Implement operator overlay improvements and refine bus demux skills - #82
div0-space wants to merge 1020 commits into
Conversation
There was a problem hiding this comment.
An organization admin can view or raise the cap at claude.ai/admin-settings/claude-code. The cap resets at the start of the next billing period.
Once the cap resets or is raised, reopen this pull request to trigger a review.
There was a problem hiding this comment.
Pull request overview
This PR tightens “operator intent” routing across overlay paste, clarifies and enforces Layer 1 (live refinement) arming/receipts, and expands the documented/tested contracts around transcript lanes, settings truth, and bus demux tooling.
Changes:
- Refines overlay paste targeting: latch a non-self frontmost app, improve activation confirmation, and make all paste paths restore the user clipboard.
- Reframes Layer 1 as a product-mode decision (with typed receipts) and adds contract/acceptance fixtures + parity tests for arming, onset preservation, and repetition identity.
- Adds/updates operational docs and skills around transcript bus demux and layered transcription semantics; introduces lexicon learning threshold configuration.
Reviewed changes
Copilot reviewed 61 out of 61 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
| tests/fixtures/layered_engine_acceptance.json | Adds canonical Layer 1 acceptance vectors |
| tests/e2e_streaming_chunks.rs | Adds onset-token regression test |
| tests/e2e_overlay_delivery_parity.rs | Adds Layer 1 receipt/arming assertions + acceptance tests |
| skills/codescribe/SKILL.md | New skill doc for bus attach workflow |
| skills/codescribe/references/live-vs-seal.md | Documents “act on seal” rule |
| skills/codescribe/references/attach.md | Documents bus path + naming |
| skills/codescribe/README.md | Adds skill quick reference |
| skills/codescribe/FLOW.md | Mermaid flow for attach behavior |
| skills/codescribe/examples/example-prompt.md | Adds example trigger + expected behavior |
| scripts/tests/bus-demux-test.sh | Adds hermetic demux CLI checks |
| scripts/e2e-blackhole-dictation.sh | Updates layered override logging semantics |
| scripts/bus-demux.py | Introduces transcript bus demux CLI |
| README.md | Updates product description + engine framing |
| Makefile | Updates parity lane pin commentary/guard |
| macos/CodescribeTests/SettingsTruthTests.swift | Updates settings truth + adds runtime-state tests |
| macos/CodescribeTests/OverlayResizeHitTests.swift | Adds tests for overlay resize geometry |
| macos/CodescribeTests/DeveloperSurfaceTests.swift | Updates Lab/overlay gating expectation |
| macos/Codescribe/Screens/Settings/SettingsViewModel.swift | Adds LocalWhisperRuntimeState + atomic persistence rules |
| macos/Codescribe/Screens/Settings/LabPanel.swift | Updates Lab UI copy + behavior |
| macos/Codescribe/Screens/Settings/EnginePanel.swift | Reworks engine controls + live refinement status UI |
| macos/Codescribe/Screens/Overlay/DictationOverlayWindow.swift | Adds fat-band resize hit testing + cursors |
| macos/Codescribe/Core/DeveloperSurface.swift | Changes overlay gating logic |
| macos/Codescribe/Core/AppModel.swift | Adjusts overlay suppression logging |
| macos/Codescribe/Bridge/codescribe_ffi.swift | Updates FFI docs/checksum for quality changes |
| docs/WHISPER_LIVE.md | Updates Layer 1 status/default narrative |
| docs/TRANSCRIPT_LANES.md | Updates lane map + adds superseding laws |
| docs/TRANSCRIPT_BUS.md | Adds named-agent demux usage snippet |
| docs/THE_ENGINE_ROADMAP.md | Updates current truth around Layer 1 defaults |
| docs/THE_ENGINE_CONTRACT.md | Major contract update: span authority, receipts, settings |
| docs/STT_CONTRACT.md | Updates STT status + layered promotion semantics |
| docs/OVERLAY_STREAMING.md | Updates layer inventory/status table |
| docs/KORA_CODESCRIBE_JOURNAL.md | Adds extracted evidence journal |
| docs/env.md | Updates env docs for layered + final pass |
| docs/ENV_REGISTRY.toml | Updates layered default + adds lexicon min corrections var |
| docs/DELIVERY_ROUTE.md | Clarifies clipboard borrow/restore + activation notes |
| docs/ARCHITECTURE.md | Updates layer status + wiring claims |
| docs/ADR/2026-05-26-LAYERED_INCREMENTAL_TRANSCRIPTION.md | Revises ADR invariants + default status |
| core/stt/tail_provider.rs | Exposes TailSampleRange::contains for crate use |
| core/stt/tail_patcher/mod.rs | Reframes layered phase parsing/default behavior |
| core/quality/overlay_quality.rs | Adds N-correction lexicon learning gate + receipts |
| core/pipeline/tests/regressions.rs | Adds regressions for Layer 1 receipt ordering |
| core/pipeline/streaming/session.rs | Adds typed TailPatchSessionReceipt + VAD-route refusal evidence |
| core/pipeline/streaming/mod.rs | Re-exports receipt symbols |
| core/pipeline/stream_postprocess.rs | Adjusts tests for lexicon threshold override |
| core/config/settings.rs | Updates layered settings semantics/comments |
| core/audio/streaming_recorder.rs | Threads tail-patch receipt through production replay |
| core/asr_session/recorder.rs | Adds LocalTailPatchDisposition + Layer1Decision variant |
| core/asr_session/mod.rs | Re-exports new layer1 symbols |
| core/asr_session/cloud.rs | Tightens ws/wss endpoint guard condition |
| core/asr_session/bootstrap.rs | Resolves Layer 1 decision by product mode + override |
| bridge/src/quality.rs | Updates evidence-only semantics docs |
| app/os/selection.rs | Adds paste latch helpers + foreign frontmost memory |
| app/controller/tests.rs | Adds activation-confirmation unit test |
| app/controller/quality_delivery.rs | Uses paste_and_restore for delivery paste |
| app/controller/overlay_paste.rs | Adds overlay_float_still_confirms_activation helper |
| app/controller/mod.rs | Uses prior-frontmost capture for overlay paste context |
| app/controller/final_pass.rs | Updates final-pass vs layered doc comments |
| AGENT_BUS.md | Adds signal about Layer 1 default OFF |
| .grok/skills/bus-demux/SKILL.md | Adds minimal bus-demux skill doc |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 82 out of 83 changed files in this pull request and generated 1 comment.
Suppressed comments (1)
scripts/bus-demux.py:140
iter_new_linesrewindsoffsetfor an incomplete last line by re-encoding the decoded string (lines.pop().encode('utf-8')). Witherrors='replace'this can change the byte length (e.g., when a multi-byte UTF-8 sequence is split across reads), causing the follower to skip or duplicate bytes. Rewind should be computed on the rawchunkbytes (e.g., using the lastb'\n'index) rather than re-encoding text.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 96 out of 97 changed files in this pull request and generated 3 comments.
Suppressed comments (1)
core/pipeline/streaming/silero_fusion.rs:327
pause_evidence_for_rangelinearly scans and clones fromself.sidebandeach time it’s called. If this is invoked once per sealed span, the total work can become O(n²) over a session asself.sidebandgrows.
Consider indexing by sample range (monotonic cursor) or pruning the underlying storage so this remains bounded per call.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 112 out of 113 changed files in this pull request and generated 1 comment.
Suppressed comments (1)
scripts/build-app.sh:68
shutil.copytree(skill_source, …)uses the defaultsymlinks=False, which dereferences any symlinks inskills/codescribeand copies their target bytes into the staged payload. That defeats the laterpath.is_symlink()guard (the staged file is no longer a symlink) and can accidentally bundle out-of-tree content. Consider either (a) scanningskill_source.rglob('*')and failing on anyis_symlink()before copying, or (b) callingshutil.copytree(..., symlinks=True)so symlinks are preserved and then rejected by the existing check.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 114 out of 115 changed files in this pull request and generated no new comments.
Suppressed comments (1)
Previously missed (1) — in code that hasn't changed since the last review.
macos/Codescribe/Screens/Overlay/DictationOverlayWindow.swift:451
- For macOS < 15, corner resize hits currently show a crosshair cursor (
default: return .crosshair). This looks like a selection/crosshair cursor rather than a resize affordance and may confuse users. Consider using diagonal resize cursors for corner cases (e.g..resizeDiagonalUpLeftDownRight/.resizeDiagonalUpRightDownLeft) to match platform conventions.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 114 out of 115 changed files in this pull request and generated 7 comments.
Suppressed comments (1)
core/asr_session/bootstrap.rs:160
- Reserved
phase2–phase4values are treated as armed here, while Settings classifies every value exceptphase1as a configuration mismatch andENV_REGISTRY.toml:569says phases 2–4 are reserved. This makes the UI report “Degraded” even though the next recording runs Layer 1. Onlyphase1should arm the current lane; reserved phases should use the invalid/degraded disposition until implemented.
Some(value) => match layered_phase_from_raw(Some(value)) {
Some(phase) => LocalTailPatchDisposition::ArmedPhase(phase),
None if matches!(
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 116 out of 117 changed files in this pull request and generated 1 comment.
Suppressed comments (3)
skills/codescribe/SKILL.md:110
- The documented attach sequence cannot complete: the first
--become --followprocess keeps the provider/session lease lock, so launching this second command with the same provider/session is rejected as a duplicate (SessionLease._acquire_lock). Either bind the running follower through its supported protocol or explicitly stop it before reattaching; otherwise users never reach the named mailbox.
app/controller/overlay_paste.rs:150 - This treats “Codescribe is still frontmost” as proof that an arbitrary foreign target activated.
activateWithOptionsonly confirms the request was accepted, and the wait has already timed out, so a failed activation while the overlay remains key now passes the disposition check and sends Cmd+V into Codescribe. A positive signal from the target application is required; self still being frontmost cannot safely confirm activation.
wait_confirmed
|| frontmost_after_activate
.map(str::trim)
.is_some_and(|name| !name.is_empty() && target_is_self_app(name))
core/asr_session/bootstrap.rs:157
- The PR description says the layered-transcription default is now off, but an absent override is resolved to
ArmedDefault, and Settings/tests also present Local Power as armed by default. This materially changes recording behavior and contradicts both the stated change and the new default-off notes inAGENT_BUS.md/THE_ENGINE_ROADMAP.md; choose one default and align runtime, tests, and contracts.
fn local_tail_patch_disposition(raw: Option<&str>) -> LocalTailPatchDisposition {
match raw {
None => LocalTailPatchDisposition::ArmedDefault,
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…ble pin to the anchor menu Authored-By: codex <agents@vetcoders.io>
…us row Sample review of build 1452 (codescribe-1452-sample-review.md): 97.4% of scan samples sat in serde_json::from_str::<Value> and 41% in memmove, almost all of it building full JSON trees carrying transcript payloads the ack scan never reads. - Rows now deserialize into a typed AckScanRow borrowing six scalar fields (kind, status, delivery_id, spoken, reply_id, emitted_at); no Value tree, no payload copies. - A substring prefilter skips deserialization entirely for rows naming neither "delivery_id" nor "agent_reply" — every actionable row names one, and our bus writers emit keys as literal ASCII. - A single row above 8 MiB is dropped unparsed: its bytes stop holding the carry buffer, and the offset advances only once its newline lands, so a still-growing row is never split. The head fingerprint is taken from the first 256 buffered bytes, so an oversize first row still fingerprints the bus. - Tests: oversize row dropped while the next row is read; a rowless oversize tail never advances the mark. Authored-By: claude <agents@vetcoders.io> Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Playback failure can mute capture, security checks are globally disabled, and the cut violates documented authority and terminology contracts.
Review effort: Balanced
Findings: 4
Open (14)
Sandbox inherited data directory explicitly Nested content shape breaks tool activity decoding Keep security rules enabled with targeted suppressions Require an explicit microphone streaming destination Refer to human requesters as Founders, not operators Report only Cloud mode as unavailable without consent Keep Settings synchronized with tray badge changes Use the keychain-free snapshot entry point in the signature test Require the schema discriminator in receipt validation Remove competing CLI executable entry points Replace prohibited Legacy terminology Rename forbidden prior-format terminology Disclose Swift 6 concurrency migration scope Remove transient branch-specific wording from the evidence description
…rols Merge the visual follow-up into the current checkout, preserving Claude’s ACK scanner and persistent-channel changes. Keep Setup glass on its surface and share flat actions with rounded hairline focus. Coauthored: Claude
Disable credential-store access explicitly for snapshot-cache fixtures, including custom Cargo target directories. Reuse the scope-owned bundle fixture under the test-isolation feature so existing process cache state is restored after each test.
…count cannot speak - resolve_auth_with: a signed-in OpenAI account has no public audio permission, so speech now falls back to the stored API key instead of refusing outright; the account stays authoritative for every non-speech request (Founder order, 2026-09-29) - speech_availability mirrors the fallback and touches the Keychain lazily, only when the account alone cannot speak - the capability message no longer claims that no fallback was attempted; it now names the missing key - new test: a_speechless_account_falls_back_to_the_stored_key (key fallback, terminal refusal without a key, xAI OAuth untouched) Gates: cargo test -p codescribe-core --lib llm::speech 16/16; clippy -D warnings clean. Authored-By: claude <agents@vetcoders.io> Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It spans security gates, microphone transport, runtime authority, serialization, Swift concurrency, and core transcription behavior, with unresolved blocking findings.
Review effort: Balanced
Findings: 4
Open (17)
Sandbox inherited data directory explicitly Nested content shape breaks tool activity decoding Keep security rules enabled with targeted suppressions Require an explicit microphone streaming destination Remove dormant transport selector accessor · New Name the correct test data directory variable · New Refer to human requesters as Founders, not operators Report only Cloud mode as unavailable without consent Keep Settings synchronized with tray badge changes Use the keychain-free snapshot entry point in the signature test Require the schema discriminator in receipt validation Remove competing CLI executable entry points Rename prohibited comment terminology · New Replace prohibited Legacy terminology Rename forbidden prior-format terminology Disclose Swift 6 concurrency migration scope Remove transient branch-specific wording from the evidence description
| /// Compatibility accessor for the Apple bridge transport token. | ||
| /// | ||
| /// `stream` selects progressive Apple AudioBuffer delivery; `wav` and | ||
| /// `transcribe_live` name the older Apple temp-WAV request transport. A fresh | ||
| /// Loctree 600-file structural census on 2026-08-25 found this definition and | ||
| /// its re-export but no caller. That is a structural observation, not runtime | ||
| /// proof, and this helper does not select or restore a VAD/scheduler pipeline. |
| set -euo pipefail | ||
|
|
||
| real_home="${HOME:?HOME is required}" | ||
| sandbox_root="${CODESCRIBE_TEST_DATA_DIR:?TEST_DATA_DIR_SETUP is required}" |
|
|
||
| /// Process-global broadcast carrying voice-assistive reply events to the UI. | ||
| pub mod agent_delivery; | ||
| /// Command surfaces shared by `codescribe <subcommand>` and the legacy bins. |
- _speak_openai: api.openai.com/v1/audio/speech, PCM s16le 24 kHz, the
same TLS-only opener discipline as the xAI speaker; playback factored
into _play_pcm_24k and shared by both vendors
- vendor selection: --tts-vendor flag, then the name's voices.json
profile "provider", then the xai default; the reply envelope records
tts_vendor
- _openai_speech_key reads LLM_OPENAI_API_KEY from env or a plain
Keychain item only; the app's Keychain bundle stays app-private by
design (Codex OAuth has no public audio permission, so this speaker
is key-only)
- Founder order: channel-1 seal 24f9c654 ("zalacz sie pod glosy
OpenAI"), 2026-09-29
Receipt: reply 75548d73280d086fdefeffce landed on the bus with
spoken=false and a truthful tts_error until a helper-visible key exists.
Authored-By: claude <agents@vetcoders.io>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It includes an unsafe default microphone destination, inaccurate UI and ADR documentation, and unresolved repository authority-rule violations.
Review effort: Balanced
Findings: 4
Open (17)
Sandbox inherited data directory explicitly Nested content shape breaks tool activity decoding Keep security rules enabled with targeted suppressions Require an explicit microphone streaming destination Name the correct test data directory variable Remove dormant transport selector accessor Refer to human requesters as Founders, not operators Report only Cloud mode as unavailable without consent Keep Settings synchronized with tray badge changes Use the keychain-free snapshot entry point in the signature test Require the schema discriminator in receipt validation Remove competing CLI executable entry points Rename prohibited comment terminology Replace prohibited Legacy terminology Rename forbidden prior-format terminology Disclose Swift 6 concurrency migration scope Remove transient branch-specific wording from the evidence description
… bus Engine (Rust): - the audience binding entry carries an optional "bus"; resolve_digit hands it to BoundAgentSession and pre-W5 bindings keep the shared bus - dispatch_agent_channel opens the channel TranscriptBus at the binding bus (open_with_path is now pub(crate)); open and silence-seal receipts follow the same routing via OpenAgentChannel.bus - append_json_line creates a missing parent directory so a receipt never vanishes before the attach engine makes the buses folder - new test: a_binding_bus_routes_the_channel_receipts_to_the_dedicated_file Attach engine (bus-demux): - --attach without an explicit --bus creates <bridge-home>/buses/channel-<n>.jsonl (dir 0700, file 0600), writes the binding "bus", and migrates a follower sitting on another bus: SIGTERM, wait, lease rewritten to the new bus with cursor 0, pending deliveries and acknowledgment markers untouched - channel occupancy is still decided by identity alone; the bus is routing and may be updated for the same owner - --ack checks the lease bus only when --bus is explicit, so a migrated session acknowledges without knowing its bus Receipts: isolated bridge-home run — attach on an explicit bus, then a bus-less attach migrated the live follower (binding.bus set, lease bus switched, cursor 0, old pid retired), and a third attach was idempotent (same pid, no respawn). cargo test 621/621, clippy -D warnings clean. Runtime sync of the attach change is deliberately deferred until a build with the engine routing is installed; syncing earlier would migrate followers onto buses the running app does not write. The quiet-contract reopen re-resolves the binding, so channels self-heal onto their dedicated buses at the first delivery after that build. Authored-By: claude <agents@vetcoders.io> Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- end_channel_session returns the whole-capture WAV path when the channel owned the capture; a shared capture stays open and owes the channel no WAV (unchanged behaviour, the path was simply discarded) - close_open_channel archives that audio through the same retain_session_audio store and retention rules as dictation (W5 MUST: channel sessions persisted only .slots.jsonl, never audio) - the channel keeps its last non-empty projection, so the archived take carries the heard words in its slug and transcript; a voiceless close archives truthfully as no-speech Gates: cargo test streaming_recorder 30/30, agent_channel 10/10; clippy -D warnings clean. The live round-trip receipt (an .m4a in the daily store after a channel take) lands with the next installed build. Authored-By: claude <agents@vetcoders.io> Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The unusually broad runtime, transcription, UI, security-gate, and tooling changes include unresolved contract and correctness issues.
Review effort: Balanced
Findings: 4
Open (17)
Sandbox inherited data directory explicitly Nested content shape breaks tool activity decoding Keep security rules enabled with targeted suppressions Require an explicit microphone streaming destination Name the correct test data directory variable Remove dormant transport selector accessor Refer to human requesters as Founders, not operators Report only Cloud mode as unavailable without consent Keep Settings synchronized with tray badge changes Use the keychain-free snapshot entry point in the signature test Require the schema discriminator in receipt validation Remove competing CLI executable entry points Rename prohibited comment terminology Replace prohibited Legacy terminology Rename forbidden prior-format terminology Disclose Swift 6 concurrency migration scope Remove transient branch-specific wording from the evidence description
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It contains incorrect runtime/status reporting, a flaky streaming test, authority-rule violations, and substantial undocumented scope.
Review effort: Balanced
Findings: 4
Open (17)
Sandbox inherited data directory explicitly Nested content shape breaks tool activity decoding Keep security rules enabled with targeted suppressions Require an explicit microphone streaming destination Name the correct test data directory variable Remove dormant transport selector accessor Refer to human requesters as Founders, not operators Report only Cloud mode as unavailable without consent Keep Settings synchronized with tray badge changes Use the keychain-free snapshot entry point in the signature test Require the schema discriminator in receipt validation Remove competing CLI executable entry points Rename prohibited comment terminology Replace prohibited Legacy terminology Rename forbidden prior-format terminology Disclose Swift 6 concurrency migration scope Remove transient branch-specific wording from the evidence description
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved security regressions, credential-persistence ordering, stale Voice Lab state, and incorrect bus timing can affect production behavior.
Review effort: Balanced
Findings: 5
Open (19)
Remove global pre-push exclusions for security rules · New Sandbox inherited data directory explicitly Nested content shape breaks tool activity decoding Keep security rules enabled with targeted suppressions Require an explicit microphone streaming destination Scope helper state to the selected correction row · New Name the correct test data directory variable Remove dormant transport selector accessor Refer to human requesters as Founders, not operators Report only Cloud mode as unavailable without consent Keep Settings synchronized with tray badge changes Use the keychain-free snapshot entry point in the signature test Require the schema discriminator in receipt validation Remove competing CLI executable entry points Rename prohibited comment terminology Replace prohibited Legacy terminology Rename forbidden prior-format terminology Disclose Swift 6 concurrency migration scope Remove transient branch-specific wording from the evidence description
| - id: semgrep | ||
| name: semgrep security scan | ||
| entry: semgrep scan --config auto --error . | ||
| entry: scripts/git-hooks/embargo-guard.sh semgrep -- semgrep scan --config auto --config .semgrep.yaml --error --exclude-rule rust.actix.path-traversal.tainted-path.tainted-path --exclude-rule javascript.lang.security.detect-insecure-websocket.detect-insecure-websocket . |
| @@ -484,7 +478,7 @@ struct VoiceLabPanel: View { | |||
| Spacer() | |||
| Text("\(safeIndex + 1) of \(corrections.count)") | |||
| .font(CSFont.mono(10.5, .medium)) | |||
| .foregroundStyle(CSColor.textFaintAlt) | |||
| .foregroundStyle(Color.secondary) | |||
| Spacer() | |||
| Button("Next") { correctionIndex = min(corrections.count - 1, safeIndex + 1) } | |||
…tings save Root cause of the settings.json.bak graveyard (285 backups on div0, a screen-long wall on the second machine, 2026-09-29): launch repair seeded the legacy speech.engine.cloud_transcription_endpoint whenever it was absent, the typed serializer drops that key on every ordinary save, and the next load seeded it again — each round backing the file up. The one-shot lane migration already refuses this loop on its side (needs_migration), but the seeder kept feeding it. - repair_settings seeds cloud_transcription_endpoint only while the migration still has work to do: when file_transcription_endpoint and live_transcription_endpoint are both empty - new test: a_migrated_config_is_never_reseeded_or_backed_up_again (migrated lane + pack present -> no actions, no backups) Gates: config::repair 7/7; clippy -D warnings clean. The fix rides the next installed build; existing .bak files are the Founder's data and are left untouched. Authored-By: claude <agents@vetcoders.io> Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The diff retains competing CLI authorities, contains contract/documentation inconsistencies, and substantially exceeds the scope described by the PR.
Review effort: Balanced
Findings: 5
Open (19)
Remove global pre-push exclusions for security rules Sandbox inherited data directory explicitly Nested content shape breaks tool activity decoding Keep security rules enabled with targeted suppressions Require an explicit microphone streaming destination Scope helper state to the selected correction row Name the correct test data directory variable Remove dormant transport selector accessor Refer to human requesters as Founders, not operators Report only Cloud mode as unavailable without consent Keep Settings synchronized with tray badge changes Use the keychain-free snapshot entry point in the signature test Require the schema discriminator in receipt validation Remove competing CLI executable entry points Rename prohibited comment terminology Replace prohibited Legacy terminology Rename forbidden prior-format terminology Disclose Swift 6 concurrency migration scope Remove transient branch-specific wording from the evidence description



This pull request introduces several improvements and clarifications to the handling of overlay pasting, frontmost app detection, and Layer 1 transcription logic, along with documentation and test updates. The most significant changes are grouped below:
Overlay Paste and Frontmost App Handling:
capture_frontmost_app_only_with_prior_frontmostfunction, which better preserves the correct target app and avoids mistakenly selecting Codescribe as the paste target. This includes tracking the last foreign (non-Codescribe) frontmost app and ensuring overlays never latch onto Codescribe itself. (app/controller/mod.rs,app/os/selection.rs) [1] [2] [3] [4]paste_latch_from_frontmostand related helpers to ensure the paste target is always a valid, non-self application, and added tests to guarantee this behavior. (app/os/selection.rs) [1] [2]Overlay Activation and Confirmation Logic:
overlay_float_still_confirms_activationand associated unit tests. (app/controller/overlay_paste.rs,app/controller/tests.rs) [1] [2]Clipboard and Pasting Improvements:
clipboard::paste_and_restore, which better preserves clipboard state during automated pasting. (app/controller/mod.rs,app/controller/quality_delivery.rs) [1] [2]Layer 1 Transcription and Documentation:
CODESCRIBE_LAYERED_TRANSCRIPTIONsetting, its promotion to user settings, and its new default-off behavior. Documentation and comments were updated to reflect these changes and the distinction between Apple-only and Local Power modes. (README.md,Makefile,AGENT_BUS.md,app/controller/final_pass.rs,core/asr_session/bootstrap.rs) [1] [2] [3] [4] [5] [6]Quality Correction and Lexicon Learning:
bridge/src/quality.rs) [1] [2]Additional minor changes include skill documentation and symlinks for the
bus-demuxandcodescribeskills. [1] [2]## SummaryWhat changed, and why?
User Impact
What does this improve or prevent for a real codescribe user?
Runtime Impact
Verification
cargo fmt --allcargo clippy -- -D warningscargo testmake semgrepAdd targeted commands, screenshots, recordings, or release-artifact checks here:
Release Notes
Should this appear in
CHANGELOG.md?