fix(contracts): tolerate unknown keybinding commands on client decode - #238
Open
bulgadev wants to merge 89 commits into
Open
fix(contracts): tolerate unknown keybinding commands on client decode#238bulgadev wants to merge 89 commits into
bulgadev wants to merge 89 commits into
Conversation
Add custom "Open with" applications Source: tim-smart#4 Source head: 8c4bdfb Source commits: 08e1a4f,cd43a401c6c148f1fe26cff72104ac527ea189f3,a8370e7502c552ebb064436e42e1c00f86f0946b,8c4bdfbc5b57f6b600233244d330f9efa41dc498 Imported: complete product delta from the source PR. (cherry picked from commit 9fae005)
Load direnv environments for provider sessions Source: tim-smart#5 Source head: 8f5fc87 Source commits: e4f0701,0d1463af61e0bd174f698b2519ebf3b207a2eaca,a66e4160d5f4b79140ec8fbcbc6aa66af750a991,8f5fc87c13f4628c179cda44d4f32f7fe4d316b2 Imported: complete product delta from the source PR. (cherry picked from commit 0da8bfe)
Add unsigned retry for commit signing failures Source: tim-smart#6 Source head: 7d65c5a Source commits: 18ee567,72a6fae23c86708080c4fed346d5bf0f136f0221,6614b28239ed2330a8f601357a413f2d50da195a,ec169369daa554541511aa28f551b36f3dd26485,7d65c5a224e97a6b811b0a84892f1fda065c5963 Imported: complete product delta from the source PR. (cherry picked from commit 03671a2)
Add /new command for contextual threads Source: tim-smart#7 Source head: 2051a80 Source commits: 2051a80 Imported: complete product delta from the source PR. (cherry picked from commit 4d94f31)
Add session dashboard board Source: tim-smart#8 Source head: d9f8e4d Source commits: 268fb8d,dde20f271f674da22dd8f3a08201c2acf5e58ee5,df4a145e7b2cd2dc17a7a595267d2d8eb0a2a3f0,ce5723ddb0bf630a18d4cb8227b5344d12626e72,ad8c1a6af41161e1fc38a52f681b306517c7b918,6281887e6125317da0c7b4252d59bfd41c9bf35e,550db6316c634febdbe1cb27334d1347c23c7b2a,d9f8e4d0a8dc22231ca315f3c595c3597f3b13e5 Imported: complete product delta from the source PR. (cherry picked from commit cd0e281)
Recover interrupted provider turns after server restarts Source: tim-smart#9 Source head: b181832 Source commits: 7f69028,1d52bce1376766d804ef884d7d50b8b6d1b48cf7,b181832560177250b90bbfe07b0882c9e5b93493 Imported: complete product delta from the source PR. (cherry picked from commit 83de8f5)
Avoid repeated thread snapshot loads during subscription retries Source: tim-smart#10 Source head: c8c9ead Source commits: c8c9ead Imported: complete product delta from the source PR. (cherry picked from commit 9e400c3)
Add image upload button to compact chat composer Source: tim-smart#11 Source head: 1ff63f9 Source commits: 1ff63f9 Imported: complete product delta from the source PR. (cherry picked from commit 720ec65)
Truncate mobile branch toolbar controls Source: tim-smart#12 Source head: 1b7d444 Source commits: 1b7d444 Imported: complete product delta from the source PR. (cherry picked from commit dc2bbb4)
Clean up worktrees when archiving threads Source: tim-smart#13 Source head: a23f42d Source commits: 4a19470,1b6688aa5b641010cb2e9dad23d36d87257403ad,9ed32aa3923fb674380564b1ffcb3268290069b9,a23f42d6ac671ea36b8db5d03934c089a31be448 Imported: complete product delta from the source PR. (cherry picked from commit 7e02dc9)
Pass hosted app channel into Vercel web builds Source: tim-smart#14 Source head: de6966a Source commits: de6966a Imported: complete product delta from the source PR. (cherry picked from commit 6333d8d)
Allow worktrees to reuse the selected branch Source: tim-smart#15 Source head: 2d3900b Source commits: cd60531,2d3900ba36c9397dc4fbe879c613a809f6b45384 Imported: complete product delta from the source PR. (cherry picked from commit 5e7dff2)
Add optional worktree removal confirmation Source: tim-smart#16 Source head: c3f509f Source commits: 76f063e,c3f509fe8f690b704bb34692d9c132c0644db777 Imported: complete product delta from the source PR. (cherry picked from commit 9886109)
Stop retrying unavailable thread subscriptions Source: tim-smart#17 Source head: 1359af8 Source commits: 1359af8 Imported: complete product delta from the source PR. (cherry picked from commit 7b37a7a)
Compatibility fix for running the selected Tim stack on the fork CI matrix. Source adaptation review: patroza#31. (cherry picked from commit 6edd39a)
Keep the selected Tim Open With feature portable on non-macOS builders and avoid treating custom app definitions as macOS bundles. Source adaptation review: patroza#33. (cherry picked from commit 15a7d2a)
…nd; green tip Bring Tim layer tip to typecheck green by joining main ref-refresh VCS client state with fork failureKind/worktree-cleanup contracts, restoring filterBrowseEntries/reuse-base-branch surfaces Tim dropped, and fixing ChatView/Board call-site type errors left by incomplete Tim joins. (cherry picked from commit 0e24917)
Bring fork/tim typecheck/test green after main pingdotgg#2679 + Tim client-runtime rewrite: rejoin EnvironmentSubscriptionRpcTag/localApi/ws scopes, wire BackgroundPolicy/ResourceTelemetry layers, force openpgp for signing tests on hosts with gpg.format=ssh, and treat TRACE2 child_exit without child_class as hook finish (git 2.55+).
…troza#29) Source: pingdotgg#4018 Source SHA: de8fd65 Imported: bounded server activity snapshots, cursor pagination, lazy web history loading, reconnect-safe reset/dedup, and disabled eager browser sidebar hydration. Adapted: preserved Tim thread lifecycle handling and Omega composer/minimap behavior while resolving current-stack conflicts. Excluded: none of the source PR behavior; native mobile pagination remains separate because pingdotgg#4018 intentionally excludes it.
…#3510) (patroza#35) Source: pingdotgg#3510 Source SHA: 034f493 Imported: native mobile lazy loading for older thread activity, a 1,000-event subscription catch-up ceiling with snapshot fallback, and synchronized stale snapshot watermarks. Adapted: applied above the refreshed pingdotgg#4018 web/server candidate and preserved Tim lifecycle handling plus our mobile composer changes. Excluded: pingdotgg#3510 server/web pagination duplicated by pingdotgg#4018, the later shared-hook refactor, formatting-only commits, and contract comments. The shared refactor can be revisited independently after production validation.
…oza#34) Source: pingdotgg#4176 Source SHA: 56b6615 Imported: O(1) command read-model maps, deleted-thread eviction, VCS cache cleanup, browser surface cleanup, preview idle TTL, and per-thread UI cleanup. Adapted: preserved our thread settlement, snooze, and sequential worktree deletion actions while wiring upstream cleanup into the current hook. Excluded: none. Co-authored-by: Rusiru Sadathana <27785781+RusiruSadathana@users.noreply.github.com>
patroza#44) Source: pingdotgg#4506 Source SHA: f7eaa00 Imported unchanged as one candidate provenance commit.
…tgg#4558) Imported from https://github.com/pingdotgg/t3code/pull/4558\n\nAdapted to retain our provider restart-recovery constants while replacing the local default-title check with the shared policy.
After rebasing candidates onto the green tim tip, restore missing EnvironmentThread loading fields, ChatView sendDisabledReason/threadSyncPhase wiring, and orchestration.getThreadActivities auth coverage.
…oza#215) * fix(stack): repair post-restack CI breakage from product merges Drop the accidental createdAt on thread.title.regeneration.complete so it matches upstream and production dispatch, fix Hermes-unsafe toSorted in thread search keys, and refresh title-regeneration/supervisor test fixtures for the expanded wakeup and command-read-model shapes. * fix(server): declare auth scopes for searchThreads WS RPCs Mirror RpcAuthorization entries in the ws.ts runtime scope map so orchestration.searchThreads (and serverUpdateServerWithProgress) authorize instead of throwing at the router seam. --------- Co-authored-by: T3 Code PR Stack <41898282+github-actions[bot]@users.noreply.github.com>
…roza#220) ws.ts kept a parallel RPC_REQUIRED_SCOPE Map while RpcAuthorization.ts owned the typed RPC_REQUIRED_SCOPES table. Identity methods were added only to the typed table, so production failed with "has no declared authorization scope" for identity.getSessionClaim. Route observeRpc* through requiredScopeForRpcMethod and drop the Map. Co-authored-by: T3 Code PR Stack <41898282+github-actions[bot]@users.noreply.github.com>
That durable conflict resolution reintroduced the pre-pingdotgg#2679 RPC auth Map on every restack, undoing typed requiredScopeForRpcMethod. Tim product deltas in ws.ts must 3-way merge with main's auth path instead.
Co-authored-by: T3 Code PR Stack <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: T3 Code PR Stack <41898282+github-actions[bot]@users.noreply.github.com>
* fix(stack): forbid blind product conflict resolution * refactor(stack): protect future workspace sources by structure --------- Co-authored-by: T3 Code PR Stack <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: T3 Code PR Stack <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: T3 Code PR Stack <41898282+github-actions[bot]@users.noreply.github.com>
* Revert "fix(mobile): keep conversation feed visible (patroza#232)" This reverts commit bb01fe8. * Revert "fix(mobile): reduce thread feed scroll jank (pingdotgg#4874)" This reverts commit 9e3e9bb. --------- Co-authored-by: T3 Code PR Stack <41898282+github-actions[bot]@users.noreply.github.com>
…ng up (pingdotgg#4867)" (patroza#235) This reverts commit 90f3913. Co-authored-by: T3 Code PR Stack <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: T3 Code PR Stack <41898282+github-actions[bot]@users.noreply.github.com>
The server's keybinding command set grows over time (e.g. filePicker.toggle, projectSearch.toggle). A client built against an older contracts build must not fail to decode the entire server.getConfig response because one rule references an unknown command. ResolvedKeybindingsConfig now drops rules whose command does not match the known union on decode, while keeping encoding and server-side authoring validation unchanged. This is a forward-compatibility fix: the closed KeybindingCommand union stays strict for authoring (KeybindingRule / KeybindingsConfig), but the resolved config array (consumed by getConfig, subscribeServerConfig, upsert, and remove across vscode, web, and mobile) silently skips unknown entries. Co-Authored-By: Claude <noreply@anthropic.com>
Owner
|
Thanks a lot for the contribution! Requesting changes:
|
patroza
force-pushed
the
fork/changes
branch
15 times, most recently
from
August 1, 2026 07:06
46a7aa8 to
d8ee8ae
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
When a T3 Code server introduces new keybinding commands (e.g.
filePicker.toggle,projectSearch.toggle), clients built against an older contracts build fail to decode the entireserver.getConfigresponse becauseResolvedKeybindingsConfiguses a closed union (KeybindingCommand) that rejects unknown values.This manifested in the VS Code extension as:
The pairing itself succeeded (bearer token exchanged and stored), but the subsequent
getConfigRPC failed during schema validation, blocking the connection.Solution
Make the decode side of
ResolvedKeybindingsConfigforward-compatible: rules whosecommanddoes not match the known union are silently dropped on decode, while known rules round-trip unchanged. Encoding is unaffected, so the server (which only ever emits known commands) and the strict authoring path (KeybindingRule/KeybindingsConfig) keep their exact behavior.This is the same forward-compat pattern used elsewhere in the codebase (e.g.
ProviderOptionSelectionsinmodel.tstolerates legacy shapes viaSchema.decodeTo+transformOrFail).Scope
ResolvedKeybindingsConfigis consumed by all four wire schemas that carry resolved keybindings:server.getConfig(initial config fetch)subscribeServerConfig(config stream)serverUpsertKeybinding/serverRemoveKeybinding(mutation results)All three clients (vscode, web, mobile) share the same
RpcClient.make(WsRpcGroup)decode path, so this fix unblocks all of them simultaneously.Changes
packages/contracts/src/keybindings.ts: wrapResolvedKeybindingsConfigwith adecodeTotransform that filters unknown rules viaSchema.decodeUnknownOption(ResolvedKeybindingRule)per element.packages/contracts/src/keybindings.test.ts: two new tests verifying unknown commands are dropped and all-unknown arrays decode as empty.Verification
pnpm --filter @t3tools/contracts test: 238 tests passed (19 files)pnpm exec vp check packages/contracts/src/keybindings.ts packages/contracts/src/keybindings.test.ts: 0 errors, 0 warningsELECTRON_SKIP_BINARY_DOWNLOAD=1 pnpm exec vp run -r --cache --log labeled typecheck: exit 0