You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix: stop treating every self-created Cinna agent as a catalog install, and stop deleting server-hosted agents from the desktop. cinna-server stamps a non-null bundle_id on every agent at creation, so isBundleAgent reading bundle_uuid or bundle_id labelled an agent the user had just made "Uninstall agent" and, through canDevelopAgent, hid Develop from its own author; the predicate now requires bundle_uuid with an explicit is_publisher_install false, and canDevelopAgent calls it rather than restating it. The agent page's menu now offers Open on the server and nothing destructive, Delete agent stays for the direct connections this app really owns, and the unreachable agent:delete-remote channel, its preload binding, hook and service are removed rather than left as a destructive path no surface exercises.
fix: give a build workspace that belongs to a different Cinna account its own attention reason and a way out of it. Reconnect renames /Cloud/ aside with a timestamp and sets the signed-in account up fresh, running on the shared operation chain and re-reading the state after the wait so a workspace that has since recovered is never archived, while a rename the filesystem refuses comes back as state instead of a throw the Settings card swallowed silently. Re-authenticate runs the in-place OAuth round trip from the build page and the detail modal, and per-action pending state replaces the single busy flag so the button row cannot re-wrap under the user's own click.
docs: define which behavior belongs to Hub core and which belongs to desktop UI in the developer and reviewer instructions. Document platform and event injection, runtime ownership, handler boundaries and the moved desktop integrations. Record the offline and packaged validation results while keeping the remaining Linux and macOS SSH, authentication and supervision checks explicitly unverified.
test: update two stale offline E2E assumptions reproduced on the unchanged baseline. Select OpenCode explicitly and check its approval control alongside the independent delegation controls, then distinguish task-list discovery from legitimate Inbox detail reads. The full offline suite passes with 146 tests and three live-only skips.
test: guard the Hub boundary and exercise the shared runtime under plain Node. The offline spike activates a fixed profile, detaches a viewer, parks and answers a permission through Inbox, and verifies the completed transcript after reopening SQLite through a diagnostic adapter. Add import and bundle checks, a Linux CI job and a dedicated test target without introducing a production daemon or headless keystore.
refactor: extract the shared Hub runtime behind explicit platform services while keeping the desktop in process. Core startup, shutdown, readiness and event delivery no longer depend on Electron windows or IPC registration, and desktop integrations live behind injected host capabilities. Preserve desktop behavior with a transport-neutral handler registry, packaged adapter resolution and updated unit coverage.
test: E2E specs for folder Run All Jobs, Delete task, Show in the Chats list, Delete run on an orphaned row and Open on the server. A loopback A2A agent holds each run open until the test releases it, so running-run refusals and skips are exercised for real. The E2E guide lists the new fixture and the dialog strings.
feat: job page rebuilt like the task page — Run, Edit and a ⋯ with Delete job, Prompt and Tasks history on the left, a Details card on the right with the agent's location as the routing badge. Tasks history uses the Inbox row style, pages ten at a time with new runs on top, and only runs whose task is gone get a ⋯ with Delete run. The task page gains a ⋯ with Open on the server, Show in the Chats list (which reveals the row in the sidebar) and Delete task. Both Details cards take turns in the secondary buttons' border glow.
feat: deleting a job-run task removes its run and chat in one transaction, and task:delete-preview tells the dialog exactly what will go. Both task and run deletes refuse while the chat's run is still going, and share the full hard-delete cleanup with permanentDelete. Job runs carry taskLive, so a run whose task is gone can be told apart.
feat: job folder ⋯ menu replaces the gear — it opens beside the row, outside the sidebar, with Run All Jobs above Edit and Delete. Run All starts the folder's runnable jobs one at a time, re-checking each just before it starts so none runs twice. The menu closes on a scroll that moves its row, and the folder delete dialog is anchored at the top.
fix: frosted surfaces actually blur — lightningcss kept only the -webkit-backdrop-filter line when it followed the standard one, and Chromium ignores it. Popovers, dialogs and the dark sidebar now list the prefixed property first, so the standard blur survives the build.
feat: chat row summary tooltip takes the blurred floating-panel look and an occasional border glow — the same translucent, blurred shell as the routing badge's popover instead of a solid background. About one opening in three gets a single pass of the secondary buttons' border glow from a random corner, decided when it opens so a sweep down the list is not a row of lights. It follows the Extra UI animation preference and the existing reduced-motion rule, and is not part of the buttons' one-at-a-time scheduler.
chore: UX reviewer learns the hover tooltip pattern — the sidebar chat-row summary is the reference for any list the user scans for one row among similar ones. A scanning tooltip opens with no delay, complete or not at all, leads with what tells the rows apart and is not shown when it would only restate the row. One the user may act in or copy from sits adjacent to the block that opened it, takes pointer events and closes only after the pointer has left both. The reviewer drives it with the real mouse: sweep, straight and edge travel at several speeds, return to the row, diagonal aim, what it covers while rested on, what moves the trigger, and nested native titles.
test: E2E for the chat row summary tooltip — an agent chat's tooltip beside its row with the other agent, Started and Lasted, and a mode chat naming its mode. It stays open while the real pointer moves from the row onto it and goes once the pointer leaves both. An empty chat shows none, and a click on a hovered row still opens the chat with no tooltip left behind. The E2E guide lists the tooltip's accessible names and notes that chats seeded over IPC get summaries only after a relaunch.
feat: summary tooltip on sidebar chat rows — hovering a chat opens, at once and just right of the row, who it is with (agent type icon and name, or the chat mode, or the model), the other agents that took part, when it started and how long it lasted. It is hoverable: it stays open while the pointer moves onto it, closes shortly after leaving both, only one is ever open, and a chat with nothing to say beyond its start time shows none. Summaries are resolved in main and travel on their own un-polled chat:list-summaries channel, refreshed with the chat list's invalidations and when a background run ends, because chat:list is polled every second and the message scans must never ride on it. usePopover gains a right placement with a vertical clamp and now measures before paint.
test: E2E for the markdown Contents panel, and the file-refs spec reaching Open and Open folder through the ⋯ menu
feat: Contents panel for long markdown previews — H1–H4 headings, click to scroll, current section followed, the card widening to the right or the panel overlaying in narrow windows. Open and Open folder move into a ⋯ menu in the preview header.
test: E2E for bare, kit and cloud delegations and their permission settings, and the file-handover spec for the shared gate
feat: handover bus — any folder agent can delegate to a bare folder, a kit agent or a cloud agent through the cinna handover tools, with one delegation record, depth cap, gate and wake across the file, local and cloud channels; contract clauses for out-of-folder writes and folder-session MCP
feat: render markdown frontmatter as a key/value card, and JSON previews as a collapsible tree
switch default theme to system instead of a dark theme
test: drop the Claude whole-flow placeholder, which no test change can unblock
test: let the tool-loop reattach spec accept the open round's in-flight draft row
fix: publish a conductor's Cinna tool block only after the engine's own tool_call notice, so it no longer lands above the text before it
test: expect a streamed failed A2A task to keep its answer as a row above a generic error
test: update E2E specs for the wire-only turn header and the chat mode form redesign
fix: keep a Claude subagent's work in its own lane, nested under its Agent call, so it no longer cuts the agent's reply mid-word or speaks as the agent, and keep single newlines in user bubbles
fix: check the accent-tinted file reference fill in the stylesheet test, matching 85aee61
fix: show on Settings → Features what AI Functions actually run on, decided in main
fix: allow a conductor's Cinna tool asks only for tools Cinna offered it, and keep short Codex titles that prefix the prompt
feat: allow Cinna tool asks on conducting sessions, name Codex chats by their thread title, and close runtime follow-ups
feat: add the whole-flow level for the pinned runtimes
feat: run Claude Code on a pinned CLI too, reuse an exact-version install, and contract it
feat: run Codex on a pinned CLI that Cinna installs, with an interface contract
fix: give a Codex conductor a new session when its tools change
fix: close runtime conductor review findings
feat: enable restricted Codex chat and utility sessions
fix: preserve runtime function instructions and pause rate-limited conductors
feat: run chat coordination through local ACP runtimes
Add file handovers: any adopted bare folder accepts .cinna/handovers//brief.md, which the desktop records as a task for that folder's agent, gates in the Inbox (or auto-runs where the agent allows it and the directory is git-ignored), tracks through report.md, and returns to the requesting chat as a system turn, with revisions and fan-out groups. Bare agents now run on the folder's native setup — Claude with the user's settings, hooks, skills and MCP servers under the claude_code preset, Codex with the desktop context as developer instructions — while kit folders and the build session stay isolated. Agents learn their id and the protocol in the system prompt and their chat, task and depth in a wire-only turn header.