fix(server): prevent accidental service downgrades - #5302

Merged
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback
Sep 2, 2026
Merged

fix(server): prevent accidental service downgrades#5302
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 3, 2026

Copy link
Copy Markdown
Member

An older CLI can replace a newer background service during install, update, or T3 Connect setup.

This reports the installed version and requires --allow-downgrade before replacing it with an older version. It checks again before writing service files, so a completed remote update cannot bypass the guard. Onboarding leaves newer services unchanged. The existing systemd, launchd, and pending-update behavior stays intact.

Verified with 41 focused service tests, the server typecheck, changed-file lint, formatting, and git diff --check. Tests use temporary files and fake service/process runners. No real service was changed.

This retains Theo Browne's service guard. The broader original work is preserved on an archive branch.

Made with GPT-5.6 Sol in the Codex harness.


Note

Medium Risk
Changes install/update/onboarding paths for systemd and launchd with a new guard that could block legitimate repairs if version detection is wrong; extensive tests mitigate this.

Overview
Prevents an older CLI from replacing a newer installed background service during service install, service update, or T3 Connect onboarding unless the user passes --allow-downgrade.

Service status now surfaces installedVersion and, when the service is newer than the CLI, points to an exact-version repair command instead of t3@latest. reconcileService and BootService.install compare versions with compareExactServiceVersions; a second check runs after stopping the unit (via serviceStateActiveVersion) so a remote update that finishes during shutdown cannot be overwritten. Onboarding skips prompts and leaves a newer service unchanged; BootServiceDowngradeRefusedError is handled like other non-fatal setup failures. User docs describe version pinning and downgrade behavior.

Reviewed by Cursor Bugbot for commit 1b02641. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Prevent accidental BootService downgrades in CLI install and update

  • BootService.install now reads the final service state after stopping the unit and refuses to install if the active version is newer than the CLI, returning BootServiceDowngradeRefusedError; the stopped service is restarted on refusal.
  • Adds a shared --allow-downgrade flag to the service install and update commands so users can explicitly authorize a downgrade.
  • BootServiceStatus now includes a validated installedVersion; the status formatter prints an exact-version repair command instead of the generic latest command when a newer service is detected.
  • Onboarding no longer prompts to replace a known newer background service and logs that it was left unchanged; a downgrade refusal during onboarding is converted to a warning and false.
  • Risk: install changed from an Effect property to an optional-options function in bootService.ts — all in-tree call sites are updated, but out-of-tree consumers calling the old Effect form will break.

Macroscope summarized 1b02641.

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 8139ea6c-fd64-4178-a628-1ac012e24188

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
Comment threadapps/server/src/server.ts
Comment threadapps/server/src/server.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a wrapper error's message now interpolates cause.message, which the Effect error conventions disallow. Everything else in the changed service/error code (new ServiceDowngradeRefusedError, catchTags handling, relay endpoint reconcile handler, RPC schema-defect mapping) follows the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/cli/pair.ts Outdated
Comment threadapps/server/src/cloud/http.ts Outdated
Comment threadapps/server/src/cli/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes the default behavior of background-service installation and updates by refusing downgrades unless an explicit override is supplied. The implementation is localized and well covered by tests, but this product-default change warrants human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadpackages/client-runtime/src/authorization/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from b400658 to a94e3caCompareAugust 3, 2026 22:54
Comment threadapps/server/src/cli/service.ts Outdated
Comment threadpackages/client-runtime/src/rpc/session.ts
Comment threadinfra/relay/src/http/Api.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c23ddca to 68db573CompareAugust 4, 2026 18:15
Comment threadinfra/relay/src/db.ts Outdated
Comment threadpackages/tailscale/src/tailscale.ts
Comment threadapps/web/src/connection/platform.ts
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c11fc14 to 2896676CompareAugust 5, 2026 05:12
Comment threadapps/server/src/cloud/bootService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 2896676. Configure here.

Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotggt3dotgg changed the title fix: harden remote server lifecyclefix(server): prevent accidental service downgradesSep 2, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from 21ef91a to 1b02641CompareSeptember 2, 2026 00:36
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Sep 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.4 KiB+301 B (+2.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.5 KiB+303 B (+4.7%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB57.0 KiB+2.3 KiB (+4.2%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.2 KiB13.2 KiB+80 B (+0.6%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.3 KiB6.3 KiB+83 B (+1.3%)7.8 KiB
ClaudeLive turn WebSocket decoded55.5 KiB56.3 KiB+840 B (+1.5%)66.4 KiB
ClaudeLive turn messages880 (0.0%)21

Baseline: b21d872 · PR result: 1b02641 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@t3dotgg
t3dotgg merged commit 0e77fbd into mainSep 2, 2026
25 checks passed
@t3dotgg
t3dotgg deleted the t3code/review-high-priority-feedback branch September 2, 2026 01:25
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…5302 tests
Upstream's new desktop-app CLI tests and service-downgrade tests hardcode
upstream identity (default home .t3, txcode->t3code service names); port
them to the fork's deliberate divergence (.txcode, txcode.service,
net.coriou.txcode.service) so fork-intent behavior is what's verified.
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…dotgg#8824/pingdotgg#5302
Auto-merged upstream files introduced user-facing 'T3 Code' strings
describing our own desktop app and CLI UX. Ported to 'Tx Code' in
lockstep with their test assertions (app.test, DesktopAppUpdate.test).
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
… commits)
Daily sync 2026-09-02 (main pass + top-up) plus CTO identity-port amendment:
fork 'Tx Code' strings ported into 11 new desktop-app/CLI surfaces from
pingdotgg#8824/pingdotgg#5302. Gates green per sync report; focused identity tests re-run.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(server): prevent accidental service downgrades - #5302

Merged
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback
Sep 2, 2026
Merged

fix(server): prevent accidental service downgrades#5302
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 3, 2026

Copy link
Copy Markdown
Member

An older CLI can replace a newer background service during install, update, or T3 Connect setup.

This reports the installed version and requires --allow-downgrade before replacing it with an older version. It checks again before writing service files, so a completed remote update cannot bypass the guard. Onboarding leaves newer services unchanged. The existing systemd, launchd, and pending-update behavior stays intact.

Verified with 41 focused service tests, the server typecheck, changed-file lint, formatting, and git diff --check. Tests use temporary files and fake service/process runners. No real service was changed.

This retains Theo Browne's service guard. The broader original work is preserved on an archive branch.

Made with GPT-5.6 Sol in the Codex harness.


Note

Medium Risk
Changes install/update/onboarding paths for systemd and launchd with a new guard that could block legitimate repairs if version detection is wrong; extensive tests mitigate this.

Overview
Prevents an older CLI from replacing a newer installed background service during service install, service update, or T3 Connect onboarding unless the user passes --allow-downgrade.

Service status now surfaces installedVersion and, when the service is newer than the CLI, points to an exact-version repair command instead of t3@latest. reconcileService and BootService.install compare versions with compareExactServiceVersions; a second check runs after stopping the unit (via serviceStateActiveVersion) so a remote update that finishes during shutdown cannot be overwritten. Onboarding skips prompts and leaves a newer service unchanged; BootServiceDowngradeRefusedError is handled like other non-fatal setup failures. User docs describe version pinning and downgrade behavior.

Reviewed by Cursor Bugbot for commit 1b02641. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Prevent accidental BootService downgrades in CLI install and update

  • BootService.install now reads the final service state after stopping the unit and refuses to install if the active version is newer than the CLI, returning BootServiceDowngradeRefusedError; the stopped service is restarted on refusal.
  • Adds a shared --allow-downgrade flag to the service install and update commands so users can explicitly authorize a downgrade.
  • BootServiceStatus now includes a validated installedVersion; the status formatter prints an exact-version repair command instead of the generic latest command when a newer service is detected.
  • Onboarding no longer prompts to replace a known newer background service and logs that it was left unchanged; a downgrade refusal during onboarding is converted to a warning and false.
  • Risk: install changed from an Effect property to an optional-options function in bootService.ts — all in-tree call sites are updated, but out-of-tree consumers calling the old Effect form will break.

Macroscope summarized 1b02641.

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 8139ea6c-fd64-4178-a628-1ac012e24188

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
Comment threadapps/server/src/server.ts
Comment threadapps/server/src/server.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a wrapper error's message now interpolates cause.message, which the Effect error conventions disallow. Everything else in the changed service/error code (new ServiceDowngradeRefusedError, catchTags handling, relay endpoint reconcile handler, RPC schema-defect mapping) follows the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/cli/pair.ts Outdated
Comment threadapps/server/src/cloud/http.ts Outdated
Comment threadapps/server/src/cli/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes the default behavior of background-service installation and updates by refusing downgrades unless an explicit override is supplied. The implementation is localized and well covered by tests, but this product-default change warrants human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadpackages/client-runtime/src/authorization/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from b400658 to a94e3caCompareAugust 3, 2026 22:54
Comment threadapps/server/src/cli/service.ts Outdated
Comment threadpackages/client-runtime/src/rpc/session.ts
Comment threadinfra/relay/src/http/Api.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c23ddca to 68db573CompareAugust 4, 2026 18:15
Comment threadinfra/relay/src/db.ts Outdated
Comment threadpackages/tailscale/src/tailscale.ts
Comment threadapps/web/src/connection/platform.ts
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c11fc14 to 2896676CompareAugust 5, 2026 05:12
Comment threadapps/server/src/cloud/bootService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 2896676. Configure here.

Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotggt3dotgg changed the title fix: harden remote server lifecyclefix(server): prevent accidental service downgradesSep 2, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from 21ef91a to 1b02641CompareSeptember 2, 2026 00:36
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Sep 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.4 KiB+301 B (+2.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.5 KiB+303 B (+4.7%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB57.0 KiB+2.3 KiB (+4.2%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.2 KiB13.2 KiB+80 B (+0.6%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.3 KiB6.3 KiB+83 B (+1.3%)7.8 KiB
ClaudeLive turn WebSocket decoded55.5 KiB56.3 KiB+840 B (+1.5%)66.4 KiB
ClaudeLive turn messages880 (0.0%)21

Baseline: b21d872 · PR result: 1b02641 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@t3dotgg
t3dotgg merged commit 0e77fbd into mainSep 2, 2026
25 checks passed
@t3dotgg
t3dotgg deleted the t3code/review-high-priority-feedback branch September 2, 2026 01:25
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…5302 tests
Upstream's new desktop-app CLI tests and service-downgrade tests hardcode
upstream identity (default home .t3, txcode->t3code service names); port
them to the fork's deliberate divergence (.txcode, txcode.service,
net.coriou.txcode.service) so fork-intent behavior is what's verified.
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…dotgg#8824/pingdotgg#5302
Auto-merged upstream files introduced user-facing 'T3 Code' strings
describing our own desktop app and CLI UX. Ported to 'Tx Code' in
lockstep with their test assertions (app.test, DesktopAppUpdate.test).
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
… commits)
Daily sync 2026-09-02 (main pass + top-up) plus CTO identity-port amendment:
fork 'Tx Code' strings ported into 11 new desktop-app/CLI surfaces from
pingdotgg#8824/pingdotgg#5302. Gates green per sync report; focused identity tests re-run.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): prevent accidental service downgrades - #5302

Merged
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback
Sep 2, 2026
Merged

fix(server): prevent accidental service downgrades#5302
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 3, 2026

Copy link
Copy Markdown
Member

An older CLI can replace a newer background service during install, update, or T3 Connect setup.

This reports the installed version and requires --allow-downgrade before replacing it with an older version. It checks again before writing service files, so a completed remote update cannot bypass the guard. Onboarding leaves newer services unchanged. The existing systemd, launchd, and pending-update behavior stays intact.

Verified with 41 focused service tests, the server typecheck, changed-file lint, formatting, and git diff --check. Tests use temporary files and fake service/process runners. No real service was changed.

This retains Theo Browne's service guard. The broader original work is preserved on an archive branch.

Made with GPT-5.6 Sol in the Codex harness.


Note

Medium Risk
Changes install/update/onboarding paths for systemd and launchd with a new guard that could block legitimate repairs if version detection is wrong; extensive tests mitigate this.

Overview
Prevents an older CLI from replacing a newer installed background service during service install, service update, or T3 Connect onboarding unless the user passes --allow-downgrade.

Service status now surfaces installedVersion and, when the service is newer than the CLI, points to an exact-version repair command instead of t3@latest. reconcileService and BootService.install compare versions with compareExactServiceVersions; a second check runs after stopping the unit (via serviceStateActiveVersion) so a remote update that finishes during shutdown cannot be overwritten. Onboarding skips prompts and leaves a newer service unchanged; BootServiceDowngradeRefusedError is handled like other non-fatal setup failures. User docs describe version pinning and downgrade behavior.

Reviewed by Cursor Bugbot for commit 1b02641. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Prevent accidental BootService downgrades in CLI install and update

  • BootService.install now reads the final service state after stopping the unit and refuses to install if the active version is newer than the CLI, returning BootServiceDowngradeRefusedError; the stopped service is restarted on refusal.
  • Adds a shared --allow-downgrade flag to the service install and update commands so users can explicitly authorize a downgrade.
  • BootServiceStatus now includes a validated installedVersion; the status formatter prints an exact-version repair command instead of the generic latest command when a newer service is detected.
  • Onboarding no longer prompts to replace a known newer background service and logs that it was left unchanged; a downgrade refusal during onboarding is converted to a warning and false.
  • Risk: install changed from an Effect property to an optional-options function in bootService.ts — all in-tree call sites are updated, but out-of-tree consumers calling the old Effect form will break.

Macroscope summarized 1b02641.

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 8139ea6c-fd64-4178-a628-1ac012e24188

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
Comment threadapps/server/src/server.ts
Comment threadapps/server/src/server.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a wrapper error's message now interpolates cause.message, which the Effect error conventions disallow. Everything else in the changed service/error code (new ServiceDowngradeRefusedError, catchTags handling, relay endpoint reconcile handler, RPC schema-defect mapping) follows the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/cli/pair.ts Outdated
Comment threadapps/server/src/cloud/http.ts Outdated
Comment threadapps/server/src/cli/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes the default behavior of background-service installation and updates by refusing downgrades unless an explicit override is supplied. The implementation is localized and well covered by tests, but this product-default change warrants human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadpackages/client-runtime/src/authorization/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from b400658 to a94e3caCompareAugust 3, 2026 22:54
Comment threadapps/server/src/cli/service.ts Outdated
Comment threadpackages/client-runtime/src/rpc/session.ts
Comment threadinfra/relay/src/http/Api.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c23ddca to 68db573CompareAugust 4, 2026 18:15
Comment threadinfra/relay/src/db.ts Outdated
Comment threadpackages/tailscale/src/tailscale.ts
Comment threadapps/web/src/connection/platform.ts
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c11fc14 to 2896676CompareAugust 5, 2026 05:12
Comment threadapps/server/src/cloud/bootService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 2896676. Configure here.

Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotggt3dotgg changed the title fix: harden remote server lifecyclefix(server): prevent accidental service downgradesSep 2, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from 21ef91a to 1b02641CompareSeptember 2, 2026 00:36
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Sep 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.4 KiB+301 B (+2.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.5 KiB+303 B (+4.7%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB57.0 KiB+2.3 KiB (+4.2%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.2 KiB13.2 KiB+80 B (+0.6%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.3 KiB6.3 KiB+83 B (+1.3%)7.8 KiB
ClaudeLive turn WebSocket decoded55.5 KiB56.3 KiB+840 B (+1.5%)66.4 KiB
ClaudeLive turn messages880 (0.0%)21

Baseline: b21d872 · PR result: 1b02641 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@t3dotgg
t3dotgg merged commit 0e77fbd into mainSep 2, 2026
25 checks passed
@t3dotgg
t3dotgg deleted the t3code/review-high-priority-feedback branch September 2, 2026 01:25
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…5302 tests
Upstream's new desktop-app CLI tests and service-downgrade tests hardcode
upstream identity (default home .t3, txcode->t3code service names); port
them to the fork's deliberate divergence (.txcode, txcode.service,
net.coriou.txcode.service) so fork-intent behavior is what's verified.
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…dotgg#8824/pingdotgg#5302
Auto-merged upstream files introduced user-facing 'T3 Code' strings
describing our own desktop app and CLI UX. Ported to 'Tx Code' in
lockstep with their test assertions (app.test, DesktopAppUpdate.test).
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
… commits)
Daily sync 2026-09-02 (main pass + top-up) plus CTO identity-port amendment:
fork 'Tx Code' strings ported into 11 new desktop-app/CLI surfaces from
pingdotgg#8824/pingdotgg#5302. Gates green per sync report; focused identity tests re-run.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): prevent accidental service downgrades - #5302

Merged
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback
Sep 2, 2026
Merged

fix(server): prevent accidental service downgrades#5302
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 3, 2026

Copy link
Copy Markdown
Member

An older CLI can replace a newer background service during install, update, or T3 Connect setup.

This reports the installed version and requires --allow-downgrade before replacing it with an older version. It checks again before writing service files, so a completed remote update cannot bypass the guard. Onboarding leaves newer services unchanged. The existing systemd, launchd, and pending-update behavior stays intact.

Verified with 41 focused service tests, the server typecheck, changed-file lint, formatting, and git diff --check. Tests use temporary files and fake service/process runners. No real service was changed.

This retains Theo Browne's service guard. The broader original work is preserved on an archive branch.

Made with GPT-5.6 Sol in the Codex harness.


Note

Medium Risk
Changes install/update/onboarding paths for systemd and launchd with a new guard that could block legitimate repairs if version detection is wrong; extensive tests mitigate this.

Overview
Prevents an older CLI from replacing a newer installed background service during service install, service update, or T3 Connect onboarding unless the user passes --allow-downgrade.

Service status now surfaces installedVersion and, when the service is newer than the CLI, points to an exact-version repair command instead of t3@latest. reconcileService and BootService.install compare versions with compareExactServiceVersions; a second check runs after stopping the unit (via serviceStateActiveVersion) so a remote update that finishes during shutdown cannot be overwritten. Onboarding skips prompts and leaves a newer service unchanged; BootServiceDowngradeRefusedError is handled like other non-fatal setup failures. User docs describe version pinning and downgrade behavior.

Reviewed by Cursor Bugbot for commit 1b02641. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Prevent accidental BootService downgrades in CLI install and update

  • BootService.install now reads the final service state after stopping the unit and refuses to install if the active version is newer than the CLI, returning BootServiceDowngradeRefusedError; the stopped service is restarted on refusal.
  • Adds a shared --allow-downgrade flag to the service install and update commands so users can explicitly authorize a downgrade.
  • BootServiceStatus now includes a validated installedVersion; the status formatter prints an exact-version repair command instead of the generic latest command when a newer service is detected.
  • Onboarding no longer prompts to replace a known newer background service and logs that it was left unchanged; a downgrade refusal during onboarding is converted to a warning and false.
  • Risk: install changed from an Effect property to an optional-options function in bootService.ts — all in-tree call sites are updated, but out-of-tree consumers calling the old Effect form will break.

Macroscope summarized 1b02641.

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 8139ea6c-fd64-4178-a628-1ac012e24188

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
Comment threadapps/server/src/server.ts
Comment threadapps/server/src/server.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a wrapper error's message now interpolates cause.message, which the Effect error conventions disallow. Everything else in the changed service/error code (new ServiceDowngradeRefusedError, catchTags handling, relay endpoint reconcile handler, RPC schema-defect mapping) follows the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/cli/pair.ts Outdated
Comment threadapps/server/src/cloud/http.ts Outdated
Comment threadapps/server/src/cli/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes the default behavior of background-service installation and updates by refusing downgrades unless an explicit override is supplied. The implementation is localized and well covered by tests, but this product-default change warrants human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadpackages/client-runtime/src/authorization/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from b400658 to a94e3caCompareAugust 3, 2026 22:54
Comment threadapps/server/src/cli/service.ts Outdated
Comment threadpackages/client-runtime/src/rpc/session.ts
Comment threadinfra/relay/src/http/Api.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c23ddca to 68db573CompareAugust 4, 2026 18:15
Comment threadinfra/relay/src/db.ts Outdated
Comment threadpackages/tailscale/src/tailscale.ts
Comment threadapps/web/src/connection/platform.ts
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c11fc14 to 2896676CompareAugust 5, 2026 05:12
Comment threadapps/server/src/cloud/bootService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 2896676. Configure here.

Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotggt3dotgg changed the title fix: harden remote server lifecyclefix(server): prevent accidental service downgradesSep 2, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from 21ef91a to 1b02641CompareSeptember 2, 2026 00:36
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Sep 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.4 KiB+301 B (+2.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.5 KiB+303 B (+4.7%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB57.0 KiB+2.3 KiB (+4.2%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.2 KiB13.2 KiB+80 B (+0.6%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.3 KiB6.3 KiB+83 B (+1.3%)7.8 KiB
ClaudeLive turn WebSocket decoded55.5 KiB56.3 KiB+840 B (+1.5%)66.4 KiB
ClaudeLive turn messages880 (0.0%)21

Baseline: b21d872 · PR result: 1b02641 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@t3dotgg
t3dotgg merged commit 0e77fbd into mainSep 2, 2026
25 checks passed
@t3dotgg
t3dotgg deleted the t3code/review-high-priority-feedback branch September 2, 2026 01:25
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…5302 tests
Upstream's new desktop-app CLI tests and service-downgrade tests hardcode
upstream identity (default home .t3, txcode->t3code service names); port
them to the fork's deliberate divergence (.txcode, txcode.service,
net.coriou.txcode.service) so fork-intent behavior is what's verified.
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…dotgg#8824/pingdotgg#5302
Auto-merged upstream files introduced user-facing 'T3 Code' strings
describing our own desktop app and CLI UX. Ported to 'Tx Code' in
lockstep with their test assertions (app.test, DesktopAppUpdate.test).
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
… commits)
Daily sync 2026-09-02 (main pass + top-up) plus CTO identity-port amendment:
fork 'Tx Code' strings ported into 11 new desktop-app/CLI surfaces from
pingdotgg#8824/pingdotgg#5302. Gates green per sync report; focused identity tests re-run.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(server): prevent accidental service downgrades - #5302

Merged
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback
Sep 2, 2026
Merged

fix(server): prevent accidental service downgrades#5302
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 3, 2026

Copy link
Copy Markdown
Member

An older CLI can replace a newer background service during install, update, or T3 Connect setup.

This reports the installed version and requires --allow-downgrade before replacing it with an older version. It checks again before writing service files, so a completed remote update cannot bypass the guard. Onboarding leaves newer services unchanged. The existing systemd, launchd, and pending-update behavior stays intact.

Verified with 41 focused service tests, the server typecheck, changed-file lint, formatting, and git diff --check. Tests use temporary files and fake service/process runners. No real service was changed.

This retains Theo Browne's service guard. The broader original work is preserved on an archive branch.

Made with GPT-5.6 Sol in the Codex harness.


Note

Medium Risk
Changes install/update/onboarding paths for systemd and launchd with a new guard that could block legitimate repairs if version detection is wrong; extensive tests mitigate this.

Overview
Prevents an older CLI from replacing a newer installed background service during service install, service update, or T3 Connect onboarding unless the user passes --allow-downgrade.

Service status now surfaces installedVersion and, when the service is newer than the CLI, points to an exact-version repair command instead of t3@latest. reconcileService and BootService.install compare versions with compareExactServiceVersions; a second check runs after stopping the unit (via serviceStateActiveVersion) so a remote update that finishes during shutdown cannot be overwritten. Onboarding skips prompts and leaves a newer service unchanged; BootServiceDowngradeRefusedError is handled like other non-fatal setup failures. User docs describe version pinning and downgrade behavior.

Reviewed by Cursor Bugbot for commit 1b02641. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Prevent accidental BootService downgrades in CLI install and update

  • BootService.install now reads the final service state after stopping the unit and refuses to install if the active version is newer than the CLI, returning BootServiceDowngradeRefusedError; the stopped service is restarted on refusal.
  • Adds a shared --allow-downgrade flag to the service install and update commands so users can explicitly authorize a downgrade.
  • BootServiceStatus now includes a validated installedVersion; the status formatter prints an exact-version repair command instead of the generic latest command when a newer service is detected.
  • Onboarding no longer prompts to replace a known newer background service and logs that it was left unchanged; a downgrade refusal during onboarding is converted to a warning and false.
  • Risk: install changed from an Effect property to an optional-options function in bootService.ts — all in-tree call sites are updated, but out-of-tree consumers calling the old Effect form will break.

Macroscope summarized 1b02641.

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 8139ea6c-fd64-4178-a628-1ac012e24188

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
Comment threadapps/server/src/server.ts
Comment threadapps/server/src/server.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a wrapper error's message now interpolates cause.message, which the Effect error conventions disallow. Everything else in the changed service/error code (new ServiceDowngradeRefusedError, catchTags handling, relay endpoint reconcile handler, RPC schema-defect mapping) follows the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/cli/pair.ts Outdated
Comment threadapps/server/src/cloud/http.ts Outdated
Comment threadapps/server/src/cli/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes the default behavior of background-service installation and updates by refusing downgrades unless an explicit override is supplied. The implementation is localized and well covered by tests, but this product-default change warrants human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadpackages/client-runtime/src/authorization/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from b400658 to a94e3caCompareAugust 3, 2026 22:54
Comment threadapps/server/src/cli/service.ts Outdated
Comment threadpackages/client-runtime/src/rpc/session.ts
Comment threadinfra/relay/src/http/Api.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c23ddca to 68db573CompareAugust 4, 2026 18:15
Comment threadinfra/relay/src/db.ts Outdated
Comment threadpackages/tailscale/src/tailscale.ts
Comment threadapps/web/src/connection/platform.ts
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c11fc14 to 2896676CompareAugust 5, 2026 05:12
Comment threadapps/server/src/cloud/bootService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 2896676. Configure here.

Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotggt3dotgg changed the title fix: harden remote server lifecyclefix(server): prevent accidental service downgradesSep 2, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from 21ef91a to 1b02641CompareSeptember 2, 2026 00:36
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Sep 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.4 KiB+301 B (+2.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.5 KiB+303 B (+4.7%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB57.0 KiB+2.3 KiB (+4.2%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.2 KiB13.2 KiB+80 B (+0.6%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.3 KiB6.3 KiB+83 B (+1.3%)7.8 KiB
ClaudeLive turn WebSocket decoded55.5 KiB56.3 KiB+840 B (+1.5%)66.4 KiB
ClaudeLive turn messages880 (0.0%)21

Baseline: b21d872 · PR result: 1b02641 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@t3dotgg
t3dotgg merged commit 0e77fbd into mainSep 2, 2026
25 checks passed
@t3dotgg
t3dotgg deleted the t3code/review-high-priority-feedback branch September 2, 2026 01:25
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…5302 tests
Upstream's new desktop-app CLI tests and service-downgrade tests hardcode
upstream identity (default home .t3, txcode->t3code service names); port
them to the fork's deliberate divergence (.txcode, txcode.service,
net.coriou.txcode.service) so fork-intent behavior is what's verified.
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…dotgg#8824/pingdotgg#5302
Auto-merged upstream files introduced user-facing 'T3 Code' strings
describing our own desktop app and CLI UX. Ported to 'Tx Code' in
lockstep with their test assertions (app.test, DesktopAppUpdate.test).
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
… commits)
Daily sync 2026-09-02 (main pass + top-up) plus CTO identity-port amendment:
fork 'Tx Code' strings ported into 11 new desktop-app/CLI surfaces from
pingdotgg#8824/pingdotgg#5302. Gates green per sync report; focused identity tests re-run.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): prevent accidental service downgrades - #5302

Merged
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback
Sep 2, 2026
Merged

fix(server): prevent accidental service downgrades#5302
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 3, 2026

Copy link
Copy Markdown
Member

An older CLI can replace a newer background service during install, update, or T3 Connect setup.

This reports the installed version and requires --allow-downgrade before replacing it with an older version. It checks again before writing service files, so a completed remote update cannot bypass the guard. Onboarding leaves newer services unchanged. The existing systemd, launchd, and pending-update behavior stays intact.

Verified with 41 focused service tests, the server typecheck, changed-file lint, formatting, and git diff --check. Tests use temporary files and fake service/process runners. No real service was changed.

This retains Theo Browne's service guard. The broader original work is preserved on an archive branch.

Made with GPT-5.6 Sol in the Codex harness.


Note

Medium Risk
Changes install/update/onboarding paths for systemd and launchd with a new guard that could block legitimate repairs if version detection is wrong; extensive tests mitigate this.

Overview
Prevents an older CLI from replacing a newer installed background service during service install, service update, or T3 Connect onboarding unless the user passes --allow-downgrade.

Service status now surfaces installedVersion and, when the service is newer than the CLI, points to an exact-version repair command instead of t3@latest. reconcileService and BootService.install compare versions with compareExactServiceVersions; a second check runs after stopping the unit (via serviceStateActiveVersion) so a remote update that finishes during shutdown cannot be overwritten. Onboarding skips prompts and leaves a newer service unchanged; BootServiceDowngradeRefusedError is handled like other non-fatal setup failures. User docs describe version pinning and downgrade behavior.

Reviewed by Cursor Bugbot for commit 1b02641. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Prevent accidental BootService downgrades in CLI install and update

  • BootService.install now reads the final service state after stopping the unit and refuses to install if the active version is newer than the CLI, returning BootServiceDowngradeRefusedError; the stopped service is restarted on refusal.
  • Adds a shared --allow-downgrade flag to the service install and update commands so users can explicitly authorize a downgrade.
  • BootServiceStatus now includes a validated installedVersion; the status formatter prints an exact-version repair command instead of the generic latest command when a newer service is detected.
  • Onboarding no longer prompts to replace a known newer background service and logs that it was left unchanged; a downgrade refusal during onboarding is converted to a warning and false.
  • Risk: install changed from an Effect property to an optional-options function in bootService.ts — all in-tree call sites are updated, but out-of-tree consumers calling the old Effect form will break.

Macroscope summarized 1b02641.

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 8139ea6c-fd64-4178-a628-1ac012e24188

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
Comment threadapps/server/src/server.ts
Comment threadapps/server/src/server.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a wrapper error's message now interpolates cause.message, which the Effect error conventions disallow. Everything else in the changed service/error code (new ServiceDowngradeRefusedError, catchTags handling, relay endpoint reconcile handler, RPC schema-defect mapping) follows the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/cli/pair.ts Outdated
Comment threadapps/server/src/cloud/http.ts Outdated
Comment threadapps/server/src/cli/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes the default behavior of background-service installation and updates by refusing downgrades unless an explicit override is supplied. The implementation is localized and well covered by tests, but this product-default change warrants human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadpackages/client-runtime/src/authorization/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from b400658 to a94e3caCompareAugust 3, 2026 22:54
Comment threadapps/server/src/cli/service.ts Outdated
Comment threadpackages/client-runtime/src/rpc/session.ts
Comment threadinfra/relay/src/http/Api.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c23ddca to 68db573CompareAugust 4, 2026 18:15
Comment threadinfra/relay/src/db.ts Outdated
Comment threadpackages/tailscale/src/tailscale.ts
Comment threadapps/web/src/connection/platform.ts
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c11fc14 to 2896676CompareAugust 5, 2026 05:12
Comment threadapps/server/src/cloud/bootService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 2896676. Configure here.

Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotggt3dotgg changed the title fix: harden remote server lifecyclefix(server): prevent accidental service downgradesSep 2, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from 21ef91a to 1b02641CompareSeptember 2, 2026 00:36
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Sep 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.4 KiB+301 B (+2.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.5 KiB+303 B (+4.7%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB57.0 KiB+2.3 KiB (+4.2%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.2 KiB13.2 KiB+80 B (+0.6%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.3 KiB6.3 KiB+83 B (+1.3%)7.8 KiB
ClaudeLive turn WebSocket decoded55.5 KiB56.3 KiB+840 B (+1.5%)66.4 KiB
ClaudeLive turn messages880 (0.0%)21

Baseline: b21d872 · PR result: 1b02641 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@t3dotgg
t3dotgg merged commit 0e77fbd into mainSep 2, 2026
25 checks passed
@t3dotgg
t3dotgg deleted the t3code/review-high-priority-feedback branch September 2, 2026 01:25
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…5302 tests
Upstream's new desktop-app CLI tests and service-downgrade tests hardcode
upstream identity (default home .t3, txcode->t3code service names); port
them to the fork's deliberate divergence (.txcode, txcode.service,
net.coriou.txcode.service) so fork-intent behavior is what's verified.
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…dotgg#8824/pingdotgg#5302
Auto-merged upstream files introduced user-facing 'T3 Code' strings
describing our own desktop app and CLI UX. Ported to 'Tx Code' in
lockstep with their test assertions (app.test, DesktopAppUpdate.test).
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
… commits)
Daily sync 2026-09-02 (main pass + top-up) plus CTO identity-port amendment:
fork 'Tx Code' strings ported into 11 new desktop-app/CLI surfaces from
pingdotgg#8824/pingdotgg#5302. Gates green per sync report; focused identity tests re-run.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): prevent accidental service downgrades - #5302

Merged
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback
Sep 2, 2026
Merged

fix(server): prevent accidental service downgrades#5302
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 3, 2026

Copy link
Copy Markdown
Member

An older CLI can replace a newer background service during install, update, or T3 Connect setup.

This reports the installed version and requires --allow-downgrade before replacing it with an older version. It checks again before writing service files, so a completed remote update cannot bypass the guard. Onboarding leaves newer services unchanged. The existing systemd, launchd, and pending-update behavior stays intact.

Verified with 41 focused service tests, the server typecheck, changed-file lint, formatting, and git diff --check. Tests use temporary files and fake service/process runners. No real service was changed.

This retains Theo Browne's service guard. The broader original work is preserved on an archive branch.

Made with GPT-5.6 Sol in the Codex harness.


Note

Medium Risk
Changes install/update/onboarding paths for systemd and launchd with a new guard that could block legitimate repairs if version detection is wrong; extensive tests mitigate this.

Overview
Prevents an older CLI from replacing a newer installed background service during service install, service update, or T3 Connect onboarding unless the user passes --allow-downgrade.

Service status now surfaces installedVersion and, when the service is newer than the CLI, points to an exact-version repair command instead of t3@latest. reconcileService and BootService.install compare versions with compareExactServiceVersions; a second check runs after stopping the unit (via serviceStateActiveVersion) so a remote update that finishes during shutdown cannot be overwritten. Onboarding skips prompts and leaves a newer service unchanged; BootServiceDowngradeRefusedError is handled like other non-fatal setup failures. User docs describe version pinning and downgrade behavior.

Reviewed by Cursor Bugbot for commit 1b02641. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Prevent accidental BootService downgrades in CLI install and update

  • BootService.install now reads the final service state after stopping the unit and refuses to install if the active version is newer than the CLI, returning BootServiceDowngradeRefusedError; the stopped service is restarted on refusal.
  • Adds a shared --allow-downgrade flag to the service install and update commands so users can explicitly authorize a downgrade.
  • BootServiceStatus now includes a validated installedVersion; the status formatter prints an exact-version repair command instead of the generic latest command when a newer service is detected.
  • Onboarding no longer prompts to replace a known newer background service and logs that it was left unchanged; a downgrade refusal during onboarding is converted to a warning and false.
  • Risk: install changed from an Effect property to an optional-options function in bootService.ts — all in-tree call sites are updated, but out-of-tree consumers calling the old Effect form will break.

Macroscope summarized 1b02641.

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 8139ea6c-fd64-4178-a628-1ac012e24188

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
Comment threadapps/server/src/server.ts
Comment threadapps/server/src/server.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a wrapper error's message now interpolates cause.message, which the Effect error conventions disallow. Everything else in the changed service/error code (new ServiceDowngradeRefusedError, catchTags handling, relay endpoint reconcile handler, RPC schema-defect mapping) follows the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/cli/pair.ts Outdated
Comment threadapps/server/src/cloud/http.ts Outdated
Comment threadapps/server/src/cli/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes the default behavior of background-service installation and updates by refusing downgrades unless an explicit override is supplied. The implementation is localized and well covered by tests, but this product-default change warrants human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadpackages/client-runtime/src/authorization/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from b400658 to a94e3caCompareAugust 3, 2026 22:54
Comment threadapps/server/src/cli/service.ts Outdated
Comment threadpackages/client-runtime/src/rpc/session.ts
Comment threadinfra/relay/src/http/Api.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c23ddca to 68db573CompareAugust 4, 2026 18:15
Comment threadinfra/relay/src/db.ts Outdated
Comment threadpackages/tailscale/src/tailscale.ts
Comment threadapps/web/src/connection/platform.ts
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c11fc14 to 2896676CompareAugust 5, 2026 05:12
Comment threadapps/server/src/cloud/bootService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 2896676. Configure here.

Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotggt3dotgg changed the title fix: harden remote server lifecyclefix(server): prevent accidental service downgradesSep 2, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from 21ef91a to 1b02641CompareSeptember 2, 2026 00:36
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Sep 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.4 KiB+301 B (+2.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.5 KiB+303 B (+4.7%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB57.0 KiB+2.3 KiB (+4.2%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.2 KiB13.2 KiB+80 B (+0.6%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.3 KiB6.3 KiB+83 B (+1.3%)7.8 KiB
ClaudeLive turn WebSocket decoded55.5 KiB56.3 KiB+840 B (+1.5%)66.4 KiB
ClaudeLive turn messages880 (0.0%)21

Baseline: b21d872 · PR result: 1b02641 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@t3dotgg
t3dotgg merged commit 0e77fbd into mainSep 2, 2026
25 checks passed
@t3dotgg
t3dotgg deleted the t3code/review-high-priority-feedback branch September 2, 2026 01:25
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…5302 tests
Upstream's new desktop-app CLI tests and service-downgrade tests hardcode
upstream identity (default home .t3, txcode->t3code service names); port
them to the fork's deliberate divergence (.txcode, txcode.service,
net.coriou.txcode.service) so fork-intent behavior is what's verified.
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…dotgg#8824/pingdotgg#5302
Auto-merged upstream files introduced user-facing 'T3 Code' strings
describing our own desktop app and CLI UX. Ported to 'Tx Code' in
lockstep with their test assertions (app.test, DesktopAppUpdate.test).
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
… commits)
Daily sync 2026-09-02 (main pass + top-up) plus CTO identity-port amendment:
fork 'Tx Code' strings ported into 11 new desktop-app/CLI surfaces from
pingdotgg#8824/pingdotgg#5302. Gates green per sync report; focused identity tests re-run.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(server): prevent accidental service downgrades - #5302

Merged
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback
Sep 2, 2026
Merged

fix(server): prevent accidental service downgrades#5302
t3dotgg merged 1 commit into
mainfrom
t3code/review-high-priority-feedback

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 3, 2026

Copy link
Copy Markdown
Member

An older CLI can replace a newer background service during install, update, or T3 Connect setup.

This reports the installed version and requires --allow-downgrade before replacing it with an older version. It checks again before writing service files, so a completed remote update cannot bypass the guard. Onboarding leaves newer services unchanged. The existing systemd, launchd, and pending-update behavior stays intact.

Verified with 41 focused service tests, the server typecheck, changed-file lint, formatting, and git diff --check. Tests use temporary files and fake service/process runners. No real service was changed.

This retains Theo Browne's service guard. The broader original work is preserved on an archive branch.

Made with GPT-5.6 Sol in the Codex harness.


Note

Medium Risk
Changes install/update/onboarding paths for systemd and launchd with a new guard that could block legitimate repairs if version detection is wrong; extensive tests mitigate this.

Overview
Prevents an older CLI from replacing a newer installed background service during service install, service update, or T3 Connect onboarding unless the user passes --allow-downgrade.

Service status now surfaces installedVersion and, when the service is newer than the CLI, points to an exact-version repair command instead of t3@latest. reconcileService and BootService.install compare versions with compareExactServiceVersions; a second check runs after stopping the unit (via serviceStateActiveVersion) so a remote update that finishes during shutdown cannot be overwritten. Onboarding skips prompts and leaves a newer service unchanged; BootServiceDowngradeRefusedError is handled like other non-fatal setup failures. User docs describe version pinning and downgrade behavior.

Reviewed by Cursor Bugbot for commit 1b02641. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Prevent accidental BootService downgrades in CLI install and update

  • BootService.install now reads the final service state after stopping the unit and refuses to install if the active version is newer than the CLI, returning BootServiceDowngradeRefusedError; the stopped service is restarted on refusal.
  • Adds a shared --allow-downgrade flag to the service install and update commands so users can explicitly authorize a downgrade.
  • BootServiceStatus now includes a validated installedVersion; the status formatter prints an exact-version repair command instead of the generic latest command when a newer service is detected.
  • Onboarding no longer prompts to replace a known newer background service and logs that it was left unchanged; a downgrade refusal during onboarding is converted to a warning and false.
  • Risk: install changed from an Effect property to an optional-options function in bootService.ts — all in-tree call sites are updated, but out-of-tree consumers calling the old Effect form will break.

Macroscope summarized 1b02641.

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 8139ea6c-fd64-4178-a628-1ac012e24188

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
Comment threadapps/server/src/server.ts
Comment threadapps/server/src/server.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding: a wrapper error's message now interpolates cause.message, which the Effect error conventions disallow. Everything else in the changed service/error code (new ServiceDowngradeRefusedError, catchTags handling, relay endpoint reconcile handler, RPC schema-defect mapping) follows the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/cli/pair.ts Outdated
Comment threadapps/server/src/cloud/http.ts Outdated
Comment threadapps/server/src/cli/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The PR changes the default behavior of background-service installation and updates by refusing downgrades unless an explicit override is supplied. The implementation is localized and well covered by tests, but this product-default change warrants human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadpackages/client-runtime/src/authorization/service.ts
Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from b400658 to a94e3caCompareAugust 3, 2026 22:54
Comment threadapps/server/src/cli/service.ts Outdated
Comment threadpackages/client-runtime/src/rpc/session.ts
Comment threadinfra/relay/src/http/Api.ts Outdated
Comment threadapps/web/src/components/ChatView.tsx Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
Comment threadinfra/relay/src/db.ts Outdated
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Aug 3, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c23ddca to 68db573CompareAugust 4, 2026 18:15
Comment threadinfra/relay/src/db.ts Outdated
Comment threadpackages/tailscale/src/tailscale.ts
Comment threadapps/web/src/connection/platform.ts
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from c11fc14 to 2896676CompareAugust 5, 2026 05:12
Comment threadapps/server/src/cloud/bootService.ts

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 2896676. Configure here.

Comment threadpackages/client-runtime/src/authorization/service.ts Outdated
@t3dotggt3dotgg changed the title fix: harden remote server lifecyclefix(server): prevent accidental service downgradesSep 2, 2026
@t3dotgg
t3dotggforce-pushed the t3code/review-high-priority-feedback branch from 21ef91a to 1b02641CompareSeptember 2, 2026 00:36
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Sep 2, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.4 KiB+301 B (+2.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.5 KiB+303 B (+4.7%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB57.0 KiB+2.3 KiB (+4.2%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.2 KiB13.2 KiB+80 B (+0.6%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.3 KiB6.3 KiB+83 B (+1.3%)7.8 KiB
ClaudeLive turn WebSocket decoded55.5 KiB56.3 KiB+840 B (+1.5%)66.4 KiB
ClaudeLive turn messages880 (0.0%)21

Baseline: b21d872 · PR result: 1b02641 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@t3dotgg
t3dotgg merged commit 0e77fbd into mainSep 2, 2026
25 checks passed
@t3dotgg
t3dotgg deleted the t3code/review-high-priority-feedback branch September 2, 2026 01:25
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…5302 tests
Upstream's new desktop-app CLI tests and service-downgrade tests hardcode
upstream identity (default home .t3, txcode->t3code service names); port
them to the fork's deliberate divergence (.txcode, txcode.service,
net.coriou.txcode.service) so fork-intent behavior is what's verified.
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
…dotgg#8824/pingdotgg#5302
Auto-merged upstream files introduced user-facing 'T3 Code' strings
describing our own desktop app and CLI UX. Ported to 'Tx Code' in
lockstep with their test assertions (app.test, DesktopAppUpdate.test).
Coriou added a commit to Coriou/txcode that referenced this pull request Sep 2, 2026
… commits)
Daily sync 2026-09-02 (main pass + top-up) plus CTO identity-port amendment:
fork 'Tx Code' strings ported into 11 new desktop-app/CLI surfaces from
pingdotgg#8824/pingdotgg#5302. Gates green per sync report; focused identity tests re-run.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg