Skip to content

Make new thread workspace intent explicit#118

Merged
yaacovcorcos merged 21 commits into
mainfrom
agent/safer-new-thread-workspace-20260724
Jul 24, 2026
Merged

Make new thread workspace intent explicit#118
yaacovcorcos merged 21 commits into
mainfrom
agent/safer-new-thread-workspace-20260724

Conversation

@yaacovcorcos

@yaacovcorcos yaacovcorcos commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Outcome

Ordinary New Thread actions now use the project's configured default workspace instead of silently inheriting the branch or worktree of the thread being viewed. Users who intentionally want that checkout get an explicit context-menu action:

  • New thread on branch (...)
  • New thread in worktree (...)

This keeps the safe default and the expert continuation workflow together.

Scient-native adaptation

  • Adds typed workspace intents: project-default, local-container, existing-local, and existing-worktree.
  • Routes global, provider, editor, terminal, Studio/container, sidebar, App Snap, recent-view, /clear, and pull-request entry points through one ownership/supersession coordinator.
  • Preserves prompts and attachments until the intended destination actually commits.
  • Validates exact branch/worktree context after navigation ownership and fails closed if it moved or disappeared.
  • Serializes non-cancellable pull-request preparation before later presentation changes.
  • Uses a supported global TanStack history blocker for push/replace/Back/Forward, with per-renderer tokens safe across reloads and long histories.
  • Separates route commitment from slower post-navigation work. A committed terminal destination remains valid browser history while native terminal promotion is pending.
  • Keeps Studio/container creation intentionally local for both fresh and reuse-eligible flows.
  • Preserves Scient identity, provider/session behavior, credentials, permissions, updater/release controls, and Git mutation boundaries.

Concurrency and data-loss fixes

The final candidate closes all issues found during review:

  1. Stored/route draft reuse and fresh creation share one ordered coordinator; an older request cannot replace a newer mapping or delete its prompt/attachments.
  2. Global browser navigation supersedes in-flight new-thread work through the actual history destination seam.
  3. Route tokens use a random renderer-session namespace and track only genuinely uncommitted destinations; reloads and histories beyond 128 entries remain valid.
  4. Stored and fresh owned routes preflight exact ownership before bypassing the approved history blocker.
  5. Once a route commits, markRouteCommitted() releases its token before slow terminal promotion. Deterministic unit and real-router Back tests keep promotion pending and prove the committed destination restores correctly.
  6. Terminal project-default fallback is truthful local mode when no concrete worktree exists.
  7. Reuse-eligible Studio/container creation cannot fall back to an unrelated project worktree.

Mainline composition

  • Final base: cfc702a
  • Final candidate: a96d3c6
  • Branch: agent/safer-new-thread-workspace-20260724

Current main was merged normally, without rebase or force-push. The earlier Sidebar conflict was resolved by preserving both #111's truthful automation/status/shortcut behavior and this PR's explicit workspace-intent menu. Main changes from #114, #103, #120, and #115 are included. The #115 Add Project drag/drop implementation is byte-identical to current main after composition, preserving its document-level file-drop guard and popup behavior.

Donor provenance and disposition

  • T3 Code reference: 2f41c073a2f846e9a96082e76cd1b2c3a7e44c18, “Stop new threads inheriting checkout/branch from viewed thread.”
  • Disposition: Adapt/Reimplement the safety and interaction concept on Scient-owned seams.
  • No donor code was copied or cherry-picked.
  • T3-specific sidebar versions, command-palette architecture, persistence assumptions, and broad thread-action refactors were not adopted.
  • This PR does not advance the parent T3 review boundary or claim review of the complete intervening donor range.

Exact verification

At exact final head a96d3c6:

  • bun run scient:upstream-check --intake — passed:
    • Scient brand/identity
    • full format verification
    • lint: 0 errors
    • all package typechecks
    • complete bun run test matrix, including web 3,087/3,087
    • desktop/web builds
    • release smoke
    • clean-worktree certification
  • Focused affected unit tests — 53/53 passed.
  • Real-router navigation tests — 3/3 passed, including Back during delayed terminal promotion.
  • Stable browser matrix — 345 passed, 19 skipped.
  • Geometry matrix — 19 passed, 345 skipped by geometry configuration.
  • Real Electron overlay lifecycle — passed:
    • heldOccludedMs: 31250
    • openMode: suppress
    • closeMode: send
    • recovered width: 700
  • git diff --check — passed.
  • Verification left no tracked or untracked artifacts.

The stable browser runner emitted its known nonfatal ResizeObserver-loop console noise while every process exited successfully. Electron emitted a nonfatal Mojo diagnostic while lifecycle acceptance passed.

Independent final review

Exactly three fresh, independent, read-only reviews examined base ca615ee to exact candidate 35dfc78 after final verification:

  1. Correctness/reliability/concurrency/performance: P0 0, P1 0, P2 0, P3 0.
  2. Security/privacy/data loss/release safety: P0 0, P1 0, P2 0, P3 0.
  3. Architecture/maintainability/product design/accessibility/lineage: P0 0, P1 0, P2 0; one P3 evidence recommendation only.

There are no unresolved P0, P1, or P2 findings.

Manual and UI evidence

Earlier isolated native-app validation confirmed:

  • the context menu displayed New thread on branch (agent/safer-new-thread-workspace-20260724);
  • activation produced a Local draft with the exact selected branch;
  • the exercised flow had no browser warnings or errors;
  • the responsive state was inspected at 768 px.

The visible wording and action are unchanged in the final head. A retained native-menu screenshot/recording and explicit keyboard/assistive-technology capture remain a P3 evidence recommendation, not a code blocker. Screen-reader and zoom testing were not performed; no new custom control or visual system was introduced.

Risk, rollback, and release boundary

  • Primary risk is new-thread routing and draft ownership under rapid or interleaved navigation; deterministic regression coverage exercises the identified interleavings.
  • No feature-owned server migration, credential, permission, updater, signing, packaging, or publication behavior is introduced.
  • Rollback after integration: revert the PR merge. Stored workspace-origin decoding remains backward-compatible.
  • This PR remains draft. Do not merge, mark ready, or include in a release until hosted checks for the exact head are green and the merge steward explicitly approves it.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL labels Jul 24, 2026
@yaacovcorcos yaacovcorcos added the on-hold Work intentionally paused; do not merge until explicitly resumed. label Jul 24, 2026
@github-actions github-actions Bot added size:XXL and removed size:XL labels Jul 24, 2026
@yaacovcorcos
yaacovcorcos marked this pull request as ready for review July 24, 2026 21:36
@yaacovcorcos yaacovcorcos removed the on-hold Work intentionally paused; do not merge until explicitly resumed. label Jul 24, 2026
@yaacovcorcos
yaacovcorcos merged commit 341055d into main Jul 24, 2026
15 checks passed
@yaacovcorcos
yaacovcorcos deleted the agent/safer-new-thread-workspace-20260724 branch July 24, 2026 21:36
yaacovcorcos added a commit that referenced this pull request Jul 24, 2026
* Route telemetry through ScientFactory gateway (#43)

* Fix unsigned macOS release signatures (#44)

* Add consent-aware desktop analytics (#47)

* Fix Claude terminal auth and connection recovery (#52)

* fix provider status refresh invariants

* fix Claude auth recovery

* Use direct OAuth for Grok sign-in (#53)

* Use direct OAuth for Grok sign-in

* Expose safe Grok OAuth browser fallback

* Secure Scient state initialization (#48)

* Secure Scient state initialization

* Allow legacy migration state test

* fix(security): harden private state files

* test(security): lock private file boundaries

* fix(security): reject unsafe private file nodes

* Supervise the desktop backend lifecycle (#49)

* Supervise the desktop backend lifecycle

* fix(desktop): preserve backend lifecycle ownership

* fix(desktop): replace semantically unready backends

* fix(desktop): close backend lifecycle races

* Supervise desktop connection recovery (#50)

* Supervise desktop connection recovery

* Isolate provider dialog browser fixtures

* fix(desktop): bind activation readiness generation

* fix(web): enforce single-owner connection recovery

* style(web): format connection recovery

* fix(web): satisfy connection transport types

* fix(web): harden stream and terminal recovery

* fix(web): fail closed on stuck stream cancellation

* fix(web): preserve terminal recovery ordering

* fix(web): clamp reconnect jitter ceilings

* fix(desktop): preserve connection wake after restack

* Define safe RPC recovery policies (#51)

* Define safe RPC recovery policies

* test(web): cover RPC recovery integration

* fix(web): recover after uncertain mutation failures

* test(web): type RPC recovery harness precisely

* fix(web): recover a failed replay generation

* Surface connection recovery diagnostics (#55)

* Surface connection recovery diagnostics

* test(web): cover connection recovery experience

* style(web): format recovery browser coverage

* fix(web): keep recovery diagnostics current

* Recover Codex sessions after authentication loss (#56)

* fix: recover Codex sessions after auth loss

* fix(codex): gate auth recovery by provider mode

* fix: harden Codex authentication recovery

* Support Linux desktop development launch (#57)

* Secure Scient state initialization

* Allow legacy migration state test

* Supervise the desktop backend lifecycle

* Supervise desktop connection recovery

* Define safe RPC recovery policies

* Surface connection recovery diagnostics

* Support Linux desktop development launch

* Isolate provider dialog browser fixtures

* fix(desktop): fail closed on unsafe Linux sandbox

* style(desktop): format Linux launcher hardening

* fix(release): preserve AppImage sandbox

* revert(release): keep AppImage migration out of launcher hardening

* fix(desktop): honor Linux user namespace sandbox

* Fix Antigravity browser authentication (#59)

* Fix Antigravity browser authentication

* Harden Antigravity authentication lifecycle

* Close Antigravity code window deterministically

* Keep Antigravity code submission cancellable

* Scope desktop signing credentials by platform (#60)

* Fix managed Antigravity updates, authentication, and dialog UX (#62)

* Fix trusted Antigravity install and update routing

* Fix Antigravity browser authentication and models

* Refine provider connection dialog actions

* Harden managed provider update recovery

* Stabilize macOS release identity (#63)

* Reduce unintended macOS permission prompts (#64)

* Stabilize macOS release identity

* Reduce unintended macOS permission prompts

* Apply repository formatting

* Control macOS notarization lifecycle (#65)

* Add Evidence to Note as a latent built-in (#70)

* Harden bidirectional chat rendering (#71)

* feat(web): harden bidirectional chat rendering

* fix(web): close bidi review gaps

* Add Medical Exam Study built-in (#72)

* Fix YAML frontmatter in Markdown previews (#69)

* Add T3-inspired project source dialog (#76)

* Add project source dialog

* Harden project source cloning

* Add T3-style right dock surfaces (#77)

* Add T3-style right dock surfaces

* Fix right dock test formatting

* fix: remove AppSnap startup announcement (#80)

* Add artifact preview cards to chat (#81)

* fix: select providers after connection (#82)

* Add message-level conversation forks (#78)

* Add message-level conversation forks

* Stabilize hosted fork browser test

* Close message fork boundary gaps

* Close final fork review gaps

* Resolve final fork recertification blockers

* Avoid replaying completed fork bootstrap

* Harden fork lineage and restart recovery

* Stabilize cold browser geometry startup

* Repair legacy fork title families

* Preserve unrecorded fork rename boundaries

* Clear drifted fork title lineage

* Improve desktop contribution workflow (#75)

* Set default base font to 15px and fix numeric editing (#79)

* Increase default base font size to 15px

* Fix manual font size editing

* Preserve external font setting updates

* Use recommended provider model defaults (#83)

* Use recommended provider model defaults

* Apply repository formatting

* Update browser expectation for Codex default

* Preserve explicit drafts before model discovery

* Respect live provider model availability

* Align desktop approval policy (#85)

* Fix release-candidate regressions (#86)

* Fix release candidate regressions

* Fix long transcript fork validation

* fix(release): preserve Linux sandbox (#87)

* fix(release): preserve Linux sandbox

* test(release): resolve nested builder package

* test(release): follow Bun package symlinks

* fix: preserve whitespace in folder browsing (#90)

* Collapse long assistant artifact shelves (#91)

* Remove project setup confirmation card (#93)

* Build unified notification system (#96)

* Hide provider setup banner on empty chats (#94)

* Hide provider setup banner on empty chats

* Stabilize empty provider banner coverage

* Harden provider banner browser readiness

* Fix Droid model discovery lifecycle (#95)

* Add ChatGPT-first voice transcription with local Whisper fallback (#97)

* feat(voice): define transcription backend contract

* feat(voice): add verified local transcription core

* Fix ChatGPT voice account context

* feat(voice): add ChatGPT-first local Whisper fallback

* Default Git writing to GPT-5.6 Luna (#99)

* Apply updated settings defaults once (#101)

* Apply updated settings defaults once

* Enable Studio in its browser fixture

* Improve voice dictation and active-turn composer controls (#102)

* Improve voice recording controls

* Add live local voice previews

* Keep voice send locked through completion

* Keep active-turn composer actions available

* Pin Whisper runtime source revision

* Fix voice transition regressions

* Fix folder picker navigation and project opening (#98)

* Fix folder picker navigation and project opening

* Tighten project setup choices

* Prevent duplicate folder picker submissions

* Fix Whisper runtime packaging on Windows (#104)

* fix: make Whisper packaging cross-platform safe

* fix: verify signed Windows Whisper runtime

* Secure HTML artifact previews with isolated execution (#100)

* feat: add secure HTML artifact previews

* fix: enforce HTML preview ownership boundaries

* Document cross-platform manual verification

* Use trash icon for voice cancel action (#106)

* Fix browser pane close and runtime recovery (#113)

* Isolate temporary Claude discovery from MCP servers (#116)

* Respect reduced motion in thread spinner (#84)

Adapt the upstream accessibility concept while retaining Scient-owned spinner geometry.

* Harden upstream-derived release tooling (#109)

* Salvage safe PR 61 interaction improvements (#107)

* Salvage safe PR 61 interaction improvements

* Harden terminal selection copy handling

* Adapt Studio Git gating and folder access (#108)

* Adapt Studio folder controls from Synara

* Gate Studio review command on repository detection

* Improve changed-file accessibility and density (#110)

* Add compact previews for bulky changed-file cards (#117)

* Improve changed-file accessibility and density

* Add compact changed-file previews

* Ensure changed-file previews show every file

* feat: add curated in-app release notes (#112)

* feat: add curated release notes workflow

* fix: harden release note experience

* refactor: share release note footer layout

* test: keep release note diagnostics concise

* Reject developer-facing release note copy

* Revert "Reject developer-facing release note copy"

This reverts commit 1006003.

* Harden release note structural validation

* Harden release note asset validation

* Resolve release note certification findings

* Bound release note PNG chunk parsing

* Validate all release note PNG chunk CRCs

* Fix browser multi-tab controls and menu occlusion (#119)

* Fix browser multi-tab controls and menu occlusion

* Keep browser sessions alive under overlays

* Harden browser overlay lifecycle coverage

* Complete browser tab and overlay semantics

* Restore focus after final browser tab closes

* Synchronize split-pane browser focus

* Harden Electron overlay lifecycle runner

* Isolate macOS Electron test bundle state

* Keep Electron lifecycle tests fully hermetic

* Resolve Electron sandbox from workspace package

* Guarantee Electron test harness cleanup

* Register Electron fixture cleanup immediately

* Restore focus after browser close controls

* Complete browser close focus recovery

* Handle early Electron test interruptions

* Cover earliest Electron setup interruption

* Refine branch and automation workflow affordances (#111)

* Refine upstream-derived workflow affordances

* Respect resolved automation triage state

* Fix native branch clipboard acceptance

* Document native workflow UX acceptance

* Add universal local file viewer (#114)

* Add universal local file viewer

* Harden local HTML preview capabilities

* Resolve HTML preview review blockers

* Close final HTML preview review gaps

* Fail closed on truncated active HTML

* Preserve complex HTML preview dependencies

* Fail closed on SVG runtime link mutation

* Block alternate network egress in HTML previews

* Recover HTML preview network setup

* Serialize HTML preview retries

* Occlude native HTML previews under overlays

* Harden provider installation and sign-in (#103)

* Harden provider installation and sign-in

* Fix Windows provider runtime test fixtures

* Make Windows PATH test path-stable

* Close provider onboarding reliability gaps

* Keep post-install sign-in recovery on the correct path

* Canonicalize Windows runtime discovery test paths

* Harden provider device-code recovery

* Harden OpenCode and Kilo turn completion (#120)

* Harden OpenCode and Kilo turn completion

* fix(provider): isolate OpenCode turn completion ownership

* fix(provider): close OpenCode completion review races

* fix(provider): fence OpenCode reply and replay races

* fix(provider): clean interrupted OpenCode replies

* fix(provider): harden OpenCode interaction ownership

* fix(provider): fail closed on ambiguous replies

* Harden OpenCode lifecycle retirement

* Serialize OpenCode session retirement

* Make OpenCode retirement interruption safe

* Finalize confirmed OpenCode process exits

* Add native folder drop to Add Project (#115)

* feat(projects): add native folder drop intake

* fix(projects): harden folder drop feedback

* fix(projects): keep folder errors visible

* fix(projects): preserve compact folder dialog footer

* fix(projects): harden native folder intake

* docs(qa): align folder intake evidence

* fix(projects): scope folder drop to dialog

* test(projects): cover platform folder labels

* docs: correct folder drop verification evidence

* docs: qualify native drag evidence

* docs: refresh folder drop verification evidence

* docs: refresh folder drop certification evidence

* docs: recertify folder drop on latest main

* Neutralize project drops outside dialog

* Update folder drop acceptance evidence

* Make new thread workspace intent explicit (#118)

* fix(web): make new thread workspace intent explicit

* fix(web): serialize distinct new thread intents

* test(web): type exact workspace branch mocks

* fix(web): preserve new thread request ordering

* fix(web): preserve latest new thread intent

* fix(web): coordinate all new thread navigation

* fix(web): preserve latest navigation across preparation

* fix(web): close remaining navigation races

* chore: clean merged sidebar imports

* fix(web): close terminal and route ownership gaps

* fix(web): coordinate every new-thread route intent

* fix(web): enforce route ownership before history commits

* test(web): use typed routes in navigation guard proof

* fix(web): release committed navigation ownership

* docs: add Scient 0.5.13 release notes

* chore: keep promotion tree aligned with main

* chore: restore test cleanup in promotion tree

* chore: align promotion test tree
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant