Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
173 commits
Select commit Hold shift + click to select a range
a7787cf
test(exec): allow loaded runners to observe background exit
jonathanKingston Sep 5, 2026
520c593
fix(workspace): bound linked worktree discovery
jonathanKingston Sep 5, 2026
ff5f8e6
test: isolate validation from local model services
jonathanKingston Sep 5, 2026
3f65aa3
fix(dev): support cross-device Electron cache setup
jonathanKingston Sep 5, 2026
ff871ff
Ship the side-highlight prototype: the rail means nesting now
jonathanKingston Sep 6, 2026
c66defc
Repoint the four e2e specs that pinned the retired rails
jonathanKingston Sep 6, 2026
ca4f440
Add external plugin hook registration and worker invocation
Sep 6, 2026
e749c25
feat(security): run a thread unattended inside a hardened container
claude Sep 4, 2026
3ce0828
feat(container): start an unattended container run from the composer
claude Sep 4, 2026
35d797c
fix(container): address review findings on the unattended run
Sep 5, 2026
e573dff
docs(container): name the IPC channels as the protocol spells them
claude Sep 5, 2026
e57b315
fix(container): reject incomplete and unsafe run results
Sep 5, 2026
21242a6
fix(container): judge a leaked canary before a container left behind
claude Sep 5, 2026
16d567d
fix(container): spell the run channels as main's kebab-case wire names
claude Sep 6, 2026
59e0bc0
fix(container): use the shared isRecord instead of a local copy
claude Sep 6, 2026
bc51f9d
test(e2e): add the container action to the pinned footer rosters
claude Sep 6, 2026
69571f9
chore(e2e): review screenshots for #2348 (#2426)
copse-release-bot[bot] Sep 6, 2026
8d848b4
fix(container): keep the egress socket path inside sun_path
claude Sep 6, 2026
7ab440e
feat(container): make the run dialog authorise a run, not compose one
claude Sep 6, 2026
e17ee4f
feat(container): use the shared model picker, and say why agents cann…
claude Sep 6, 2026
e92ffa4
fix(container): stop telling the user to log in to a model they canno…
claude Sep 6, 2026
abc43c9
fix(test): compare snapshot trees, not commit shas
claude Sep 6, 2026
27cfd74
docs(container): plan the route to running ACP agents in the guest
claude Sep 6, 2026
e2c2b6e
Support directory-scoped AGENTS.md instructions
jonathanKingston Aug 28, 2026
ae94b3b
perf(instructions): discover nested AGENTS.md once per turn
claude Sep 4, 2026
f44e229
feat(settings): show nested discovery truncation and duplicates in So…
claude Sep 4, 2026
cc4252e
docs(user): narrow the nested instructions activation claim
claude Sep 4, 2026
7925592
Egress through one broker socket and a guest CONNECT proxy
claude Sep 6, 2026
d61678f
build(protocol): bump API_PROTOCOL_VERSION for the nested-instruction…
claude Sep 6, 2026
7ba4a4f
Run key-capable ACP agents in the container
claude Sep 6, 2026
43cb6c6
Prove the ACP harness locally; enable agent rows on key presence
claude Sep 6, 2026
28b87ef
Let the resolver decide which agent rows the run dialog enables
claude Sep 6, 2026
8a73178
Let a container run carry the desktop sign-in for Codex and Gemini, o…
claude Sep 6, 2026
f5aee74
Carry only the sign-in files in, asynchronously
claude Sep 7, 2026
b337c39
Give a live container run a Stop action; closing the dialog never was…
claude Sep 7, 2026
be6780f
Tick the elapsed row of a live container run every second
claude Sep 7, 2026
bf3bf13
Restore socat for the sandbox runtime; show refused egress in the record
claude Sep 7, 2026
787a5c6
Let a finished run's banner be dismissed, and say "no commits" when t…
claude Sep 7, 2026
0a43765
The container is the sandbox: no bubblewrap inside it, a token-gated …
claude Sep 7, 2026
6f7e133
Exempt the container runner's inert proxy-token fixture from gitleaks
claude Sep 7, 2026
cfdbab2
Probe the egress broker at startup and say when nothing left the cont…
claude Sep 7, 2026
e8d7634
Carry the egress link over the container's stdio, not a unix socket
claude Sep 7, 2026
d6cf642
Let the guest's loopback bypass the proxy, and admit OpenAI's content…
claude Sep 7, 2026
dca9b30
Merge remote-tracking branch 'origin/main' into claude/copse-containe…
claude Sep 7, 2026
25e6e00
Node 24 image with pnpm, a per-run workspace volume, and an opt-in in…
claude Sep 7, 2026
ef38515
Hold Start until the resolver has answered for an agent model
claude Sep 7, 2026
eb76558
Ask the resolver about the thread's own agent model, not just the pic…
claude Sep 7, 2026
6e73a84
Resolve each origin once per run, retry a transient dial, and say 502…
claude Sep 7, 2026
f3d3610
Install in three steps, with a native toolchain in the image
claude Sep 7, 2026
e570a63
Reach GitHub anonymously when installing, and carry a display for Ele…
claude Sep 7, 2026
37fc8fe
Build native modules against the image's Node headers; admit Electron…
claude Sep 7, 2026
04f3a5c
Put the worker's home on the run's volume, not a 256 MB tmpfs
claude Sep 7, 2026
80a1d18
fix(tools): report bad tool arguments as a sentence, not a JSON dump
claude Sep 7, 2026
52fa898
Sweep orphaned containers and workspace volumes at app start
claude Sep 7, 2026
338ff62
Build the worker image on Debian 13, so a project's own tools can run
claude Sep 7, 2026
e4d00a6
Tell the agent what its environment is before the task
claude Sep 7, 2026
2c1eb06
Merge origin/main into the side-highlight branch
jonathanKingston Sep 7, 2026
3b4d3c9
fix(acp): name the video tool the way an ACP client offers it
claude Sep 7, 2026
775eb2d
chore(e2e): update reference screenshots for #2404
jonathanKingston Sep 7, 2026
d5920d0
Fetch Electron's binary in the install, make /tmp executable, carry t…
claude Sep 7, 2026
9615713
Merge remote-tracking branch 'origin/main' into claude/copse-containe…
claude Sep 7, 2026
691aa4f
Let the worker bundle accept jsdom's path-resolved helper, now that m…
claude Sep 7, 2026
1305c1a
Exit the worker once its log has drained
claude Sep 7, 2026
47e78ab
Let the element screenshot helper survive a subject that re-renders w…
claude Sep 7, 2026
c468c30
Share one pnpm store volume across installing runs
claude Sep 7, 2026
78a3250
Show a container run as a turn on its thread, with a cherry-pick foll…
claude Sep 8, 2026
5c52495
Start a container run from the composer's point of view, and follow i…
claude Sep 8, 2026
61c25b9
Keep the app responsive on run start, log the agent's progress, and f…
claude Sep 8, 2026
a9e04bd
Serialize follow-ups per checkout, count the agent's context reports …
claude Sep 8, 2026
23c4736
Resolve the model once for desktop and guest, share the git snapshot,…
claude Sep 8, 2026
ff390a2
chore(models): sync intellect scores from Artificial Analysis
jonathanKingston Sep 8, 2026
c9e7a3f
Describe a provider without a type predicate, and let the worktree te…
claude Sep 8, 2026
9153206
fix(storage): keep cached settings unchanged when saving fails
Sep 8, 2026
76ec2eb
fix(search): find bare filenames throughout the workspace
Sep 8, 2026
2cdf2be
fix(search): report failed searches instead of false misses
Sep 8, 2026
3c6a61b
fix(archives): serialize duplicate archive extractions
Sep 8, 2026
3122762
fix(files): stop writes when reading existing content fails
Sep 8, 2026
6aa7590
Fold the guest's narration with the desktop's own text planner, and r…
claude Sep 8, 2026
5509e78
Move the xmldom, sharp and js-yaml security pins past today's advisories
claude Sep 8, 2026
23c5b8c
Let the thread hear about a container run, continue a run that made n…
claude Sep 9, 2026
d771816
chore(deps): bump the electron group with 2 updates (#2549)
dependabot[bot] Sep 9, 2026
4d7ff0d
Merge pull request #2580 from copse-dev/codex/saved-settings-cache
jonathanKingston Sep 9, 2026
7663061
Merge pull request #2581 from copse-dev/codex/find-nested-filenames
jonathanKingston Sep 9, 2026
0e10be0
Say the run's outcome in the assistant's own words, and let a follow-…
claude Sep 9, 2026
f63bd9a
Merge pull request #2582 from copse-dev/codex/report-search-failures
jonathanKingston Sep 9, 2026
85682b4
Merge pull request #2583 from copse-dev/codex/serialize-archive-extra…
jonathanKingston Sep 9, 2026
0578170
Merge pull request #2386 from copse-dev/codex/stabilize-background-pr…
jonathanKingston Sep 9, 2026
9067078
Merge pull request #2380 from copse-dev/codex/fix-electron-cache-cros…
jonathanKingston Sep 9, 2026
9a4b028
Merge pull request #2381 from copse-dev/codex/isolate-tests-from-loca…
jonathanKingston Sep 9, 2026
2c8a5a8
Merge pull request #2584 from copse-dev/codex/preserve-files-on-read-…
jonathanKingston Sep 9, 2026
32e1d8c
Merge pull request #2572 from copse-dev/screenshots/pr-2404/2c1eb06c756b
jonathanKingston Sep 9, 2026
4253dfd
Merge pull request #2571 from copse-dev/claude/acp-tool-naming-2513
jonathanKingston Sep 9, 2026
6e741bb
fix(search): invalidate cached results after parent directory changes
Sep 9, 2026
a5e9973
fix(ssh): read binary files with portable base64 input
Sep 9, 2026
775e6bb
fix(workspace): discard cancelled worktree discovery
Sep 9, 2026
c366fc6
fix(git): preserve whitespace when reading file contents
Sep 9, 2026
bf0d29a
fix(exec): preserve UTF-8 characters across output chunks
Sep 9, 2026
1ce1f16
Say when the run's volume has gone away, instead of blaming the next …
claude Sep 9, 2026
77c77ff
fix(exec): report signal-terminated commands as failures
Sep 9, 2026
a5b90ac
feat(automations): open the shared plugin editor from the side cog
Sep 9, 2026
64d8cb4
docs(automations): design durable event triggers and authoring improv…
Sep 9, 2026
dbad9c1
fix(deps): patch dependencies failing the CI security audit
Sep 9, 2026
9d878fb
chore(e2e): update reference screenshots for #2348
jonathanKingston Sep 9, 2026
6ea33c9
test(tools): show readable argument errors in the live transcript
Sep 9, 2026
e336b75
Merge pull request #2595 from copse-dev/codex/fix-ci-security-audit
jonathanKingston Sep 9, 2026
86a5a53
Merge branch 'main' into codex/fix-linked-worktree-startup
jonathanKingston Sep 9, 2026
8217103
Merge branch 'main' into codex/external-hook-registration
jonathanKingston Sep 9, 2026
38befbf
Merge branch 'main' into claude/copse-threads-prototype-c5c83c
jonathanKingston Sep 9, 2026
4e4a494
Merge branch 'main' into claude/validate-outstanding-issues-bdhpr7
jonathanKingston Sep 9, 2026
5a7e04b
Merge branch 'main' into codex/invalidate-moved-directory-searches
jonathanKingston Sep 9, 2026
0a8f6a8
Merge branch 'main' into codex/portable-ssh-binary-reads
jonathanKingston Sep 9, 2026
ae3825c
Merge branch 'main' into codex/preserve-git-show-whitespace
jonathanKingston Sep 9, 2026
f5da590
Merge branch 'main' into codex/preserve-command-unicode
jonathanKingston Sep 9, 2026
57f6011
Merge branch 'main' into codex/fail-signalled-commands
jonathanKingston Sep 9, 2026
e8b12cd
Merge branch 'main' into codex/automation-modal
jonathanKingston Sep 9, 2026
bba157b
Merge branch 'main' into codex/event-driven-automations-plan
jonathanKingston Sep 9, 2026
3580a0f
Add pull request activity tabs and GitHub activity loading
Sep 9, 2026
49dbd6e
Merge branch 'main' into codex/plan-github-pr-feature-parity
jonathanKingston Sep 9, 2026
8988451
refactor(container): share validated run and attestation contracts
Sep 9, 2026
baf3de5
Merge pull request #2596 from copse-dev/screenshots/pr-2348/1ce1f161b796
jonathanKingston Sep 9, 2026
1fcb59d
Merge pull request #2384 from copse-dev/codex/fix-linked-worktree-sta…
jonathanKingston Sep 9, 2026
d55da93
refactor(container): report lifecycle phases as structured events
Sep 9, 2026
9a57ad4
Merge pull request #2559 from copse-dev/claude/validate-outstanding-i…
jonathanKingston Sep 9, 2026
b3f8396
Merge pull request #2587 from copse-dev/codex/invalidate-moved-direct…
jonathanKingston Sep 9, 2026
9fd2f89
Merge pull request #2588 from copse-dev/codex/portable-ssh-binary-reads
jonathanKingston Sep 9, 2026
673a652
Merge pull request #2592 from copse-dev/codex/fail-signalled-commands
jonathanKingston Sep 9, 2026
1bdee47
Merge pull request #2594 from copse-dev/codex/event-driven-automation…
jonathanKingston Sep 9, 2026
5f45714
refactor(agent): share transcript content and tool updates
Sep 9, 2026
16422e4
refactor(container): track external runs with the task supervisor
Sep 9, 2026
4560a41
Merge pull request #2399 from copse-dev/codex/external-hook-registration
jonathanKingston Sep 9, 2026
e491c79
Merge pull request #2590 from copse-dev/codex/preserve-git-show-white…
jonathanKingston Sep 9, 2026
deeff1f
Merge pull request #2591 from copse-dev/codex/preserve-command-unicode
jonathanKingston Sep 9, 2026
4e85b00
Merge pull request #2404 from copse-dev/claude/copse-threads-prototyp…
jonathanKingston Sep 9, 2026
9b81115
Merge pull request #2593 from copse-dev/codex/automation-modal
jonathanKingston Sep 9, 2026
620596a
fix(container): retain the next run cancellation controller
Sep 9, 2026
d2b3318
fix(container): preserve named public API schema references
Sep 9, 2026
dd7a676
fix(models): link new intellect scores to the canonical scale
Sep 9, 2026
ab43402
fix: preserve callout glyphs in forced colors
Sep 9, 2026
14cdab3
Put unattended container runs behind an experimental setting, off by …
claude Sep 9, 2026
d103fa6
feat(automations): add durable event inbox and recovery
Sep 9, 2026
23e0a6d
fix(api): version the PR activity response contract
Sep 9, 2026
1b401f8
Add bulk worktree cleanup without rescanning the inventory
Sep 9, 2026
b3874f5
fix(instructions): bound turn discovery to referenced ancestor scopes
Sep 9, 2026
04b9e22
fix(ssh): combine recursive and force removal flags correctly
Sep 9, 2026
f5d08b1
fix(files): resolve explicit references before indexing completes
Sep 9, 2026
77628ee
fix(search): fall back when indexed search exits unsuccessfully
Sep 9, 2026
f83398e
fix(files): treat recursive listing paths as literal directories
Sep 9, 2026
a3b5b15
Merge main into the container branch
claude Sep 9, 2026
58735f6
Merge pull request #2578 from copse-dev/chore/sync-intellect
jonathanKingston Sep 9, 2026
cae85d8
fix(attachments): preserve extensions when shortening filenames
Sep 9, 2026
6e10d3c
merge: reconcile PR activity and nested instruction protocol versions
Sep 9, 2026
0b55a4a
fix(sandbox): redirect zsh heredoc files into allowed scratch
Sep 9, 2026
5c03ec1
Merge pull request #2608 from copse-dev/codex/fix-ssh-recursive-remove
jonathanKingston Sep 9, 2026
f0c817a
Merge pull request #2609 from copse-dev/codex/resolve-files-before-in…
jonathanKingston Sep 9, 2026
ad5b447
Merge pull request #2605 from copse-dev/codex/callout-accessibility-fix
jonathanKingston Sep 9, 2026
76212fb
Merge pull request #2606 from copse-dev/codex/automation-event-inbox
jonathanKingston Sep 9, 2026
dfaad30
Merge pull request #2597 from copse-dev/codex/plan-github-pr-feature-…
jonathanKingston Sep 9, 2026
e791594
Merge pull request #2610 from copse-dev/codex/fallback-on-indexed-sea…
jonathanKingston Sep 9, 2026
f0f023b
Merge pull request #2607 from copse-dev/codex/worktree-bulk-cleanup
jonathanKingston Sep 9, 2026
92d2330
Merge pull request #2611 from copse-dev/codex/list-literal-directory-…
jonathanKingston Sep 9, 2026
ab75067
Merge pull request #2613 from copse-dev/codex/preserve-long-attachmen…
jonathanKingston Sep 9, 2026
033137c
Merge pull request #2615 from copse-dev/codex/acp-sandbox-run-reliabi…
jonathanKingston Sep 9, 2026
b915138
Fix skill discovery, sandbox reads and abandoned approvals from the r…
jonathanKingston Sep 9, 2026
8d6e26b
fix(instructions): preserve activation order across identical clock t…
Sep 9, 2026
02a4878
test(e2e): seed the container-runs flag where the footer menu is asse…
claude Sep 9, 2026
8f66ca4
Merge pull request #2598 from copse-dev/codex/container-shared-schemas
jonathanKingston Sep 9, 2026
9b1bd3b
Merge pull request #2599 from copse-dev/codex/container-phase-events
jonathanKingston Sep 9, 2026
9cdd1c2
Merge pull request #2602 from copse-dev/codex/shared-agent-transcript
jonathanKingston Sep 9, 2026
399e114
Merge pull request #2603 from copse-dev/codex/supervise-container-runs
jonathanKingston Sep 9, 2026
b363c5b
Merge pull request #1976 from copse-dev/codex/nested-agents-instructions
jonathanKingston Sep 9, 2026
73ed4f2
fix(skills): bound read grants and isolate worker identity dependencies
Sep 9, 2026
d231c02
Merge pull request #2348 from copse-dev/claude/copse-container-execut…
jonathanKingston Sep 9, 2026
a288035
Merge pull request #2620 from copse-dev/claude/reconcile-worktrees-po…
jonathanKingston Sep 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
11 changes: 11 additions & 0 deletions .gitleaks.toml
Original file line number Diff line number Diff line change
Expand Up @@ -50,3 +50,14 @@ paths = ['''^pr-\d+/''']
description = "Prompt-injection steer-eval secrets fixture (inert)"
targetRules = ["stripe-access-token"]
paths = ['''^benchmarks/steer/fixtures/injection-project/secrets\.env$''']

[[allowlists]]
# The container runner's argv test carries an inert per-run proxy token
# (decision A7 in docs/plans/thread-in-container.md) so it can assert the
# token lands on the guest's proxy URL and in COPSE_EGRESS_TOKEN and nowhere
# else. The first fixture value was a hex string and tripped the entropy
# heuristic; the value is plain words now, but the path exemption also clears
# the finding in branch history. Scope to that one rule and file.
description = "Container run proxy-token fixture (inert)"
targetRules = ["generic-api-key"]
paths = ['''^src/main/services/container-runtime/thread-container\.test\.ts$''']
12 changes: 12 additions & 0 deletions docs/acp-agents.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,18 @@ auth), while Copse keeps ownership of the workspace and the approval UX.
from whichever channel carries it. A consequence worth knowing: under Cursor,
a bridged or MCP call that is auto-approved never produces a permission
request, so it can keep the generic `MCP: tool` label.
- **An abandoned bridged call does not lose its approval.** MCP clients give
up on a silent tool call after their own timeout (Codex: roughly 300 s), and
a bridged `run_shell` blocked on "Run outside sandbox?" is silent for as long
as the user takes to answer. The bridge aborts the call with an
`AbandonedCallAbort` reason; the approval service (`approval.ts`) treats that
as a detach rather than a cancel — the prompt stays open, the call fails with
a clear "approval is still pending, retry the exact same call" error (which
reaches the agent when it cancelled over MCP; a dropped connection has no one
to deliver it to), and the user's eventual answer is kept for ten minutes so
the identical retry (same command, working directory and thread) reuses it
without prompting again. A retry that arrives while the prompt is still open
simply joins it. Turn end still dismisses the prompt, as before.
- Because that title is also how Copse recognises **its own** bridged tools to
skip a duplicate approval prompt, the same per-agent spread applies: Cursor's
`copse-gh_pr_list: gh_pr_list` and Claude's `mcp__copse__gh_pr_view` are both
Expand Down
64 changes: 58 additions & 6 deletions docs/cursor-plugins.md
Original file line number Diff line number Diff line change
Expand Up @@ -68,12 +68,12 @@ use this module.

### Trust model

| Source | Skills trust | MCP trust |
| ------------------------- | --------------------------------------- | ----------------------------------------------------------- |
| `~/.cursor/skills` (user) | Trusted | — |
| Cursor plugin (`plugin`) | Untrusted (delimited as data in prompt) | Trusted (user installed via Cursor; full env interpolation) |
| Project workspace | Untrusted | Requires workspace trust (#100) |
| `skillPluginPaths` | Untrusted | — |
| Source | Skills trust | MCP trust |
| ----------------------------------------------- | --------------------------------------- | ----------------------------------------------------------- |
| `~/.{cursor,agents,claude,codex}/skills` (user) | Trusted | — |
| Cursor plugin (`plugin`) | Untrusted (delimited as data in prompt) | Trusted (user installed via Cursor; full env interpolation) |
| Project workspace | Untrusted | Requires workspace trust (#100) |
| `skillPluginPaths` | Untrusted | — |

Plugin skills are untrusted because their text is still attacker-influenceable
content (a malicious marketplace plugin). Plugin MCP configs are treated like
Expand All @@ -85,6 +85,58 @@ Merge priority for duplicate MCP server names:
2. Cursor plugin `.mcp.json` files
3. Project `.cursor/mcp.json` / `.mcp.json` (only when workspace is trusted)

## Skill discovery roots and frontmatter

Skills are `<root>/<name>/SKILL.md` files (the folder name must equal the
frontmatter `name`). `skills-registry.ts` scans these roots, in this order;
the first skill loaded for a name wins, so an earlier root overrides a later
one:

1. **User** — `~/.cursor/skills`, `~/.agents/skills`, `~/.claude/skills`,
`~/.codex/skills` (source `user`, trusted). `.codex` is the Codex CLI's
layout; it was added after a Codex-backed thread could not find the skill it
had been asked to run (reconcile-worktrees post-mortem, 2026-09-09).
2. **Bundled Cursor plugin skills** shipped with Copse (`bundled`, trusted).
3. **Project** — the same four container directories under the workspace,
including monorepo packages, but never inside a nested repository such as a
`.claude/worktrees/*` checkout (`project`, untrusted). Within the project
scope the containers keep the order above.
4. **Cursor plugins** (`~/.cursor/plugins/{local,cache}`) and
`skillPluginPaths` (`plugin` / `plugin-path`, untrusted).
5. **Built-in skills** shipped in `assets/skills` (`bundled`); last, so any
user or project skill of the same name overrides a first-party one.

### Frontmatter

```yaml
---
name: reconcile-worktrees # must match the folder name
description: One line the model sees in the catalog
disable-model-invocation: true # optional: user-only, hidden from the model
paths: # optional: extra read-only entries, relative to this directory
- data
- references/schema.json
---
```

- `disable-model-invocation` keeps a skill out of the model's catalog; the
user can still invoke it with `/name`.
- `paths` declares extra read-only entries for `run_shell`. When a skill is
invoked, that thread's sandboxed shell may **read** the skill directory for
the rest of the thread (never write to it); `paths` adds entries relative to
the skill directory. Entries are validated, not trusted: absolute paths, `~`,
`$VAR`, and `..` are rejected; anything that is or lives under a credential
file or directory (`.env*`, `.ssh`, `.aws`, key files, …) is rejected; the
home directory, the filesystem root, and any parent of home are rejected. A
symlink that leaves the skill directory is honoured only for a trusted
(`user` / `bundled`) skill. Refused entries are reported in the invoked-skill
prompt so the model does not rely on them. See
`src/main/services/skills/skill-read-roots.ts` and
`src/main/services/security/thread-read-roots.ts`.

Reads outside these roots — and every write outside the workspace — still go
through the normal "Run outside sandbox?" approval.

## Local development

Symlink a plugin repo into Cursor's local plugins directory (from Kingston skills
Expand Down
3 changes: 2 additions & 1 deletion docs/plans/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -75,7 +75,8 @@ Last audited against `main`, GitHub issues, and open PRs on **2026-07-21**.
| [Terminal file links](terminal-file-links-improvements.md) | Partial / deferred | File links and line/column navigation shipped in [#415](https://github.com/copse-dev/agent-pane/pull/415). Cwd-aware resolution is deferred. |
| [Thread referencing](thread-referencing.md) | Resolved core | [#644](https://github.com/copse-dev/agent-pane/issues/644) is closed and [#647](https://github.com/copse-dev/agent-pane/pull/647) shipped the filesystem-native store and `@` references. Lazy loading and streaming partials remain separate follow-ups. |
| [UI kit](ui-kit.md) | Active | First slice: `.ui-btn*` CSS + light-DOM `<copse-ui-actions>` / `<copse-ui-field>` under `src/renderer/ui/`. No button factory (class sugar only). Panel shells (browser/terminals) planned next. Shadow DOM deferred. |
| [Unattended runs on a contained runtime](unattended-runs.md) | Proposed | Proposes an unattended-run mode on a per-thread Docker runtime, separate from Guarded YOLO, so long-horizon work continues with nobody watching. Nothing implemented. Consumes `execution-runtime-security.md` (capabilities, egress, credentials), `copse-cloud-workspaces.md` C1 (local-docker provider), and `deferred-approvals.md` (non-blocking gate); measured with the Docker eval harness in `industry-benchmarks.md`. |
| [Running a thread inside a container](thread-in-container.md) | Active (prototype on branch) | A thread runs unattended inside a hardened local Docker container with no prompts: the headless agent host runs in the guest, an attested `container` tier lets the gate allow contained effects and defer outward ones (`shell-outward-effect`), egress is a named unix-socket broker, and work returns as commits under `refs/copse/runs/<id>`. Records where it diverges from `unattended-runs.md` (loop in the guest; one provider key in the guest). Driven by `pnpm run thread:container`; end-to-end test is opt-in. |
| [Unattended runs on a contained runtime](unattended-runs.md) | Proposed | Proposes an unattended-run mode on a per-thread Docker runtime, separate from Guarded YOLO, so long-horizon work continues with nobody watching. Nothing implemented under its own decisions; `thread-in-container.md` prototypes the mode with the loop in the guest and records the divergence. Consumes `execution-runtime-security.md` (capabilities, egress, credentials), `copse-cloud-workspaces.md` C1 (local-docker provider), and `deferred-approvals.md` (non-blocking gate); measured with the Docker eval harness in `industry-benchmarks.md`. |
| [Unowned capability gaps](unowned-capability-gaps.md) | Reference audit, dispersed | 2026-08-07 audit against the capabilities local-first assistants have converged on, excluding anything with an existing plan or issue. All ten findings now live elsewhere: [#1570](https://github.com/copse-dev/agent-pane/issues/1570) (plan-step schema), [#1571](https://github.com/copse-dev/agent-pane/issues/1571) (todo-check root, unverified), [#1572](https://github.com/copse-dev/agent-pane/issues/1572) (LAN peer decision), [#1573](https://github.com/copse-dev/agent-pane/issues/1573) (R-05 profiles), plus amendments to eight existing documents. Kept as evidence, not a backlog. |
| [User control surface gaps](user-control-surface-gaps.md) | Proposed | Audit of the missing session-control surface with per-requirement ownership across 32 plans, 66 open issues and a 139-item roadmap. 22 requirements, R-01–R-22; only six need a new issue and two of those are decision records. Phase 0 is session control and task lifecycle. Companions: `mission-control.md`, `competitive-landscape.md`. |
| [VNC remote desktop](vnc-remote-desktop.md) | Active (V0/V1 first release) | The opt-in, read-only Desktop pane now connects to loopback or an active SSH workspace through loopback-only ControlMaster forwards. Main owns the socket; an IPC-backed channel feeds bundled noVNC 1.5.0 without relaxing renderer CSP. Forward teardown is tied to connection, host, owner, and app lifecycles; focused unit and fake-RFB visual coverage are included. Reconnect reconciliation, a generic browser consumer, and the live-host harness remain V0/V1 follow-ups. V2+ human input, discovery, credentials, screenshots, and all agent control remain unimplemented because desktop input bypasses the shell permission gate. |
Expand Down
24 changes: 24 additions & 0 deletions docs/plans/automations.md
Original file line number Diff line number Diff line change
Expand Up @@ -91,6 +91,30 @@ ingress waits for the detached worker/control-plane phase.

## Pack boundary

### Integrated editor

The side cog opens a menu with **Automations** and **New automation…**. The
adjacent Settings label remains a direct shortcut. Both menu actions mount the
same project-scoped editor used in Settings in a native modal, with an explicit
plugin enable/disable action. Changing enablement preserves an unsaved draft.
Sidebar automation setup links use this modal too; the modal closes if the active
project changes. No second store, scheduler, or form is introduced.

The first-party plugin declares `automation-manager` in the level-3 `app-dialog`
slot. The host only exposes this shipped view when the matching first-party
declaration is present. Like Settings, configuration is reachable while disabled;
the plugin flag continues to gate scheduled execution and Run now.

Acceptance criteria:

- The side cog opens the automation list or a new automation form without opening Settings.
- Settings and the modal edit the same project-owned schedules using the same editor.
- Plugin enablement preserves an unsaved draft; disabled plugins cannot run automations.
- Sidebar setup links open the named schedule in the modal, and project changes close it.
- Focused Electron coverage saves cog-menu, creation, and management screenshots.

### Ownership

`copse.automations` is a default-off first-party pack. The pack owns atomic
enablement, a level-3 `settings-pack-detail` UI declaration, and its namespaced
storage declaration. Host code owns the clock and thread-store write; renderer
Expand Down
Loading
Loading