iMessage Mode.

* Ensure Rust toolchain is installed for nucleo FFI builds

* Document nucleo FFI thread and ABI assumptions

* Reuse nucleo index in preview search test helper

* Install Rust for activation perf builds

---------

Co-authored-by: Tobi Lutke <tobi@shopify.com>
Co-authored-by: Austin Wang <austinwang115@gmail.com>
Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Kevin Peng <48529172+kays0x@users.noreply.github.com>
lawrencecchen added a commit that referenced this pull request May 15, 2026
* Optimize command palette search

* Reduce command palette typing frame work

* Fix command palette result rendering

* Ignore stale command palette row snapshots

* Use command ids for palette row identity

* Match Zed-style palette result limiting

* Reduce palette preview search frame misses

* Use nucleo for command palette search (#4078)

* feat: improve markdown viewer

* fix: address markdown review feedback

* fix: clean up markdown review issues

* fix: address markdown review feedback

* fix: address latest markdown review

* Fix #3807: bring notification CLI to panel parity (#3811)

* Prove notification CLI parity is missing

Add behavior-level coverage for the missing notification socket and CLI actions before implementing them. The tests drive V2 notification action methods, CLI subcommands, extended list fields, and the UI open-notification flow so CI can show the pre-fix gap.

Constraint: Regression tests must be committed before the implementation for issue #3807

Constraint: Local Swift tests are not run in this repo; verification is through CI

Confidence: high

Scope-risk: narrow

Tested: git diff --check

Not-tested: Swift/XCUITest execution; intentionally deferred to CI

* Make notification actions scriptable from the CLI

The notifications panel already owned the behavior for dismissing, marking read, opening, and jumping to unread rows. This wires the socket and CLI to those existing store/AppDelegate paths, extends list output with panel metadata, and documents the new command surface without introducing a second notification action model.

Constraint: Existing Notifications page behavior must remain the source of truth

Constraint: Direct xcodebuild and local Swift/XCUITest runs are forbidden in this workspace

Rejected: Duplicate CLI-side focus or read-state logic | would diverge from AppDelegate.openNotification and TerminalNotificationStore semantics

Confidence: medium

Scope-risk: moderate

Tested: git diff --check

Tested: jq empty Resources/Localizable.xcstrings

Tested: python3 -m json.tool Resources/Localizable.xcstrings

Not-tested: Swift unit/UI execution; deferred to CI per repo policy

* Make notification CI compile under strict concurrency

The notification parity implementation introduced a shared formatter on a main-actor type and a test helper that crossed actor boundaries through escaping closures. This keeps the socket behavior unchanged while making date formatting local to the main-actor call path and keeping the XCTest socket request helper from capturing actor-isolated state in the background request closure.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace

Rejected: Run xcodebuild locally to confirm | user explicitly warned direct xcodebuild can deadlock the machine

Confidence: medium

Scope-risk: narrow

Tested: git diff --check

Tested: jq empty Resources/Localizable.xcstrings

Not-tested: Swift compilation and XCTest execution; deferred to CI

* Make notification parity actions atomic and exact

Review feedback exposed two behavior risks in the notification parity path: bulk dismissal was implemented as client-side list-and-loop work, and jump-to-unread could report one unread notification while opening a later valid one. The server now owns already-read dismissal as a single V2 action, the jump helper returns the notification it actually opened, and event/list parsing details match those server semantics.

Constraint: Notification action logic must reuse the existing store and AppDelegate paths

Rejected: Split TerminalController into new controllers in this PR | broad refactor is unrelated to issue #3807 and would obscure the parity fix

Confidence: medium

Scope-risk: moderate

Tested: git diff --check

Tested: jq empty Resources/Localizable.xcstrings

Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace instructions

* Expose app test symbols to CLI notification coverage

The integration regression exercises real app-backed notification state through the CLI harness, so the test target must import the built app module the same way the socket action tests do.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace
Rejected: Verify with xcodebuild locally | user explicitly forbids direct xcodebuild
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI

* Make notification list and dismiss payloads stable

Review caught two small contract hazards in the new notification RPC surface: the dismiss result used mixed JSON types, and a pipe in the appended tab title could shift the legacy list parser. The server now reports dismissals as counts consistently and escapes only the new trailing list field, with the CLI decoding it after structural parsing.

Constraint: The V1 list response remains pipe-delimited for backward compatibility, so only newly appended trailing fields can be encoded without changing old parser behavior
Rejected: Replace list_notifications with JSON-only output | existing V1 parsers depend on the line format
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace policy

* Return async notification socket responses from tests

CircleCI caught a compile-only issue in the async V2 test helper: the continuation result was awaited but not returned from the method that promises a response dictionary. Returning the continuation value restores the helper contract without changing the exercised socket behavior.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace
Rejected: Verify with local xcodebuild | user explicitly forbids direct xcodebuild
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI

* Avoid blocking notification CLI integration sockets

The integration regression has to create AppKit-backed notification state on the main actor, but running the CLI subprocess synchronously there can block the socket handler's main-actor store mutations. The test now awaits subprocess work on a background queue and verifies read state through the same CLI list path.

Constraint: Socket notification handlers intentionally hop to the main actor for store and AppDelegate work
Rejected: Run the CLI synchronously from the main actor | it can deadlock the in-process socket server during tests
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace policy

* Harden notification CLI response contracts

The notification parity path now distinguishes new list-notification trailer fields from old pipe-heavy bodies, rejects surface-only mark-read selectors, and returns post-open read state by marking through the shared store path after a successful focus action.

Constraint: list_notifications remains a legacy pipe-delimited protocol, so the new trailer needs its own discriminator while older body parsing keeps joining payload[6...]
Rejected: Add a third list_notifications sentinel field | the issue asked for exactly the two appended fields
Rejected: Rely on AppDelegate delayed mark-read for socket JSON | CLI callers need the open response and subsequent list output to reflect the explicit action
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI per workspace policy

* Make CLI integration helper capture explicit self

CircleCI's Swift compile step requires explicit self when the background subprocess closure calls the test helper method. This keeps the deadlock fix intact while satisfying Swift capture rules.

Constraint: Local Swift tests and direct xcodebuild are explicitly forbidden in this workspace
Rejected: Verify with local xcodebuild | user explicitly forbids direct xcodebuild
Confidence: high
Scope-risk: narrow
Tested: git diff --check
Tested: jq empty Resources/Localizable.xcstrings
Not-tested: Swift compilation and XCTest execution; deferred to CI

* Make CLI presentation flags order-independent

Users naturally put presentation flags next to the command they are inspecting. Normalize --json and --id-format after command selection so docs examples such as cmux list-notifications --json produce JSON while still preserving literal flag-looking values for command options.

Constraint: Do not run reload.sh before CI is green; never run bare xcodebuild.

Rejected: Documentation-only correction | leaves copy-pasted command behavior surprising.

Rejected: Notification-only --json handling | repeats the same parser split for future JSON-capable commands.

Confidence: medium

Scope-risk: moderate

Directive: Keep presentation flag parsing centralized; update commandOptionsWithValues when adding value-taking command options.

Tested: git diff --check

Not-tested: Local XCTest/build per repo policy; CI will verify.

* Fix notification surface selector error message

* Make notification open mark read synchronously

* Fix CLI presentation flag parsing

* Test notification mark-read missing id

* Reject missing notification mark-read ids

* fix: polish markdown viewer dogfood

* Fix shared WebView task manager attribution

Fixes shared WebContent resource attribution in task manager rows and adds regression coverage.

* Prevent display-link crash from terminal portal layout reentry (#3885)

* Pin portal sync deferral during SwiftUI host callbacks

The silent-exit crash path points at SwiftUI/AppKit layout recursion reaching a CATransaction display-link flush. This test locks the intended invariant: geometry callbacks originating from the SwiftUI NSViewRepresentable host must defer portal reconciliation instead of forcing immediate AppKit layout, even while an interactive resize is active.

Constraint: Local tests are intentionally not run in this repository; CI owns regression proof.\nRejected: Assert on source text or unified-log contents | timing-dependent and not executable through the policy seam.\nConfidence: medium\nScope-risk: narrow\nDirective: Keep immediate portal flushing owned by external AppKit resize observers, not SwiftUI host callbacks.\nTested: Not run locally per repository policy and user instruction.\nNot-tested: Full multi-session crash reproduction is timing-dependent and not deterministic.

* Prevent portal layout reentry from terminal host callbacks

The terminal NSViewRepresentable host was allowed to bind into the window portal and synchronously flush AppKit layout from update/layout callbacks. That made SwiftUI's own host layout and the external terminal portal both believe they could drive geometry in the same render turn, matching the NSHostingView reentrant-layout warnings reported before the CATransaction display-link abort.\n\nThe portal now treats SwiftUI host callbacks as state capture only: they register the binding and schedule the portal owner to reconcile geometry after the current render turn. Immediate geometry flushing remains available to the portal's external AppKit resize observers, which are outside SwiftUI body/layout evaluation. The launch path also records clean exits and posts a one-time TerminalNotificationStore breadcrumb when a newer ghostty Breakpad envelope is found after an unclean exit.

Constraint: Local tests and app builds are not run before CI for this branch; verification is delegated to CI, then the required tagged reload.\nRejected: Wrap the CATransaction/display-link exception in @try/@catch | it would hide AppKit's abort symptom without removing the reentrant layout owner split.\nRejected: Keep immediate sync during interactive SwiftUI host callbacks | still allows layoutSubtreeIfNeeded inside the representable layout/update path.\nConfidence: medium\nScope-risk: moderate\nDirective: SwiftUI/AppKit host callbacks must not force terminal portal layout synchronously; add external observer paths for any future immediate resize flushing.\nTested: git diff --check; jq empty Resources/Localizable.xcstrings\nNot-tested: Local XCTest/build/repro per repository and user instructions; 75-minute multi-session crash reproduction is not deterministic.

* Record clean-exit breadcrumb after teardown

The crash breadcrumb should compare Breakpad envelopes against the last successfully completed termination path. Recording the timestamp after teardown avoids marking an exit clean before session persistence, process cleanup, and notification cleanup have finished.

Constraint: This is a follow-up correctness tweak before CI settled.\nRejected: Keep the timestamp at the start of applicationWillTerminate | a crash during termination cleanup could suppress the next-launch breadcrumb.\nConfidence: high\nScope-risk: narrow\nDirective: Only update the clean-exit timestamp after teardown work that must complete for a clean quit.\nTested: git diff --check; jq empty Resources/Localizable.xcstrings\nNot-tested: Local tests/builds per repository and user instructions.

* Defer first portal install from SwiftUI callbacks

A deferred SwiftUI host bind could still create the WindowTerminalPortal for the first time, and the initializer previously installed the host with an immediate layout flush. Threading the same deferral flag through portal creation keeps the invariant complete: representable update/layout callbacks never synchronously flush terminal portal layout, even on first bind.

Constraint: Must preserve immediate install behavior for non-SwiftUI external portal callers
Rejected: Assume portals already exist before host callbacks | first terminal bind in a new window can create one
Confidence: high
Scope-risk: narrow
Directive: Any future portal creation path from SwiftUI callbacks must carry deferred synchronization through initialization
Tested: git diff --check; jq empty Resources/Localizable.xcstrings
Not-tested: Local tests/builds per repository and user instructions

* Move crash breadcrumb work out of launch hot path

The crash breadcrumb scanner is pure Foundation logic, so it now lives in its own source file and performs the crash-directory scan from a detached utility task. App launch only schedules the check once, then posts the existing localized notification after the background scan returns to the main actor. The terminal host geometry policy is also simplified to make the always-deferred invariant explicit at the call site.

Constraint: Local build/tests are intentionally skipped until CI completes per issue instructions
Rejected: Keep synchronous directory enumeration in AppDelegate.configure | startup should not block on crash artifact I/O
Rejected: Preserve the dead immediate portal sync branch | host callbacks are never allowed to force layout synchronously
Confidence: high
Scope-risk: narrow
Directive: Do not reintroduce synchronous crash-directory scans or immediate portal layout flushes from SwiftUI host callbacks
Tested: git diff --check; jq empty Resources/Localizable.xcstrings; plutil -lint GhosttyTabs.xcodeproj/project.pbxproj
Not-tested: Local build/tests per repository and user instructions

* Tighten portal geometry regression seam

* Fix crash breadcrumb actor isolation

* Mark crash breadcrumb async helper nonisolated

* Make crash breadcrumb scan concurrent

* fix: remove inert crash breadcrumb cooldown key

* fix: use renamed crash breadcrumb annotation

* fix: own crash breadcrumb scan task

* Hide sidebar descriptions in title-only mode (#4040)

* Hide sidebar descriptions in title-only mode

* Add sidebar description visibility toggle

* Let sidebar titles use trailing slack

* Float sidebar shortcut hints over rows

* Remove unused sidebar width helper

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add Pi agent icon

PR: https://github.com/manaflow-ai/cmux/pull/4057

* Keep Claude Running after clear (#3631)

* Prove Claude clear hook loses running status

The regression exercises the Claude hook handler directly with a SessionStart payload whose source is clear, then sends a late Stop for the previous session. The current handler does not promote the clear boundary to Running or reject stale Stop mutations, so this test is expected to fail before the lifecycle fix.

Constraint: Tests must exercise the hook handler directly rather than driving the full app.

Confidence: high

Scope-risk: narrow

Directive: Keep this regression on the direct CLI hook path; do not replace it with source-text assertions.

Tested: Not run locally per repository policy.

Not-tested: CI red/green proof pending on GitHub Actions.

* Prove Claude clear should own running status

Add hook-level regression coverage for Claude Code /clear. The tests drive the bundled CLI against a mock cmux socket so CI proves SessionStart(source=clear) must set the visible Running status and a prior session Stop must not clobber that fresh lifecycle.

Constraint: Local tests are intentionally not run; CI owns test execution for this task.
Confidence: high
Scope-risk: narrow
Tested: Not run locally per instruction
Not-tested: Full app UI repro under CI

* Ignore stale Claude hook events after clear

Claude /clear starts a fresh hook lifecycle but the sidebar status key is shared at the workspace level. Persist the active Claude session per workspace, promote clear SessionStart to a visible Running state, and ignore teardown or notification mutations from sessions that are no longer current.

Constraint: Claude Code emits /clear as SessionStart(source=clear).
Rejected: Only set Running on clear SessionStart | late Stop from the previous lifecycle could still clobber the new status.
Confidence: high
Scope-risk: narrow
Directive: Future Claude hook status mutations must respect the active workspace session before touching claude_code.
Tested: Not run locally per instruction
Not-tested: Full app UI after CI

* Prove Claude clear hook loses running status

The regression exercises the Claude hook handler directly with a SessionStart payload whose source is clear, then sends a late Stop for the previous session. The current handler does not promote the clear boundary to Running or reject stale Stop mutations, so this test is expected to fail before the lifecycle fix.

Constraint: Tests must exercise the hook handler directly rather than driving the full app.

Confidence: high

Scope-risk: narrow

Directive: Keep this regression on the direct CLI hook path; do not replace it with source-text assertions.

Tested: Not run locally per repository policy.

Not-tested: CI red/green proof pending on GitHub Actions.

* Keep Claude clear sessions authoritative

Claude /clear arrives as a SessionStart source=clear event, but the hook store only remembered routing data. This change makes the store also own the active session for each workspace, promotes clear starts to Running, and ignores visible Stop/Notification/SessionEnd mutations when their session no longer matches the active workspace session.

Constraint: Claude Code documents SessionStart source=clear for /clear lifecycle boundaries.

Rejected: Only set Running on source=clear | old Stop and SessionEnd events could still clobber the new session afterward.

Confidence: high

Scope-risk: narrow

Directive: Visible Claude hook mutations must pass active-session ownership checks before changing sidebar status or notifications.

Tested: Not run locally per repository policy.

Not-tested: CI red/green proof pending on GitHub Actions.

* Allow Claude sessions to advance turns

A visible hook mutation can only be rejected as stale after the active session boundary is known. Keeping a completed turn id active after Stop made the next prompt in the same Claude session look stale before it could promote its own turn.

The Stop path now refreshes the active session with no turn id once the completed turn has been accepted, preserving stale-session protection across /clear while allowing normal multi-turn prompts to re-enter Running. The regression now exercises that two-turn path before the clear boundary.

Constraint: Do not run local tests; CI owns verification for this branch.
Rejected: Ignore turn id in all current-session checks | would weaken stale turn filtering for late Stop and Notification events.
Confidence: high
Scope-risk: narrow
Directive: Do not persist a completed turn id past Stop without proving the next prompt-submit can promote a new turn.
Tested: git diff --check
Not-tested: Local unit/regression tests per project policy

* Remove duplicate Claude clear helper

The branch integration accidentally kept two isClaudeClearSessionStart definitions in CLI/cmux.swift. The duplicate version referenced a non-existent parsedInput.source property, so Swift would reject the file before CI could exercise the hook lifecycle tests.

Keep the existing implementation that reads source from the parsed hook object and delete only the duplicate helper.

Constraint: Fix review-reported compile blocker without changing lifecycle behavior.
Rejected: Add source to ClaudeHookParsedInput | unnecessary for this compile fix and broader than the failing duplicate.
Confidence: high
Scope-risk: narrow
Directive: Keep exactly one Claude clear source helper unless the parsed input model is intentionally extended.
Tested: git diff --check; rg confirms a single isClaudeClearSessionStart definition and no parsedInput.source reference.
Not-tested: Local tests per project policy

* Restore Claude hook compileability after lifecycle merge

The active-session merge left behind the old source-property helper alongside the newer compact-payload helper. Removing the duplicate keeps source=clear detection on the JSON payload and avoids both the redeclaration and missing-property errors.

Constraint: Do not run local tests; CI owns verification for this branch
Rejected: Reintroduce ClaudeHookParsedInput.source | duplicates state already retained in the compact hook payload
Confidence: high
Scope-risk: narrow
Tested: git diff --check; rg verified a single isClaudeClearSessionStart definition and no parsedInput.source references
Not-tested: Local compile/test execution per task policy

* Normalize Claude active-session cleanup keys

The active-session map is keyed by normalized workspace id, so cleanup after consuming a session must use the same normalized key. Otherwise a record containing incidental whitespace could leave a stale active-session entry behind.

Constraint: Address reviewer-reported lifecycle cleanup edge case without changing visible hook behavior.
Rejected: Store raw workspace ids as active map keys | inconsistent with existing upsert normalization and lookup guards.
Confidence: high
Scope-risk: narrow
Directive: Any activeSessionsByWorkspace lookup should use the normalized workspace key, matching insertion.
Tested: git diff --check
Not-tested: Local tests per project policy

* Harden CI Zig downloads against transient upstream failures

CircleCI and the activation workflow both depend on ziglang.org tarballs during remote macOS setup. A transient 500 from that host failed the debug build before any project code compiled, so the install path now retries downloads and avoids unnecessary Homebrew update/cleanup churn on CircleCI.

Constraint: CI must be made green remotely without running local tests or local xcodebuild.

Rejected: Push an empty commit to rerun CI | would leave the same upstream download flake unchanged.

Confidence: high

Scope-risk: narrow

Directive: Keep Zig installer retries in remote CI setup paths; failures here happen before project build logic runs.

Tested: git diff --check

Not-tested: Local tests and local builds not run per repository/user policy.

* Cover stale Claude session-end lifecycle

Greptile identified that stale SessionEnd exercises a different clear-state path than stale Stop. The existing active-session guard already blocks the mutation, so the regression now drives that hook directly and asserts the active /clear session keeps its status, PID, and notifications intact.

Constraint: Do not run local tests; CI is the verification source for this branch.

Rejected: Add another Swift integration test | the existing Python hook harness already executes the CLI handler through the socket path used by CI.

Confidence: high

Scope-risk: narrow

Tested: Not run locally per repo policy.

Not-tested: Local test execution.

* Stop activation CI from stalling on Zig downloads

The activation workflow was cancelled before build because repeated ziglang.org transfers crawled for the full job timeout. Prefer Homebrew's pinned zig@0.15 bottle on macOS runners, then keep the direct tarball path as a bounded fallback with connection, total-time, and minimum-speed limits.

Constraint: The failed check never reached project build or tests; the only failing surface was CI tool bootstrap.

Rejected: Increase the job timeout | it would hide the bootstrap failure and delay feedback.

Confidence: medium

Scope-risk: narrow

Directive: Keep activation workflow tool bootstrap bounded so performance CI reaches the benchmark or fails quickly.

Tested: git diff --check

Not-tested: Local workflow execution, per repository and user instruction.

* Gate Claude session-end cleanup on the consumed workspace

Greptile noted that session-end computed the current-session guard from the fallback workspace while clearing the consumed session's workspace. Move the guard next to the mutation target so stale cleanup and visible cleanup always evaluate the same workspace identity.

Constraint: This is follow-up review hardening on the existing active-session model.

Rejected: Collapse activeSessionsByWorkspace into sessions in this PR | per-workspace current-session lookup is the intended lifecycle boundary for stale event gating.

Confidence: high

Scope-risk: narrow

Directive: SessionEnd visible cleanup must be gated against the workspace being cleared, not an earlier fallback lookup.

Tested: git diff --check

Not-tested: Local test execution, per repository and user instruction.

* Gate Claude session-end cleanup on consumed workspace

A late SessionEnd can be resolved through fallback surface lookup, so the workspace used to find a record is not always the workspace whose visible state would be cleared. Move the staleness check after consume() and evaluate it against the consumed session's workspace, where the clear_status and notification cleanup actually run.

Constraint: Hook events are delivered by short-lived CLI processes and must tolerate stale or partial Claude payloads

Rejected: Keep the pre-consume fallback workspace guard | it can validate one workspace while clearing another

Confidence: high

Scope-risk: narrow

Tested: Added Swift integration regression for stale SessionEnd fallback cleanup

Not-tested: Local tests not run per repository policy

* Make stale Claude session-end test consume the seeded session

Greptile caught that the Swift regression used an unknown session id, so the hook returned before reaching the intended consumed-session visibility guard. Use the seeded stale session id in the SessionEnd payload so the test exercises consume(), then verifies that stale visible cleanup is blocked.

Constraint: Address high-priority review feedback without running local tests.

Rejected: Leave Python-only coverage | the Swift regression would continue passing for the wrong reason.

Confidence: high

Scope-risk: narrow

Directive: Stale session-end regressions should consume a known stale session before asserting visible cleanup is skipped.

Tested: git diff --check

Not-tested: Local tests per repository and user instruction

* Cover fallback Claude session-end consumption

The stale SessionEnd regression should prove the handler consumed the stale session through fallback lookup before deciding whether visible state may be cleared. Use an unknown late session id and assert the seeded stale session is removed from the store, so the test cannot pass without exercising the consumed-workspace guard.

Constraint: Review feedback flagged the prior Swift regression as able to pass without covering the intended guard

Rejected: Use the stored stale session id directly | that only covers the ordinary mapped-session stale path

Confidence: high

Scope-risk: narrow

Tested: Not run locally per repository policy; CI will run the Swift regression

Not-tested: Local XCTest execution

* Keep Claude clear ownership panel-scoped

The clear SessionStart path now owns the active Claude boundary only for explicit clear events, so late startup/resume SessionStart events from the previous session cannot reclaim the workspace before their stale Stop or SessionEnd arrives. The same clear path now passes the resolved surface id into status updates so split panels receive the Running state in the intended pane.

Constraint: Local test execution is disallowed by repository policy; CI remains the behavioral gate.

Rejected: Let every SessionStart mark active | late non-clear events can overwrite the clear boundary.

Rejected: Drop fail-open isCurrent behavior | transient store errors should not hide legitimate current status updates.

Confidence: medium

Scope-risk: moderate

Directive: Do not let non-clear Claude SessionStart events replace an explicit /clear active boundary without adding event ordering metadata.

Tested: python3 -m py_compile tests/test_claude_hook_clear_running_status.py; git diff --check; conflict marker scan.

Not-tested: Local Swift/unit/UI test execution per repo policy.

* Protect Claude clear state from stale session cleanup

Late hook events can arrive after an explicit /clear boundary. The SessionStart handler now skips PID registration when the event is stale against the active session, and SessionEnd consumption preserves the active session when the incoming turn id is older than the stored active turn.

Constraint: Local test execution is disallowed by repository policy; CI remains the behavioral gate.

Rejected: Clear active ownership before checking currentness | same-session stale SessionEnd would fail open and apply cleanup.

Rejected: Keep prefix-only command assertions | option ordering changes would make the regression test brittle.

Confidence: medium

Scope-risk: moderate

Directive: Do not consume a Claude session or replace its PID from a hook event that is stale relative to active session/turn state.

Tested: python3 -m py_compile tests/test_claude_hook_clear_running_status.py; git diff --check; conflict marker scan.

Not-tested: Local Swift/unit/UI test execution per repo policy.

* Allow new Claude sessions to replace stopped owners

A stopped Claude turn must keep the same session eligible for the next turn, but it must not strand the workspace if that process exits before session-end. Mark stopped ownership as replaceable and let only session activation paths use that escape hatch; clear-session ownership remains non-replaceable so stale pre-clear events stay blocked. Session-end fallback cleanup now checks the consumed session id so missing input session ids do not fail open.\n\nConstraint: /clear SessionStart must continue to suppress stale pre-clear startup, stop, and session-end events\nRejected: Clear active ownership on Stop | breaks same-session multi-turn prompt-submit currentness\nConfidence: medium\nScope-risk: narrow\nTested: git diff --check; conflict-marker scan\nNot-tested: local XCTest per repo policy; CI will run cmux unit regressions

* test: cover codex hooks TOML features section

* fix: harden hook config and auth token cache

* test: cover sign-out browser auth loading cleanup

* fix: cancel browser auth on sign-out

* test: cover codex config read failures

* fix: fail closed on codex config read errors

* test: cover auth sign-out callback race

* fix: discard auth callback after sign-out

* fix: keep claude subcommands out of hook injection

* fix: dismiss stale sparkle update replies

* fix: redact auth logs while preserving observability

* fix: reset update checks and guard sign-out races

* fix: preserve update metadata from driver state

* fix: await auth token assertions before comparing

* fix: address wrapper and auth review feedback

* fix: address session and config review feedback

* ci: retrigger pending checks

* fix: clear stale ime and auth token state

* fix: clean legacy codex hooks config

* test: cover legacy codex hooks markers

* fix: clean empty codex features table

* fix: preserve browser key reentry dispatch

* Fix new-workspace caller window routing (#4042)

* test: cover new workspace caller routing

* fix: route new workspace to caller context

* Add iMessage workspace insertion regression test

* Reset Kitty keyboard mode at shell prompt boundaries (#3870)

* Prove stale Kitty keyboard state leaks CSI-u key bytes

The regression exercises a hosted Ghostty terminal, leaves Kitty keyboard protocol enabled as a crashed TUI would, mirrors the clear-history socket handler clear_screen path, and captures raw PTY stdin bytes for a plain c key. Current behavior should encode CSI-u instead of a single ASCII byte, making the test fail until the protocol state is reset at the shell prompt boundary.

Constraint: Regression must cover PTY input bytes, not source text shape
Confidence: high
Scope-risk: narrow
Directive: Keep this test on the real ghostty_surface_key path; sendText alone bypasses the keyboard encoder
Tested: Manual current-main repro captured c9;1:3uc9;1:3uc9;1:3u after Kitty enable plus clear-history
Not-tested: Local unit execution deferred to CI per requested red/green workflow

* Reset stale Kitty keyboard mode at prompt boundaries

A crashed TUI can leave Ghostty's Kitty keyboard protocol stack pushed after clear-history, causing normal shell input to be encoded as CSI-u. Resetting the stack from the shell prompt hook makes the prompt boundary the ownership point for returning interactive shells to plain byte input.

Constraint: Fix must run through shell integration because Ghostty keeps protocol state inside the terminal surface

Rejected: Reset only in clear-history socket path | stale state also leaks after any crashed TUI returns to prompt

Confidence: high

Scope-risk: narrow

Directive: Keep prompt-boundary reset paired across bash and zsh integrations

Tested: Not run locally per repository testing policy; regression added in prior commit

Not-tested: CI not yet completed

* Clarify Kitty reset fixture failures

The stale keyboard regression now fails at the fixture boundary if the zsh integration does not emit the expected reset bytes, instead of falling through to a misleading PTY byte mismatch.

Constraint: Repository policy forbids local test execution for this PR loop

Confidence: high

Scope-risk: narrow

Tested: Not run locally per repository policy; CI will run the affected XCTest

Not-tested: Local XCTest execution

* chore: retrigger Vercel checks

* Add Kitty reset shell hook coverage

* Reset all terminal keyboard protocols at prompt

* Fix terminal keyboard reset test expectations

* Clarify disabling agent session auto-resume for #3640 (#3991)

* docs: explain disabling agent auto resume

* docs: name auto resume config path

* Fix stale restored agent resume state

* Harden restored agent hook liveness

* refactor: share restored agent normalization

* Honor iMessage workspace ordering and previews

* Add workspace cwd inheritance setting (#3921)

* feat: add workspace cwd inheritance setting

* fix: align workspace cwd setting key naming

* fix: apply workspace cwd setting to detached creation

* fix: expose workspace cwd inheritance setting

* fix: route pane break through detached workspace creation

* fix: keep pane break response pane ids non-null

* fix: distinguish pane break resolution errors

* Approve installed Codex hooks (#4035)

* Approve installed Codex hooks

* Address Codex hook trust review feedback

* Avoid tomllib in Codex hook tests

* Align Codex hook trust test mirror

* Harden Codex hook trust ownership

* Preserve legacy Codex hook cleanup

* Fix workspace unit test after merge

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Revert "Approve installed Codex hooks (#4035)" (#4074)

This reverts commit e4546b7675a4ffa5a41a5429218b60f4e7644e21.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Fix workspace unit test transfer resume state (#4076)

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Clarify in cmux --help that reload-config covers Ghostty config too (#4060)

* Clarify cmux help that reload-config covers Ghostty config too

`cmux reload-config` reloads BOTH ~/.config/cmux/cmux.json and Ghostty
config (~/.config/ghostty/config) and refreshes terminals in place, but
the help/docs only mentioned cmux.json. Agents (and humans) reading the
help would think they had to restart cmux after editing Ghostty config.

- cmux --help "Agent Help" now tells agents where Ghostty config lives
  and that reload-config picks it up live.
- cmux docs settings, cmux settings path, cmux config --help now list
  ~/.config/ghostty/config as a related (not cmux-owned) location and
  describe reload-config's actual scope.
- cmux schema sidebarAppearance.tintOpacity description now notes it's
  sidebar-only, and points to Ghostty background-opacity / blur for
  terminal transparency.
- skills/cmux/SKILL.md mirrors the wording.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Align ghostty_config JSON shape across CLI surfaces

Cursor Bugbot and Greptile both flagged that `cmux settings path --json`
emitted `ghostty_config` as a string while `cmux docs settings --json`
emitted it as an object {path, note}. An agent reading both outputs with
the same key expectation would have to special-case the type.

Standardize on the object shape with `path` and `note` in both, matching
docsPayload. This is the agent-discoverability path the PR is trying to
make reliable, so making the shape consistent is on-purpose.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Use canonical Ghostty config key background-blur (not background-blur-radius)

CodeRabbit flagged that `background-blur-radius` is outdated. Verified
against the Ghostty submodule at ghostty/src/config/Config.zig: line 70
declares `background-blur-radius` as a compatibilityRenamed alias for
`background-blur`. The current canonical key is `background-blur` and it
accepts the same integer value (e.g. `background-blur = 20`).

Update the two docs that introduced the alias name:
- skills/cmux/SKILL.md
- web/data/cmux.schema.json (sidebarAppearance.tintOpacity description)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Add nucleo FFI command palette benchmark

* Open right sidebar tools as panes (#4065)

* Open right sidebar tools as panes

* Remove unreachable sidebar pane commands

* Fix sidebar pane unit test build

* Address sidebar pane review feedback

* Fix vault pane focus tracking

* Address right sidebar pane review followups

* Use modern sidebar pane flash observer

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Save crash diagnostics under cmux state (#4077)

* Save crash diagnostics under cmux state

* fix: key GhosttyKit artifacts by crash path

* fix: pin cmux crash GhosttyKit archive

* fix: mark crash breadcrumb scan concurrent

* fix: keep crash scan compatible with Xcode 16

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Menubar global search P1 (#3908)

* Ship local global search as a remappable menubar flow

Phase 1 needs browser and markdown value without terminal scrollback, so the index owns durable FTS5 upserts while AppDelegate keeps one navigation path from palette rows to focused panels. The global shortcut is wired through the existing shortcut settings instead of a standalone Carbon shim so Settings and cmux.json remain authoritative.

Constraint: Phase 1 excludes Ghostty terminal scrollback capture

Constraint: User required no local test execution and no reload before CI is green

Rejected: Hardcoded GlobalSearchHotkey shim | violates KeyboardShortcutSettings policy

Confidence: medium

Scope-risk: broad

Directive: Keep future terminal capture feeding SearchIndex documents through GlobalSearchCoordinator rather than adding another palette/navigation path

Tested: git diff --check; python3 -m json.tool Resources/Localizable.xcstrings; python3 -m json.tool web/data/cmux.schema.json; plutil -lint GhosttyTabs.xcodeproj/project.pbxproj

Not-tested: Local unit/UI tests and tagged app launch per task constraints

* Remove duplicate search refresh work

Cursor review pointed out that the menubar toggle and palette onAppear both refreshed the live index. Keeping the refresh in the palette lifecycle avoids resetting browser debounce tasks while still indexing each time the palette opens, and removing the unused workspace delete API keeps the storage surface honest.

Constraint: Review feedback came from PR #3908 after the first CI pass started

Rejected: Keep both refresh calls | causes avoidable debounce cancellation and slower browser result availability

Confidence: high

Scope-risk: narrow

Directive: Add workspace-level deletion only when a real workspace teardown caller is wired

Tested: git diff --check; python3 -m json.tool Resources/Localizable.xcstrings; python3 -m json.tool web/data/cmux.schema.json; plutil -lint GhosttyTabs.xcodeproj/project.pbxproj

Not-tested: Local tests/build per task constraints

* Fix global search stale index entries

* Address global search review feedback

* Fix search query token mapping compile error

* Fix global search CI failures

* Fix stale unavailable markdown search entries

* Cancel stale markdown search captures

* Cancel global search refresh on dismiss

* Fix global search review followups

* Address global search post-CI feedback

* Preserve markdown panel title search on read failure

* Address global search lifecycle feedback

* Address global search review lifecycle feedback

* Refine global search capture ownership

* fix: address global search review blockers

* feat: show open panels in global search

* fix: cover right sidebar tool panel in search

* Fix cmuxTests: rename restorableAgentAutoResumePending to restorableAgentResumeState (#4068)

* fix: handle repeated assistant imessage completions

* Open supported files in cmux on cmd-click (#4041)

* Open supported files in cmux on cmd-click

* Add cmd-click file preview verification script

* Reuse right pane for cmd-click file previews

* Keep cmd-click UI test terminal after preview focus

* Accept numeric cmd-click test payload values

* Capture cmd-click UI test window snapshots

* Add file-type-aware external open actions

* Address supported file routing review feedback

* Fix external open menu sendability warnings

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Suppress native proxy icon on cmux main windows (#3973)

* Add proxy icon regression test

* Suppress native proxy icon on cmux windows

* chore: retrigger preview deployments

* Refine native proxy icon suppression

* fix: keep titlebar folder icon aligned

* fix: restore titlebar folder icon leading offset

* test: cover folder icon frame replacement

* fix: resync folder icon on frame replacement

* test: cover folder icon ancestor movement

* fix: track folder icon ancestor movement

* fix: address folder icon review feedback

* test: stabilize folder icon ancestor sync

* fix: handle sidebar tool panels in global search

---------

Co-authored-by: austinpower1258 <austinwang115@gmail.com>

* Close browser panels when pages request window close (#4070)

* Add browser self-close restore regression test

* Close browser panels from WebKit close callbacks

* fix: index right sidebar tool panels as titles

* fix: keep web close callback synchronous

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add notification policy hooks

Merged https://github.com/manaflow-ai/cmux/pull/4054

* Fix sidebar unread badge after re-marking notifications (#4084)

* Add sidebar unread notification regression test

* Keep sidebar notification badge live during menu freeze

* Cover sidebar presentation fallback cases

* Limit Cloud VMs by active provider state (#4046)

* test: cover active vm limit with paused freestyle vms

* fix: enforce cloud vm limits by active state

* fix: parallelize cloud vm status refresh

* chore: update web security dependencies

* fix: handle right sidebar tools in global search

* fix: guard cloud vm status refresh races

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Fix Settings search synonyms (#4082)

* Add settings search synonym regressions

* Fix settings search synonyms

* Add shortcut bindings anchor regression

* Cover clickable PR settings search alias

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add tagged debug CLI helper (#4092)

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add unread defer shortcut (#4086)

* Add unread defer shortcut

* fix: address unread defer feedback

* fix: keep manual unread jump explicit

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Document notification hooks default off

Document that notification hooks are off by default and style the config key in localized docs.

* Approve installed Codex hooks after dogfood (#4075)

* Reapply Codex hook approval changes for dogfood

* Notify on Codex plan input requests

* Handle Codex plan question transcript items

* Address Codex hook review feedback

* Recover malformed Codex hook trust blocks

* Avoid duplicate consecutive cmux hook reinserts

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Document session restore behavior

Adds session restore docs, blog, README updates, and review cleanup.

* Use nucleo for command palette search

* Skip unrestorable Claude startup sessions

PR: https://github.com/manaflow-ai/cmux/pull/4079

* Revert "Suppress native proxy icon on cmux main windows" (#4099)

* Revert "Suppress native proxy icon on cmux main windows (#3973)"

This reverts commit 5048440ff44b4edbe328b65403724ff79476b2e6.

* Fix titlebar proxy icon without detached panel sync

* Apply proxy icon override to fallback config

* Restore key regain redraw invariant

* Tune nucleo palette initialism ranking

* Fix terminal portal resize lag (#4102)

* Fix Korean 2-Set terminal arrows (#4095)

* Add Korean 2-Set arrow IME regression

* Restore Korean 2-Set arrow forwarding

* Restore Zhuyin IME command routing

* Address IME review feedback

* Fix Korean IME regression test compile

* Address IME review follow-ups

* Address Bopomofo preedit review feedback

* Avoid idle Zhuyin key suppression

* Remove dead text input wrapper

* Address IME suppression review feedback

* Fix palette stitched highlight precedence

* Add Codex Teams subagent panes

* Open markdown files in preview panels from cmux open (#4085)

* fix: open markdown files in preview panels

* fix: preserve markdown viewer transparency

* fix: mute markdown open-with header button

* fix: align markdown header controls

* fix: align file header controls

* fix: address markdown review feedback

* test: cover opaque text editor alpha

* fix: align header open fallback

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Add task manager sorting and program aggregates (#4066)

* Add task manager sorting and program aggregates

* Add sorting to cmux top output

* Add flat TSV cmux top output

* Add coding agent task manager totals

* Make task manager program totals payload-backed

* Recognize agent launcher process names in task manager

* Fix task manager test build helpers

* Recognize Claude versioned launcher processes

* Show loading state before task manager sample

* Recognize versioned agent process names

* Use agent totals for task manager hierarchy icons

* fix: address task manager review feedback

* fix: address follow-up task manager review

* fix: address final task manager review

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Keep manual unread sticky until terminal interaction (#4104)

* test: cover sticky manual unread state

* fix: keep manual unread sticky until terminal input

* fix: show workspace manual unread pane ring

* fix: sync manual unread badge on focus changes

* fix: stabilize manual unread representative fallback

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: austinpower1258 <austinwang115@gmail.com>

* Bump version to 0.64.5 (#4107)

* Fix Pi Vault icon and JSONL titles (#4120)

* test: cover Pi JSONL content block titles

* fix: parse Pi JSONL text blocks for Vault titles

* fix: align Pi JSONL title role handling

* fix: require typed text blocks for Pi titles

* Improve Cloud VM error guidance (#4094)

* Improve Cloud VM error guidance

* Address final Cloud VM review feedback

* Narrow Cloud VM sanitizer env var block

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Keep selected workspace visible after sidebar reorders

* Add sidebar scroll regression for workspace move to top

* Reveal selected workspace after sidebar reorders

* Handle right sidebar tool panels in global search

* Test workspace move to top visibility only

* Refine sidebar reorder scroll trigger

* Add move-to-top notification regression

* Skip no-op move-to-top notifications

* Assert no-op move-to-top keeps order

* Require matching manager for reorder scroll

* Scroll selected workspace on index shifts

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Use transparent backgrounds for file preview panels (#4088)

* Handle right sidebar tools in global search browse hits

* Use transparent backgrounds for file preview panels

* Cover panel theme background preservation

* Fix PDF file preview open menu

* Make file open menu button compact

* Fix PDF open menu chrome button

* Fix PDF open-with chrome click target

* Address file preview chrome review feedback

* Fix PDF background cache invalidation

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Inherit stdin in backgrounded ssh inside startup wrapper (#4135)

* Add regression test for SSH startup wrapper dropping stdin

After PR #3786 backgrounded the ssh invocation inside the startup
wrapper for signal/reconnect handling, `cmux ssh <host>` sessions
stopped forwarding keystrokes from the surface PTY to the remote
shell. Output flowed back (the remote prompt rendered in cmux UI),
but anything typed never reached zsh on the other side, which sat
blocked in `do_poll` on the remote pts.

Root cause: POSIX sh redirects stdin of an async command (`&`) to
/dev/null when job control is off — the default for the `/bin/sh -c …`
that runs the startup wrapper. Without an explicit `<&0` on the
`&`'d ssh line, the local PTY stdin is silently dropped.

This commit adds the failing regression test. The fix follows in
the next commit so CI can prove the test catches the bug.

* Inherit stdin in backgrounded ssh inside startup wrapper

PR #3786 wrapped the ssh invocation in `while :; do … & wait` to enable
SIGHUP/INT/TERM trap handling and reconnect-on-exit-255. Backgrounding
ssh, however, drops its stdin: POSIX sh redirects fd 0 of any async
command to /dev/null when job control is off, which is the default for
the `/bin/sh -c …` host that runs this wrapper.

As a result, output from the remote still flowed back to the surface
PTY (ssh's stdout/stderr stayed wired) but the user's keystrokes never
reached the remote — they hit ttysNNN on the Mac side, kernel echoed
them locally, but ssh's stdin was /dev/null so nothing was forwarded.
zsh on the far side sat in `do_poll` forever.

Explicit `<&0` on both the `command` line and the `( … )` shell-snippet
form overrides the POSIX default and re-attaches the wrapper's own
stdin to the backgrounded ssh process.

Verified with the regression test added in the previous commit, plus
manual repro on Darwin:

    /bin/sh -c 'cat &  wait'           # cat's fd 0 → /dev/null (bug)
    /bin/sh -c 'cat <&0 &  wait'       # cat's fd 0 → parent stdin (fix)

* Add docs search

Adds localized Pagefind docs search with heading anchors and section-aware results.

* Fix Swift interpolation escape in SSH stdin regression test (#4154)

`testSSHStartupForwardsStdinToBackgroundedSSH` used `\"<empty>\"` inside a
`\(...)` string interpolation. Swift parses `\"` as the end of the outer
literal, breaking compilation of cmuxTests on main:

    Cannot find ')' to match opening '(' in string interpolation
    Unterminated string literal

That kept `ci/circleci: macos-unit-tests` red on main after #4135 even
though `macos-debug-build` and `macos-release-build` still passed (the
test target was the only thing affected). The runtime fix (`<&0` on the
backgrounded ssh) is unchanged and was verified end-to-end on a cloud Mac.

Inside an interpolation, the string is already a Swift expression and
literal quotes are unescaped; drop the four backslashes.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Add command palette settings toggles

Adds command palette toggles for boolean Settings rows, including iMessage Mode.

* Ensure Rust toolchain is installed for nucleo FFI builds

* Document nucleo FFI thread and ABI assumptions

* Reuse nucleo index in preview search test helper

* Install Rust for activation perf builds

---------

Co-authored-by: Tobi Lutke <tobi@shopify.com>
Co-authored-by: Austin Wang <austinwang115@gmail.com>
Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Kevin Peng <48529172+kays0x@users.noreply.github.com>

* Address command palette review feedback

* Address command palette review follow-ups

* Fix command palette preview responsiveness

* Build command palette search index off main actor

* Keep small cold palette searches synchronous

* fix: clear panel badges when marking notifications read

* fix: preserve nucleo normalized matches

* fix: preserve typo fallback with nucleo search

* fix: keep search fallback semantics

* fix: keep nucleo aliases authoritative

* fix: preserve typo fallback without ffi contention

* fix: avoid stale palette reset snapshot

* fix: narrow nucleo typo fallback

* fix: address command palette review bots

* fix: preserve palette activation during index refresh

* test: cover nucleo multi-token field matching

* fix: tokenize nucleo ffi queries

* fix: preserve palette activations during index refresh

* fix: sync palette pending state before async search

* fix: keep long keyword matches below title matches

* fix: keep nucleo fuzzy matches within fields

* fix: guard palette preview reuse by fingerprint

* test: skip optional nucleo bundle check without cargo

* fix: keep final palette results uncapped

* fix: respect optional nucleo fallback

* fix: initialize rustup toolchain in release workflow

* fix: run pending palette activation after sync refresh

* Fix command palette duplicate ID indexing

* Remove stale command palette label helpers

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Tobi Lutke <tobi@shopify.com>
Co-authored-by: Austin Wang <austinwang115@gmail.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Kevin Peng <48529172+kays0x@users.noreply.github.com>

This branch was successfully deployed

1 active deployment
Preview – cmux — fe2b5b91 Deployed May 13, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant