Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
73 commits
Select commit Hold shift + click to select a range
ed2037a
feat(server): define plan capability policy
Jay1 Jul 17, 2026
3a6a0c3
feat(contracts): expose enforceable plan support
Jay1 Jul 17, 2026
af28db3
fix(orchestration): reject stale plan implementation
Jay1 Jul 17, 2026
37bafb2
fix(server): guard claude tools in plan mode
Jay1 Jul 17, 2026
7260c25
fix(orchestration): revalidate queued plan revision
Jay1 Jul 17, 2026
cbef376
fix(server): isolate opencode plan permissions
Jay1 Jul 17, 2026
44f2a48
fix(server): enforce codex plan sandbox
Jay1 Jul 17, 2026
ed8d312
feat(server): report enforceable plan providers
Jay1 Jul 17, 2026
60663ab
fix(web): scope proposed plans to current turn
Jay1 Jul 17, 2026
906db41
feat(web): snapshot plan implementation handoff
Jay1 Jul 17, 2026
3693a12
fix(web): preserve queued plan identity
Jay1 Jul 17, 2026
7017b62
fix(web): implement exact plan revision
Jay1 Jul 18, 2026
4b073cb
feat(web): expose safe plan availability
Jay1 Jul 18, 2026
0de24fe
fix(orchestration): reject unenforced plan dispatch
Jay1 Jul 18, 2026
a30b744
fix(server): retain plan callback authority
Jay1 Jul 19, 2026
e35a3f4
fix(plan): close remaining dispatch paths
Jay1 Jul 19, 2026
78234ec
fix(plan): preserve replay authority
Jay1 Jul 19, 2026
ee862e7
fix(server): order provider lifecycle events
Jay1 Jul 20, 2026
37b0953
fix(server): reconcile terminal event races
Jay1 Jul 20, 2026
eb5036a
fix(server): preserve queued plan liveness
Jay1 Jul 21, 2026
b4c063c
fix(server): isolate plan lifecycle side effects
Jay1 Jul 21, 2026
61129e7
fix(server): keep plan edits workspace-safe
Jay1 Jul 21, 2026
9277cb1
fix(plan): close app-owned mutation paths
Jay1 Jul 21, 2026
52bb73f
fix(plan): guard slash and lifecycle authority
Jay1 Jul 21, 2026
623fe09
fix(plan): bind latest plan and turn authority
Jay1 Jul 21, 2026
346769d
fix(server): retain canonical latest turn
Jay1 Jul 21, 2026
312a0a2
fix(server): replay canonical thread summaries
Jay1 Jul 21, 2026
64d2bf8
fix(plan): preserve runtime plan authority
Jay1 Jul 21, 2026
76f1007
fix(plan): harden lifecycle and rollback authority
Jay1 Jul 25, 2026
f72b679
Merge branch 'main' into feature/wave2-plan-mode-firewall
Jay1 Jul 26, 2026
d19725a
fix(server): reconcile Wave2 migration lineage
Jay1 Jul 26, 2026
97d8cad
fix(server): validate partial Wave2 migration stages
Jay1 Jul 26, 2026
e45832c
fix(server): isolate migration 032 tests
Jay1 Jul 26, 2026
522b310
feat(opencode): define managed isolation profiles
Jay1 Jul 26, 2026
0636a5a
feat(opencode): attest managed isolation runtime
Jay1 Jul 26, 2026
91207d1
fix(opencode): bind isolation to running process
Jay1 Jul 26, 2026
60c0953
fix(opencode): fail closed on identity read errors
Jay1 Jul 26, 2026
be06ca0
fix(opencode): install canonical runtime archives
Jay1 Jul 26, 2026
c5af911
feat(opencode): expose verified Plan capability
Jay1 Jul 26, 2026
219413f
fix(opencode): revalidate Plan before dispatch
Jay1 Jul 26, 2026
96b90ff
fix(opencode): harden managed runtime installation
Jay1 Jul 26, 2026
25f5984
fix(opencode): bind managed Plan session resumes
Jay1 Jul 26, 2026
cc462e2
feat(opencode): expose managed Plan verification
Jay1 Jul 26, 2026
ccf2732
fix(plan): scope capability to OpenCode profile
Jay1 Jul 26, 2026
1989659
feat(settings): add OpenCode Plan isolation profile
Jay1 Jul 26, 2026
9d03dd1
test(plan): capture profile states across breakpoints
Jay1 Jul 26, 2026
5d2807f
fix(plan): bind isolation verification lifecycle
Jay1 Jul 26, 2026
5b452b8
fix(opencode): preserve default runtime during verification
Jay1 Jul 26, 2026
6a92703
fix(settings): invalidate discovery after credential changes
Jay1 Jul 26, 2026
a21a7f0
test(plan): stabilize profile denial evidence
Jay1 Jul 26, 2026
83b9e33
test(plan): anchor denial evidence timeline
Jay1 Jul 26, 2026
4944e8e
test(plan): stabilize denial evidence raster
Jay1 Jul 26, 2026
584f3a4
test(plan): capture faithful browser evidence
Jay1 Jul 26, 2026
38b4456
fix(server): make candidate promotion interruption-safe
Jay1 Jul 26, 2026
bd137ed
fix(server): make candidate authority rollback atomic
Jay1 Jul 26, 2026
9b38a20
test(plan): serialize browser evidence raster
Jay1 Jul 26, 2026
6e120ca
test(plan): disable gpu for evidence raster
Jay1 Jul 26, 2026
8e6fedd
docs(adr): record plan mode authority
Jay1 Jul 26, 2026
94a960f
fix(server): attest managed verification candidates
Jay1 Jul 28, 2026
b56ca76
fix(server): reject opencode bootstrap side effects
Jay1 Jul 28, 2026
54a6c3f
fix(server): contain opencode isolation probe residue
Jay1 Jul 28, 2026
0e4d0a5
fix(server): isolate opencode process environment
Jay1 Jul 28, 2026
6f0a9ed
fix(server): scope provider sessions to project cwd
Jay1 Jul 28, 2026
a4bd97b
fix(server): isolate kilo plan sessions
Jay1 Jul 28, 2026
b51d52b
fix(server): recover queued plan turns after restart
Jay1 Jul 28, 2026
7643f77
fix(server): reconcile authoritative assistant snapshots
Jay1 Jul 28, 2026
bc66c03
fix(web): clarify plan mode interface states
Jay1 Jul 28, 2026
19ae8a3
test(server): stabilize isolation identity fixture
Jay1 Jul 28, 2026
af3fbc1
fix(web): prevent mobile header focus clipping
Jay1 Jul 28, 2026
335acf0
fix(web): keep plan footer actions accessible
Jay1 Jul 28, 2026
3002e88
test(server): await running isolation image
Jay1 Jul 28, 2026
91f4938
docs: add upstream UX roadmaps
Jay1 Jul 29, 2026
4afb13b
test(web): make interface clock assertion timezone-safe
Jay1 Jul 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 24 additions & 0 deletions CONTEXT.md
Original file line number Diff line number Diff line change
Expand Up @@ -198,6 +198,30 @@ Interaction mode controls the style of a provider turn. `default` is ordinary ex

Plan mode can create actionable proposed plans that may later be implemented or handed off, so UI should preserve the distinction between a plan and an ordinary assistant response.

Plan mode is also an app-owned authorization boundary. JCode's structured provider policy,
server admission, adapter permission enforcement, runtime identity, and durable turn authority
decide whether Plan is available and what a turn may do. Provider prompts and legacy capability
flags are not authority. Plan permits bounded reads and user questions and denies commands,
workspace writes, external effects, and unknown operations.

Claude Agent and Kilo are supported through provider-specific enforcement. OpenCode is
available only through a current, session-bound, authenticated JCode Managed Isolated
attestation. Codex is retained as a legacy read-only server path but is not presented as
Plan-capable. Cursor, Devin, Gemini, OpenClaw, and Pi are unsupported. The UI preserves exact
loading or denial reasons and does not silently convert unavailable Plan work to Default.

Implementing a proposed plan creates a separate Default-mode turn bound to the exact source
thread, plan ID, and `planUpdatedAt` revision. The server revalidates that reference at command
admission, queued promotion, and provider-start ingestion. Provider starts and lifecycle events
must also match durable expected-start identity, authority epoch, scope, phase, and routing.
Inbox, immutable ledger, outbox, consumer receipts, rollback tombstones, FIFO scheduling,
backpressure, quarantine, and startup redrive make that authority replayable across reordering
and restart.

The canonical decision, provider matrix, Managed OpenCode attestation contract, migration
lineage, privacy/retention rules, and non-goals are in
[ADR 0012](docs/adr/0012-plan-mode-authorization-and-durable-turn-lifecycle-authority.md).

### Thread Environment

A thread environment describes whether a thread works in the project's local workspace or an associated git worktree. `local` uses the project workspace root. `worktree` uses branch/worktree metadata and may be created for isolated implementation or pull-request preparation.
Expand Down
3 changes: 2 additions & 1 deletion DESIGN.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ JCode has two token layers: generic shadcn/Tailwind-compatible tokens and cockpi
| Terminal | `--terminal-font-family`, `--app-terminal-search-match-*`, `--app-terminal-search-active-match-*`, `--app-scrollbar-thumb`, `--app-scrollbar-thumb-hover` | Terminal xterm font, search highlights, and scrollbar parity. |
| Chrome controls | `--app-chrome-control-bg`, `--app-chrome-control-border`, `--app-chrome-control-fg`, `--app-chrome-control-hover-bg`, `--app-chrome-control-hover-fg`, `--app-chrome-control-active-bg`, `--app-control-icon-*`, `.sidebar-icon-button` | Compact icon buttons, message actions, terminal/browser/diff toolbar actions. |
| Metadata | `--app-metadata-fg`, `--app-metadata-muted-fg`, `--app-text-metadata`, `--app-text-metadata-strong` | Secondary labels, timestamps, environment labels, settings status text. |
| Status | `--app-status-{working,success,warning,input,plan,error,muted}-{fg,dot,bg,border}` | Thread, terminal, PR, plan, input, warning, success, working, error, and muted markers. |
| Status | `--app-status-{working,success,warning,input,plan,error,muted}-{fg,dot,bg,border}`, `--app-toast-warning-bg` | Thread, terminal, PR, plan, input, warning, success, working, error, and muted markers plus opaque warning toasts. |
| Agent accents | `--app-agent-chip-*`, `--app-subagent-accent-*` | Provider/agent chips and subagent identity accents. |

Source rules:
Expand Down Expand Up @@ -84,6 +84,7 @@ Rules:
- `ChatTranscriptPane` owns the transcript stage through `.app-transcript-stage` and renders `MessagesTimeline` with scroll-to-bottom chrome using `--app-scroll-button-*`.
- `MessagesTimeline` renders assistant messages in `.app-assistant-message`, user messages in `.app-user-message`, and file-change/activity summaries through `--app-work-row-*`, `--app-diff-card-*`, and metadata tokens.
- `ChatMarkdown` owns markdown scannability: headings, links, inline code role classes, code blocks, copy buttons, tables, local generated images, and lazy image rendering.
- `ComposerPlanModeBlockedReason` renders complete, wrapped Plan recovery guidance above the compact composer toolbar so narrow panes keep the required action visible.
- Chat-output semantic roles must stay conservative: file paths, commands, theme tokens, success/warning/error states can be colored; ordinary text stays neutral.

### Diff
Expand Down
Loading
Loading