Skip to content

feat(mcp): control managed terminals - #8707

Closed
juliusmarminge wants to merge 358 commits into
t3code/codex-turn-mappingfrom
agents/mcp-terminals/controls
Closed

juliusmarminge wants to merge 358 commits into
t3code/codex-turn-mappingfrom
agents/mcp-terminals/controls

Conversation

@juliusmarminge

@juliusmarminge juliusmarminge commented Aug 30, 2026 •

Copy link
Copy Markdown
Member

Problem

Direct PTY access was not available through the built-in MCP server, and existing terminal reads could not safely expose persisted history without retention side effects. A PTY exit queued immediately before clear could also be discarded, leaving the session and script ownership falsely running.

Change

Add current-project, thread-scoped managed terminal list/read/open/write/resize/clear/restart/close tools on the existing TerminalManager. Reads inspect bounded retained memory only and never spawn, attach, restart, or touch persisted history. PTY event drains now share the Manager thread lock, and clear discards pending output while preserving a queued exit and its drain ownership.

Behavior

Mutations use explicit terminal IDs, derive the target thread's nested execution directory and worktree environment, and require both caller and target to be full-access/default under the shared serialized admission lock. Existing-only restart and strict write avoid close/exit races; startup failures are not reported as opened. PTY input remains non-idempotent and reports acceptance rather than shell success. A clear cannot revive a process whose exit was already queued.

Focused validation

  • 60 focused TerminalManager tests, including deterministic exit-queued → clear → drain behavior with no polling or scheduler timing assumptions
  • focused terminal MCP service coverage and targeted lint
  • production HTTP tools/list root-object schemas and Claude read-only exposure from the original layer validation

Dependency

Bottom layer of native stack #8715, based on immutable rollout base agents/mcp-controls/base-490318a at 490318afa505d3d033295eca12d7e62b4b922725. #8714 depends on its scoped terminal service, atomic fresh-open primitive, and terminal-incarnation handles.

Implemented by GPT-5.6-Sol via Codex in T3 Code.

Note

Add MCP toolkit to control managed terminals

  • Adds TerminalMcpService and eight MCP tools (list, read, open, write, resize, clear, restart, close) that let agents inspect and control managed terminals within the caller's project scope
  • Expands TerminalManager with fresh-open, loaded-session inspection, strict and handle-validated writes, resize-and-inspect, existing-only restart, and handle-validated close operations; introduces session incarnation handles to guard writes/closes across restart and close-recreate lifecycles
  • Adds terminal MCP contracts in terminalMcp.ts covering input schemas, bounded output windows, session summaries, failure codes, and result types for all eight operations
  • Server derives execution cwd and environment from target thread state; mutating operations acquire sorted caller/target admission locks and require both threads to use full-access runtime mode
  • Risk: openOrInspect no longer reopens existing sessions; restartExisting raises TerminalSessionLookupError instead of creating a missing session; writeStrict rejects non-running sessions with TerminalNotRunningError; process-event admission now validates session incarnation, so callbacks from a prior process are dropped after restart

Macroscope summarized e703b0d.


Note

High Risk
Adds MCP-driven host PTY input and process control with policy checks and locking, but mistakes in admission or races could still allow unintended shell execution or inconsistent thread state.

Overview
Exposes eight MCP tools (t3_terminal_*) so orchestration-capable agents can list, read, and mutate thread-scoped managed terminals through the existing TerminalManager, registered on the same /mcp server as orchestration and worktree tools. orchestrator_capabilities now advertises managedTerminals.

Reads (list / read) only see in-memory loaded sessions with bounded output windows; they never spawn PTYs or load persisted history. Mutations resolve cwd/env from the target thread (provider session cwd → worktree → workspace), require full-access + default on both caller and target, and run under sorted ThreadCommandExecutor locks held through the terminal side effect so policy and thread state stay consistent.

TerminalManager gains inspect-only APIs, strict/handle-guarded writes, openFresh / openOrInspect, restartExisting, and session incarnation so stale PTY output/exit drains cannot affect restarted sessions; PTY event draining now runs under the manager’s thread lock, and clear drops pending output but keeps a queued exit.

Contracts, UI presentation strings, Claude read-only pre-approval for terminal list/read, orchestrator layer/test harness wiring for injectable ThreadCommandExecutor, and user/docs updates accompany the feature.

Reviewed by Cursor Bugbot for commit e703b0d. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitai Bot commented Aug 30, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 79a55f04-2277-482a-b3fe-3a68b9e36f09

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Your free Security trial is over. An organization admin can activate Security or dismiss this notice.


Comment @coderabbitai help to get the list of available commands.

@juliusmarminge
juliusmarminge marked this pull request as ready for review August 30, 2026 00:43
@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL 1,000+ changed lines (additions + deletions). labels Aug 30, 2026

@macroscopeapp macroscopeapp Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new Effect service (TerminalMcpService), its MCP toolkit wiring, and the TerminalManager/contract changes against the service conventions. Structure, imports, Context.Service shape, make/layer exports, and dependency acquisition all look right. Two findings on the new error model.

Posted via Macroscope — Effect Service Conventions

Comment thread apps/server/src/mcp/TerminalMcpService.ts
Comment thread packages/contracts/src/terminalMcp.ts
Comment thread apps/server/src/mcp/TerminalMcpService.ts
@juliusmarminge
juliusmarminge changed the base branch from t3code/codex-turn-mapping to agents/mcp-controls/base-490318a August 30, 2026 00:51
Comment thread docs/user/agent-managed-terminals.md Outdated
Comment thread apps/server/src/mcp/TerminalMcpService.ts Outdated
@macroscopeapp

macroscopeapp Bot commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds eight production MCP tools for spawning and controlling host PTYs, alongside substantial terminal lifecycle and cross-thread locking changes. The new execution capability and shared runtime behavior have a broad, side-effectful blast radius that warrants human review.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarminge force-pushed the agents/mcp-terminals/controls branch from ed412d5 to 056dafc Compare August 30, 2026 01:01
Comment thread apps/server/src/terminal/Manager.ts
@github-actions

github-actions Bot commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

Thread transfer impact

⚠️ The latest CI run did not produce a thread transfer result for e703b0d.

This comment will update automatically after the next completed run.

Comment thread apps/server/src/mcp/TerminalMcpService.ts
Comment thread apps/server/src/mcp/TerminalMcpService.ts
@macroscopeapp

macroscopeapp Bot commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

Macroscope has since reviewed this pull request. An earlier review was skipped by a cost limit; a review has now completed, so that notice no longer applies.

@juliusmarminge
juliusmarminge force-pushed the agents/mcp-terminals/controls branch from 056dafc to a701a2d Compare August 30, 2026 01:18

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON, but a cloud agent failed to start.

Reviewed by Cursor Bugbot for commit 627a635. Configure here.

Comment thread apps/server/src/terminal/Manager.ts
@juliusmarminge
juliusmarminge force-pushed the agents/mcp-terminals/controls branch from 183b049 to 2b56591 Compare August 30, 2026 17:15
@juliusmarminge
juliusmarminge changed the base branch from agents/mcp-controls/base-490318a to t3code/codex-turn-mapping August 30, 2026 17:15
@github-actions github-actions Bot added 📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. and removed 📱 Native Change Changes the native fingerprint; merging blocks production OTAs until a new store build ships. labels Aug 30, 2026
@juliusmarminge
juliusmarminge force-pushed the agents/mcp-terminals/controls branch from 99e0bab to 8116d35 Compare August 30, 2026 20:12
Comment thread apps/server/src/terminal/Manager.ts
mwolson and others added 12 commits September 4, 2026 21:54
…7105)

Co-authored-by: Julius Marminge <julius0216@outlook.com>
Retain main's changes while preserving v2 orchestration, queue/steer controls,
composer-only tasks, timeline timers, and mobile scrolling fixes.

Port opt-in restart continuation through durable v2 effects, with shutdown
race guards, activation gating, retry deduplication, and native Codex resume.
Use narrow projection reads for control effects and runtime-request replies.
Surface Claude fallback notices without failing the turn or hiding the notice.
Report missing workspace folders before provider startup.

Carry over custom models and prices, bounded client caches and stream cleanup,
lazy image loading, persistent changed-file trees and sidebar filters, Safari
cookie import, theme fixes, POSIX file-link case, private-host favicon filtering,
native provider update paths, and platform portability updates.
Migration ids remain unchanged.

Validated scoped typechecks and focused server, web, mobile, client-runtime,
contracts, desktop, shared, SSH, script, and resource-monitor tests. Preserved
all 347 original commits and checked the final tree against both saved tips.

Model: GPT-6. Harness: Codex.
Worktree preparation previously exposed only a generic fetch failure. Classify
known authentication, network, repository access, and reference-lock errors
using stable Git diagnostics, without retaining raw output or credentials.
Unknown failures keep the existing generic message.

Cover failure classification and redaction, a real missing local remote, and
propagation into a failed prepared run without creating a worktree or running
setup. The launch test waits for the persisted failure event.

Validation: 38 focused tests, server typecheck, and scoped lint passed.
Carry main's session refresh, provider maintenance, runtime diagnostics,
composer focus, preview, usage, and mobile outbox fixes into the v2 branch.
Keep queue/steer submission, composer-only task progress, v2 subagent cards,
and LegendList scroll ownership.

Project thread and shell events before transport buffering while retaining
full durable history. Dismiss native questions when provider turns finish,
with a transaction guard that preserves answers submitted concurrently.
Port Claude limit notices and Codex file approval details to v2 adapters.

Validated with focused server, web, mobile, client-runtime, shared, desktop,
and marketing tests; affected package typechecks and scoped lint pass.
All 349 branch commits retain their authors and messages. Migration files
and the previous worktree-fetch, stash, panel, and mobile inset fixes remain
unchanged.
Offline CLI and HTTP project removal dropped force and left native v2 threads
behind. Move the nonempty-project guard and durable child cleanup into the
shared project service, and forward force from CLI, HTTP, and WebSocket calls.

Reuse the thread deletion planner and command lock, hydrate migrated history
before attachment cleanup, and validate child receipts. Commit the project
deletion after its children so failed cleanup can be retried safely.

Validation covers CLI deletion with active and archived threads, missing
workspaces, durable cleanup, partial retries, migrated attachments, receipt
collisions, and concurrent thread updates. Scoped server tests, typecheck, and
lint pass.

Implemented with Codex (GPT-6).
@juliusmarminge
juliusmarminge force-pushed the agents/mcp-terminals/controls branch from 8116d35 to 8e98035 Compare September 5, 2026 06:03
Comment thread apps/server/src/terminal/Manager.ts
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL 1,000+ changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants