Native harness audit: accepted reliability and instruction fixes - #585
Merged
Merged
Conversation
Implement the accepted native harness audit scope with regression coverage. Preserve one queued-send flow, restore applicable guidance, isolate connection generations, and keep native question answers independent. Process-group escalation remains deferred; Claude Code credential projection and duplicate-question behavior remain unchanged. Submitted via YouCoded Assistant
Resolves conflicts with the admin-password feature: toolWiring keeps both the captured instruction chain and the RunningCalls options; Bash keeps its named close/error listeners (so a failed hand-off still settles) and now also runs onCallExit from them. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… logs
- Rule path patterns: {a,b} alternatives and [abc] character classes now
match instead of silently never firing; a leading / or ./ anchors at the
rule's folder; unreadable patterns are logged.
- Instructions panel: plain-words notes instead of the model-facing notice,
folder names instead of long paths, a named "Shortened" summary, and a
note when a same-folder CLAUDE.md was not used because AGENTS.md was.
- MCP: an excluded server's real error is logged again, with every
credential value it was given blanked out.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… first Per Destin's PR-review decisions (2026-09-28): - A message sent while the assistant works is read once the whole batch of actions it already chose has run, instead of cancelling unstarted ones. - A message that joins the running turn starts the "keep going?" step count over. - When instruction files don't all fit, the session folder's own file takes the room it needs first; broader parent files get what is left and are still named if squeezed out. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A repeat Read of an unchanged file loaded, decoded and line-split the whole file on the main process before comparing it (~140 ms stall at 50 MB, affecting every window). It is now checked in 256 KB pieces before loading anything; measured longest stall at 50 MB drops to ~1 ms. Changed files are still read normally and the content comparison stays exact. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…wn check Under load the 50 ms test poll could land before the check and fail a correct dialog; the read is now released explicitly with reveal(). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…inue Per Destin's PR-review decision (Q-5, 2026-09-28): when project rules that apply to a file about to change cannot fit a small model, the model is shown the shortened rules (each naming the file to read for the rest) and asked again, exactly as when they fit. The earlier refusal ended the turn silently and left small models unable to edit files in rule-heavy projects. Rules are shown once, so the re-issued change runs; there is no loop. This reverses the accepted requirement "refuse changes when guidance cannot fit" at Destin's direction. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Per Destin (2026-09-28): a message waiting behind a busy task gets a Send now button that stops the current task, like Stop, and sends that message next, ahead of other waiting messages. New native:queue-send-now request on every surface (desktop IPC, remote WebSocket, remote shim; Android replies not-implemented like queue-remove). The practice app can now queue messages (?queueSends=1) so the strip can be reviewed. Line budgets raised by the plumbing each surface needs: native-session-host +15, App +11, remote-server +6, ipc-handlers +3, types +3, preload +2, remote-shim +1. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…sweeps They take 1.5-7 s alone and passed 30 s under verify.sh's all-at-once full run, timing out while correct. They count work, not clock time. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ds on hover Per Destin's review (2026-09-28, send-now deck S-1): a round dark button with an up arrow, rightmost in the waiting-message row; on hover or keyboard focus "Interrupt and Send Now" rolls out to the left of the arrow inside the button, using the session pills' sanctioned max-width reveal and motion tokens. The ✕ becomes the doc-comments trash icon and sits to its left, sliding with it. The item-list glyph test guarded only the strip's one ✕ exemption; with the ✕ gone it has nothing left to check, so it is removed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Per Destin's round-2 review (2026-09-28): the primary accent <Button> with the composer's own arrow glyph instead of a hand-styled dark button, so its colour, arrow, size and alignment match the app's other send buttons in every theme. The hover label reveal is unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Per Destin's round-3 review (2026-09-28): - Send now's arrow points up. - The waiting message's Edit reuses the quick chips' pencil button, now a shared EditPencilButton so the two cannot drift (QuickChips unchanged in look; its float-chrome hook class is passed in). - The rolled-out label is trimmed to its letters (text-box) so it centres in every theme font; Meadow Mist's sat ~1px high. It clips sideways only so descenders survive the trim. Design-lint ratchet lowered 542 -> 537: the strip's hand-restyled pencil Button is gone. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Per Destin's round-4 review (2026-09-28): EditPencilButton gains a plain option (same pencil and size, no box) used by the waiting-message strip; the quick chips keep their boxed button. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Per Destin's round-5 note ("bigger"): the plain pencil is 14px like the trash
beside it; the quick chips' boxed pencil is unchanged.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…iled Send now The MCP "excluded server" log line now also redacts credentials written into a server's launch arguments (--api-key x, --token=x) or its address (user:pass@, query values), not just its env/header values. A Send now request that fails (e.g. the remote connection drops) now shows a general "didn't go through — try again" toast instead of doing nothing. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Review only — do not merge yet
Destin requested commits, a branch push and a PR for a separate final review. This draft must not be merged or released automatically. Updated 2026-09-28 with the review follow-ups below.
Summary
Implements the accepted native harness audit scope:
Includes desired-behavior regressions and dev-only fixtures. Remaining defect-observation probes are not included in the app test commit; their historical copies are in the companion workspace record.
Approved exclusions
Verification and acceptance
bash scripts/verify.sh --full <app-worktree>before commit: all desktop gates passed — full tests, source/test types, knip, lint, design lint, invariants, screens and journeys.Integration status (updated 2026-09-28)
Current
masterhas been merged in (merge commit9b8d4bdaf); conflicts innative-session-host.ts,tools/bash.tsandshell-registry.test.tswere resolved (Bash keeps master's admin-passwordonCallExitbookkeeping plus this branch's failed-hand-off handling). GitHub reports the PR mergeable.bash scripts/verify.sh --fullpasses on the final commit (types, full tests, knip, lint, design lint, ast-grep, screens, journeys). Android not built here.Follow-up changes from Destin's PR review (2026-09-28)
Decisions recorded in the workspace PR (
native-harness.pr-review.questions.answers.json,native-harness.send-now*.review.answers.json).{a,b}alternatives and[abc]classes now match; a leading/or./anchors at the rule owner; unreadable patterns are logged.native:queue-send-nowon every surface; Android replies not-implemented like queue-remove): stops the current task like Stop and sends that message next. UI: accent send-style button with an up arrow that reveals "Interrupt and Send Now" on hover, trash icon (matches doc-comments), plain pencil via a new sharedEditPencilButton(QuickChips reuses it, unchanged look).LocalModelsSectionlate read, markdown streaming sweeps given a measured budget); removeditem-list-authority.test.ts, whose only exemption no longer exists. Line budgets raised for the Send now plumbing; design-lint ratchet lowered 542 → 537.Companion workspace PR: itsdestin/youcoded-dev#221.
Review entry point: audit, decisions and evidence.