You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Delete every live TWOCODE_RUNTIME / --twocode-runtime trace for parent plan #463. The Local runtime and the env/CLI switch are already gone (#436 Task 9 / #452). Task 1 (#464 on task-1-rename-pty-layer) renamed the session layer off pty. What survives is the deleted flag’s name in comments, tests, and docs: source-string absence asserts in runtime.rs (assert!(!….contains("TWOCODE_RUNTIME")) / --twocode-runtime), AGENTS.md anti-pattern lines, and current-state sentences in docs/architecture.md, docs/configuration.md, and docs/herdr-integration.md. This task is vocabulary cleanup. Same IPC semantics, same clicks and labels. No Local anything. Do not start Task 3 (repo-wide audit lock).
Herdr is the profile authority. sqlite profiles is not source of truth (the table is DROPped). projects / project_groups / checkout_notes stay in 2code sqlite. Default-runtime switch and deleting Local/PTY/profiles rows already shipped in #436 — do not re-litigate or re-add them. Never let Local and Herdr own the same worktree (Local is gone; do not bring it back). Do not change interaction. There is no Settings runtime toggle to remove; naming the deleted flag is not a click/label redesign.
This is #463 Task 2, not #394 Task 2 (#402), not #436 Task 2 (#439), and not #458 Task 2 (#460). Do not implement or close those tickets here.
Dependencies: Parent plan #463. Prerequisite: #464 (Task 1). Stack on task-1-rename-pty-layer. Open task tickets from #394 / #436 / #458, leftover gaps (#396, #397, #398, #399, #401), and line-count trackers are out of scope.
Work to complete
Replace flag-literal absence asserts with a durable invariant
In src-tauri/crates/service/src/runtime.rs, herdr_gui_startup_wires_sidecar_without_local_fallback and production_source_has_no_local_pty_runtime still assert!(!….contains("TWOCODE_RUNTIME")) and contains("--twocode-runtime") (including --twocode-runtime=local) against production runtime.rs, bridge.rs, and lib.rs. Those tests only pin that a deleted name is absent. Rewrite them so they do not nameTWOCODE_RUNTIME or --twocode-runtime.
Keep a test-enforced invariant: no environment variable or CLI flag selects a runtime backend, and the GUI backend is always Herdr. Prefer behavior and structure over a forbidden-string grep:
Pin production select_gui_backend (the function body before #[cfg(test)]) as a Herdr constant: it must not call std::env::var, std::env::var_os, or std::env::args. connect_gui_herdr / build_gui_runtime / RuntimeSelector must not parse env or argv for a backend. Do not ban Herdr process env (extra_env, XDG_CONFIG_HOME) — that is sidecar isolation, not backend selection.
Keep existing fail-closed proofs (missing/incompatible sidecar does not spawn Local). Keep LocalAdapter / RuntimeBackend::Local / mod local absence asserts that already name deleted types, not the deleted flag.
RuntimeBackend stays Herdr-only. Do not add a Settings runtime toggle or a new env/CLI switch under a different name.
Remove the flag name from live docs and comments
Rewrite current-state text that still says TWOCODE_RUNTIME / --twocode-runtime / TWOCODE_RUNTIME=local:
docs/architecture.md: service-layer sentence (“no TWOCODE_RUNTIME”) and the Design Decisions row (“Local PTY / TWOCODE_RUNTIME deleted”). State that no env or CLI flag selects a runtime backend and that RuntimeRouter is Herdr-only (fail closed if the sidecar is absent).
docs/configuration.md Environment Variables: drop TWOCODE_RUNTIME from the Local-era env list. Keep “Herdr panes own their own session environment” / dedicated 2code namespace. Do not document a runtime-backend env var, even as “removed”.
docs/herdr-integration.md: the “Removing TWOCODE_RUNTIME=local is not a click/label redesign” sentence, and Task 9 row text that names TWOCODE_RUNTIME / --twocode-runtime=local. Historical DROPped / Local-deleted contrast may stay; it must not keep the deleted flag’s literal name. Do not bump v0.9.0. Do not inflate live-probe claims.
Anti-pattern lines in AGENTS.md, src-tauri/AGENTS.md, and src-tauri/CLAUDE.md: “Reintroducing Local PTY, TWOCODE_RUNTIME, or sqlite profiles as authority” → Local PTY / an env-or-CLI runtime-backend switch / sqlite profiles as authority. Keep AGENTS.md and CLAUDE.md copies in each directory in sync. Root CLAUDE.md currently has no such line — do not add the deleted flag name there.
Production comments already say “There is no Local env or flag” (select_gui_backend, file-level runtime.rs docs). Do not reintroduce the flag name in comments.
Do not edit openspec/changes/archive/ or src-tauri/migrations/.
Prove without swallowing Task 3
After this branch, TWOCODE_RUNTIME and --twocode-runtime appear nowhere in the live tree (including tests). A repo-wide grep that still finds them in this task’s tests has failed the rewrite.
App still builds. Existing suites pass with unchanged behavior: GUI backend is always Herdr; Herdr-down still fail-closes; New Tab / write / resize / scroll / close / attach still hit RuntimeRouter; projects still round-trip in sqlite.
Do not add the repo-wide audit that fails on any live pty vocabulary, Local adapter, portable-pty spawn, sqlite session/profile authority, orTWOCODE_RUNTIME (Task 3). Do not state that audit in docs/architecture.md / AGENTS.md as a grep lock. Leftover DROP-table / pty_sessions applied-name tests and historical migration filenames stay until Task 3.
If line count grows past the estimate, open a tracking issue; do not fold Task 3 into this branch.
Likely files and directories
Update tests:src-tauri/crates/service/src/runtime.rs — rewrite TWOCODE_RUNTIME / --twocode-runtime absence asserts in herdr_gui_startup_wires_sidecar_without_local_fallback and production_source_has_no_local_pty_runtime; keep/strengthen select_gui_backend_is_always_herdr and router_production_constructor_selects_herdr.
Touch only if a source-string fixture starts asserting the old flag name:src-tauri/crates/service/tests/docs_client_mode.rs — it does not currently pin TWOCODE_RUNTIME; do not add an absence-assert that names the deleted flag.
Do not change:src-tauri/migrations/, sidecar pin v0.9.0, IPC command names, Settings runtime toggle (gone), Git/file-tree/notes/tab UI, lib.rs naming HerdrRuntimeSync, flattened-split mapping, Diesel schema, a new repo-wide pty / TWOCODE_RUNTIME grep audit, openspec/changes/archive/.
Estimated changes: 40–120 lines total, additions plus deletions, including tests and docs; excluding generated files, lockfile churn and binary artifacts. Material scope growth (Task 3 audit lock, rewriting DROP-table migration tests, renaming leftover pty vocabulary) should become a separate issue.
Acceptance criteria
TWOCODE_RUNTIME and --twocode-runtime appear nowhere in the live tree (code, comments, tests, docs, AGENTS.md / CLAUDE.md copies). Historical Diesel migration filenames and SQL table name pty_sessions are unchanged and are not this task’s leftover-flag work.
Tests that previously only asserted the deleted flag’s literal string is absent now enforce a durable invariant without naming that flag: no environment variable or CLI flag selects a runtime backend; select_gui_backend() / GUI RuntimeRouter construction is always Herdr; Herdr-down still fail-closes (no Local spawn).
Live docs describe Herdr-only RuntimeRouter without advertising a removed env/CLI switch by name. AGENTS.md / CLAUDE.md copies stay in sync where they already share text. docs/herdr-integration.md Task 9 historical row may still say Local was deleted; it must not keep TWOCODE_RUNTIME / --twocode-runtime=local.
No behavior change. No Local adapter / portable-pty spawn / new env-flag backend. sqlite profiles is not source of truth. projects still round-trip in sqlite. No second events.subscribe. lib.rs still does not name HerdrRuntimeSync. v0.9.0 pin unchanged. GUI exit still does not server stop.
Named UX exceptions: none new. Existing Herdr-backed exceptions stay (route ids workspace_id; tab ids pane_id; splits flattened as extra tabs; non-git New Profile is folder workspace.create; Herdr-down New Tab errors). Removing leftover flag vocabulary is not a click/label redesign.
Migrations under src-tauri/migrations/ are untouched. No new repo-wide pty / TWOCODE_RUNTIME audit test (Task 3). Live pty leftover in DROP-table tests / migration history is out of scope.
Tests: cargo test --workspace from src-tauri (or cargo test --workspace --exclude code where GTK is unavailable). Frontend lint/typecheck/tests only if frontend scope is introduced (none expected). bun run typegen only if IPC signatures change (none expected); do not hand-edit src/generated/.
No push. No pull request.
Out of scope
Parent-plan Task 1 (session-layer rename; already done on this stack) and Task 3 (prove-and-lock audit that fails if Local / portable-pty / env-flag backend / sqlite session-profile authority / live pty vocabulary reappear).
Renaming or editing files under src-tauri/migrations/. Rewriting migration-history tests whose SQL must use the applied table name pty_sessions.
Reintroducing a Local adapter, Settings runtime toggle, portable-pty spawn, or sqlite profiles / pty_sessions authority.
Changing the Herdr-only runtime decision, the v0.9.0 pin, GUI exit / server stop, flattened-split mapping, IPC command names, or Git/file-tree/notes/tab UI.
No behavior change. This is a documentation/test cleanup. Same IPC semantics, same clicks and labels.
No Local anything. Do not reintroduce an adapter, env flag, CLI flag, dependency, or fallback path, not even behind a cfg or a comment — including a differently named successor to TWOCODE_RUNTIME.
Migrations are history. Do not rename or edit files under src-tauri/migrations/.
Frontend callers move with the commands. This task must not rename IPC; if an accidental rename happens, update generated bindings and every caller in the same commit.
Do not treat sqlite profiles as source of truth. projects stay in 2code sqlite.
Never let Local and Herdr own the same worktree (Local is already removed; do not bring it back).
Do not change interaction unless the old UX cannot be backed by Herdr. This task has no named interaction exception.
One task; stack on task-1-rename-pty-layer. Do not push. Do not open a PR.
Why this is next
#463 has three tasks. Task 1 (#464) is done on task-1-rename-pty-layer. Task 2 is the remaining flag-name purge; Task 3’s repo-wide lock depends on tests/docs no longer containing TWOCODE_RUNTIME. The leftover open gaps (#396/#397/#398/#399/#401) are Linux-unverifiable or upstream-capability leftovers, not in-flight replacements for this work. #460 is #458 Task 2 (stale-docs sweep), not this plan.
Summary
Delete every live
TWOCODE_RUNTIME/--twocode-runtimetrace for parent plan #463. The Local runtime and the env/CLI switch are already gone (#436 Task 9 / #452). Task 1 (#464 ontask-1-rename-pty-layer) renamed the session layer offpty. What survives is the deleted flag’s name in comments, tests, and docs: source-string absence asserts inruntime.rs(assert!(!….contains("TWOCODE_RUNTIME"))/--twocode-runtime), AGENTS.md anti-pattern lines, and current-state sentences indocs/architecture.md,docs/configuration.md, anddocs/herdr-integration.md. This task is vocabulary cleanup. Same IPC semantics, same clicks and labels. No Local anything. Do not start Task 3 (repo-wide audit lock).Herdr is the profile authority. sqlite
profilesis not source of truth (the table is DROPped).projects/project_groups/checkout_notesstay in 2code sqlite. Default-runtime switch and deleting Local/PTY/profilesrows already shipped in #436 — do not re-litigate or re-add them. Never let Local and Herdr own the same worktree (Local is gone; do not bring it back). Do not change interaction. There is no Settings runtime toggle to remove; naming the deleted flag is not a click/label redesign.This is #463 Task 2, not #394 Task 2 (#402), not #436 Task 2 (#439), and not #458 Task 2 (#460). Do not implement or close those tickets here.
Dependencies: Parent plan #463. Prerequisite: #464 (Task 1). Stack on
task-1-rename-pty-layer. Open task tickets from #394 / #436 / #458, leftover gaps (#396, #397, #398, #399, #401), and line-count trackers are out of scope.Work to complete
Replace flag-literal absence asserts with a durable invariant
src-tauri/crates/service/src/runtime.rs,herdr_gui_startup_wires_sidecar_without_local_fallbackandproduction_source_has_no_local_pty_runtimestillassert!(!….contains("TWOCODE_RUNTIME"))andcontains("--twocode-runtime")(including--twocode-runtime=local) against productionruntime.rs,bridge.rs, andlib.rs. Those tests only pin that a deleted name is absent. Rewrite them so they do not nameTWOCODE_RUNTIMEor--twocode-runtime.select_gui_backend_is_always_herdrandrouter_production_constructor_selects_herdr:select_gui_backend()/RuntimeSelector::default()/RuntimeRouter::neware Herdr-only.select_gui_backend(the function body before#[cfg(test)]) as a Herdr constant: it must not callstd::env::var,std::env::var_os, orstd::env::args.connect_gui_herdr/build_gui_runtime/RuntimeSelectormust not parse env or argv for a backend. Do not ban Herdr process env (extra_env,XDG_CONFIG_HOME) — that is sidecar isolation, not backend selection.LocalAdapter/RuntimeBackend::Local/mod localabsence asserts that already name deleted types, not the deleted flag.RuntimeBackendstays Herdr-only. Do not add a Settings runtime toggle or a new env/CLI switch under a different name.Remove the flag name from live docs and comments
TWOCODE_RUNTIME/--twocode-runtime/TWOCODE_RUNTIME=local:docs/architecture.md: service-layer sentence (“noTWOCODE_RUNTIME”) and the Design Decisions row (“Local PTY /TWOCODE_RUNTIMEdeleted”). State that no env or CLI flag selects a runtime backend and thatRuntimeRouteris Herdr-only (fail closed if the sidecar is absent).docs/configuration.mdEnvironment Variables: dropTWOCODE_RUNTIMEfrom the Local-era env list. Keep “Herdr panes own their own session environment” / dedicated2codenamespace. Do not document a runtime-backend env var, even as “removed”.docs/herdr-integration.md: the “RemovingTWOCODE_RUNTIME=localis not a click/label redesign” sentence, and Task 9 row text that namesTWOCODE_RUNTIME/--twocode-runtime=local. Historical DROPped / Local-deleted contrast may stay; it must not keep the deleted flag’s literal name. Do not bump v0.9.0. Do not inflate live-probe claims.AGENTS.md,src-tauri/AGENTS.md, andsrc-tauri/CLAUDE.md: “Reintroducing Local PTY,TWOCODE_RUNTIME, or sqliteprofilesas authority” → Local PTY / an env-or-CLI runtime-backend switch / sqliteprofilesas authority. Keep AGENTS.md and CLAUDE.md copies in each directory in sync. RootCLAUDE.mdcurrently has no such line — do not add the deleted flag name there.select_gui_backend, file-levelruntime.rsdocs). Do not reintroduce the flag name in comments.openspec/changes/archive/orsrc-tauri/migrations/.Prove without swallowing Task 3
TWOCODE_RUNTIMEand--twocode-runtimeappear nowhere in the live tree (including tests). A repo-widegrepthat still finds them in this task’s tests has failed the rewrite.RuntimeRouter;projectsstill round-trip in sqlite.ptyvocabulary, Local adapter,portable-ptyspawn, sqlite session/profile authority, orTWOCODE_RUNTIME(Task 3). Do not state that audit indocs/architecture.md/AGENTS.mdas a grep lock. Leftover DROP-table /pty_sessionsapplied-name tests and historical migration filenames stay until Task 3.Likely files and directories
src-tauri/crates/service/src/runtime.rs— rewriteTWOCODE_RUNTIME/--twocode-runtimeabsence asserts inherdr_gui_startup_wires_sidecar_without_local_fallbackandproduction_source_has_no_local_pty_runtime; keep/strengthenselect_gui_backend_is_always_herdrandrouter_production_constructor_selects_herdr.docs/architecture.md,docs/configuration.md,docs/herdr-integration.md(flag-name sentences / Task 9 row only).AGENTS.md,src-tauri/AGENTS.md,src-tauri/CLAUDE.md.src-tauri/crates/service/tests/docs_client_mode.rs— it does not currently pinTWOCODE_RUNTIME; do not add an absence-assert that names the deleted flag.src-tauri/migrations/, sidecar pin v0.9.0, IPC command names, Settings runtime toggle (gone), Git/file-tree/notes/tab UI,lib.rsnamingHerdrRuntimeSync, flattened-split mapping, Diesel schema, a new repo-widepty/TWOCODE_RUNTIMEgrep audit,openspec/changes/archive/.Estimated changes: 40–120 lines total, additions plus deletions, including tests and docs; excluding generated files, lockfile churn and binary artifacts. Material scope growth (Task 3 audit lock, rewriting DROP-table migration tests, renaming leftover
ptyvocabulary) should become a separate issue.Acceptance criteria
TWOCODE_RUNTIMEand--twocode-runtimeappear nowhere in the live tree (code, comments, tests, docs, AGENTS.md / CLAUDE.md copies). Historical Diesel migration filenames and SQL table namepty_sessionsare unchanged and are not this task’s leftover-flag work.select_gui_backend()/ GUIRuntimeRouterconstruction is always Herdr; Herdr-down still fail-closes (no Local spawn).RuntimeRouterwithout advertising a removed env/CLI switch by name. AGENTS.md / CLAUDE.md copies stay in sync where they already share text.docs/herdr-integration.mdTask 9 historical row may still say Local was deleted; it must not keepTWOCODE_RUNTIME/--twocode-runtime=local.profilesis not source of truth.projectsstill round-trip in sqlite. No secondevents.subscribe.lib.rsstill does not nameHerdrRuntimeSync. v0.9.0 pin unchanged. GUI exit still does notserver stop.workspace_id; tab idspane_id; splits flattened as extra tabs; non-git New Profile is folderworkspace.create; Herdr-down New Tab errors). Removing leftover flag vocabulary is not a click/label redesign.src-tauri/migrations/are untouched. No new repo-widepty/TWOCODE_RUNTIMEaudit test (Task 3). Liveptyleftover in DROP-table tests / migration history is out of scope.cargo test --workspacefromsrc-tauri(orcargo test --workspace --exclude codewhere GTK is unavailable). Frontend lint/typecheck/tests only if frontend scope is introduced (none expected).bun run typegenonly if IPC signatures change (none expected); do not hand-editsrc/generated/.Out of scope
portable-pty/ env-flag backend / sqlite session-profile authority / liveptyvocabulary reappear).src-tauri/migrations/. Rewriting migration-history tests whose SQL must use the applied table namepty_sessions.profiles/pty_sessionsauthority.server stop, flattened-split mapping, IPC command names, or Git/file-tree/notes/tab UI.Standing constraints
TWOCODE_RUNTIME.src-tauri/migrations/.profilesas source of truth.projectsstay in 2code sqlite.profilesrows already shipped in Plan: 2code as a Herdr client (profiles derived from Herdr) #436; this task does not re-litigate those decisions and does not change them.task-1-rename-pty-layer. Do not push. Do not open a PR.Why this is next
#463 has three tasks. Task 1 (#464) is done on
task-1-rename-pty-layer. Task 2 is the remaining flag-name purge; Task 3’s repo-wide lock depends on tests/docs no longer containingTWOCODE_RUNTIME. The leftover open gaps (#396/#397/#398/#399/#401) are Linux-unverifiable or upstream-capability leftovers, not in-flight replacements for this work. #460 is #458 Task 2 (stale-docs sweep), not this plan.