Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
86 commits
Select commit Hold shift + click to select a range
48bcb0c
feat(design): add secure spatial context pipeline
sambitcreate Aug 31, 2026
940cd38
feat(design): ship the full spatial canvas workspace
sambitcreate Aug 31, 2026
483d2e8
docs(design): unify the workspace roadmap
sambitcreate Aug 31, 2026
19b87f0
feat(design): add source-backed designer runtime
sambitcreate Aug 31, 2026
c54bf6d
feat(design): complete point-to-review workflow
sambitcreate Aug 31, 2026
c660c24
docs(design): archive the completed MVP roadmap
sambitcreate Aug 31, 2026
6990065
test(design): cover source context and overlay invariants
sambitcreate Aug 31, 2026
da1104b
perf(design): index canvas selection context
sambitcreate Aug 31, 2026
b465668
feat(design): add durable project storage and exports
sambitcreate Sep 1, 2026
1c0abdf
feat(design): add recoverable workspace handoff
sambitcreate Sep 1, 2026
8259645
feat(design): add local design system context
sambitcreate Sep 1, 2026
ad56d35
feat(design): add comments and bounded direct edits
sambitcreate Sep 1, 2026
9010e54
feat(design): add durable multifile source actions
sambitcreate Sep 1, 2026
7ac323f
feat(design): contain Vite and Next preview transport
sambitcreate Sep 1, 2026
ff1c776
feat(design): add crash-safe project lifecycle
sambitcreate Sep 1, 2026
e29c534
feat(design): bind project services to the main process
sambitcreate Sep 1, 2026
9a53cb3
feat(design): add project library and inspector UI
sambitcreate Sep 1, 2026
f7646eb
feat(design): wire durable workspace IPC and context
sambitcreate Sep 1, 2026
d83f28f
feat(design): integrate the durable project workspace
sambitcreate Sep 1, 2026
d4704d3
feat(design): update onboarding for durable projects
sambitcreate Sep 1, 2026
7bbd334
test(design): verify offline project exports
sambitcreate Sep 1, 2026
50e16e8
docs(design): archive the completed alignment plan
sambitcreate Sep 1, 2026
9f338f1
Merge origin/main into feature/design-workspace
sambitcreate Sep 1, 2026
54737a6
fix(workspaces): defer cyclic llm dependency
sambitcreate Sep 1, 2026
1c24fd1
fix(updater): preserve checked handler boundary
sambitcreate Sep 1, 2026
d0b2731
test(subagents): follow routed chat deletion
sambitcreate Sep 1, 2026
56ba7f7
test(design): await preview source updates
sambitcreate Sep 1, 2026
7c64b62
feat(design): explain canvas tools on hover
sambitcreate Sep 1, 2026
06c4dfc
fix(design): separate prototype storage from workspace authority
sambitcreate Sep 2, 2026
8c21a7a
fix(design): bind app previews and edits to projects
sambitcreate Sep 2, 2026
7f4dfb4
feat(design): add reconnect flow and atomic prompt preflight
sambitcreate Sep 2, 2026
4d3f2bf
docs: record alternate-port dev launch papercut
sambitcreate Sep 2, 2026
52f948e
Merge origin/main into feature/design-workspace
sambitcreate Sep 2, 2026
5d7e56f
test(design): align generation authority contracts
sambitcreate Sep 2, 2026
b6fbecd
feat(design): split Agent and Design workspaces
sambitcreate Sep 2, 2026
77e1b28
feat(design): dock composer in project conversation
sambitcreate Sep 2, 2026
cc89706
docs(design): record workspace mode decisions
sambitcreate Sep 2, 2026
4b3796d
fix(design): simplify scoped composer controls
sambitcreate Sep 2, 2026
7732a4c
fix(design): close compact sidebar on mode switch
sambitcreate Sep 2, 2026
dc25aee
test(design): stabilize source preview revisions
sambitcreate Sep 2, 2026
6a0e806
test(design): retry revision preview readiness
sambitcreate Sep 2, 2026
c06b1cc
fix(design): make startup recovery dependency-safe
sambitcreate Sep 2, 2026
9d8a057
fix(design): preserve route and composer state
sambitcreate Sep 2, 2026
156cda2
fix(design): preserve migrated project authority
sambitcreate Sep 2, 2026
2d0bd3d
fix(design): close migration and route authority races
sambitcreate Sep 2, 2026
06dc03e
fix(design): persist model revision lineage
sambitcreate Sep 2, 2026
b412d73
test(design): make preview revision checks exact
sambitcreate Sep 2, 2026
dfdf882
fix(design): contain source preview navigation
sambitcreate Sep 2, 2026
39e631e
fix(design): keep rejected mode switches in place
sambitcreate Sep 2, 2026
747e9fc
test(design): cover accepted mode switching
sambitcreate Sep 2, 2026
3af236f
fix(design): keep action controls in conversation rail
sambitcreate Sep 2, 2026
9d23587
test(bots): settle skill watchers before edits
sambitcreate Sep 2, 2026
23277ec
fix(design): hide migrated projects from Agent lists
sambitcreate Sep 2, 2026
529b789
docs: clarify machine-local papercuts policy
sambitcreate Sep 2, 2026
47b7549
fix(design): resolve conversation rail review gaps
sambitcreate Sep 2, 2026
104886d
fix(design): unlock stale todo conversations
sambitcreate Sep 2, 2026
f6b84fd
test(subagents): make grace timing deterministic
sambitcreate Sep 2, 2026
68f9161
fix(sidebar): simplify mode picker contrast
sambitcreate Sep 2, 2026
a314fdc
fix(sidebar): align mode menu corners
sambitcreate Sep 2, 2026
7cb5ab4
test(design): allow source preview integration startup
sambitcreate Sep 2, 2026
8d518ce
fix(sidebar): soften mode menu shell
sambitcreate Sep 2, 2026
136ac57
fix(sidebar): enforce matching mode menu radius
sambitcreate Sep 2, 2026
162b62b
fix(design): make artifact publication durable
sambitcreate Sep 2, 2026
80827f4
fix(design): reconcile canvas recovery state
sambitcreate Sep 2, 2026
5c003d0
fix(design): make cancelled drafts recoverable
sambitcreate Sep 2, 2026
ec62962
test(design): pin durable route recovery
sambitcreate Sep 2, 2026
8735cfc
fix(design): surface terminal publication conflicts
sambitcreate Sep 2, 2026
4bda677
fix(design): clarify recovery guidance
sambitcreate Sep 2, 2026
ad03fff
docs(design): plan Stitch-inspired studio
sambitcreate Sep 3, 2026
bac4e17
feat(design): establish screen-centered workbench
sambitcreate Sep 3, 2026
4715a5a
feat(design): add durable project v2 semantics
sambitcreate Sep 3, 2026
615d58a
test(diagnostics): keep forged records within retention
sambitcreate Sep 3, 2026
1a338f6
merge: integrate current main into Design Studio
sambitcreate Sep 12, 2026
313965c
test: make unknown push outcome fixture deterministic
sambitcreate Sep 12, 2026
3f8545f
feat(design): persist Explore and Refine direction workflows
sambitcreate Sep 12, 2026
622e014
feat(design): add reviewed project Design Language
sambitcreate Sep 12, 2026
c4e64da
feat(design): verify exact prototype routes in isolated host
sambitcreate Sep 12, 2026
8d98763
feat(design): export reviewed project bundles and handoff scope
sambitcreate Sep 12, 2026
75d90ee
fix(design): preserve completed handoff replay after source changes
sambitcreate Sep 12, 2026
0dcd91b
fix(design): reconcile export review after project changes
sambitcreate Sep 12, 2026
37c7d37
docs(design): record reviewed Studio implementation and acceptance
sambitcreate Sep 12, 2026
1edd278
Merge current main into Design Studio preserving recovery contracts
sambitcreate Sep 22, 2026
133b96c
Improve Studio preview reuse, history loading, and process cleanup
sambitcreate Sep 22, 2026
15700da
Keep papercut scratch local per project policy
sambitcreate Sep 22, 2026
241ef92
Handle exact same-page Vite reload interruptions in preview test
sambitcreate Sep 22, 2026
577d17a
Archive completed Studio research plan with CI evidence
sambitcreate Sep 22, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ Thumbs.db
tmp/*

# Local agent troubleshooting notes
.papercuts/
**/.papercuts/

# Local git worktrees
.worktrees/
Expand Down
55 changes: 55 additions & 0 deletions .memory/studio-research-improvements.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
# Studio PR #85 — 2026-09-22

Preserved `feature/stitch-design-studio` (original head 37c7d37fa) in isolated
`feature/studio-research-upgrade`. Main integration is separate commit 1edd2781.
See docs/plans/completed/studio-research-improvements-plan.md for verified sources, changes,
explicit deferrals, review findings and acceptance scope. Existing PR must be
updated, never duplicated; no merge/release/deploy authorized.

Integration preserved both sides of 13 conflicts, including detached generation
recovery, Aiden Live, Studio ownership and DataStore publication receipts.
Sol medium review found a task-chip spacing mismatch; fixed. Three source tests
were adapted for conditional Studio layout and its prepared workspace argument.
122 focused tests and type checks passed.

Post-change reviewers caught fallback History dates/provenance, a redundant
post-edit source read, incompatible connected-source context on Explore, duplicate
preview document allocation, and loss of process failure state after cleanup.
Fixes preserve exact authorization and visible failure recovery. Native Design
exclusion remains unchanged; Android parity checks and iOS generic hardware test compilation passed, as did
production build, type/lint and remote checks (462 pass, one skip). Hosted
exact-head checks remain pending.

Follow-up at 2026-09-22 11:38 UTC: head 133b96c55 has successful Ubuntu
checks, while CI run 35719548500 still has verify and Deterministic Electron
E2E queued with unassigned macos-26 runners. PR comments and review threads are
empty. This is an external runner blocker, not passing CI. Removed previously
tracked papercut scratch from Git while retaining the ignored local file, per
the updated project instructions; no implementation changed.

Hosted verify run 35722837750/job 106729478113 subsequently failed at the
source-designer browser test: Undo's Vite reload interrupted page.goto with
Chromium's alternate same-page navigation message. All 451 Design tests passed;
the browser retry passed but fail-on-flaky correctly failed the job. Prepared a
test-only fix in tests/generative-ui/source-designer.spec.ts matching the exact
target and cleaned same-origin/path destination, with positive/negative cases.
Both independent Sol medium reviewers found no issues. Classifier test passed
three repetitions; browser integration could not launch under the newly
restricted sandbox (MachPortRendezvousServer permission denied). Git metadata
is read-only and coordinator notification was denied by the tool because
approval policy is never. Patch retained at /tmp/studio-pr85-vite-reload.patch;
fix is uncommitted and unpushed. Do not claim hosted CI or browser reruns passed.

12:43 UTC follow-up: head remains 15700da226; Deterministic Electron E2E
job 106729477692 succeeded. Release consumer contract also succeeded; verify
still failed as above, with its downstream native/build steps skipped. No PR
comments or review threads. Local fix lint and TypeScript checks passed.

14:07 UTC: unrestricted permissions restored. Real source-designer browser
tests passed all nine cases across three repetitions with retries disabled,
including Apply/Undo and ambiguous-component rejection. Both prior Sol reviews
cover this unchanged test-only fix. Coordinator notification now succeeded.
The full Generative UI browser suite also passed all 12 tests with retries
disabled. Hosted acceptance still requires the new pushed head's checks.

14:41 UTC: all applicable hosted checks passed on 241ef9272416dffb433145d345d9b1e1ed53c5e8 (CI35738331314 and release contract35738331308). Android path-skipped; no comments/review threads. Plan archived as complete. Documentation-only completion commit will receive its own exact-head check before monitoring closes.
854 changes: 0 additions & 854 deletions .papercuts/troubleshooting.md

This file was deleted.

2 changes: 1 addition & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ OpenRouter benchmark insights are also manual-only. The live app may contact onl

## Papercuts

For complex workflows, record concise implementation friction in `.papercuts/troubleshooting.md` as it occurs.
Papercut notes are machine-local scratch and are intentionally ignored by Git. For complex workflows, record concise implementation friction in `.papercuts/troubleshooting.md` as it occurs, but do not commit the folder or its contents.

## Tests

Expand Down
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@ I don't come from a coding background. I'd been bouncing between the coding agen
## Features

- **Aiden Live (Beta)** - use the blue orb for an explicitly started voice session with visible listening, thinking, speaking, approval, and error states. First use walks through model access, microphone, and Screen & Accessibility permissions once; computer actions and scheduled tasks retain Aiden's existing approval boundaries.
- **Design Workspace** - open Design from the persistent sidebar and work on a durable React Flow-powered canvas of live, network-free HTML artboards and image references. Projects restore their exact canvas, history, comments, and source connection; Preview, Code, export, design-system context, reviewed multi-file actions, hash-safe Undo, and recoverable workspace handoff are built in. See the [shipped MVP](docs/plans/completed/design-workspace-plan.md) and [completed durable-project follow-on](docs/plans/completed/design-workspace-claude-alignment-plan.md).
- **Command palette and shortcuts** - `⌘K` searches commands, chats, models, providers, Settings, and appearance actions. One typed command system also powers native menus, visible shortcut labels, transactional global hotkeys, and the searchable Keyboard Shortcuts editor.
- **Commands and explicit skills** - type `/` at the start of the composer to search Aiden app commands, or `$` to search the active workspace's available skills. Commands reuse canonical app workflows; an explicitly selected skill is revalidated for the active workspace, applies to one accepted message, and persists only safe display provenance.
- **Native Subagents** - a foreground chat can delegate up to four fresh `scout`, `planner`, or `reviewer` tasks. Children are read/search-only, inherit the approved workspace and model, stop with the parent, and appear as live chips plus an inspectable **Subagents** view in Environment.
Expand All @@ -38,6 +39,7 @@ I don't come from a coding background. I'd been bouncing between the coding agen
The roadmap is maintained in [the plan index](docs/plans/README.md). These bullets name only the unfinished parts of partially shipped work or features with no runtime implementation yet; they are directions, not release promises:

- **Designer Mode** - no Designer Mode runtime exists yet. The proposed flow selects UI in a local Vite app, requests a bounded change, requires approval, and reviews the exact action diff; Phase 0 remains a go/no-go validation gate. See the [Designer Mode plan](docs/plans/designer-mode-plan.md).
- **Durable Design Projects and handoff** - named local projects persist the full canvas and expose Preview, Code, History, deterministic standalone/ZIP export, managed-worktree-first **Continue in workspace**, local design-system context, comments, bounded direct manipulation, and reviewed source changes. See the [completed Design Workspace follow-on plan](docs/plans/completed/design-workspace-claude-alignment-plan.md).
- **Static-catalog overlays and provider completion** - Pi built-in discovery, encrypted credentials, provider-owned authentication, native streaming, stored dynamic catalogs, manual refresh, and voice credential lookup already ship. Remaining work includes remote overlays for otherwise-static hosted catalogs, Pi-native custom-endpoint composition, historical message provenance, scalable large-catalog recovery UX, and rollout cleanup. See the [Dynamic Model Catalog](docs/plans/dynamic-model-catalog-plan.md) and [Pi Provider Integration](docs/plans/pi-provider-integration-plan.md) plans.
- **Truthful generation progress notes** - no progress-note runtime exists yet. The plan would show one temporary acknowledgement after an otherwise-silent start, using an explicitly selected on-device or verified hosted route without exposing hidden reasoning. See the [Generation Progress Notes plan](docs/plans/generation-progress-notes-plan.md).
- **Long-session context and run control** - model-aware deterministic compaction already ships. Remaining work includes visible compaction activity, reconstructable structured checkpoints, durable-versus-working memory separation, queued follow-up messages, and safe mid-run redirects. See the [Compaction](docs/plans/compaction-plan.md) and [Taracodlab Learnings](docs/plans/taracodlab-learnings-plan.md) plans.
Expand Down
16 changes: 16 additions & 0 deletions THIRD_PARTY_NOTICES.md
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,22 @@ Copyright (c) 2013-2026 Khan Academy and other contributors

MIT License. See https://github.com/KaTeX/KaTeX/blob/main/LICENSE.txt

## React Flow

`@xyflow/react` powers the spatial Design Workspace canvas.

Copyright (c) 2019-2025 webkid GmbH

MIT License. See https://github.com/xyflow/xyflow/blob/main/LICENSE

## React Grab

A minimized bundle of `react-grab/primitives` is vendored into `resources/generative-ui` for Design-only element hit testing inside sandboxed preview guests. Aiden does not initialize React Grab's full overlay or telemetry path.

Copyright (c) 2025 Aiden Bai

MIT License. See https://github.com/aidenybai/react-grab/blob/main/LICENSE

## rpiv extensions

Aiden's native extensions adapt interaction and state-management ideas from
Expand Down
86 changes: 86 additions & 0 deletions docs/architecture/design-comments-direct-edits.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,86 @@
# Design comments and bounded direct edits

Status: Implemented. Comments, direct-edit IPC, pointer/keyboard controls, durable connected review,
prototype revision creation, and exact immutable undo are wired.

## Authority boundary

Comments and direct-manipulation gestures are context. They never grant repository, command,
network, Git, preview-session, or artifact-write authority.

A comment target is durable only when all of these identities are present:

- Design Project ID;
- artboard lineage ID;
- immutable revision media ID;
- an exact, single-match selector identity; and
- either the generated artifact content hash or a relative, source-version/range/preimage-hash
connected-source identity.

An ephemeral React Grab selection or preview capability is insufficient and is never persisted.
When the current immutable revision or full source binding changes, the store marks the older
comment stale. Stale comments remain visible and can be resolved or reopened, but are never
silently retargeted.

The comment store is main-owned, atomic, schema- and byte-bounded, and written with mode `0600`.
All writes use both database revision CAS and, for existing comments, comment revision CAS.
Corrupt or unsupported on-disk data makes the store unavailable rather than allowing a later
write to replace it.

## Literal edit matrix

The direct-edit core accepts only:

- margin, padding, and gap spacing literals;
- width and height literals;
- enumerated alignment values;
- semantic CSS custom-property token names for color roles;
- border-radius literals; and
- bounded static plain text.

CSS expressions, URLs, raw colors, arbitrary properties, negative values, markup-like text,
localized or dynamic text, rich text, computed classes, ambiguous selector/component matches,
and repeated literal-definition matches fail closed. Proof facts must report exactly one selector,
component, and literal definition match.

Within one accepted gesture envelope, the proposal and undo identities are deterministic. That
gives the integration coordinator one idempotency key and one future undo record. A renderer IPC
retry is a new attended gesture with a newly minted gesture ID; it is not deduplicated against a
previous ambiguous request.

## Origin-specific output

Prototype edits produce a `prototype-revision-request` pinned to the base media ID and artifact
hash. The request instructs an artifact adapter to create a new immutable revision; the core never
overwrites artifact bytes.

The main adapter re-reads the committed source, verifies its SHA-256 identity, proves one exact
`data-aiden-id` target and one literal inline definition, and derives a deterministic new media ID
from the proposal. It stages the new bytes, CAS-appends the lineage in the Design Project, appends
the chat artifact idempotently, and only then commits the staged bytes. A pre-CAS failure discards
only the exact pending row. A post-CAS interruption deliberately leaves the pending row for the
existing startup recovery path, so retries and restarts converge on one immutable revision.

Connected-app edits produce a `designer-action-request` carrying the relative path, full source
version, exact range, preimage, and independently verified preimage hash. The core never writes
source. An integration adapter must turn that semantic literal edit into one exact replacement,
then submit it through the existing Designer Action review/apply/undo transaction. Full permission
must not bypass that review.

The connected adapter resolves the live source-selection capability again, compares every path,
version, range, preimage, hash, and selector fact with the proposal, and parses the canonical TSX.
Only a single literal inline JSX style property or a single plain JSX text node is rewritten. The
caller must also provide a trusted source-graph proof that the enclosing component has one use;
missing or ambiguous graph evidence fails closed. The result is submitted to
`SourceDesignerActionService.propose`, so apply and undo retain the same review transaction as
every other Designer Action.

## Intentional limitations

The
prototype adapter intentionally supports only literal inline HTML style declarations and plain
text nodes. The connected adapter intentionally supports only literal inline JSX style objects and
plain JSX text nodes. Stylesheets, classes, spreads, expressions, component indirection, localized
text, rich children, ambiguous selectors, and repeated definitions fail closed instead of being
guessed. Color changes additionally require the main caller to resolve the token from the current
trusted design-system snapshot; renderer-reported token names are never sufficient authority.
Loading
Loading