Skip to content

Launch restored agent sessions via startup commands - #4777

Merged
lawrencecchen merged 13 commits into
mainfrom
feat-agent-restore-launcher
May 27, 2026
Merged

lawrencecchen merged 13 commits into
mainfrom
feat-agent-restore-launcher

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented May 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Launch restored Claude/Codex resume commands through Ghostty startup commands instead of initial input.
  • Keep agent-hook resume bindings on the same startup-command path.
  • Preserve non-agent resume bindings on initial input.

Tests

  • Local compile-only build: xcodebuild -project cmux.xcodeproj -scheme cmux -configuration Debug -destination platform=macOS,arch=arm64 -derivedDataPath /tmp/cmux-agent-restore-launcher-build build
  • AWS M4 Pro: cmuxTests/AgentSessionAutoResumeSettingsTests, 10 tests, 0 failures

Dogfood

  • Tagged build will be provided in chat after local reload.

View with Codesmith Autofix with Codesmith
Need help on this PR? Tag @codesmith with what you need. Autofix is disabled.


Note

Medium Risk
Changes session-restore startup paths and generated shell scripts that run user resume commands; remote vs local behavior diverges, but approval gates and extensive auto-resume tests limit blast radius.

Overview
Restored Claude/Codex-style agent sessions and agent-hook resume bindings now auto-launch through a temporary /bin/zsh startup command instead of piping the resume line as initial terminal input. The launcher script runs the resume in the user’s login shell, re-applies cmux zsh integration, then execs back to the normal shell.

Local restore picks either a startup command (agent + agent-hook, via self-deleting scripts under cmux-agent-resume / surface-resume) or input (e.g. non-agent tmux bindings). Remote workspaces keep the configured remote initialCommand and still send agent resume as inline input, including when it exceeds the usual inline size cap. Scrollback replay and resume-state tracking were updated for command-driven auto-resume (e.g. .autoResumeCommandRunning vs .awaitingAutoResumeCommand).

Reviewed by Cursor Bugbot for commit dc6dd63. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Restored agent and agent‑hook resumes now launch via a self‑deleting zsh startup command that runs in the user’s login shell, re‑enters cmux zsh integration, then execs back to it. Remote workspaces keep their remote startup command; agent resumes are sent as inline input (including long inputs), and launchers now handle zsh/bash and csh/tcsh.

  • New Features

    • Generate temporary zsh launcher scripts for agent resumes and agent‑hook bindings that self-delete, run in the user’s login shell, re-enter cmux zsh integration, support zsh/bash and csh/tcsh, and exec -l via TerminalStartupReturnShellScript.
    • Add SessionRestorableAgentSnapshot.resumeStartupCommand() and SurfaceResumeBindingSnapshot.startupCommandWithLauncherScript() to produce startup commands.
  • Refactors

    • Introduce Workspace.SurfaceResumeStartupLaunch to choose command vs input and wire initialCommand/initialInput; gate launcher usage with allowLauncherScript (disabled for remote) and keep oversized remote input with allowOversizedInlineInput.
    • Preserve remote startup: keep the remote initialCommand and send agent resume via initialInput; track .awaitingAutoResumeCommand when inline input drives auto-resume, and .autoResumeCommandRunning when a startup command does.
    • Update scrollback replay to detect any startup launch via hasResumeStartupWork; remove an unused restore-launch flag.

Written for commit dc6dd63. Summary will update on new commits. Review in cubic

Summary by CodeRabbit

  • New Features

    • Session restoration can create on-disk launcher scripts and invoke /bin/zsh to resume sessions; scripts can optionally return to the user’s login shell.
  • Refactor

    • Restore flow now treats startup work as either a launch command or inline input, improving resume decisioning, initial input/command precedence, and scrollback replay behavior.
  • Tests

    • Auto-resume tests updated to verify launcher-script startup behavior and guard against unintended input injection.

Review Change Stack

@vercel

vercel Bot commented May 26, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview, Comment May 27, 2026 4:53am
cmux-staging Ready Ready Preview, Comment May 27, 2026 4:53am

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented May 26, 2026 •

Copy link
Copy Markdown

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Refactors session restoration to produce launcher-script-backed startup commands (optionally returning to the user's login shell), introduces SurfaceResumeStartupLaunch to distinguish command vs input, and rewires restore control flow, scrollback gating, lifecycle decisions, and tests.

Changes

Session Restore with Launcher Scripts and Login Shell Return

Layer / File(s) Summary
Launcher script enhancements with login shell support
Sources/RestorableAgentSession.swift, Sources/SessionPersistence.swift
SessionRestorableAgentSnapshot.resumeStartupCommand and SurfaceResumeBindingSnapshot.startupCommandWithLauncherScript now write launcher scripts and return quoted /bin/zsh invocations. AgentResumeScriptStore.writeLauncherScript and SurfaceResumeBindingScriptStore.writeLauncherScript gain a returnToLoginShell parameter; script writers build an array of lines and always write a trailing newline.
Structured resume launch result and approval logic
Sources/Workspace.swift
Adds SurfaceResumeStartupLaunch enum with initialCommand/initialInput, plus factory/approval helpers (surfaceResumeStartupLaunch) that compute the effective resume binding and whether launcher-script-driven startup work should run.
Terminal restoration using structured launch result
Sources/Workspace.swift
Terminal snapshot restoration now uses surfaceResumeStartupLaunch() to derive effectiveResumeBinding, recomputes working directories and tmux start command based on presence of launch work, reorders startup command/input precedence (remote-PTY, tmux launcher, binding/agent launch), gates scrollback replay on hasResumeStartupWork, updates debug logging, and switches agent lifecycle selection to the launch-based decision.
Test updates for startup command assertions
cmuxTests/AgentSessionAutoResumeSettingsTests.swift
Tests updated to assert auto-resume via debugInitialCommand() (nil when disabled, or a /bin/zsh launcher invocation when enabled). Adds assertAgentAutoResumeUsesStartupCommand to read and validate on-disk launcher scripts and confirm the appended login-shell exec line.

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related issues

Possibly related PRs

  • manaflow-ai/cmux#4237: Overlaps with earlier changes around persisted SurfaceResumeBindingSnapshot usage and restore startup input/command handling.

🐰 I scribble scripts beneath the moonlit log,
I tuck commands in shells to finish with a jog,
I add a tiny exec to send you back to home,
Resume hops back, no session left to roam,
I clean the temp file and nibble on a chrome.


Caution

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

  • Ignore

❌ Failed checks (1 error, 1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Cmux Swift @Concurrent ❌ Error File I/O functions resumeStartupCommand() and startupCommandWithLauncherScript() lack @concurrent annotation when called from @MainActor code performing synchronous disk writes. Add @concurrent annotation to these disk I/O functions or extract file operations into an off-MainActor hop.
Docstring Coverage ⚠️ Warning Docstring coverage is 6.90% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Description check ❓ Inconclusive PR description covers core changes and testing but omits detailed demo, changelog updates, and complete checklist. Clarify whether a demo video is needed for the startup-command changes; confirm if changelog/docs were updated; verify all checklist items are complete before merge.
✅ Passed checks (14 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and specifically describes the main change: launching restored agent sessions via startup commands instead of initial input.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed New types marked nonisolated, test helper marked @MainActor; SessionRestorableAgentSnapshot's implicit MainActor is existing debt not worsened by PR.
Cmux Swift Blocking Runtime ✅ Passed No blocking/timing synchronization patterns found in modified production code.
Cmux No Hacky Sleeps ✅ Passed PR modifies only Swift files, which are explicitly excluded from this rule's scope. Swift timing is covered by swift-blocking-runtime.md per the rule file.
Cmux Swift Concurrency ✅ Passed PR adds synchronous APIs with no DispatchQueue, Combine, completion-handlers, or fire-and-forget Tasks introduced.
Cmux Swift File And Package Boundaries ✅ Passed All changes to existing oversized files stay under 250-line threshold (RestorableAgentSession +25, SessionPersistence +41, Workspace +106). No new large files, properly encapsulated script stores.
Cmux Swift Logging ✅ Passed All NSLog calls are guarded by #if DEBUG; debug logging uses #if DEBUG-guarded cmuxDebugLog. No print/debugPrint/dump found. No logging violations per .github/review-bot-rules/swift-logging.md.
Cmux User-Facing Error Privacy ✅ Passed PR adds launcher script infrastructure for agent resume without exposing session IDs, credentials, or sensitive details in user-facing errors, logs, or commands shown to users.
Cmux Full Internationalization ✅ Passed The PR adds startup command methods returning /bin/zsh literals, which are protocol tokens/command names that must remain exact per allowed cases in the i18n rules.
Cmux Swiftui State Layout ✅ Passed PR adds only nonisolated enum SurfaceResumeStartupLaunch and static methods—no new @Published/@observable state, layout issues, or render-time mutations.
Cmux Architecture Rethink ✅ Passed No violations. Single-source resolution in createPanel, one entrypoint wiring to surface, state derived from actual values. No timing, locks, observers, or split lifecycle.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PR adds no NSWindow, NSPanel, NSWindowController, or SwiftUI Window/WindowGroup code. SurfaceResumeStartupLaunch is a data enum, not a window type.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat-agent-restore-launcher

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@greptile-apps

greptile-apps Bot commented May 26, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR routes local agent and agent-hook resume sessions through Ghostty initialCommand (via a self-deleting temp zsh launcher) rather than initialInput, so the terminal gets a proper login-shell environment. Remote workspaces are unchanged: initialCommand keeps the remote SSH command and agent resumes are sent as initialInput, with oversized commands now allowed through a new allowOversizedInlineInput flag.

  • TerminalStartupReturnShellScript.commandThenReturnLines generates shell code that runs the resume command in the user's login shell, re-enters cmux zsh integration, then exec -ls back to an interactive shell.
  • SurfaceResumeStartupLaunch (now a proper enum) distinguishes startup-command from startup-input paths; surfaceResumeStartupLaunch dispatches to the right path per workspace type.
  • Scrollback-replay gating migrates from a nil-string sentinel to a dedicated hasResumeStartupWork: Bool parameter, and agent resume state gains a distinct .autoResumeCommandRunning case for the new startup-command path.

Confidence Score: 5/5

Safe to merge. The change is well-scoped to the session restore flow and all four new/modified paths are covered by updated or new tests that pass.

The core logic change — routing local agent resumes through a startup command rather than initial input — is straightforward and isolated to the restore path. Remote workspace behavior is preserved by explicit branching on remoteStartupCommand != nil. The self-deleting launcher script pattern is identical to existing pre-PR behavior; only the returnToLoginShell body is new. No new concurrency primitives, no new actor isolation boundaries, and no user-facing strings were added.

Sources/Workspace.swift — the snapshot path still gates scrollback persistence via surfaceResumeStartupInput (input-only) while the restore path uses surfaceResumeStartupLaunch; the two remain consistent today but diverge in API intent.

Important Files Changed

Filename Overview
Sources/SessionPersistence.swift Adds TerminalStartupReturnShellScript.commandThenReturnLines for launcher script generation and SurfaceResumeBindingSnapshot.startupCommandWithLauncherScript; SurfaceResumeBindingScriptStore.writeLauncherScript gains returnToLoginShell to optionally wrap the inline input in the new login-shell path. Logic is clean and well-encapsulated.
Sources/RestorableAgentSession.swift Adds resumeStartupCommand() (startup-command path for local resumes) and allowOversizedInlineInput to the inline-input path for remote use; AgentResumeScriptStore.writeLauncherScript gains returnToLoginShell. Both new code paths are tested.
Sources/Workspace.swift Core restore wiring: introduces SurfaceResumeStartupLaunch enum, surfaceResumeStartupLaunch, and approvedSurfaceResumeBinding; gates scrollback replay via hasResumeStartupWork: Bool; dispatches to startup-command vs input per workspace type. Snapshot path still calls surfaceResumeStartupInput (input-only API) to decide hasResumeStartupWork, while the restore path uses the new surfaceResumeStartupLaunch; currently consistent but the two code paths use different APIs for the same gate.
cmuxTests/AgentSessionAutoResumeSettingsTests.swift Tests updated to assert startup-command (not input) for all local auto-resume paths; two new remote tests cover the SSH keep-command and oversized-input cases; helper assertAgentAutoResumeUsesStartupCommand verifies script content including shell-integration reentry lines.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[restoreSessionSnapshot] --> B{remoteStartupCommand?}
    B -- Yes --> C[surfaceResumeStartupInput\nallowLauncherScript: false]
    C --> D[".input(resumeCmd)"]
    B -- No --> E[surfaceResumeStartupLaunch\nallowLauncherScript: true]
    E --> F{isAgentHookBinding?}
    F -- Yes --> G[startupCommandWithLauncherScript]
    G --> H[".command('/bin/zsh script.zsh')"]
    F -- No --> I[startupInputWithLauncherScript]
    I --> J[".input(cmd or scriptPath)"]
    D --> K{agentResumeLaunch}
    J --> K
    H --> K
    K -- remoteStartupCommand != nil --> L[resumeStartupInput\nallowOversizedInlineInput: true\n.input]
    K -- else --> M[resumeStartupCommand\n.command]
    H --> N[restoredStartupCommand]
    M --> N
    D --> O[restoredStartupInput]
    L --> O
    J --> O
    N --> P[newTerminalSurface\ninitialCommand]
    O --> Q[newTerminalSurface\ninitialInput]
    P --> R{Agent state}
    Q --> R
    R -- command --> S[.autoResumeCommandRunning]
    R -- input --> T[.awaitingAutoResumeCommand]
    R -- none --> U[.manualResumeAvailable]
Loading

Reviews (12): Last reviewed commit: "Handle csh agent restore launchers" | Re-trigger Greptile

Comment thread Sources/Workspace.swift Outdated
Comment thread Sources/Workspace.swift
coderabbitai[bot]
coderabbitai Bot previously requested changes May 26, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@cmuxTests/AgentSessionAutoResumeSettingsTests.swift`:
- Around line 233-236: Replace the lenient containment check on
restoredRemoteCommand with a strict equality assertion against the original
remoteCommand: remove the XCTAssertTrue(...contains("cmux-macmini")) line and
instead assert XCTAssertEqual(restoredRemoteCommand, remoteCommand), keeping the
existing XCTAssertEqual(restoredPanel.surface.debugInitialCommand(),
restoredRemoteCommand) if still desired; reference
restored.remoteConfiguration?.terminalStartupCommand (restoredRemoteCommand),
restoredPanel.surface.debugInitialCommand(), and remoteCommand to locate where
to change the assertions.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 3328b6b2-bb67-4a2f-8b54-fa7922243b8c

📥 Commits

Reviewing files that changed from the base of the PR and between 46b5f21 and cda9159.

📒 Files selected for processing (1)
  • cmuxTests/AgentSessionAutoResumeSettingsTests.swift

Comment thread cmuxTests/AgentSessionAutoResumeSettingsTests.swift Outdated
Comment thread Sources/Workspace.swift

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
Sources/SessionPersistence.swift (1)

364-379: ⚠️ Potential issue | 🟠 Major | 🏗️ Heavy lift

Fix surface-resume launcher scripts forcing zsh interpreter

Sources/SessionPersistence.swift’s startupCommandWithLauncherScript/SurfaceResumeBindingScriptStore.writeLauncherScript hard-code /bin/zsh (#!/bin/zsh + returned /bin/zsh <script>). For agent-hook resumes, Workspace.swift routes to .command(...), which means binding.command is evaluated by zsh even when inlineStartupInput would otherwise be fed to the user’s login shell as raw text (e.g., when environment is nil/empty). This can break restore for non-zsh syntax.

Adjust the launcher-script execution to run the saved inlineInput under the user’s actual shell (or wrap via $SHELL -lc), or restrict launcher-script usage to commands known to be zsh-safe. Add a regression test for a non-zsh-only binding syntax on agent-hook resume.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@Sources/SessionPersistence.swift` around lines 364 - 379,
startupCommandWithLauncherScript is currently forcing /bin/zsh when returning
the launcher invocation and SurfaceResumeBindingScriptStore.writeLauncherScript
embeds a zsh shebang; change the launcher execution to run under the user's
login shell instead (e.g. use $SHELL -lc '<script path>' or construct the
command using the environment SHELL value via shellSingleQuoted) so
inlineStartupInput is evaluated by the user's shell, and/or remove the hardcoded
#!/bin/zsh from writeLauncherScript; update startupCommandWithLauncherScript to
return something like "$SHELL -lc <script>" (using shellSingleQuoted for safety)
and add a regression test in Workspace/agent-hook resume paths that verifies a
non-zsh-only binding syntax is preserved on resume.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@Sources/SessionPersistence.swift`:
- Around line 364-379: startupCommandWithLauncherScript is currently forcing
/bin/zsh when returning the launcher invocation and
SurfaceResumeBindingScriptStore.writeLauncherScript embeds a zsh shebang; change
the launcher execution to run under the user's login shell instead (e.g. use
$SHELL -lc '<script path>' or construct the command using the environment SHELL
value via shellSingleQuoted) so inlineStartupInput is evaluated by the user's
shell, and/or remove the hardcoded #!/bin/zsh from writeLauncherScript; update
startupCommandWithLauncherScript to return something like "$SHELL -lc <script>"
(using shellSingleQuoted for safety) and add a regression test in
Workspace/agent-hook resume paths that verifies a non-zsh-only binding syntax is
preserved on resume.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 407f14c5-359b-4b5e-98cb-82972e02771a

📥 Commits

Reviewing files that changed from the base of the PR and between cda9159 and c521df9.

📒 Files selected for processing (4)
  • Sources/RestorableAgentSession.swift
  • Sources/SessionPersistence.swift
  • Sources/Workspace.swift
  • cmuxTests/AgentSessionAutoResumeSettingsTests.swift

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit f9aca65. Configure here.

Comment thread Sources/Workspace.swift
@lawrencecchen
lawrencecchen dismissed coderabbitai[bot]’s stale review May 26, 2026 17:51

Stale CodeRabbit changes request addressed by ad5efed; inline thread PRRT_kwDORDHQWM6EzwFb is resolved and the latest CodeRabbit check is green.

@lawrencecchen
lawrencecchen deleted the feat-agent-restore-launcher branch May 27, 2026 04:58
Vangor added a commit to Vangor/most that referenced this pull request May 27, 2026
* test: cover external dot path open

* fix: open external path arguments without socket access

* fix: preserve explicit socket path opens

* fix: bound launchservices open helper

* fix: avoid blocking primitive in open helper

* fix: format localized path open errors

* fix: complete path open localization

* fix: scrub socket env for external path opens

* fix: localize path open success output

* Add cmux.xcworkspace with Packages visible alongside the project (manaflow-ai#4834)

* Add cmux.xcworkspace with Packages visible alongside the project

Top-level navigator shows cmux.xcodeproj plus every Packages/* SPM
package as siblings, so local packages are editable in the same window
without nesting under the project node. Additive only: existing
-project build flows (reload.sh, CI) keep working unchanged.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Ignore xcshareddata under xcworkspaces

Xcode auto-creates xcshareddata inside .xcworkspace bundles for
WorkspaceSettings.xcsettings, IDEWorkspaceChecks.plist, and SwiftPM
configuration. None of those carry intentional shared state for cmux
today (build is driven by reload.sh and CI, no private SPM registry,
no custom file headers). Ignoring them prevents Xcode bookkeeping
churn in commits. Project-level xcshareddata (shared .xcscheme files)
is unaffected because the pattern only matches inside .xcworkspace
directories.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>

* fix: scrub legacy panel env for path opens

* fix: limit path open locale entries

* Redesign notifications popover: bigger, minimal, swipe to dismiss (manaflow-ai#4778)

* Redesign notifications popover: bigger, minimal, swipe to dismiss

- Larger frame (min 460x480, ideal 560x620, max 760x760) so more
  notifications are visible at once.
- Compact rows with a thin accent bar for unread, tighter typography,
  hover-revealed clear button. No more boxed cards per row, just
  dividers between rows.
- Drag a row left or right to dismiss; passing the threshold slides it
  out and removes the notification. Tap to open as before.
- Empty/loading/populated states share the same outer frame so the
  popover stops resizing when notifications come and go.

* Show jump-to-latest keyboard shortcut next to button label

* Stabilize hover on notification rows: dedicated background tracking layer

.onHover and .onTapGesture on the same SwiftUI node share AppKit's
mouse-tracking pipeline and arbitrate against each other, producing
flaky enter/exit events right after the popover opens and when
crossing rows fast. Move hover detection to a transparent background
layer using .onContinuousHover, scope the opacity animation to the
background only so it does not re-animate dragOffset, and bump the
hover opacity from 0.07 to 0.11 so it is visible against
.windowBackgroundColor in light mode.

* Use NSTrackingArea for notification row hover

SwiftUI's .onHover and .onContinuousHover still arbitrate with the
parent .onTapGesture in macOS popover content, leaving rows where
hover never fires (notably on first popover open and when crossing
between LazyVStack rows). Replace the SwiftUI hover modifier with an
NSViewRepresentable that installs an NSTrackingArea
(.mouseEnteredAndExited + .activeAlways + .inVisibleRect). The
tracking NSView returns nil from hitTest so clicks pass through to
the SwiftUI parent's tap gesture, and the view syncs current
inside/outside state on tracking-area install for the case where the
pointer is already inside the row when the popover opens.

* Notifications popover: keep timestamp visible, drop hover animation, add right-click menu

- Always show row timestamp (removed the hide-on-hover opacity).
- Removed the hover background fade animation so it's an instant flip.
- Right-click a row for Open / Mark as Read / Mark as Unread / Dismiss.
- Added TerminalNotificationStore.markUnread(id:) sibling to markRead(id:).
- Added en/ja localizations for the new menu strings.

* Notifications popover: drop top margin, always semibold title

* Make notifications popover resizable, taller default

Default size bumped to 560x760 (was 560x620 ideal). User can drag a
bottom-right resize handle to set their own size; the chosen width
and height persist via @AppStorage. Bounds are 420x320 .. 1000x1200.

* Notifications popover: invisible corner resize, drop swipe-to-dismiss

NSPopover has no native resize chrome and there's no first-class
SwiftUI resize API for it. The closest native-feeling thing is a
hit-only corner region that drives a state-driven .frame: no visual
button, just a resizeLeftRight cursor on hover (closest standard
NSCursor to a diagonal resize).

Also removed swipe-to-dismiss. The hover X button and the right-click
Dismiss menu item are the dismiss surfaces; swiping rows in an
NSPopover row list isn't a macOS convention.

* Notifications popover: fix glitchy resize via AppKit screen coords

SwiftUI's DragGesture reports translation in a local coordinate space
that is literally being resized under the cursor as the popover grows.
Each frame the gesture re-derives translation from a moving anchor,
which produces dimension oscillation (the popover jumps between two
sizes).

Replace the SwiftUI gesture with an NSViewRepresentable that tracks
NSEvent.mouseLocation in global screen coordinates. Screen coordinates
are stable regardless of popover resize, so deltas are monotonic.
Also disable implicit animation on the .frame width/height so the
popover follows the cursor 1:1.

* Notifications popover: use diagonal resize cursor on bottom-right corner

* Notifications popover: address review feedback

- unreadCount uses notificationMenuSnapshot.unreadCount instead of
  reducing the live list, so the badge stays consistent with the
  hasUnreadNotifications / hasNotifications guards that drive the
  Jump to Latest / Clear All disabled states.
- Hide the visual keyboard-shortcut chip from accessibility; the
  button already exposes the shortcut via .accessibilityValue, so
  VoiceOver no longer reads it twice.
- Add a row-level accessibility action to dismiss a notification,
  since the visible clear button is hover-only. Adds the localized
  string notifications.row.clear (en/ja).

* markUnread(id:): clear manual workspace unread to avoid double-count

When a user marks a read notification unread, the notification itself
now provides the workspace unread indicator. If the workspace also had
a manual unread flag set, the popover header, dock badge, and
workspace badge would double-count that workspace because the count
builders sum notification unread counts and workspace indicators.

Mirrors what markLatestNotificationAsOldestUnread already does in the
same file. Found by Codex review.

* Restore Button wrapper on notification rows for keyboard access

Replacing the original Button with .onTapGesture removed rows from
the SwiftUI key-view loop, so keyboard-only users could tab to the
header controls but not open a row. The original reason for dropping
Button was that SwiftUI's .onHover arbitrated with the row's primary
action — but hover is now driven entirely by an AppKit NSTrackingArea
(HoverTrackingRepresentable), independent of the row's activation
node. The Button wrapper is therefore safe again and restores
space/return activation in the key-view loop. Found by Codex review.

* Notifications popover: persist resize once on mouseUp, clamp drag baseline

- Live resize uses @State (liveWidth/liveHeight); @AppStorage is
  written exactly once when the user releases the mouse, instead of
  on every mouseDragged event. Each @AppStorage write was hitting
  UserDefaults and broadcasting UserDefaults.didChangeNotification to
  every app-wide observer.
- Drag baseline now comes from the clamped (currently displayed)
  size, not raw saved doubles, so a drag that starts with out-of-bounds
  stored values doesn't lose initial pointer travel re-entering the
  visible range.

* Notifications popover: clear button as ZStack sibling, not nested in row Button

Nesting clearButton inside the row's Button(action: onOpen) label
created the classic SwiftUI nested-button hit-test problem on macOS:
clicks on the inner X could be consumed by the outer row Button's
tap area instead of clearing the notification. Move clearButton out
of rowContent and into a ZStack(alignment: .trailing) at the body
level so it's a sibling of the row Button with an independent hit
target. Found by Codex review.

* Notifications popover: clamp to screen, hide hover-only X from focus

- Clamp the popover's frame against NSScreen.main?.visibleFrame minus
  an 80pt margin so the bottom-right resize handle stays reachable
  even when the saved size was captured on a larger display.
- Mark the hover-only clear button .accessibilityHidden(!isHovering)
  so Full Keyboard Access / VoiceOver doesn't focus an invisible
  dismiss control. Dismissal is still exposed via the row's
  accessibility action and the right-click menu. Found by Codex.

* CI: retry — GitHub Actions infra was returning 403/404 on codeload

* CI: retrigger now that GitHub Actions infra is back

* Mark-as-Read context menu: clear focused pane indicator too

A user-initiated 'Mark as Read' should mirror the full dismissal
intent, so the pane's focused-read indicator for that surface should
clear alongside flipping the notification's isRead flag. Otherwise
the unread count drops but the pane badge remains visible until the
user later interacts with the terminal. Found by Codex review.

* Notifications popover: clamp against host window's screen, fix hover sync race

- Clamp popover size against the screen of NSApp.keyWindow (the
  popover's anchor window), not NSScreen.main. On multi-monitor
  setups the popover may appear on a different display than 'main'.
- Remove the DispatchQueue.main.async hop in HoverTrackingNSView's
  updateTrackingAreas; the queued onChange(true) could land after
  mouseExited's synchronous onChange(false), leaving rows stuck in
  the hovered state. updateTrackingAreas already runs on the main
  thread, so the call is fine synchronously. Found by Cursor Bugbot.

* Mark-as-Read: only clear focused pane indicator for pane-scoped notifications

clearFocusedReadIndicator treats surfaceId == nil as 'clear any pane
indicator for this tab', so passing nil for a workspace-level
notification would wipe an unrelated pane's badge. Gate the call on
notification.surfaceId being non-nil. Found by Codex review.

* Notifications popover: add a11y label/hint to resize handle

The localized notifications.resize key existed but was never wired
to the actual control. Adds .accessibilityLabel/.accessibilityHint
so VoiceOver and Full Keyboard Access users can discover the resize
affordance. Found by Cursor Bugbot.

* Notifications popover: move accessibility identifier back onto the row Button

XCUITests query rows with app.buttons["NotificationPopoverRow.<id>"].
The previous pass put .accessibilityIdentifier on the combined outer
ZStack, exposing the row as a container rather than a button, which
breaks both XCUITest lookups and the button accessibility role for
assistive tech. Move identifier + primary action + clear action back
onto the inner Button. Found by Codex review.

* Notifications popover: snapshot list before LazyVStack; clear restored unread on markUnread

- ForEach now iterates an immutable snapshot captured outside the
  LazyVStack instead of reading notificationStore.notifications
  inside the row builder; the previous code reintroduced a store
  dependency below the list boundary, which CLAUDE.md flags as the
  same anti-pattern that caused the LazyLayoutViewCache spin-loop
  in the sessions panel (manaflow-ai#2586).
- markUnread(id:) now also clears the restored workspace unread
  indicator for the tab, so a session-restored unread hint plus a
  user-toggled unread notification no longer double-count in the
  header/dock/workspace badges. Found by Codex review.

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Remove History from right sidebar (manaflow-ai#4785)

* Remove History mode from right sidebar

Drops the History tab from the right sidebar mode picker along with its
keyboard shortcut, command palette entries, and the 'Open Full History'
menu button. Recently Closed/Focused submenus and Reopen Last Closed
still work from the menu bar.

* Drop tests for deleted HistoryDayGrouping helper

* Tolerate obsolete history mode and restore focus-history menu key

- SessionRightSidebarToolPanelSnapshot now decodes an unknown mode (e.g.
  legacy 'history') as nil instead of failing the entire snapshot, so
  upgraded users can still restore prior sessions.
- Restore the 'menu.history.showFullFocusHistory' key still referenced
  by AppDelegate+FocusHistoryContextMenu for non-sidebar focus history.

* Remove duplicate @mainactor attribute left by prior edit

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Launch restored agent sessions via startup commands (manaflow-ai#4777)

* Test agent restore startup command launch

* Launch restored agents with startup commands

* Tighten restored startup launch state

* Preserve remote startup for agent restore

* Relax remote startup restore assertion

* Fix startup restore lifecycle

* Remove unused restore launch flag

* Run startup resumes in login shell

* Tighten remote restore assertion

* Handle csh agent restore launchers

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Wrap workspace titles in sidebar (manaflow-ai#4848)

* Wrap workspace titles in sidebar

* Add workspace title wrap toggle

* Localize workspace title wrap setting

* Align wrapped workspace title accessories

* Reset workspace title wrap preference

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* test: cover bare relative external path open

* fix: open bare relative path arguments externally

* fix: preserve refresh surfaces command precedence

* fix: keep bare path command matching case-sensitive

* Add secure cmux navigation links (manaflow-ai#4857)

* Add secure cmux navigation links

* Localize cmux navigation link labels

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Fix matched sidebar terminal background (manaflow-ai#4780)

* test: cover matched sidebar background tint

* fix: match sidebar terminal background

* fix: remove dead sidebar overlay path

* test: cover matched sidebar boundary separators

* fix: keep matched sidebar separators visible

* test: cover matched sidebar chrome borders

* test: sample sidebar boundary resizers

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Fix JSONC comment skipper for CRLF line endings (manaflow-ai#4869)

* Fix JSONC // comment skipper for CRLF line endings

Swift treats \r\n as a single extended grapheme cluster, so the existing
source[index] != "\n" check inside the three // line-comment skippers
never matches a CRLF line ending. On a file with CRLF throughout, the
loop runs past the rest of the file looking for a standalone LF and
strips everything after the first //. preprocess() then produces
truncated JSON and loadCmuxSettingsRoot() / jsonObject() throw
"Unexpected end of file".

This was breaking the tmux corpus terminal-nightly job's
testSurfaceResumeApprovalWritesRecordsIntoCmuxJSON, which explicitly
exercises the CRLF path. Match any character whose first scalar is CR
or LF so we stop at CR, LF, or CRLF correctly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Allow workflow_dispatch to run tmux corpus terminal-nightly

So this workflow's macOS test job is reproducible on demand for branches
under review, not only on the nightly schedule.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Fix JSONC editor indent detection for CRLF line endings

indentationBeforeLine walked back to find the start of the line
containing a given index by stopping at "\n" or "\r" characters, but on
CRLF input Swift treats "\r\n" as a single extended grapheme cluster
that equals neither. The loop then walked past every line break to the
start of the file and returned an empty indent, so newly inserted
properties (e.g. resumeCommands) ended up at the wrong indentation
level. Reuse the isLineTerminator helper that already handles CRLF
correctly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Open forked conversations without palette action probe (manaflow-ai#4852)

* Open forked conversations without palette action probe

* Fix fork probe snapshot selection

* Refresh fork probe cache per palette session

* Preserve verified fork probe visibility

* Preserve fork snapshot cache during live refresh

* Allow verified fallback fork execution

* Reprobe fork cache after fallback clears

* Preserve focus after instant fork commands

* Clear fork cache on execution failure

* Avoid stale fork cache on palette reopen

* Clear stale fallback fork cache before reprobe

* Preserve verified fork cache on palette reopen

* Require verified fork snapshot before fallback execution

* Track actual fork fallback usage

* Preserve verified fork cache fallback flag

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* test: cover bonsplit tab indicator drift

* fix: update bonsplit tab indicator handling

* Skip Cmd+Shift key forwarding test when Ghostty surface init fails (manaflow-ai#4871)

The tmux corpus terminal-nightly runner cannot initialize a
Metal-backed Ghostty surface; embedded_window logs
"error initializing surface err=error.OutOfMemory" for every surface
the suite creates, and ghostty_surface_new returns nil. The test then
fails XCTAssertTrue on performKeyEquivalentAfterMenuMiss because
ensureSurfaceReadyForInput cannot return a live surface, which looks
like a key-forwarding regression rather than the environment issue
that it is.

Skip the test (via XCTSkipUnless on TerminalSurface.hasLiveSurface)
when the surface fails to initialize, so CI surfaces the real problem
(Metal unavailable on this runner) without masking it as a key-bind
regression. The test still runs end-to-end on developer machines and
on runners with a logged-in GUI session.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Add algorithmic complexity review rule (manaflow-ai#4866)

* Add algorithmic complexity review rule

* Align algorithmic complexity review hint

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Narrow AppDelegate CI quarantine (manaflow-ai#4874)

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Restore browser devtools config CI coverage

* Add prompt and rules deeplinks (manaflow-ai#4839)

* Add prompt and rules deeplinks

* Preserve encoded punctuation in text deeplinks

* Localize text deeplink dialogs

* Support Freestyle SSH link users

* Harden prompt and rules deeplinks

* Suppress welcome for text deeplinks

* Restore SSH deeplink trust gate

* Preserve plus signs in text deeplinks

* Respect no-focus for text deeplink target selection

* Use deterministic text deeplink target

* Start background text deeplink targets

* Report text deeplink send failures

* Handle mixed deeplink batches safely

* Gate mixed external deeplink batches

* Report failed external text deeplink sends

* Stop after handling external cmux links

* Allow multiline cmux text links

* Reject control characters in cmux text links

* Polish external cmux link handling

* Label sendTextWhenReady callbacks

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Make session index backfill linear (manaflow-ai#4868)

* Make session index backfill linear

* Stabilize session index backfill tie breaks

* Fix session index tie-break test setup

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Optimize batch workspace sidebar actions (manaflow-ai#4865)

* Optimize batch workspace sidebar actions

* Preserve workspace selection after drag reorder

* Harden workspace batch action coverage

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* test: harden bonsplit scroll indicator check

* Restore browser remote store CI coverage

* Make browser search providers configurable (manaflow-ai#4849)

* feat: make browser search providers configurable

* fix: keep parsing browser settings after invalid custom search config

* test: harden custom search config regression

* fix: handle custom search edge cases

* fix: validate custom search fallbacks

* fix: localize search engine labels

* fix: gate stale search suggestions

* fix: allow blank custom search names

* fix: add exa search provider

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Restore browser lifecycle CI coverage

* docs: add cmux ssh deep links (manaflow-ai#4833)

* docs: add cmux ssh deep links

* docs: add cmux deeplink fallback pages

* docs: add deeplink locale fallbacks

* docs: tighten deeplink fallback validation

* docs: mirror native ssh deeplink validation

* docs: localize deeplink messages

* docs: canonicalize rules deeplink alternates

* Allow Freestyle SSH deeplink users

* docs: validate text deeplink fallback params

* docs: ignore blank optional deeplink params

* docs: address deeplink review comments

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Restore file preview review CI coverage

* Pin Xcode 26 (objectVersion 60) and add pbxproj normalizer + CI guard (manaflow-ai#4836)

* Add deterministic normalizer for cmux.xcodeproj/project.pbxproj

scripts/normalize-pbxproj.py sorts the high-churn sections (PBXBuildFile,
PBXFileReference, and the files = (...) arrays inside Sources / Resources
/ Frameworks / CopyFiles build phases) into a deterministic order keyed
on the entry comment plus UUID. The Xcode build does not care about the
order of these flat dictionary sections; sorting them just kills the
nondeterministic diff noise Xcode generates on every UI touch.

Does not touch UUIDs, comments, or PBXGroup children = (...) arrays
(navigator order is intentional). Idempotent: a second run produces zero
diff.

Standalone in this commit so the diff is just the script. The next
commit applies the script and bumps objectVersion in one shot, so
the resulting churn is contained and never repeated.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Pin objectVersion = 60 and normalize pbxproj

Bumps objectVersion from 56 to 60 (the format Xcode 16+ and Xcode 26
write by default) and runs scripts/normalize-pbxproj.py once to
establish the deterministic baseline. After this commit, future
diffs to project.pbxproj show only real changes, not Xcode's
nondeterministic section reordering.

One-time large diff. No semantic changes to targets, sources, build
phases, or settings: pure sort + version pin.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Add tracked pre-commit hook that normalizes pbxproj

scripts/git-hooks/pre-commit calls scripts/normalize-pbxproj.py on
cmux.xcodeproj/project.pbxproj when it is staged and re-stages the
result. scripts/install-git-hooks.sh points the clone at this directory
via `git config core.hooksPath scripts/git-hooks`, and scripts/setup.sh
auto-runs it so devs get the hook without a separate manual step.

After this, Xcode's nondeterministic reordering of build-file and
file-reference sections is canceled out at commit time. The CI guard
in the next commit enforces the rule for anyone who bypasses the hook
with --no-verify or who never ran setup.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Add CI guard for objectVersion pin and pbxproj normalization

scripts/check-pbxproj.sh asserts cmux.xcodeproj/project.pbxproj has
objectVersion = 60 (Xcode 26 default) and that the file is normalized
per scripts/normalize-pbxproj.py. Wired as a step in the
workflow-guard-tests job so every PR is gated.

This catches anyone who bypasses the pre-commit hook with --no-verify
or who never ran scripts/setup.sh. The error message points at the
exact fix path.

To bump the pin (e.g., when the team adopts a newer Xcode major), edit
EXPECTED_OBJECT_VERSION in this script and the matching line in
CLAUDE.md.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Add .xcode-version and document Xcode 26 pin in CLAUDE.md

.xcode-version records the major (26.0) for tooling that reads it
(xcodes CLI, some CI helpers).

CLAUDE.md gains an Xcode toolchain section explaining the pin, the
normalizer + pre-commit hook + CI guard mechanics, and the procedure
for bumping the pin in the future.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Read .xcode-version as the source of truth in check-pbxproj.sh

scripts/check-pbxproj.sh now reads .xcode-version and maps the Xcode
major to the expected objectVersion via a one-entry case statement.
Bumping the team's Xcode pin becomes a one-file edit (.xcode-version),
with a script update only required when Apple actually changes
objectVersion in a new Xcode major.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Address CodeRabbit findings on check-pbxproj.sh and pre-commit hook

scripts/check-pbxproj.sh now passes "$PBXPROJ" explicitly to
normalize-pbxproj.py instead of letting it default to a path relative
to the current working directory, so the guard works regardless of
where CI invokes it.

scripts/git-hooks/pre-commit refuses to run when the working-tree
pbxproj has unstaged changes. Previously the hook would normalize
the working-tree file and `git add` the result, which silently staged
any unstaged hunks the user had deliberately left out of the commit.
The hook now exits non-zero with a clear message telling the user to
either stage the whole file or stash the unstaged hunks first.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Address Greptile findings: misleading comment + bump-step docs

scripts/normalize-pbxproj.py: the comment said "preserve empty lines
exactly where they are" but the implementation collapses blanks to a
trailing group. Reworded the comment to match the actual behavior.

CLAUDE.md: the bump procedure now mentions opening cmux.xcodeproj in
the new Xcode so objectVersion gets rewritten automatically. Without
that step a developer following the docs alone would update only the
pin file and the script case, and the CI guard would fail on their
next commit.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>

* Add scripts/cleanup-dev-builds.sh for safely reclaiming tagged DerivedData (manaflow-ai#4837)

* Add scripts/cleanup-dev-builds.sh

Removes tagged dev-build artifacts produced by scripts/reload.sh:
DerivedData/cmux-<tag>/ (multi-GB each), /tmp/cmux-<tag>/, the per-tag
debug socket and logs, the reload log, and the App Support cmuxd dev
socket. Defaults to dry-run; pass --apply to delete.

Safety rules always on:
  - Skip the tag of any running `cmux DEV <tag>` app
  - Skip the tag pointed at by /tmp/cmux-last-cli-path
  - Skip any tag tied to a live git worktree
Filters: --older-than DAYS, --keep TAG (repeatable).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Drop "worktree exists" safety rule in cleanup-dev-builds.sh

Existence of a git worktree with the same name is a weak signal of
active use, and HQ tends to accumulate worktrees long after the
work is done. The rule made cleanup over-protective for the typical
case (worktree still around from a merged or abandoned PR).

The remaining safety rules (skip running app, skip the tag pointed
at by /tmp/cmux-last-cli-path) plus --keep TAG and --older-than DAYS
cover what we actually want without false positives.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Add /cleanup-builds slash command

Wraps scripts/cleanup-dev-builds.sh with the standard preview ->
confirm -> apply flow. Sits alongside the existing .claude/commands
(pull, sync-branch, release, etc.) and enforces user confirmation
before --apply.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Address review feedback on cleanup-dev-builds

CodeRabbit + Greptile findings, all real:

- Active-tag extraction from /tmp/cmux-last-cli-path now uses a regex
  match on /cmux-<tag>/ anywhere in the path, not just a strict
  $DERIVED_DATA_ROOT/cmux- prefix. Also avoids the unquoted parameter
  expansion that could be sensitive to glob metacharacters in
  DERIVED_DATA_ROOT.
- discover_tags switched from find | xargs basename to a shell glob
  loop. Cleaner, works on macOS regardless of xargs flavor, handles
  the empty case naturally.
- --older-than no longer skips tags whose DerivedData was already
  deleted (age == -1 sentinel). Orphan sockets/logs for those tags
  now get cleaned instead of being silently retained.
- "freed" label reworded as "freed (estimated)" because the byte
  count is measured during planning, not after rm.
- .claude/commands/cleanup-builds.md: blank lines around fenced
  blocks (MD031).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>

* Fix agent resume when saved cwd is deleted (manaflow-ai#4859)

* test: cover agent resume with deleted cwd

* fix: resume agents when saved cwd is gone

* fix: harden restored cwd guard

* fix: skip ghostty cwd for guarded restore commands

* fix: drop duplicate cwd args on restore

* fix: preserve shell args during cwd cleanup

* fix: preserve custom resume cwd arguments

* fix: preserve shell syntax during cwd cleanup

* chore: remove unused shell word helper

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Restore file preview text saving CI coverage

* Restore browser session history CI coverage

* chore(rename): swap bundle id, product name, config dir to most

Visual rename pass — upstream-merge friendly. Touches user-visible
surfaces only; keeps Swift identifiers, package dirs, env vars,
and on-disk xcodeproj/test target names so cmux upstream merges
remain conflict-free.

- pbxproj: PRODUCT_BUNDLE_IDENTIFIER com.cmuxterm.* → com.4etverg.most*
- pbxproj: PRODUCT_NAME cmux → most ("cmux DEV" → "most DEV")
- Entitlements: app group ids release/nightly → com.4etverg.most[.nightly]
- CLI config path: ~/.config/cmux/cmux.json → ~/.config/most/most.json
- One-shot legacy config migration in KeyboardShortcutSettingsFileStore
- README.md (English) user-visible refs flipped; upstream URLs preserved

Co-Authored-By: OpenAI Codex (gpt-5.4-mini) <noreply@openai.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(configuration): rename to most.json + document migration

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Abdulaziz Albahar <67667005+azooz2003-bit@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Co-authored-by: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com>
Co-authored-by: Konstantin <your@email.ar>
Co-authored-by: OpenAI Codex (gpt-5.4-mini) <noreply@openai.com>
Vangor added a commit to Vangor/most that referenced this pull request May 30, 2026
* test: cover external dot path open

* fix: open external path arguments without socket access

* fix: preserve explicit socket path opens

* fix: bound launchservices open helper

* fix: avoid blocking primitive in open helper

* fix: format localized path open errors

* fix: complete path open localization

* fix: scrub socket env for external path opens

* fix: localize path open success output

* Add cmux.xcworkspace with Packages visible alongside the project (manaflow-ai#4834)

* Add cmux.xcworkspace with Packages visible alongside the project

Top-level navigator shows cmux.xcodeproj plus every Packages/* SPM
package as siblings, so local packages are editable in the same window
without nesting under the project node. Additive only: existing
-project build flows (reload.sh, CI) keep working unchanged.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Ignore xcshareddata under xcworkspaces

Xcode auto-creates xcshareddata inside .xcworkspace bundles for
WorkspaceSettings.xcsettings, IDEWorkspaceChecks.plist, and SwiftPM
configuration. None of those carry intentional shared state for cmux
today (build is driven by reload.sh and CI, no private SPM registry,
no custom file headers). Ignoring them prevents Xcode bookkeeping
churn in commits. Project-level xcshareddata (shared .xcscheme files)
is unaffected because the pattern only matches inside .xcworkspace
directories.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>

* fix: scrub legacy panel env for path opens

* fix: limit path open locale entries

* Redesign notifications popover: bigger, minimal, swipe to dismiss (manaflow-ai#4778)

* Redesign notifications popover: bigger, minimal, swipe to dismiss

- Larger frame (min 460x480, ideal 560x620, max 760x760) so more
  notifications are visible at once.
- Compact rows with a thin accent bar for unread, tighter typography,
  hover-revealed clear button. No more boxed cards per row, just
  dividers between rows.
- Drag a row left or right to dismiss; passing the threshold slides it
  out and removes the notification. Tap to open as before.
- Empty/loading/populated states share the same outer frame so the
  popover stops resizing when notifications come and go.

* Show jump-to-latest keyboard shortcut next to button label

* Stabilize hover on notification rows: dedicated background tracking layer

.onHover and .onTapGesture on the same SwiftUI node share AppKit's
mouse-tracking pipeline and arbitrate against each other, producing
flaky enter/exit events right after the popover opens and when
crossing rows fast. Move hover detection to a transparent background
layer using .onContinuousHover, scope the opacity animation to the
background only so it does not re-animate dragOffset, and bump the
hover opacity from 0.07 to 0.11 so it is visible against
.windowBackgroundColor in light mode.

* Use NSTrackingArea for notification row hover

SwiftUI's .onHover and .onContinuousHover still arbitrate with the
parent .onTapGesture in macOS popover content, leaving rows where
hover never fires (notably on first popover open and when crossing
between LazyVStack rows). Replace the SwiftUI hover modifier with an
NSViewRepresentable that installs an NSTrackingArea
(.mouseEnteredAndExited + .activeAlways + .inVisibleRect). The
tracking NSView returns nil from hitTest so clicks pass through to
the SwiftUI parent's tap gesture, and the view syncs current
inside/outside state on tracking-area install for the case where the
pointer is already inside the row when the popover opens.

* Notifications popover: keep timestamp visible, drop hover animation, add right-click menu

- Always show row timestamp (removed the hide-on-hover opacity).
- Removed the hover background fade animation so it's an instant flip.
- Right-click a row for Open / Mark as Read / Mark as Unread / Dismiss.
- Added TerminalNotificationStore.markUnread(id:) sibling to markRead(id:).
- Added en/ja localizations for the new menu strings.

* Notifications popover: drop top margin, always semibold title

* Make notifications popover resizable, taller default

Default size bumped to 560x760 (was 560x620 ideal). User can drag a
bottom-right resize handle to set their own size; the chosen width
and height persist via @AppStorage. Bounds are 420x320 .. 1000x1200.

* Notifications popover: invisible corner resize, drop swipe-to-dismiss

NSPopover has no native resize chrome and there's no first-class
SwiftUI resize API for it. The closest native-feeling thing is a
hit-only corner region that drives a state-driven .frame: no visual
button, just a resizeLeftRight cursor on hover (closest standard
NSCursor to a diagonal resize).

Also removed swipe-to-dismiss. The hover X button and the right-click
Dismiss menu item are the dismiss surfaces; swiping rows in an
NSPopover row list isn't a macOS convention.

* Notifications popover: fix glitchy resize via AppKit screen coords

SwiftUI's DragGesture reports translation in a local coordinate space
that is literally being resized under the cursor as the popover grows.
Each frame the gesture re-derives translation from a moving anchor,
which produces dimension oscillation (the popover jumps between two
sizes).

Replace the SwiftUI gesture with an NSViewRepresentable that tracks
NSEvent.mouseLocation in global screen coordinates. Screen coordinates
are stable regardless of popover resize, so deltas are monotonic.
Also disable implicit animation on the .frame width/height so the
popover follows the cursor 1:1.

* Notifications popover: use diagonal resize cursor on bottom-right corner

* Notifications popover: address review feedback

- unreadCount uses notificationMenuSnapshot.unreadCount instead of
  reducing the live list, so the badge stays consistent with the
  hasUnreadNotifications / hasNotifications guards that drive the
  Jump to Latest / Clear All disabled states.
- Hide the visual keyboard-shortcut chip from accessibility; the
  button already exposes the shortcut via .accessibilityValue, so
  VoiceOver no longer reads it twice.
- Add a row-level accessibility action to dismiss a notification,
  since the visible clear button is hover-only. Adds the localized
  string notifications.row.clear (en/ja).

* markUnread(id:): clear manual workspace unread to avoid double-count

When a user marks a read notification unread, the notification itself
now provides the workspace unread indicator. If the workspace also had
a manual unread flag set, the popover header, dock badge, and
workspace badge would double-count that workspace because the count
builders sum notification unread counts and workspace indicators.

Mirrors what markLatestNotificationAsOldestUnread already does in the
same file. Found by Codex review.

* Restore Button wrapper on notification rows for keyboard access

Replacing the original Button with .onTapGesture removed rows from
the SwiftUI key-view loop, so keyboard-only users could tab to the
header controls but not open a row. The original reason for dropping
Button was that SwiftUI's .onHover arbitrated with the row's primary
action — but hover is now driven entirely by an AppKit NSTrackingArea
(HoverTrackingRepresentable), independent of the row's activation
node. The Button wrapper is therefore safe again and restores
space/return activation in the key-view loop. Found by Codex review.

* Notifications popover: persist resize once on mouseUp, clamp drag baseline

- Live resize uses @State (liveWidth/liveHeight); @AppStorage is
  written exactly once when the user releases the mouse, instead of
  on every mouseDragged event. Each @AppStorage write was hitting
  UserDefaults and broadcasting UserDefaults.didChangeNotification to
  every app-wide observer.
- Drag baseline now comes from the clamped (currently displayed)
  size, not raw saved doubles, so a drag that starts with out-of-bounds
  stored values doesn't lose initial pointer travel re-entering the
  visible range.

* Notifications popover: clear button as ZStack sibling, not nested in row Button

Nesting clearButton inside the row's Button(action: onOpen) label
created the classic SwiftUI nested-button hit-test problem on macOS:
clicks on the inner X could be consumed by the outer row Button's
tap area instead of clearing the notification. Move clearButton out
of rowContent and into a ZStack(alignment: .trailing) at the body
level so it's a sibling of the row Button with an independent hit
target. Found by Codex review.

* Notifications popover: clamp to screen, hide hover-only X from focus

- Clamp the popover's frame against NSScreen.main?.visibleFrame minus
  an 80pt margin so the bottom-right resize handle stays reachable
  even when the saved size was captured on a larger display.
- Mark the hover-only clear button .accessibilityHidden(!isHovering)
  so Full Keyboard Access / VoiceOver doesn't focus an invisible
  dismiss control. Dismissal is still exposed via the row's
  accessibility action and the right-click menu. Found by Codex.

* CI: retry — GitHub Actions infra was returning 403/404 on codeload

* CI: retrigger now that GitHub Actions infra is back

* Mark-as-Read context menu: clear focused pane indicator too

A user-initiated 'Mark as Read' should mirror the full dismissal
intent, so the pane's focused-read indicator for that surface should
clear alongside flipping the notification's isRead flag. Otherwise
the unread count drops but the pane badge remains visible until the
user later interacts with the terminal. Found by Codex review.

* Notifications popover: clamp against host window's screen, fix hover sync race

- Clamp popover size against the screen of NSApp.keyWindow (the
  popover's anchor window), not NSScreen.main. On multi-monitor
  setups the popover may appear on a different display than 'main'.
- Remove the DispatchQueue.main.async hop in HoverTrackingNSView's
  updateTrackingAreas; the queued onChange(true) could land after
  mouseExited's synchronous onChange(false), leaving rows stuck in
  the hovered state. updateTrackingAreas already runs on the main
  thread, so the call is fine synchronously. Found by Cursor Bugbot.

* Mark-as-Read: only clear focused pane indicator for pane-scoped notifications

clearFocusedReadIndicator treats surfaceId == nil as 'clear any pane
indicator for this tab', so passing nil for a workspace-level
notification would wipe an unrelated pane's badge. Gate the call on
notification.surfaceId being non-nil. Found by Codex review.

* Notifications popover: add a11y label/hint to resize handle

The localized notifications.resize key existed but was never wired
to the actual control. Adds .accessibilityLabel/.accessibilityHint
so VoiceOver and Full Keyboard Access users can discover the resize
affordance. Found by Cursor Bugbot.

* Notifications popover: move accessibility identifier back onto the row Button

XCUITests query rows with app.buttons["NotificationPopoverRow.<id>"].
The previous pass put .accessibilityIdentifier on the combined outer
ZStack, exposing the row as a container rather than a button, which
breaks both XCUITest lookups and the button accessibility role for
assistive tech. Move identifier + primary action + clear action back
onto the inner Button. Found by Codex review.

* Notifications popover: snapshot list before LazyVStack; clear restored unread on markUnread

- ForEach now iterates an immutable snapshot captured outside the
  LazyVStack instead of reading notificationStore.notifications
  inside the row builder; the previous code reintroduced a store
  dependency below the list boundary, which CLAUDE.md flags as the
  same anti-pattern that caused the LazyLayoutViewCache spin-loop
  in the sessions panel (manaflow-ai#2586).
- markUnread(id:) now also clears the restored workspace unread
  indicator for the tab, so a session-restored unread hint plus a
  user-toggled unread notification no longer double-count in the
  header/dock/workspace badges. Found by Codex review.

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Remove History from right sidebar (manaflow-ai#4785)

* Remove History mode from right sidebar

Drops the History tab from the right sidebar mode picker along with its
keyboard shortcut, command palette entries, and the 'Open Full History'
menu button. Recently Closed/Focused submenus and Reopen Last Closed
still work from the menu bar.

* Drop tests for deleted HistoryDayGrouping helper

* Tolerate obsolete history mode and restore focus-history menu key

- SessionRightSidebarToolPanelSnapshot now decodes an unknown mode (e.g.
  legacy 'history') as nil instead of failing the entire snapshot, so
  upgraded users can still restore prior sessions.
- Restore the 'menu.history.showFullFocusHistory' key still referenced
  by AppDelegate+FocusHistoryContextMenu for non-sidebar focus history.

* Remove duplicate @mainactor attribute left by prior edit

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Launch restored agent sessions via startup commands (manaflow-ai#4777)

* Test agent restore startup command launch

* Launch restored agents with startup commands

* Tighten restored startup launch state

* Preserve remote startup for agent restore

* Relax remote startup restore assertion

* Fix startup restore lifecycle

* Remove unused restore launch flag

* Run startup resumes in login shell

* Tighten remote restore assertion

* Handle csh agent restore launchers

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Wrap workspace titles in sidebar (manaflow-ai#4848)

* Wrap workspace titles in sidebar

* Add workspace title wrap toggle

* Localize workspace title wrap setting

* Align wrapped workspace title accessories

* Reset workspace title wrap preference

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* test: cover bare relative external path open

* fix: open bare relative path arguments externally

* fix: preserve refresh surfaces command precedence

* fix: keep bare path command matching case-sensitive

* Add secure cmux navigation links (manaflow-ai#4857)

* Add secure cmux navigation links

* Localize cmux navigation link labels

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Fix matched sidebar terminal background (manaflow-ai#4780)

* test: cover matched sidebar background tint

* fix: match sidebar terminal background

* fix: remove dead sidebar overlay path

* test: cover matched sidebar boundary separators

* fix: keep matched sidebar separators visible

* test: cover matched sidebar chrome borders

* test: sample sidebar boundary resizers

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Fix JSONC comment skipper for CRLF line endings (manaflow-ai#4869)

* Fix JSONC // comment skipper for CRLF line endings

Swift treats \r\n as a single extended grapheme cluster, so the existing
source[index] != "\n" check inside the three // line-comment skippers
never matches a CRLF line ending. On a file with CRLF throughout, the
loop runs past the rest of the file looking for a standalone LF and
strips everything after the first //. preprocess() then produces
truncated JSON and loadCmuxSettingsRoot() / jsonObject() throw
"Unexpected end of file".

This was breaking the tmux corpus terminal-nightly job's
testSurfaceResumeApprovalWritesRecordsIntoCmuxJSON, which explicitly
exercises the CRLF path. Match any character whose first scalar is CR
or LF so we stop at CR, LF, or CRLF correctly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Allow workflow_dispatch to run tmux corpus terminal-nightly

So this workflow's macOS test job is reproducible on demand for branches
under review, not only on the nightly schedule.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Fix JSONC editor indent detection for CRLF line endings

indentationBeforeLine walked back to find the start of the line
containing a given index by stopping at "\n" or "\r" characters, but on
CRLF input Swift treats "\r\n" as a single extended grapheme cluster
that equals neither. The loop then walked past every line break to the
start of the file and returned an empty indent, so newly inserted
properties (e.g. resumeCommands) ended up at the wrong indentation
level. Reuse the isLineTerminator helper that already handles CRLF
correctly.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Open forked conversations without palette action probe (manaflow-ai#4852)

* Open forked conversations without palette action probe

* Fix fork probe snapshot selection

* Refresh fork probe cache per palette session

* Preserve verified fork probe visibility

* Preserve fork snapshot cache during live refresh

* Allow verified fallback fork execution

* Reprobe fork cache after fallback clears

* Preserve focus after instant fork commands

* Clear fork cache on execution failure

* Avoid stale fork cache on palette reopen

* Clear stale fallback fork cache before reprobe

* Preserve verified fork cache on palette reopen

* Require verified fork snapshot before fallback execution

* Track actual fork fallback usage

* Preserve verified fork cache fallback flag

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* test: cover bonsplit tab indicator drift

* fix: update bonsplit tab indicator handling

* Skip Cmd+Shift key forwarding test when Ghostty surface init fails (manaflow-ai#4871)

The tmux corpus terminal-nightly runner cannot initialize a
Metal-backed Ghostty surface; embedded_window logs
"error initializing surface err=error.OutOfMemory" for every surface
the suite creates, and ghostty_surface_new returns nil. The test then
fails XCTAssertTrue on performKeyEquivalentAfterMenuMiss because
ensureSurfaceReadyForInput cannot return a live surface, which looks
like a key-forwarding regression rather than the environment issue
that it is.

Skip the test (via XCTSkipUnless on TerminalSurface.hasLiveSurface)
when the surface fails to initialize, so CI surfaces the real problem
(Metal unavailable on this runner) without masking it as a key-bind
regression. The test still runs end-to-end on developer machines and
on runners with a logged-in GUI session.

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Add algorithmic complexity review rule (manaflow-ai#4866)

* Add algorithmic complexity review rule

* Align algorithmic complexity review hint

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Narrow AppDelegate CI quarantine (manaflow-ai#4874)

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Restore browser devtools config CI coverage

* Add prompt and rules deeplinks (manaflow-ai#4839)

* Add prompt and rules deeplinks

* Preserve encoded punctuation in text deeplinks

* Localize text deeplink dialogs

* Support Freestyle SSH link users

* Harden prompt and rules deeplinks

* Suppress welcome for text deeplinks

* Restore SSH deeplink trust gate

* Preserve plus signs in text deeplinks

* Respect no-focus for text deeplink target selection

* Use deterministic text deeplink target

* Start background text deeplink targets

* Report text deeplink send failures

* Handle mixed deeplink batches safely

* Gate mixed external deeplink batches

* Report failed external text deeplink sends

* Stop after handling external cmux links

* Allow multiline cmux text links

* Reject control characters in cmux text links

* Polish external cmux link handling

* Label sendTextWhenReady callbacks

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Make session index backfill linear (manaflow-ai#4868)

* Make session index backfill linear

* Stabilize session index backfill tie breaks

* Fix session index tie-break test setup

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Optimize batch workspace sidebar actions (manaflow-ai#4865)

* Optimize batch workspace sidebar actions

* Preserve workspace selection after drag reorder

* Harden workspace batch action coverage

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* test: harden bonsplit scroll indicator check

* Restore browser remote store CI coverage

* Make browser search providers configurable (manaflow-ai#4849)

* feat: make browser search providers configurable

* fix: keep parsing browser settings after invalid custom search config

* test: harden custom search config regression

* fix: handle custom search edge cases

* fix: validate custom search fallbacks

* fix: localize search engine labels

* fix: gate stale search suggestions

* fix: allow blank custom search names

* fix: add exa search provider

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Restore browser lifecycle CI coverage

* docs: add cmux ssh deep links (manaflow-ai#4833)

* docs: add cmux ssh deep links

* docs: add cmux deeplink fallback pages

* docs: add deeplink locale fallbacks

* docs: tighten deeplink fallback validation

* docs: mirror native ssh deeplink validation

* docs: localize deeplink messages

* docs: canonicalize rules deeplink alternates

* Allow Freestyle SSH deeplink users

* docs: validate text deeplink fallback params

* docs: ignore blank optional deeplink params

* docs: address deeplink review comments

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Restore file preview review CI coverage

* Pin Xcode 26 (objectVersion 60) and add pbxproj normalizer + CI guard (manaflow-ai#4836)

* Add deterministic normalizer for cmux.xcodeproj/project.pbxproj

scripts/normalize-pbxproj.py sorts the high-churn sections (PBXBuildFile,
PBXFileReference, and the files = (...) arrays inside Sources / Resources
/ Frameworks / CopyFiles build phases) into a deterministic order keyed
on the entry comment plus UUID. The Xcode build does not care about the
order of these flat dictionary sections; sorting them just kills the
nondeterministic diff noise Xcode generates on every UI touch.

Does not touch UUIDs, comments, or PBXGroup children = (...) arrays
(navigator order is intentional). Idempotent: a second run produces zero
diff.

Standalone in this commit so the diff is just the script. The next
commit applies the script and bumps objectVersion in one shot, so
the resulting churn is contained and never repeated.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Pin objectVersion = 60 and normalize pbxproj

Bumps objectVersion from 56 to 60 (the format Xcode 16+ and Xcode 26
write by default) and runs scripts/normalize-pbxproj.py once to
establish the deterministic baseline. After this commit, future
diffs to project.pbxproj show only real changes, not Xcode's
nondeterministic section reordering.

One-time large diff. No semantic changes to targets, sources, build
phases, or settings: pure sort + version pin.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Add tracked pre-commit hook that normalizes pbxproj

scripts/git-hooks/pre-commit calls scripts/normalize-pbxproj.py on
cmux.xcodeproj/project.pbxproj when it is staged and re-stages the
result. scripts/install-git-hooks.sh points the clone at this directory
via `git config core.hooksPath scripts/git-hooks`, and scripts/setup.sh
auto-runs it so devs get the hook without a separate manual step.

After this, Xcode's nondeterministic reordering of build-file and
file-reference sections is canceled out at commit time. The CI guard
in the next commit enforces the rule for anyone who bypasses the hook
with --no-verify or who never ran setup.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Add CI guard for objectVersion pin and pbxproj normalization

scripts/check-pbxproj.sh asserts cmux.xcodeproj/project.pbxproj has
objectVersion = 60 (Xcode 26 default) and that the file is normalized
per scripts/normalize-pbxproj.py. Wired as a step in the
workflow-guard-tests job so every PR is gated.

This catches anyone who bypasses the pre-commit hook with --no-verify
or who never ran scripts/setup.sh. The error message points at the
exact fix path.

To bump the pin (e.g., when the team adopts a newer Xcode major), edit
EXPECTED_OBJECT_VERSION in this script and the matching line in
CLAUDE.md.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Add .xcode-version and document Xcode 26 pin in CLAUDE.md

.xcode-version records the major (26.0) for tooling that reads it
(xcodes CLI, some CI helpers).

CLAUDE.md gains an Xcode toolchain section explaining the pin, the
normalizer + pre-commit hook + CI guard mechanics, and the procedure
for bumping the pin in the future.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Read .xcode-version as the source of truth in check-pbxproj.sh

scripts/check-pbxproj.sh now reads .xcode-version and maps the Xcode
major to the expected objectVersion via a one-entry case statement.
Bumping the team's Xcode pin becomes a one-file edit (.xcode-version),
with a script update only required when Apple actually changes
objectVersion in a new Xcode major.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Address CodeRabbit findings on check-pbxproj.sh and pre-commit hook

scripts/check-pbxproj.sh now passes "$PBXPROJ" explicitly to
normalize-pbxproj.py instead of letting it default to a path relative
to the current working directory, so the guard works regardless of
where CI invokes it.

scripts/git-hooks/pre-commit refuses to run when the working-tree
pbxproj has unstaged changes. Previously the hook would normalize
the working-tree file and `git add` the result, which silently staged
any unstaged hunks the user had deliberately left out of the commit.
The hook now exits non-zero with a clear message telling the user to
either stage the whole file or stash the unstaged hunks first.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Address Greptile findings: misleading comment + bump-step docs

scripts/normalize-pbxproj.py: the comment said "preserve empty lines
exactly where they are" but the implementation collapses blanks to a
trailing group. Reworded the comment to match the actual behavior.

CLAUDE.md: the bump procedure now mentions opening cmux.xcodeproj in
the new Xcode so objectVersion gets rewritten automatically. Without
that step a developer following the docs alone would update only the
pin file and the script case, and the CI guard would fail on their
next commit.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>

* Add scripts/cleanup-dev-builds.sh for safely reclaiming tagged DerivedData (manaflow-ai#4837)

* Add scripts/cleanup-dev-builds.sh

Removes tagged dev-build artifacts produced by scripts/reload.sh:
DerivedData/cmux-<tag>/ (multi-GB each), /tmp/cmux-<tag>/, the per-tag
debug socket and logs, the reload log, and the App Support cmuxd dev
socket. Defaults to dry-run; pass --apply to delete.

Safety rules always on:
  - Skip the tag of any running `cmux DEV <tag>` app
  - Skip the tag pointed at by /tmp/cmux-last-cli-path
  - Skip any tag tied to a live git worktree
Filters: --older-than DAYS, --keep TAG (repeatable).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Drop "worktree exists" safety rule in cleanup-dev-builds.sh

Existence of a git worktree with the same name is a weak signal of
active use, and HQ tends to accumulate worktrees long after the
work is done. The rule made cleanup over-protective for the typical
case (worktree still around from a merged or abandoned PR).

The remaining safety rules (skip running app, skip the tag pointed
at by /tmp/cmux-last-cli-path) plus --keep TAG and --older-than DAYS
cover what we actually want without false positives.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Add /cleanup-builds slash command

Wraps scripts/cleanup-dev-builds.sh with the standard preview ->
confirm -> apply flow. Sits alongside the existing .claude/commands
(pull, sync-branch, release, etc.) and enforces user confirmation
before --apply.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* Address review feedback on cleanup-dev-builds

CodeRabbit + Greptile findings, all real:

- Active-tag extraction from /tmp/cmux-last-cli-path now uses a regex
  match on /cmux-<tag>/ anywhere in the path, not just a strict
  $DERIVED_DATA_ROOT/cmux- prefix. Also avoids the unquoted parameter
  expansion that could be sensitive to glob metacharacters in
  DERIVED_DATA_ROOT.
- discover_tags switched from find | xargs basename to a shell glob
  loop. Cleaner, works on macOS regardless of xargs flavor, handles
  the empty case naturally.
- --older-than no longer skips tags whose DerivedData was already
  deleted (age == -1 sentinel). Orphan sockets/logs for those tags
  now get cleaned instead of being silently retained.
- "freed" label reworded as "freed (estimated)" because the byte
  count is measured during planning, not after rm.
- .claude/commands/cleanup-builds.md: blank lines around fenced
  blocks (MD031).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>

* Fix agent resume when saved cwd is deleted (manaflow-ai#4859)

* test: cover agent resume with deleted cwd

* fix: resume agents when saved cwd is gone

* fix: harden restored cwd guard

* fix: skip ghostty cwd for guarded restore commands

* fix: drop duplicate cwd args on restore

* fix: preserve shell args during cwd cleanup

* fix: preserve custom resume cwd arguments

* fix: preserve shell syntax during cwd cleanup

* chore: remove unused shell word helper

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>

* Restore file preview text saving CI coverage

* Restore browser session history CI coverage

* chore(rename): swap bundle id, product name, config dir to most

Visual rename pass — upstream-merge friendly. Touches user-visible
surfaces only; keeps Swift identifiers, package dirs, env vars,
and on-disk xcodeproj/test target names so cmux upstream merges
remain conflict-free.

- pbxproj: PRODUCT_BUNDLE_IDENTIFIER com.cmuxterm.* → com.4etverg.most*
- pbxproj: PRODUCT_NAME cmux → most ("cmux DEV" → "most DEV")
- Entitlements: app group ids release/nightly → com.4etverg.most[.nightly]
- CLI config path: ~/.config/cmux/cmux.json → ~/.config/most/most.json
- One-shot legacy config migration in KeyboardShortcutSettingsFileStore
- README.md (English) user-visible refs flipped; upstream URLs preserved

Co-Authored-By: OpenAI Codex (gpt-5.4-mini) <noreply@openai.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(configuration): rename to most.json + document migration

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Lawrence Chen <lawrencecchen@users.noreply.github.com>
Co-authored-by: Abdulaziz Albahar <67667005+azooz2003-bit@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Co-authored-by: Lawrence Chen <54008264+lawrencecchen@users.noreply.github.com>
Co-authored-by: Konstantin <your@email.ar>
Co-authored-by: OpenAI Codex (gpt-5.4-mini) <noreply@openai.com>
li0near added a commit to li0near/cmux that referenced this pull request Jun 5, 2026
Documents the post-migration session-attach + host-adapter overhaul
landed across 8 commits (1c49bdf … e12028d):

  - §1 status table: new row "18 Dogfood: session-attach + host-
    adapter overhaul" ✅ done with full commit-range reference and
    summary of architectural changes (host-adapter restructure,
    logger seam, resolver paths 1 + 2, SSH transport scaffolding).

  - §14 progress log: append-only entry "[Phase 18]" walking the
    eight commits with their roles, the architectural pollution
    discovered + cleaned during dogfood (cross-instance panel-UUID
    overlap polluting the dev build's session snapshot), and the
    user-confirmed dogfood verification.

  - §16 deferred-task ledger: new entries J–N. Items A/B/C/G stay
    as pre-existing speculative deferrals.
      J. SSH "Set session id" UI (transport infrastructure shipped;
         activation UI deferred).
      K. Daemon-side process enumeration over RPC for remote
         workspaces (depends on cmuxd-remote work + manifest bump).
      L. Codex restored-snapshot transcriptPath resolution (path 1
         returns nil for codex; path 2 still works).
      M. Upstream cmux manaflow-ai#4777 changed the restore-command-into-PTY
         mechanism; AgentX-ray no longer depends on it but the user-
         visible scrollback change should be confirmed deliberate
         upstream.
      N. More aggressive split of AgentXrayWorkspaceHost — investigated
         and rejected during Phase 18 commit 1 design; documented for
         future reference so we don't re-litigate.

No code changes.
li0near added a commit to li0near/cmux that referenced this pull request Jun 5, 2026
Resolver path 3 + inline RemoteAttachPromptView lets users attach an
AgentX-ray panel to a Claude session running on a remote host. Persists
by (destination, cwd, agentKind=.claude) so workspace renames + UUID
resets across session restore don't strand the id.

Local paths 1/2 untouched; RemoteJSONLStream quoting unchanged. The new
ControlMaster=no addition only fires when controlPath is non-nil, which
no shipping caller sets today.

Includes:
- ControlPath piggyback so AgentX-ray's `ssh exec` rides cmux's
  existing ControlMaster (extracts ControlPath from the workspace
  remote configuration's sshOptions, mirroring the precedent in
  WorkspaceRemoteSSHBatchCommandBuilder).
- Per-tab SSH inference via TerminalSSHSessionDetector.parseSSHCommandLine
  so opening `ssh user@host` inside a local-workspace terminal also
  surfaces the prompt and AgentX-ray auto-swaps transcripts on tab
  switch across local + remote tabs.
- RemoteHomeResolver caches `ssh exec echo $HOME` per
  (destination, port, identityFile, controlPath) so synthesized
  transcript paths are absolute (no tilde leaves cmux).
- "Change" link in the StatusBarView clears the persisted id and re-
  surfaces the prompt.

Codex remote attach folded into MIGRATION_PLAN §16.L (date-bucketed
~/.codex/sessions/<y>/<m>/<d>/<sid>.jsonl needs an extra `ssh exec ls`
probe). §16.I closed (audit confirmed all spike PanelView features
already ported with renames). §16.M closed (research subagent verdict:
upstream cmux manaflow-ai#4777 scrollback disappearance is a deliberate refactor
side-effect, not a UX assertion — don't file).

Tests: 64 package tests pass (was 46; +RemoteSessionStoreTests with
9 cases + AgentSessionResolverPath3Tests with 8 cases). New app-target
RemoteHomeResolverTests wired into cmuxTests via pbxproj. cmux-unit
build green.

This branch was successfully deployed

1 active deployment
Preview – cmux — dc6dd63b Deployed May 27, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant