feat(mcp): control managed terminals - #8707
juliusmarminge wants to merge 358 commits into
Conversation
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Warning Your free Security trial is over. An organization admin can activate Security or dismiss this notice. Comment |
There was a problem hiding this comment.
Reviewed the new Effect service (TerminalMcpService), its MCP toolkit wiring, and the TerminalManager/contract changes against the service conventions. Structure, imports, Context.Service shape, make/layer exports, and dependency acquisition all look right. Two findings on the new error model.
Posted via Macroscope — Effect Service Conventions
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This PR adds eight production MCP tools for spawning and controlling host PTYs, alongside substantial terminal lifecycle and cross-thread locking changes. The new execution capability and shared runtime behavior have a broad, side-effectful blast radius that warrants human review. You can add or adjust custom eligibility rules. Learn more. |
ed412d5 to
056dafc
Compare
Thread transfer impact
This comment will update automatically after the next completed run. |
|
Macroscope has since reviewed this pull request. An earlier review was skipped by a cost limit; a review has now completed, so that notice no longer applies. |
056dafc to
a701a2d
Compare
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
Bugbot Autofix is ON, but a cloud agent failed to start.
Reviewed by Cursor Bugbot for commit 627a635. Configure here.
183b049 to
2b56591
Compare
99e0bab to
8116d35
Compare
…7105) Co-authored-by: Julius Marminge <julius0216@outlook.com>
Retain main's changes while preserving v2 orchestration, queue/steer controls, composer-only tasks, timeline timers, and mobile scrolling fixes. Port opt-in restart continuation through durable v2 effects, with shutdown race guards, activation gating, retry deduplication, and native Codex resume. Use narrow projection reads for control effects and runtime-request replies. Surface Claude fallback notices without failing the turn or hiding the notice. Report missing workspace folders before provider startup. Carry over custom models and prices, bounded client caches and stream cleanup, lazy image loading, persistent changed-file trees and sidebar filters, Safari cookie import, theme fixes, POSIX file-link case, private-host favicon filtering, native provider update paths, and platform portability updates. Migration ids remain unchanged. Validated scoped typechecks and focused server, web, mobile, client-runtime, contracts, desktop, shared, SSH, script, and resource-monitor tests. Preserved all 347 original commits and checked the final tree against both saved tips. Model: GPT-6. Harness: Codex.
Worktree preparation previously exposed only a generic fetch failure. Classify known authentication, network, repository access, and reference-lock errors using stable Git diagnostics, without retaining raw output or credentials. Unknown failures keep the existing generic message. Cover failure classification and redaction, a real missing local remote, and propagation into a failed prepared run without creating a worktree or running setup. The launch test waits for the persisted failure event. Validation: 38 focused tests, server typecheck, and scoped lint passed.
Carry main's session refresh, provider maintenance, runtime diagnostics, composer focus, preview, usage, and mobile outbox fixes into the v2 branch. Keep queue/steer submission, composer-only task progress, v2 subagent cards, and LegendList scroll ownership. Project thread and shell events before transport buffering while retaining full durable history. Dismiss native questions when provider turns finish, with a transaction guard that preserves answers submitted concurrently. Port Claude limit notices and Codex file approval details to v2 adapters. Validated with focused server, web, mobile, client-runtime, shared, desktop, and marketing tests; affected package typechecks and scoped lint pass. All 349 branch commits retain their authors and messages. Migration files and the previous worktree-fetch, stash, panel, and mobile inset fixes remain unchanged.
Offline CLI and HTTP project removal dropped force and left native v2 threads behind. Move the nonempty-project guard and durable child cleanup into the shared project service, and forward force from CLI, HTTP, and WebSocket calls. Reuse the thread deletion planner and command lock, hydrate migrated history before attachment cleanup, and validate child receipts. Commit the project deletion after its children so failed cleanup can be retried safely. Validation covers CLI deletion with active and archived threads, missing workspaces, durable cleanup, partial retries, migrated attachments, receipt collisions, and concurrent thread updates. Scoped server tests, typecheck, and lint pass. Implemented with Codex (GPT-6).
8116d35 to
8e98035
Compare

Problem
Direct PTY access was not available through the built-in MCP server, and existing terminal reads could not safely expose persisted history without retention side effects. A PTY exit queued immediately before clear could also be discarded, leaving the session and script ownership falsely running.
Change
Add current-project, thread-scoped managed terminal list/read/open/write/resize/clear/restart/close tools on the existing
TerminalManager. Reads inspect bounded retained memory only and never spawn, attach, restart, or touch persisted history. PTY event drains now share the Manager thread lock, and clear discards pending output while preserving a queued exit and its drain ownership.Behavior
Mutations use explicit terminal IDs, derive the target thread's nested execution directory and worktree environment, and require both caller and target to be full-access/default under the shared serialized admission lock. Existing-only restart and strict write avoid close/exit races; startup failures are not reported as opened. PTY input remains non-idempotent and reports acceptance rather than shell success. A clear cannot revive a process whose exit was already queued.
Focused validation
TerminalManagertests, including deterministic exit-queued → clear → drain behavior with no polling or scheduler timing assumptionstools/listroot-object schemas and Claude read-only exposure from the original layer validationDependency
Bottom layer of native stack #8715, based on immutable rollout base
agents/mcp-controls/base-490318aat490318afa505d3d033295eca12d7e62b4b922725. #8714 depends on its scoped terminal service, atomic fresh-open primitive, and terminal-incarnation handles.Implemented by GPT-5.6-Sol via Codex in T3 Code.
Note
Add MCP toolkit to control managed terminals
TerminalMcpServiceand eight MCP tools (list, read, open, write, resize, clear, restart, close) that let agents inspect and control managed terminals within the caller's project scopeTerminalManagerwith fresh-open, loaded-session inspection, strict and handle-validated writes, resize-and-inspect, existing-only restart, and handle-validated close operations; introduces session incarnation handles to guard writes/closes across restart and close-recreate lifecyclesopenOrInspectno longer reopens existing sessions;restartExistingraisesTerminalSessionLookupErrorinstead of creating a missing session;writeStrictrejects non-running sessions withTerminalNotRunningError; process-event admission now validates session incarnation, so callbacks from a prior process are dropped after restartMacroscope summarized e703b0d.
Note
High Risk
Adds MCP-driven host PTY input and process control with policy checks and locking, but mistakes in admission or races could still allow unintended shell execution or inconsistent thread state.
Overview
Exposes eight MCP tools (
t3_terminal_*) so orchestration-capable agents can list, read, and mutate thread-scoped managed terminals through the existingTerminalManager, registered on the same/mcpserver as orchestration and worktree tools.orchestrator_capabilitiesnow advertisesmanagedTerminals.Reads (
list/read) only see in-memory loaded sessions with bounded output windows; they never spawn PTYs or load persisted history. Mutations resolve cwd/env from the target thread (provider session cwd → worktree → workspace), require full-access + default on both caller and target, and run under sortedThreadCommandExecutorlocks held through the terminal side effect so policy and thread state stay consistent.TerminalManagergains inspect-only APIs, strict/handle-guarded writes,openFresh/openOrInspect,restartExisting, and session incarnation so stale PTY output/exit drains cannot affect restarted sessions; PTY event draining now runs under the manager’s thread lock, and clear drops pending output but keeps a queued exit.Contracts, UI presentation strings, Claude read-only pre-approval for terminal list/read, orchestrator layer/test harness wiring for injectable
ThreadCommandExecutor, and user/docs updates accompany the feature.Reviewed by Cursor Bugbot for commit e703b0d. Bugbot is set up for automated code reviews on this repo. Configure here.