feat(desktop): update the desktop app on remote Macs from the Update button - #6554

Merged
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates
Sep 2, 2026
Merged

feat(desktop): update the desktop app on remote Macs from the Update button#6554
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 14, 2026

Copy link
Copy Markdown
Member

Remote desktop-managed servers could not update their desktop app.

This change uses a two-phase handoff. Desktop checks and downloads first, then reports a short-lived token while the backend stays connected. The client sends a commit RPC after it receives the token. It accepts success only after reconnecting to the exact prepared version, and retries a lost commit with the same token.

Preparations expire, support early cancellation, and wait up to 90 seconds for a background check. Tokens bind the downloaded version. Duplicate commits cannot start a second install. Desktop keeps windows open until Electron starts updater-controlled quit. Install failures hold a recovery reservation while stopped backends restart, and retained failures replay after restart. Tokenless desktop updates must prove the target version before the client accepts success.

Verification passed 205 focused tests and scoped typechecks across all affected packages. A child-process test passed through the real fd3/fd4 transport with the update services and telemetry services. It covered child restart, failure replay, and duplicate commits. Packaged Mac installation is not yet verified.

Failure recovery adapts #8429 without merging or closing it. Original work by Theo with Claude Code. Protocol and recovery by GPT-5.6 Sol with Codex. Failure recovery commits by Adolanium.

Note

Add server-triggered desktop app updates via server.commitDesktopUpdate RPC

  • Adds a telemetry control channel for server-to-desktop update request, commit, and cancel messages, and a DesktopRemoteUpdates listener that mirrors updater state to the server through DesktopUpdateStatusReport
  • Adds the server-side DesktopAppUpdate service that correlates status reports by request ID, maps progress stages, and returns a desktop-app self-update result with a commit token when the desktop reports ready-to-install
  • Extends DesktopUpdates with install recovery that restarts backends on installer failure, version-checked installPrepared, and a bounded state-change stream via subscribe
  • Web UI renders an Update button with confirmation for desktop-managed servers advertising the desktopAppUpdate capability; unsupported servers retain manual instructions
  • Adds reconnect-observer logic so a desktop commit lost during transport handoff waits for reconnection and retries up to three ready events before failing with ServerUpdateTerminalError
  • Behavioral Change: updater-controlled quit now destroys windows synchronously inside the before-quit-for-update listener instead of forking an async effect; ServerEnvironment advertises desktopAppUpdate: true only for desktop-managed servers with a desktopTelemetryControlFd, and serverCommitDesktopUpdate requires AuthOrchestrationOperateScope

Macroscope summarized 3eacbbb.

@coderabbitai

coderabbitaiBot commented Aug 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 370c51d2-3573-4944-9650-f5f3100b931b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 14, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions: one finding — Effect.catchTag used in the new DesktopAppUpdate service; the repo convention is Effect.catchTags({ ... }) even for a single tag. Everything else in the new service/layer code (namespace subpath imports, inline Context.Service interface, make + layer exports, Foo["Service"] typing, environment-acquired dependencies, no runtime escapes) matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
Comment threadapps/server/src/cloud/selfUpdate.ts
@github-actions

github-actionsBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.3 KiB+164 B (+1.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.4 KiB+166 B (+2.6%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB55.6 KiB+910 B (+1.6%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.4 KiB13.3 KiB−158 B (−1.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+3 B (+0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.6 KiB6.4 KiB−161 B (−2.4%)7.8 KiB
ClaudeLive turn WebSocket decoded57.8 KiB56.4 KiB−1.4 KiB (−2.5%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: 8efd4e9 · PR result: 3eacbbb · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/remoteUpdateFlow.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This cross-layer feature adds an authenticated remote desktop-update protocol and a two-phase workflow that can download, install, quit, relaunch, and recover the desktop app. It introduces substantial production behavior across the desktop, server, client runtime, UI, and contracts, including a sensitive authorization change, so the side effects require human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadpackages/contracts/src/resourceTelemetry.ts Outdated
Comment threadapps/web/src/components/ServerUpdateAction.tsx Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Sep 1, 2026
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from c9f5fb4 to ec91c4cCompareSeptember 2, 2026 01:01
@t3dotggt3dotgg added the preview:mac Build an Apple Silicon DMG for this PR on every push. label Sep 2, 2026
@github-actions

github-actionsBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

macOS preview

The preview download was removed because this PR closed or the preview label was removed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadpackages/client-runtime/src/state/server.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts
t3dotggand others added 5 commits September 1, 2026 18:22
…button
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…try hardening
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tting
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… field
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…naturally
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
t3dotggand others added 9 commits September 1, 2026 18:22
…ress install
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ation
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Install stopped backends, destroyed every window, then called quitAndInstall. If that last step failed, quitting was cleared and an error was stored, but the windows were already gone. There was no path to open one again.
Call quitAndInstall first. Destroy windows only after that starts.
Install still stops backends before quitAndInstall. If that last step fails, the window stayed up but the pool was already down, so the UI was disconnected.
On install failure, start the stopped backends again.
# Conflicts:
#	apps/desktop/src/updates/DesktopUpdates.test.ts
#	apps/desktop/src/updates/DesktopUpdates.ts
Prepare the desktop update before returning the progress result, then commit
the install only after the client receives its token. Retry lost commits by
token and require the prepared version after reconnect.
Keep windows open until updater-controlled quit and restart stopped backends
when Electron reports an install failure.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from 9a3ed9a to 8fec783CompareSeptember 2, 2026 01:23
Comment threadpackages/client-runtime/src/state/server.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/app/DesktopLifecycle.ts
t3dotggand others added 2 commits September 1, 2026 18:32
@t3dotgg

t3dotgg commented Sep 2, 2026

Copy link
Copy Markdown
MemberAuthor

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

Fixed and pushed in cb96a8e268b5acc0d7f40017a5b0b30fff582af8. Remote commit now joins only when the exact downloaded version still matches and the updater's install reservation is active. Ordinary quit and relaunch no longer count as an install handoff. Tests use a real competing local install and cover normal quit separately. The coordination hold is cleared, subject to normal CI and review.

Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
…mpletes
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0fc8f4a. Configure here.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotgg merged commit b2f25d3 into mainSep 2, 2026
28 checks passed
@t3dotgg
t3dotgg deleted the t3code/remote-mac-app-updates branch September 2, 2026 02:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
amitbet pushed a commit to amitbet/a2code that referenced this pull request Sep 2, 2026
Resolves 48 conflicts. Brings in Claude Fable 5.1 (claude-fable-5-1, requires
Claude Code >= 2.1.257) via upstream's move of the Claude model list into
model-manifest.json.
Declines upstream's remote desktop-update feature (pingdotgg#6554): it is welded to the
electron-installer path this fork deleted, so its files are dropped and the
server never advertises the desktopAppUpdate capability, keeping the Update
button from offering something that can never finish.
Preserves the fork's queued-prompt steering, in-chat find, thread
fork/references/export, MCP thread search, live quota meter, machine-scoped
sidebar, payload hot-update channel, branding and trimmed CI surface. Adopts
upstream's reversal of create-time project model seeding (inside the extracted
useAddProjectFromPath hook) and renumbers upstream's migration 044 to the
fork's 047.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

preview:macBuild an Apple Silicon DMG for this PR on every push.size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@t3dotgg@Adolanium
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(desktop): update the desktop app on remote Macs from the Update button - #6554

Merged
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates
Sep 2, 2026
Merged

feat(desktop): update the desktop app on remote Macs from the Update button#6554
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 14, 2026

Copy link
Copy Markdown
Member

Remote desktop-managed servers could not update their desktop app.

This change uses a two-phase handoff. Desktop checks and downloads first, then reports a short-lived token while the backend stays connected. The client sends a commit RPC after it receives the token. It accepts success only after reconnecting to the exact prepared version, and retries a lost commit with the same token.

Preparations expire, support early cancellation, and wait up to 90 seconds for a background check. Tokens bind the downloaded version. Duplicate commits cannot start a second install. Desktop keeps windows open until Electron starts updater-controlled quit. Install failures hold a recovery reservation while stopped backends restart, and retained failures replay after restart. Tokenless desktop updates must prove the target version before the client accepts success.

Verification passed 205 focused tests and scoped typechecks across all affected packages. A child-process test passed through the real fd3/fd4 transport with the update services and telemetry services. It covered child restart, failure replay, and duplicate commits. Packaged Mac installation is not yet verified.

Failure recovery adapts #8429 without merging or closing it. Original work by Theo with Claude Code. Protocol and recovery by GPT-5.6 Sol with Codex. Failure recovery commits by Adolanium.

Note

Add server-triggered desktop app updates via server.commitDesktopUpdate RPC

  • Adds a telemetry control channel for server-to-desktop update request, commit, and cancel messages, and a DesktopRemoteUpdates listener that mirrors updater state to the server through DesktopUpdateStatusReport
  • Adds the server-side DesktopAppUpdate service that correlates status reports by request ID, maps progress stages, and returns a desktop-app self-update result with a commit token when the desktop reports ready-to-install
  • Extends DesktopUpdates with install recovery that restarts backends on installer failure, version-checked installPrepared, and a bounded state-change stream via subscribe
  • Web UI renders an Update button with confirmation for desktop-managed servers advertising the desktopAppUpdate capability; unsupported servers retain manual instructions
  • Adds reconnect-observer logic so a desktop commit lost during transport handoff waits for reconnection and retries up to three ready events before failing with ServerUpdateTerminalError
  • Behavioral Change: updater-controlled quit now destroys windows synchronously inside the before-quit-for-update listener instead of forking an async effect; ServerEnvironment advertises desktopAppUpdate: true only for desktop-managed servers with a desktopTelemetryControlFd, and serverCommitDesktopUpdate requires AuthOrchestrationOperateScope

Macroscope summarized 3eacbbb.

@coderabbitai

coderabbitaiBot commented Aug 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 370c51d2-3573-4944-9650-f5f3100b931b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 14, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions: one finding — Effect.catchTag used in the new DesktopAppUpdate service; the repo convention is Effect.catchTags({ ... }) even for a single tag. Everything else in the new service/layer code (namespace subpath imports, inline Context.Service interface, make + layer exports, Foo["Service"] typing, environment-acquired dependencies, no runtime escapes) matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
Comment threadapps/server/src/cloud/selfUpdate.ts
@github-actions

github-actionsBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.3 KiB+164 B (+1.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.4 KiB+166 B (+2.6%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB55.6 KiB+910 B (+1.6%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.4 KiB13.3 KiB−158 B (−1.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+3 B (+0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.6 KiB6.4 KiB−161 B (−2.4%)7.8 KiB
ClaudeLive turn WebSocket decoded57.8 KiB56.4 KiB−1.4 KiB (−2.5%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: 8efd4e9 · PR result: 3eacbbb · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/remoteUpdateFlow.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This cross-layer feature adds an authenticated remote desktop-update protocol and a two-phase workflow that can download, install, quit, relaunch, and recover the desktop app. It introduces substantial production behavior across the desktop, server, client runtime, UI, and contracts, including a sensitive authorization change, so the side effects require human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadpackages/contracts/src/resourceTelemetry.ts Outdated
Comment threadapps/web/src/components/ServerUpdateAction.tsx Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Sep 1, 2026
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from c9f5fb4 to ec91c4cCompareSeptember 2, 2026 01:01
@t3dotggt3dotgg added the preview:mac Build an Apple Silicon DMG for this PR on every push. label Sep 2, 2026
@github-actions

github-actionsBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

macOS preview

The preview download was removed because this PR closed or the preview label was removed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadpackages/client-runtime/src/state/server.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts
t3dotggand others added 5 commits September 1, 2026 18:22
…button
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…try hardening
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tting
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… field
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…naturally
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
t3dotggand others added 9 commits September 1, 2026 18:22
…ress install
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ation
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Install stopped backends, destroyed every window, then called quitAndInstall. If that last step failed, quitting was cleared and an error was stored, but the windows were already gone. There was no path to open one again.
Call quitAndInstall first. Destroy windows only after that starts.
Install still stops backends before quitAndInstall. If that last step fails, the window stayed up but the pool was already down, so the UI was disconnected.
On install failure, start the stopped backends again.
# Conflicts:
#	apps/desktop/src/updates/DesktopUpdates.test.ts
#	apps/desktop/src/updates/DesktopUpdates.ts
Prepare the desktop update before returning the progress result, then commit
the install only after the client receives its token. Retry lost commits by
token and require the prepared version after reconnect.
Keep windows open until updater-controlled quit and restart stopped backends
when Electron reports an install failure.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from 9a3ed9a to 8fec783CompareSeptember 2, 2026 01:23
Comment threadpackages/client-runtime/src/state/server.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/app/DesktopLifecycle.ts
t3dotggand others added 2 commits September 1, 2026 18:32
@t3dotgg

t3dotgg commented Sep 2, 2026

Copy link
Copy Markdown
MemberAuthor

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

Fixed and pushed in cb96a8e268b5acc0d7f40017a5b0b30fff582af8. Remote commit now joins only when the exact downloaded version still matches and the updater's install reservation is active. Ordinary quit and relaunch no longer count as an install handoff. Tests use a real competing local install and cover normal quit separately. The coordination hold is cleared, subject to normal CI and review.

Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
…mpletes
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0fc8f4a. Configure here.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotgg merged commit b2f25d3 into mainSep 2, 2026
28 checks passed
@t3dotgg
t3dotgg deleted the t3code/remote-mac-app-updates branch September 2, 2026 02:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
amitbet pushed a commit to amitbet/a2code that referenced this pull request Sep 2, 2026
Resolves 48 conflicts. Brings in Claude Fable 5.1 (claude-fable-5-1, requires
Claude Code >= 2.1.257) via upstream's move of the Claude model list into
model-manifest.json.
Declines upstream's remote desktop-update feature (pingdotgg#6554): it is welded to the
electron-installer path this fork deleted, so its files are dropped and the
server never advertises the desktopAppUpdate capability, keeping the Update
button from offering something that can never finish.
Preserves the fork's queued-prompt steering, in-chat find, thread
fork/references/export, MCP thread search, live quota meter, machine-scoped
sidebar, payload hot-update channel, branding and trimmed CI surface. Adopts
upstream's reversal of create-time project model seeding (inside the extracted
useAddProjectFromPath hook) and renumbers upstream's migration 044 to the
fork's 047.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

preview:macBuild an Apple Silicon DMG for this PR on every push.size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@t3dotgg@Adolanium
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(desktop): update the desktop app on remote Macs from the Update button - #6554

Merged
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates
Sep 2, 2026
Merged

feat(desktop): update the desktop app on remote Macs from the Update button#6554
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 14, 2026

Copy link
Copy Markdown
Member

Remote desktop-managed servers could not update their desktop app.

This change uses a two-phase handoff. Desktop checks and downloads first, then reports a short-lived token while the backend stays connected. The client sends a commit RPC after it receives the token. It accepts success only after reconnecting to the exact prepared version, and retries a lost commit with the same token.

Preparations expire, support early cancellation, and wait up to 90 seconds for a background check. Tokens bind the downloaded version. Duplicate commits cannot start a second install. Desktop keeps windows open until Electron starts updater-controlled quit. Install failures hold a recovery reservation while stopped backends restart, and retained failures replay after restart. Tokenless desktop updates must prove the target version before the client accepts success.

Verification passed 205 focused tests and scoped typechecks across all affected packages. A child-process test passed through the real fd3/fd4 transport with the update services and telemetry services. It covered child restart, failure replay, and duplicate commits. Packaged Mac installation is not yet verified.

Failure recovery adapts #8429 without merging or closing it. Original work by Theo with Claude Code. Protocol and recovery by GPT-5.6 Sol with Codex. Failure recovery commits by Adolanium.

Note

Add server-triggered desktop app updates via server.commitDesktopUpdate RPC

  • Adds a telemetry control channel for server-to-desktop update request, commit, and cancel messages, and a DesktopRemoteUpdates listener that mirrors updater state to the server through DesktopUpdateStatusReport
  • Adds the server-side DesktopAppUpdate service that correlates status reports by request ID, maps progress stages, and returns a desktop-app self-update result with a commit token when the desktop reports ready-to-install
  • Extends DesktopUpdates with install recovery that restarts backends on installer failure, version-checked installPrepared, and a bounded state-change stream via subscribe
  • Web UI renders an Update button with confirmation for desktop-managed servers advertising the desktopAppUpdate capability; unsupported servers retain manual instructions
  • Adds reconnect-observer logic so a desktop commit lost during transport handoff waits for reconnection and retries up to three ready events before failing with ServerUpdateTerminalError
  • Behavioral Change: updater-controlled quit now destroys windows synchronously inside the before-quit-for-update listener instead of forking an async effect; ServerEnvironment advertises desktopAppUpdate: true only for desktop-managed servers with a desktopTelemetryControlFd, and serverCommitDesktopUpdate requires AuthOrchestrationOperateScope

Macroscope summarized 3eacbbb.

@coderabbitai

coderabbitaiBot commented Aug 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 370c51d2-3573-4944-9650-f5f3100b931b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 14, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions: one finding — Effect.catchTag used in the new DesktopAppUpdate service; the repo convention is Effect.catchTags({ ... }) even for a single tag. Everything else in the new service/layer code (namespace subpath imports, inline Context.Service interface, make + layer exports, Foo["Service"] typing, environment-acquired dependencies, no runtime escapes) matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
Comment threadapps/server/src/cloud/selfUpdate.ts
@github-actions

github-actionsBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.3 KiB+164 B (+1.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.4 KiB+166 B (+2.6%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB55.6 KiB+910 B (+1.6%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.4 KiB13.3 KiB−158 B (−1.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+3 B (+0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.6 KiB6.4 KiB−161 B (−2.4%)7.8 KiB
ClaudeLive turn WebSocket decoded57.8 KiB56.4 KiB−1.4 KiB (−2.5%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: 8efd4e9 · PR result: 3eacbbb · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/remoteUpdateFlow.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This cross-layer feature adds an authenticated remote desktop-update protocol and a two-phase workflow that can download, install, quit, relaunch, and recover the desktop app. It introduces substantial production behavior across the desktop, server, client runtime, UI, and contracts, including a sensitive authorization change, so the side effects require human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadpackages/contracts/src/resourceTelemetry.ts Outdated
Comment threadapps/web/src/components/ServerUpdateAction.tsx Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Sep 1, 2026
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from c9f5fb4 to ec91c4cCompareSeptember 2, 2026 01:01
@t3dotggt3dotgg added the preview:mac Build an Apple Silicon DMG for this PR on every push. label Sep 2, 2026
@github-actions

github-actionsBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

macOS preview

The preview download was removed because this PR closed or the preview label was removed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadpackages/client-runtime/src/state/server.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts
t3dotggand others added 5 commits September 1, 2026 18:22
…button
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…try hardening
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tting
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… field
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…naturally
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
t3dotggand others added 9 commits September 1, 2026 18:22
…ress install
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ation
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Install stopped backends, destroyed every window, then called quitAndInstall. If that last step failed, quitting was cleared and an error was stored, but the windows were already gone. There was no path to open one again.
Call quitAndInstall first. Destroy windows only after that starts.
Install still stops backends before quitAndInstall. If that last step fails, the window stayed up but the pool was already down, so the UI was disconnected.
On install failure, start the stopped backends again.
# Conflicts:
#	apps/desktop/src/updates/DesktopUpdates.test.ts
#	apps/desktop/src/updates/DesktopUpdates.ts
Prepare the desktop update before returning the progress result, then commit
the install only after the client receives its token. Retry lost commits by
token and require the prepared version after reconnect.
Keep windows open until updater-controlled quit and restart stopped backends
when Electron reports an install failure.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from 9a3ed9a to 8fec783CompareSeptember 2, 2026 01:23
Comment threadpackages/client-runtime/src/state/server.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/app/DesktopLifecycle.ts
t3dotggand others added 2 commits September 1, 2026 18:32
@t3dotgg

t3dotgg commented Sep 2, 2026

Copy link
Copy Markdown
MemberAuthor

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

Fixed and pushed in cb96a8e268b5acc0d7f40017a5b0b30fff582af8. Remote commit now joins only when the exact downloaded version still matches and the updater's install reservation is active. Ordinary quit and relaunch no longer count as an install handoff. Tests use a real competing local install and cover normal quit separately. The coordination hold is cleared, subject to normal CI and review.

Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
…mpletes
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0fc8f4a. Configure here.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotgg merged commit b2f25d3 into mainSep 2, 2026
28 checks passed
@t3dotgg
t3dotgg deleted the t3code/remote-mac-app-updates branch September 2, 2026 02:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
amitbet pushed a commit to amitbet/a2code that referenced this pull request Sep 2, 2026
Resolves 48 conflicts. Brings in Claude Fable 5.1 (claude-fable-5-1, requires
Claude Code >= 2.1.257) via upstream's move of the Claude model list into
model-manifest.json.
Declines upstream's remote desktop-update feature (pingdotgg#6554): it is welded to the
electron-installer path this fork deleted, so its files are dropped and the
server never advertises the desktopAppUpdate capability, keeping the Update
button from offering something that can never finish.
Preserves the fork's queued-prompt steering, in-chat find, thread
fork/references/export, MCP thread search, live quota meter, machine-scoped
sidebar, payload hot-update channel, branding and trimmed CI surface. Adopts
upstream's reversal of create-time project model seeding (inside the extracted
useAddProjectFromPath hook) and renumbers upstream's migration 044 to the
fork's 047.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

preview:macBuild an Apple Silicon DMG for this PR on every push.size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@t3dotgg@Adolanium
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(desktop): update the desktop app on remote Macs from the Update button - #6554

Merged
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates
Sep 2, 2026
Merged

feat(desktop): update the desktop app on remote Macs from the Update button#6554
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 14, 2026

Copy link
Copy Markdown
Member

Remote desktop-managed servers could not update their desktop app.

This change uses a two-phase handoff. Desktop checks and downloads first, then reports a short-lived token while the backend stays connected. The client sends a commit RPC after it receives the token. It accepts success only after reconnecting to the exact prepared version, and retries a lost commit with the same token.

Preparations expire, support early cancellation, and wait up to 90 seconds for a background check. Tokens bind the downloaded version. Duplicate commits cannot start a second install. Desktop keeps windows open until Electron starts updater-controlled quit. Install failures hold a recovery reservation while stopped backends restart, and retained failures replay after restart. Tokenless desktop updates must prove the target version before the client accepts success.

Verification passed 205 focused tests and scoped typechecks across all affected packages. A child-process test passed through the real fd3/fd4 transport with the update services and telemetry services. It covered child restart, failure replay, and duplicate commits. Packaged Mac installation is not yet verified.

Failure recovery adapts #8429 without merging or closing it. Original work by Theo with Claude Code. Protocol and recovery by GPT-5.6 Sol with Codex. Failure recovery commits by Adolanium.

Note

Add server-triggered desktop app updates via server.commitDesktopUpdate RPC

  • Adds a telemetry control channel for server-to-desktop update request, commit, and cancel messages, and a DesktopRemoteUpdates listener that mirrors updater state to the server through DesktopUpdateStatusReport
  • Adds the server-side DesktopAppUpdate service that correlates status reports by request ID, maps progress stages, and returns a desktop-app self-update result with a commit token when the desktop reports ready-to-install
  • Extends DesktopUpdates with install recovery that restarts backends on installer failure, version-checked installPrepared, and a bounded state-change stream via subscribe
  • Web UI renders an Update button with confirmation for desktop-managed servers advertising the desktopAppUpdate capability; unsupported servers retain manual instructions
  • Adds reconnect-observer logic so a desktop commit lost during transport handoff waits for reconnection and retries up to three ready events before failing with ServerUpdateTerminalError
  • Behavioral Change: updater-controlled quit now destroys windows synchronously inside the before-quit-for-update listener instead of forking an async effect; ServerEnvironment advertises desktopAppUpdate: true only for desktop-managed servers with a desktopTelemetryControlFd, and serverCommitDesktopUpdate requires AuthOrchestrationOperateScope

Macroscope summarized 3eacbbb.

@coderabbitai

coderabbitaiBot commented Aug 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 370c51d2-3573-4944-9650-f5f3100b931b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 14, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions: one finding — Effect.catchTag used in the new DesktopAppUpdate service; the repo convention is Effect.catchTags({ ... }) even for a single tag. Everything else in the new service/layer code (namespace subpath imports, inline Context.Service interface, make + layer exports, Foo["Service"] typing, environment-acquired dependencies, no runtime escapes) matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
Comment threadapps/server/src/cloud/selfUpdate.ts
@github-actions

github-actionsBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.3 KiB+164 B (+1.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.4 KiB+166 B (+2.6%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB55.6 KiB+910 B (+1.6%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.4 KiB13.3 KiB−158 B (−1.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+3 B (+0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.6 KiB6.4 KiB−161 B (−2.4%)7.8 KiB
ClaudeLive turn WebSocket decoded57.8 KiB56.4 KiB−1.4 KiB (−2.5%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: 8efd4e9 · PR result: 3eacbbb · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/remoteUpdateFlow.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This cross-layer feature adds an authenticated remote desktop-update protocol and a two-phase workflow that can download, install, quit, relaunch, and recover the desktop app. It introduces substantial production behavior across the desktop, server, client runtime, UI, and contracts, including a sensitive authorization change, so the side effects require human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadpackages/contracts/src/resourceTelemetry.ts Outdated
Comment threadapps/web/src/components/ServerUpdateAction.tsx Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Sep 1, 2026
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from c9f5fb4 to ec91c4cCompareSeptember 2, 2026 01:01
@t3dotggt3dotgg added the preview:mac Build an Apple Silicon DMG for this PR on every push. label Sep 2, 2026
@github-actions

github-actionsBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

macOS preview

The preview download was removed because this PR closed or the preview label was removed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadpackages/client-runtime/src/state/server.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts
t3dotggand others added 5 commits September 1, 2026 18:22
…button
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…try hardening
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tting
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… field
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…naturally
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
t3dotggand others added 9 commits September 1, 2026 18:22
…ress install
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ation
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Install stopped backends, destroyed every window, then called quitAndInstall. If that last step failed, quitting was cleared and an error was stored, but the windows were already gone. There was no path to open one again.
Call quitAndInstall first. Destroy windows only after that starts.
Install still stops backends before quitAndInstall. If that last step fails, the window stayed up but the pool was already down, so the UI was disconnected.
On install failure, start the stopped backends again.
# Conflicts:
#	apps/desktop/src/updates/DesktopUpdates.test.ts
#	apps/desktop/src/updates/DesktopUpdates.ts
Prepare the desktop update before returning the progress result, then commit
the install only after the client receives its token. Retry lost commits by
token and require the prepared version after reconnect.
Keep windows open until updater-controlled quit and restart stopped backends
when Electron reports an install failure.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from 9a3ed9a to 8fec783CompareSeptember 2, 2026 01:23
Comment threadpackages/client-runtime/src/state/server.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/app/DesktopLifecycle.ts
t3dotggand others added 2 commits September 1, 2026 18:32
@t3dotgg

t3dotgg commented Sep 2, 2026

Copy link
Copy Markdown
MemberAuthor

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

Fixed and pushed in cb96a8e268b5acc0d7f40017a5b0b30fff582af8. Remote commit now joins only when the exact downloaded version still matches and the updater's install reservation is active. Ordinary quit and relaunch no longer count as an install handoff. Tests use a real competing local install and cover normal quit separately. The coordination hold is cleared, subject to normal CI and review.

Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
…mpletes
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0fc8f4a. Configure here.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotgg merged commit b2f25d3 into mainSep 2, 2026
28 checks passed
@t3dotgg
t3dotgg deleted the t3code/remote-mac-app-updates branch September 2, 2026 02:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
amitbet pushed a commit to amitbet/a2code that referenced this pull request Sep 2, 2026
Resolves 48 conflicts. Brings in Claude Fable 5.1 (claude-fable-5-1, requires
Claude Code >= 2.1.257) via upstream's move of the Claude model list into
model-manifest.json.
Declines upstream's remote desktop-update feature (pingdotgg#6554): it is welded to the
electron-installer path this fork deleted, so its files are dropped and the
server never advertises the desktopAppUpdate capability, keeping the Update
button from offering something that can never finish.
Preserves the fork's queued-prompt steering, in-chat find, thread
fork/references/export, MCP thread search, live quota meter, machine-scoped
sidebar, payload hot-update channel, branding and trimmed CI surface. Adopts
upstream's reversal of create-time project model seeding (inside the extracted
useAddProjectFromPath hook) and renumbers upstream's migration 044 to the
fork's 047.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

preview:macBuild an Apple Silicon DMG for this PR on every push.size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@t3dotgg@Adolanium
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(desktop): update the desktop app on remote Macs from the Update button - #6554

Merged
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates
Sep 2, 2026
Merged

feat(desktop): update the desktop app on remote Macs from the Update button#6554
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 14, 2026

Copy link
Copy Markdown
Member

Remote desktop-managed servers could not update their desktop app.

This change uses a two-phase handoff. Desktop checks and downloads first, then reports a short-lived token while the backend stays connected. The client sends a commit RPC after it receives the token. It accepts success only after reconnecting to the exact prepared version, and retries a lost commit with the same token.

Preparations expire, support early cancellation, and wait up to 90 seconds for a background check. Tokens bind the downloaded version. Duplicate commits cannot start a second install. Desktop keeps windows open until Electron starts updater-controlled quit. Install failures hold a recovery reservation while stopped backends restart, and retained failures replay after restart. Tokenless desktop updates must prove the target version before the client accepts success.

Verification passed 205 focused tests and scoped typechecks across all affected packages. A child-process test passed through the real fd3/fd4 transport with the update services and telemetry services. It covered child restart, failure replay, and duplicate commits. Packaged Mac installation is not yet verified.

Failure recovery adapts #8429 without merging or closing it. Original work by Theo with Claude Code. Protocol and recovery by GPT-5.6 Sol with Codex. Failure recovery commits by Adolanium.

Note

Add server-triggered desktop app updates via server.commitDesktopUpdate RPC

  • Adds a telemetry control channel for server-to-desktop update request, commit, and cancel messages, and a DesktopRemoteUpdates listener that mirrors updater state to the server through DesktopUpdateStatusReport
  • Adds the server-side DesktopAppUpdate service that correlates status reports by request ID, maps progress stages, and returns a desktop-app self-update result with a commit token when the desktop reports ready-to-install
  • Extends DesktopUpdates with install recovery that restarts backends on installer failure, version-checked installPrepared, and a bounded state-change stream via subscribe
  • Web UI renders an Update button with confirmation for desktop-managed servers advertising the desktopAppUpdate capability; unsupported servers retain manual instructions
  • Adds reconnect-observer logic so a desktop commit lost during transport handoff waits for reconnection and retries up to three ready events before failing with ServerUpdateTerminalError
  • Behavioral Change: updater-controlled quit now destroys windows synchronously inside the before-quit-for-update listener instead of forking an async effect; ServerEnvironment advertises desktopAppUpdate: true only for desktop-managed servers with a desktopTelemetryControlFd, and serverCommitDesktopUpdate requires AuthOrchestrationOperateScope

Macroscope summarized 3eacbbb.

@coderabbitai

coderabbitaiBot commented Aug 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 370c51d2-3573-4944-9650-f5f3100b931b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 14, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions: one finding — Effect.catchTag used in the new DesktopAppUpdate service; the repo convention is Effect.catchTags({ ... }) even for a single tag. Everything else in the new service/layer code (namespace subpath imports, inline Context.Service interface, make + layer exports, Foo["Service"] typing, environment-acquired dependencies, no runtime escapes) matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
Comment threadapps/server/src/cloud/selfUpdate.ts
@github-actions

github-actionsBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.3 KiB+164 B (+1.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.4 KiB+166 B (+2.6%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB55.6 KiB+910 B (+1.6%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.4 KiB13.3 KiB−158 B (−1.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+3 B (+0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.6 KiB6.4 KiB−161 B (−2.4%)7.8 KiB
ClaudeLive turn WebSocket decoded57.8 KiB56.4 KiB−1.4 KiB (−2.5%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: 8efd4e9 · PR result: 3eacbbb · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/remoteUpdateFlow.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This cross-layer feature adds an authenticated remote desktop-update protocol and a two-phase workflow that can download, install, quit, relaunch, and recover the desktop app. It introduces substantial production behavior across the desktop, server, client runtime, UI, and contracts, including a sensitive authorization change, so the side effects require human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadpackages/contracts/src/resourceTelemetry.ts Outdated
Comment threadapps/web/src/components/ServerUpdateAction.tsx Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Sep 1, 2026
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from c9f5fb4 to ec91c4cCompareSeptember 2, 2026 01:01
@t3dotggt3dotgg added the preview:mac Build an Apple Silicon DMG for this PR on every push. label Sep 2, 2026
@github-actions

github-actionsBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

macOS preview

The preview download was removed because this PR closed or the preview label was removed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadpackages/client-runtime/src/state/server.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts
t3dotggand others added 5 commits September 1, 2026 18:22
…button
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…try hardening
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tting
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… field
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…naturally
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
t3dotggand others added 9 commits September 1, 2026 18:22
…ress install
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ation
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Install stopped backends, destroyed every window, then called quitAndInstall. If that last step failed, quitting was cleared and an error was stored, but the windows were already gone. There was no path to open one again.
Call quitAndInstall first. Destroy windows only after that starts.
Install still stops backends before quitAndInstall. If that last step fails, the window stayed up but the pool was already down, so the UI was disconnected.
On install failure, start the stopped backends again.
# Conflicts:
#	apps/desktop/src/updates/DesktopUpdates.test.ts
#	apps/desktop/src/updates/DesktopUpdates.ts
Prepare the desktop update before returning the progress result, then commit
the install only after the client receives its token. Retry lost commits by
token and require the prepared version after reconnect.
Keep windows open until updater-controlled quit and restart stopped backends
when Electron reports an install failure.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from 9a3ed9a to 8fec783CompareSeptember 2, 2026 01:23
Comment threadpackages/client-runtime/src/state/server.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/app/DesktopLifecycle.ts
t3dotggand others added 2 commits September 1, 2026 18:32
@t3dotgg

t3dotgg commented Sep 2, 2026

Copy link
Copy Markdown
MemberAuthor

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

Fixed and pushed in cb96a8e268b5acc0d7f40017a5b0b30fff582af8. Remote commit now joins only when the exact downloaded version still matches and the updater's install reservation is active. Ordinary quit and relaunch no longer count as an install handoff. Tests use a real competing local install and cover normal quit separately. The coordination hold is cleared, subject to normal CI and review.

Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
…mpletes
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0fc8f4a. Configure here.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotgg merged commit b2f25d3 into mainSep 2, 2026
28 checks passed
@t3dotgg
t3dotgg deleted the t3code/remote-mac-app-updates branch September 2, 2026 02:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
amitbet pushed a commit to amitbet/a2code that referenced this pull request Sep 2, 2026
Resolves 48 conflicts. Brings in Claude Fable 5.1 (claude-fable-5-1, requires
Claude Code >= 2.1.257) via upstream's move of the Claude model list into
model-manifest.json.
Declines upstream's remote desktop-update feature (pingdotgg#6554): it is welded to the
electron-installer path this fork deleted, so its files are dropped and the
server never advertises the desktopAppUpdate capability, keeping the Update
button from offering something that can never finish.
Preserves the fork's queued-prompt steering, in-chat find, thread
fork/references/export, MCP thread search, live quota meter, machine-scoped
sidebar, payload hot-update channel, branding and trimmed CI surface. Adopts
upstream's reversal of create-time project model seeding (inside the extracted
useAddProjectFromPath hook) and renumbers upstream's migration 044 to the
fork's 047.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

preview:macBuild an Apple Silicon DMG for this PR on every push.size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@t3dotgg@Adolanium
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(desktop): update the desktop app on remote Macs from the Update button - #6554

Merged
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates
Sep 2, 2026
Merged

feat(desktop): update the desktop app on remote Macs from the Update button#6554
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 14, 2026

Copy link
Copy Markdown
Member

Remote desktop-managed servers could not update their desktop app.

This change uses a two-phase handoff. Desktop checks and downloads first, then reports a short-lived token while the backend stays connected. The client sends a commit RPC after it receives the token. It accepts success only after reconnecting to the exact prepared version, and retries a lost commit with the same token.

Preparations expire, support early cancellation, and wait up to 90 seconds for a background check. Tokens bind the downloaded version. Duplicate commits cannot start a second install. Desktop keeps windows open until Electron starts updater-controlled quit. Install failures hold a recovery reservation while stopped backends restart, and retained failures replay after restart. Tokenless desktop updates must prove the target version before the client accepts success.

Verification passed 205 focused tests and scoped typechecks across all affected packages. A child-process test passed through the real fd3/fd4 transport with the update services and telemetry services. It covered child restart, failure replay, and duplicate commits. Packaged Mac installation is not yet verified.

Failure recovery adapts #8429 without merging or closing it. Original work by Theo with Claude Code. Protocol and recovery by GPT-5.6 Sol with Codex. Failure recovery commits by Adolanium.

Note

Add server-triggered desktop app updates via server.commitDesktopUpdate RPC

  • Adds a telemetry control channel for server-to-desktop update request, commit, and cancel messages, and a DesktopRemoteUpdates listener that mirrors updater state to the server through DesktopUpdateStatusReport
  • Adds the server-side DesktopAppUpdate service that correlates status reports by request ID, maps progress stages, and returns a desktop-app self-update result with a commit token when the desktop reports ready-to-install
  • Extends DesktopUpdates with install recovery that restarts backends on installer failure, version-checked installPrepared, and a bounded state-change stream via subscribe
  • Web UI renders an Update button with confirmation for desktop-managed servers advertising the desktopAppUpdate capability; unsupported servers retain manual instructions
  • Adds reconnect-observer logic so a desktop commit lost during transport handoff waits for reconnection and retries up to three ready events before failing with ServerUpdateTerminalError
  • Behavioral Change: updater-controlled quit now destroys windows synchronously inside the before-quit-for-update listener instead of forking an async effect; ServerEnvironment advertises desktopAppUpdate: true only for desktop-managed servers with a desktopTelemetryControlFd, and serverCommitDesktopUpdate requires AuthOrchestrationOperateScope

Macroscope summarized 3eacbbb.

@coderabbitai

coderabbitaiBot commented Aug 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 370c51d2-3573-4944-9650-f5f3100b931b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 14, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions: one finding — Effect.catchTag used in the new DesktopAppUpdate service; the repo convention is Effect.catchTags({ ... }) even for a single tag. Everything else in the new service/layer code (namespace subpath imports, inline Context.Service interface, make + layer exports, Foo["Service"] typing, environment-acquired dependencies, no runtime escapes) matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
Comment threadapps/server/src/cloud/selfUpdate.ts
@github-actions

github-actionsBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.3 KiB+164 B (+1.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.4 KiB+166 B (+2.6%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB55.6 KiB+910 B (+1.6%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.4 KiB13.3 KiB−158 B (−1.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+3 B (+0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.6 KiB6.4 KiB−161 B (−2.4%)7.8 KiB
ClaudeLive turn WebSocket decoded57.8 KiB56.4 KiB−1.4 KiB (−2.5%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: 8efd4e9 · PR result: 3eacbbb · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/remoteUpdateFlow.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This cross-layer feature adds an authenticated remote desktop-update protocol and a two-phase workflow that can download, install, quit, relaunch, and recover the desktop app. It introduces substantial production behavior across the desktop, server, client runtime, UI, and contracts, including a sensitive authorization change, so the side effects require human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadpackages/contracts/src/resourceTelemetry.ts Outdated
Comment threadapps/web/src/components/ServerUpdateAction.tsx Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Sep 1, 2026
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from c9f5fb4 to ec91c4cCompareSeptember 2, 2026 01:01
@t3dotggt3dotgg added the preview:mac Build an Apple Silicon DMG for this PR on every push. label Sep 2, 2026
@github-actions

github-actionsBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

macOS preview

The preview download was removed because this PR closed or the preview label was removed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadpackages/client-runtime/src/state/server.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts
t3dotggand others added 5 commits September 1, 2026 18:22
…button
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…try hardening
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tting
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… field
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…naturally
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
t3dotggand others added 9 commits September 1, 2026 18:22
…ress install
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ation
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Install stopped backends, destroyed every window, then called quitAndInstall. If that last step failed, quitting was cleared and an error was stored, but the windows were already gone. There was no path to open one again.
Call quitAndInstall first. Destroy windows only after that starts.
Install still stops backends before quitAndInstall. If that last step fails, the window stayed up but the pool was already down, so the UI was disconnected.
On install failure, start the stopped backends again.
# Conflicts:
#	apps/desktop/src/updates/DesktopUpdates.test.ts
#	apps/desktop/src/updates/DesktopUpdates.ts
Prepare the desktop update before returning the progress result, then commit
the install only after the client receives its token. Retry lost commits by
token and require the prepared version after reconnect.
Keep windows open until updater-controlled quit and restart stopped backends
when Electron reports an install failure.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from 9a3ed9a to 8fec783CompareSeptember 2, 2026 01:23
Comment threadpackages/client-runtime/src/state/server.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/app/DesktopLifecycle.ts
t3dotggand others added 2 commits September 1, 2026 18:32
@t3dotgg

t3dotgg commented Sep 2, 2026

Copy link
Copy Markdown
MemberAuthor

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

Fixed and pushed in cb96a8e268b5acc0d7f40017a5b0b30fff582af8. Remote commit now joins only when the exact downloaded version still matches and the updater's install reservation is active. Ordinary quit and relaunch no longer count as an install handoff. Tests use a real competing local install and cover normal quit separately. The coordination hold is cleared, subject to normal CI and review.

Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
…mpletes
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0fc8f4a. Configure here.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotgg merged commit b2f25d3 into mainSep 2, 2026
28 checks passed
@t3dotgg
t3dotgg deleted the t3code/remote-mac-app-updates branch September 2, 2026 02:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
amitbet pushed a commit to amitbet/a2code that referenced this pull request Sep 2, 2026
Resolves 48 conflicts. Brings in Claude Fable 5.1 (claude-fable-5-1, requires
Claude Code >= 2.1.257) via upstream's move of the Claude model list into
model-manifest.json.
Declines upstream's remote desktop-update feature (pingdotgg#6554): it is welded to the
electron-installer path this fork deleted, so its files are dropped and the
server never advertises the desktopAppUpdate capability, keeping the Update
button from offering something that can never finish.
Preserves the fork's queued-prompt steering, in-chat find, thread
fork/references/export, MCP thread search, live quota meter, machine-scoped
sidebar, payload hot-update channel, branding and trimmed CI surface. Adopts
upstream's reversal of create-time project model seeding (inside the extracted
useAddProjectFromPath hook) and renumbers upstream's migration 044 to the
fork's 047.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

preview:macBuild an Apple Silicon DMG for this PR on every push.size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@t3dotgg@Adolanium
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(desktop): update the desktop app on remote Macs from the Update button - #6554

Merged
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates
Sep 2, 2026
Merged

feat(desktop): update the desktop app on remote Macs from the Update button#6554
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 14, 2026

Copy link
Copy Markdown
Member

Remote desktop-managed servers could not update their desktop app.

This change uses a two-phase handoff. Desktop checks and downloads first, then reports a short-lived token while the backend stays connected. The client sends a commit RPC after it receives the token. It accepts success only after reconnecting to the exact prepared version, and retries a lost commit with the same token.

Preparations expire, support early cancellation, and wait up to 90 seconds for a background check. Tokens bind the downloaded version. Duplicate commits cannot start a second install. Desktop keeps windows open until Electron starts updater-controlled quit. Install failures hold a recovery reservation while stopped backends restart, and retained failures replay after restart. Tokenless desktop updates must prove the target version before the client accepts success.

Verification passed 205 focused tests and scoped typechecks across all affected packages. A child-process test passed through the real fd3/fd4 transport with the update services and telemetry services. It covered child restart, failure replay, and duplicate commits. Packaged Mac installation is not yet verified.

Failure recovery adapts #8429 without merging or closing it. Original work by Theo with Claude Code. Protocol and recovery by GPT-5.6 Sol with Codex. Failure recovery commits by Adolanium.

Note

Add server-triggered desktop app updates via server.commitDesktopUpdate RPC

  • Adds a telemetry control channel for server-to-desktop update request, commit, and cancel messages, and a DesktopRemoteUpdates listener that mirrors updater state to the server through DesktopUpdateStatusReport
  • Adds the server-side DesktopAppUpdate service that correlates status reports by request ID, maps progress stages, and returns a desktop-app self-update result with a commit token when the desktop reports ready-to-install
  • Extends DesktopUpdates with install recovery that restarts backends on installer failure, version-checked installPrepared, and a bounded state-change stream via subscribe
  • Web UI renders an Update button with confirmation for desktop-managed servers advertising the desktopAppUpdate capability; unsupported servers retain manual instructions
  • Adds reconnect-observer logic so a desktop commit lost during transport handoff waits for reconnection and retries up to three ready events before failing with ServerUpdateTerminalError
  • Behavioral Change: updater-controlled quit now destroys windows synchronously inside the before-quit-for-update listener instead of forking an async effect; ServerEnvironment advertises desktopAppUpdate: true only for desktop-managed servers with a desktopTelemetryControlFd, and serverCommitDesktopUpdate requires AuthOrchestrationOperateScope

Macroscope summarized 3eacbbb.

@coderabbitai

coderabbitaiBot commented Aug 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 370c51d2-3573-4944-9650-f5f3100b931b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 14, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions: one finding — Effect.catchTag used in the new DesktopAppUpdate service; the repo convention is Effect.catchTags({ ... }) even for a single tag. Everything else in the new service/layer code (namespace subpath imports, inline Context.Service interface, make + layer exports, Foo["Service"] typing, environment-acquired dependencies, no runtime escapes) matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
Comment threadapps/server/src/cloud/selfUpdate.ts
@github-actions

github-actionsBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.3 KiB+164 B (+1.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.4 KiB+166 B (+2.6%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB55.6 KiB+910 B (+1.6%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.4 KiB13.3 KiB−158 B (−1.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+3 B (+0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.6 KiB6.4 KiB−161 B (−2.4%)7.8 KiB
ClaudeLive turn WebSocket decoded57.8 KiB56.4 KiB−1.4 KiB (−2.5%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: 8efd4e9 · PR result: 3eacbbb · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/remoteUpdateFlow.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This cross-layer feature adds an authenticated remote desktop-update protocol and a two-phase workflow that can download, install, quit, relaunch, and recover the desktop app. It introduces substantial production behavior across the desktop, server, client runtime, UI, and contracts, including a sensitive authorization change, so the side effects require human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadpackages/contracts/src/resourceTelemetry.ts Outdated
Comment threadapps/web/src/components/ServerUpdateAction.tsx Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Sep 1, 2026
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from c9f5fb4 to ec91c4cCompareSeptember 2, 2026 01:01
@t3dotggt3dotgg added the preview:mac Build an Apple Silicon DMG for this PR on every push. label Sep 2, 2026
@github-actions

github-actionsBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

macOS preview

The preview download was removed because this PR closed or the preview label was removed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadpackages/client-runtime/src/state/server.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts
t3dotggand others added 5 commits September 1, 2026 18:22
…button
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…try hardening
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tting
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… field
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…naturally
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
t3dotggand others added 9 commits September 1, 2026 18:22
…ress install
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ation
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Install stopped backends, destroyed every window, then called quitAndInstall. If that last step failed, quitting was cleared and an error was stored, but the windows were already gone. There was no path to open one again.
Call quitAndInstall first. Destroy windows only after that starts.
Install still stops backends before quitAndInstall. If that last step fails, the window stayed up but the pool was already down, so the UI was disconnected.
On install failure, start the stopped backends again.
# Conflicts:
#	apps/desktop/src/updates/DesktopUpdates.test.ts
#	apps/desktop/src/updates/DesktopUpdates.ts
Prepare the desktop update before returning the progress result, then commit
the install only after the client receives its token. Retry lost commits by
token and require the prepared version after reconnect.
Keep windows open until updater-controlled quit and restart stopped backends
when Electron reports an install failure.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from 9a3ed9a to 8fec783CompareSeptember 2, 2026 01:23
Comment threadpackages/client-runtime/src/state/server.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/app/DesktopLifecycle.ts
t3dotggand others added 2 commits September 1, 2026 18:32
@t3dotgg

t3dotgg commented Sep 2, 2026

Copy link
Copy Markdown
MemberAuthor

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

Fixed and pushed in cb96a8e268b5acc0d7f40017a5b0b30fff582af8. Remote commit now joins only when the exact downloaded version still matches and the updater's install reservation is active. Ordinary quit and relaunch no longer count as an install handoff. Tests use a real competing local install and cover normal quit separately. The coordination hold is cleared, subject to normal CI and review.

Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
…mpletes
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0fc8f4a. Configure here.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotgg merged commit b2f25d3 into mainSep 2, 2026
28 checks passed
@t3dotgg
t3dotgg deleted the t3code/remote-mac-app-updates branch September 2, 2026 02:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
amitbet pushed a commit to amitbet/a2code that referenced this pull request Sep 2, 2026
Resolves 48 conflicts. Brings in Claude Fable 5.1 (claude-fable-5-1, requires
Claude Code >= 2.1.257) via upstream's move of the Claude model list into
model-manifest.json.
Declines upstream's remote desktop-update feature (pingdotgg#6554): it is welded to the
electron-installer path this fork deleted, so its files are dropped and the
server never advertises the desktopAppUpdate capability, keeping the Update
button from offering something that can never finish.
Preserves the fork's queued-prompt steering, in-chat find, thread
fork/references/export, MCP thread search, live quota meter, machine-scoped
sidebar, payload hot-update channel, branding and trimmed CI surface. Adopts
upstream's reversal of create-time project model seeding (inside the extracted
useAddProjectFromPath hook) and renumbers upstream's migration 044 to the
fork's 047.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

preview:macBuild an Apple Silicon DMG for this PR on every push.size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@t3dotgg@Adolanium
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(desktop): update the desktop app on remote Macs from the Update button - #6554

Merged
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates
Sep 2, 2026
Merged

feat(desktop): update the desktop app on remote Macs from the Update button#6554
t3dotgg merged 20 commits into
mainfrom
t3code/remote-mac-app-updates

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 14, 2026

Copy link
Copy Markdown
Member

Remote desktop-managed servers could not update their desktop app.

This change uses a two-phase handoff. Desktop checks and downloads first, then reports a short-lived token while the backend stays connected. The client sends a commit RPC after it receives the token. It accepts success only after reconnecting to the exact prepared version, and retries a lost commit with the same token.

Preparations expire, support early cancellation, and wait up to 90 seconds for a background check. Tokens bind the downloaded version. Duplicate commits cannot start a second install. Desktop keeps windows open until Electron starts updater-controlled quit. Install failures hold a recovery reservation while stopped backends restart, and retained failures replay after restart. Tokenless desktop updates must prove the target version before the client accepts success.

Verification passed 205 focused tests and scoped typechecks across all affected packages. A child-process test passed through the real fd3/fd4 transport with the update services and telemetry services. It covered child restart, failure replay, and duplicate commits. Packaged Mac installation is not yet verified.

Failure recovery adapts #8429 without merging or closing it. Original work by Theo with Claude Code. Protocol and recovery by GPT-5.6 Sol with Codex. Failure recovery commits by Adolanium.

Note

Add server-triggered desktop app updates via server.commitDesktopUpdate RPC

  • Adds a telemetry control channel for server-to-desktop update request, commit, and cancel messages, and a DesktopRemoteUpdates listener that mirrors updater state to the server through DesktopUpdateStatusReport
  • Adds the server-side DesktopAppUpdate service that correlates status reports by request ID, maps progress stages, and returns a desktop-app self-update result with a commit token when the desktop reports ready-to-install
  • Extends DesktopUpdates with install recovery that restarts backends on installer failure, version-checked installPrepared, and a bounded state-change stream via subscribe
  • Web UI renders an Update button with confirmation for desktop-managed servers advertising the desktopAppUpdate capability; unsupported servers retain manual instructions
  • Adds reconnect-observer logic so a desktop commit lost during transport handoff waits for reconnection and retries up to three ready events before failing with ServerUpdateTerminalError
  • Behavioral Change: updater-controlled quit now destroys windows synchronously inside the before-quit-for-update listener instead of forking an async effect; ServerEnvironment advertises desktopAppUpdate: true only for desktop-managed servers with a desktopTelemetryControlFd, and serverCommitDesktopUpdate requires AuthOrchestrationOperateScope

Macroscope summarized 3eacbbb.

@coderabbitai

coderabbitaiBot commented Aug 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 370c51d2-3573-4944-9650-f5f3100b931b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Aug 14, 2026

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Effect service conventions: one finding — Effect.catchTag used in the new DesktopAppUpdate service; the repo convention is Effect.catchTags({ ... }) even for a single tag. Everything else in the new service/layer code (namespace subpath imports, inline Context.Service interface, make + layer exports, Foo["Service"] typing, environment-acquired dependencies, no runtime escapes) matches the conventions.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
Comment threadapps/server/src/cloud/selfUpdate.ts
@github-actions

github-actionsBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.1 KiB13.3 KiB+164 B (+1.2%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB−2 B (−0.0%)7.3 KiB
CodexLive turn WebSocket wire6.2 KiB6.4 KiB+166 B (+2.6%)7.8 KiB
CodexLive turn WebSocket decoded54.7 KiB55.6 KiB+910 B (+1.6%)66.4 KiB
CodexLive turn messages810+2 (+25.0%)21
ClaudeTotal thread wire13.4 KiB13.3 KiB−158 B (−1.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+3 B (+0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.6 KiB6.4 KiB−161 B (−2.4%)7.8 KiB
ClaudeLive turn WebSocket decoded57.8 KiB56.4 KiB−1.4 KiB (−2.5%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: 8efd4e9 · PR result: 3eacbbb · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/updates/remoteUpdateFlow.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
@macroscopeapp

macroscopeappBot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This cross-layer feature adds an authenticated remote desktop-update protocol and a two-phase workflow that can download, install, quit, relaunch, and recover the desktop app. It introduces substantial production behavior across the desktop, server, client runtime, UI, and contracts, including a sensitive authorization change, so the side effects require human review.

You can add or adjust custom eligibility rules. Learn more.

Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts Outdated
Comment threadpackages/contracts/src/resourceTelemetry.ts Outdated
Comment threadapps/web/src/components/ServerUpdateAction.tsx Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:XL 500-999 changed lines (additions + deletions). labels Sep 1, 2026
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from c9f5fb4 to ec91c4cCompareSeptember 2, 2026 01:01
@t3dotggt3dotgg added the preview:mac Build an Apple Silicon DMG for this PR on every push. label Sep 2, 2026
@github-actions

github-actionsBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

macOS preview

The preview download was removed because this PR closed or the preview label was removed.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/server/src/desktopUpdate/DesktopAppUpdate.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts Outdated
Comment threadpackages/client-runtime/src/state/server.ts Outdated
Comment threadapps/desktop/src/updates/DesktopUpdates.ts
t3dotggand others added 5 commits September 1, 2026 18:22
…button
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…try hardening
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tting
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… field
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…naturally
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
t3dotggand others added 9 commits September 1, 2026 18:22
…ress install
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ation
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Install stopped backends, destroyed every window, then called quitAndInstall. If that last step failed, quitting was cleared and an error was stored, but the windows were already gone. There was no path to open one again.
Call quitAndInstall first. Destroy windows only after that starts.
Install still stops backends before quitAndInstall. If that last step fails, the window stayed up but the pool was already down, so the UI was disconnected.
On install failure, start the stopped backends again.
# Conflicts:
#	apps/desktop/src/updates/DesktopUpdates.test.ts
#	apps/desktop/src/updates/DesktopUpdates.ts
Prepare the desktop update before returning the progress result, then commit
the install only after the client receives its token. Retry lost commits by
token and require the prepared version after reconnect.
Keep windows open until updater-controlled quit and restart stopped backends
when Electron reports an install failure.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@t3dotgg
t3dotggforce-pushed the t3code/remote-mac-app-updates branch from 9a3ed9a to 8fec783CompareSeptember 2, 2026 01:23
Comment threadpackages/client-runtime/src/state/server.ts
Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
Comment threadapps/desktop/src/app/DesktopLifecycle.ts
t3dotggand others added 2 commits September 1, 2026 18:32
@t3dotgg

t3dotgg commented Sep 2, 2026

Copy link
Copy Markdown
MemberAuthor

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

Fixed and pushed in cb96a8e268b5acc0d7f40017a5b0b30fff582af8. Remote commit now joins only when the exact downloaded version still matches and the updater's install reservation is active. Ordinary quit and relaunch no longer count as an install handoff. Tests use a real competing local install and cover normal quit separately. The coordination hold is cleared, subject to normal CI and review.

Comment threadapps/desktop/src/updates/DesktopUpdates.ts Outdated
…mpletes
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0fc8f4a. Configure here.

Comment threadapps/desktop/src/updates/DesktopRemoteUpdates.ts
@t3dotgg
t3dotgg merged commit b2f25d3 into mainSep 2, 2026
28 checks passed
@t3dotgg
t3dotgg deleted the t3code/remote-mac-app-updates branch September 2, 2026 02:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 2, 2026
## What's Changed
* perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145
* perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052
* fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138
* fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147
* fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302
* fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941
* fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119
* fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113
* fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120
* fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154
* perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058
* feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554
* test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157
* fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142
* fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064
* fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968
* feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140
* feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143
* fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160
* fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910
## New Contributors
* @404khai made their first contribution in pingdotgg/t3code#8910
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253
amitbet pushed a commit to amitbet/a2code that referenced this pull request Sep 2, 2026
Resolves 48 conflicts. Brings in Claude Fable 5.1 (claude-fable-5-1, requires
Claude Code >= 2.1.257) via upstream's move of the Claude model list into
model-manifest.json.
Declines upstream's remote desktop-update feature (pingdotgg#6554): it is welded to the
electron-installer path this fork deleted, so its files are dropped and the
server never advertises the desktopAppUpdate capability, keeping the Update
button from offering something that can never finish.
Preserves the fork's queued-prompt steering, in-chat find, thread
fork/references/export, MCP thread search, live quota meter, machine-scoped
sidebar, payload hot-update channel, branding and trimmed CI surface. Adopts
upstream's reversal of create-time project model seeding (inside the extracted
useAddProjectFromPath hook) and renumbers upstream's migration 044 to the
fork's 047.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

preview:macBuild an Apple Silicon DMG for this PR on every push.size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@t3dotgg@Adolanium