Skip to content

Promote v1.4.0 to production - #2352

Merged
mrubens merged 92 commits into
mainfrom
release/v1.4.0
Sep 8, 2026
Merged

Promote v1.4.0 to production#2352
mrubens merged 92 commits into
mainfrom
release/v1.4.0

Conversation

@mrubens

@mrubens mrubens commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Promote v1.4.0

Frozen at 16cc5395fe80bfa450b02fab27f44f5cfe79c09d — the commit where 1.4.0 was versioned. Commits merged to develop afterward require an explicit candidate refresh or ship in the next release.

  • Merge this PR with a merge commit (do not squash or rebase).
  • If multiple promote PRs are open, merge them in version order (oldest first).
  • Monitor CI and reviews on this PR's current head, not only the release-preparation PR. Unresolved findings and missing required approvals remain blockers even with green CI.
  • After a refresh or CI reconciliation, re-check the new head; monitoring never authorizes merging or publication.
  • Merging publishes a GitHub Release for v1.4.0 and triggers the existing GHCR v* image publish (latest channel).
  • The release/v1.4.0 branch can be deleted after this PR merges.

Changelog

1.4.0 (2026-09-08)

Roomote 1.4 brings reminders, clearer shared Sessions, and richer video evidence together with easier automation setup and more reliable everyday work.

Highlights

  • Schedule reminders and bounded monitoring in a Session, see upcoming wakeups above the composer, and cancel them when they are no longer needed.
  • Follow shared work through current-viewer avatars, recognizable task identities, and inspectable task reports.
  • Share task recordings as native Slack videos and opt into higher-frame-rate capture for motion-heavy demos.
  • Keep automation work in continuous Sessions, set up a Slack manager channel more easily, and choose GPT-6 Astra through additional providers.

Minor changes

  • Enable GPT-6 Astra through Vercel AI Gateway, GitHub Copilot, or OpenCode Zen alongside existing providers, subject to the connected account's model access. Existing model defaults remain unchanged.
  • Expand Session tool exchanges to inspect image questions and results, instructions sent to delegated tasks, and incoming task reports. Consistent robot identities and task links make handoffs easier to follow, and expanded task inspections include the latest submitted report with secret redaction rather than unrelated assistant messages.
  • OpenCode subagents can make one further nested delegation or consultation, allowing depth-two assistance while preserving each role's existing tool permissions.
  • Custom automations now run through Sessions, report delegated results together with actionable suggestions, and keep accepted suggestions in their originating Session and, on Slack, its report thread, including suggestions published directly by Fast reports. Configured environments are delegation preferences rather than guaranteed sandbox launches. Configure a report destination for chat delivery; otherwise results remain in the web Session without an owner-DM fallback. Runs use the creator's credentials, automations without a creator need an admin to re-save them, and Run now reports queued rather than a launched task ID.
  • Ask a Fast Session for a reminder or recurring check, including whole-second delays, and receive results in the same conversation. Fast can offer a specific, bounded follow-up when it can verify an outstanding outcome, scheduling it after you accept; explicit monitoring requests need no additional opt-in. Ongoing-process monitoring stays quiet without news and stops at the agreed bound or earlier when resolved or no longer actionable. Upcoming wakeups show countdowns above the Session composer and can be cancelled by the Session owner or an admin. Wakeups require no administrator to schedule, are limited to ten per Session, and are cancelled when the Session is archived; delivery is best effort rather than an exact-time guarantee.
  • See other people viewing a Session through header avatars and name tooltips; your own avatar is omitted, and the indicator disappears when you are the only viewer.
  • Connecting a Slack account can set up a public #roomote-managers channel when no Manager Channel is configured, without enabling automations or replacing explicit report destinations. Existing Slack apps need updated permissions, reinstallation, and an account reconnect to use automatic channel setup.
  • Fast replies can deliver task recordings as native Slack videos, with authorized viewer links when delivery is unavailable. Motion-heavy demos can opt into native recording up to 60 FPS while ordinary recordings remain at 30 FPS. Existing Slack installations need the new files:write permission, and higher-FPS capture requires the updated recording runtime.

Patch changes

  • Automation avatars no longer show glaring white backgrounds in dark mode, while retaining their light-mode appearance.
  • Azure sandboxes enable idle suspension by default and refresh the policy when reused, resumed, or restored. The policy follows the configured timeout, normally five hours; an explicit zero retains the opt-out.
  • Web transcripts hide newly marked runtime navigation messages already represented by task cards while preserving ordinary conversation links.
  • Previously uploaded artifacts remain available when a replacement upload is interrupted; unversioned task and Session lookups return the latest completed upload while explicit-version reads retain their existing behavior.
  • Completed visual proof is no longer reported as timed out while subsequent review or pull request delivery continues.
  • USD costs use consistent thousands separators, and Task Info refreshes inference costs when opened and while visible instead of leaving stale totals on screen.
  • Device-code connections can recover after a failed authorization dialog is closed and reopened, including GitHub Copilot, ChatGPT, and xAI connections.
  • Discord automation threads accept directed follow-ups without another mention, thread replies avoid invalid inline reply references, and coding-task links clearly identify newly started work.
  • Honor custom automation model and reasoning overrides for the Fast session across initial and resumed turns, without applying them to delegated coding tasks.
  • Fast retains follow-up messages sent during response closeout for the next turn, while reactions and platform events no longer discard parked questions or turn their retry notices into false interruptions.
  • Merge announcements recover uniquely matched signed pull request screenshot URLs after redaction so images remain available without relaxing safe-fetch restrictions.
  • Session board cards and long labels stay within mobile layouts, composer suggestion hints no longer overlap typed text, and mobile suggestion buttons use a shorter Accept label while desktop retains the keyboard hint. Automations uses more of the available screen width.
  • Pull request feedback triage uses its configured queue retries after preparation failures instead of unnecessarily waiting for scheduled recovery.
  • Provider qualification verifies a real structured tool call, rejecting misleading response text while accepting fragmented streamed function names and compatible local servers that require required-tool selection instead of named-function selection. Thanks to @DarthAffe for reporting #1862.
  • Review handoffs resolve the acting user or human owner when messaging linked tasks instead of failing solely because the token lacks user context.
  • Sentry triage uses the requested accessible organization, projects, and time scope rather than assuming internal project names or implicit defaults, and asks for clarification when the scope is ambiguous.
  • New Sessions start correctly after resetting the model picker to Default.
  • Keep Slack's working indicator aligned with the active Session turn, including durable retry waits and pauses between streamed replies while tools run. Late titles and stale turn cleanup no longer clear a newer turn's indicator, and settlement waits for pending stream operations. Background delegated tasks retain their separate activity indicators.
  • Streamed output preserves UTF-8 characters split across chunks instead of replacing multibyte characters with corrupted text.
  • Native tool activity shows clear read, edit, and skill-loading labels instead of treating result text as a tool name. Edit receipts identify a filename or file count, with consistent wording across running, completed, failed, and expanded activity. Grouped edit headers continue counting edit calls rather than distinct files.
  • Correct Telegram custom automation setup guidance to explain that chat replies continue the automation Session, matching existing behavior.
  • Discord and Telegram show native typing activity while Roomote thinks and uses tools during an active Session turn, including after intermediate replies.
  • Slack provider-error notices show a compact warning and safe error message instead of repeating recovery instructions and the task link.
  • Desktop Session and Task panels open and close smoothly while preserving surviving panel state and focus, and status text uses a consistent, slower shimmer. Manual resizing stays immediate, and reduced-motion preferences are respected.
  • Roomote can choose screenshots, video, both, or no visual evidence according to what best demonstrates the work, without requiring an explicit video request.
  • Environment-backed tasks can push and create or update pull requests in other deployment-active GitHub repositories on the same GitHub App installation, without requiring those repositories in the prepared workspace.
  • MCP OAuth client registrations remain reusable through token expiry and reauthorization, with a 90-day inactivity window renewed by successful authorization exchanges and refreshes. Token lifetimes remain unchanged.
  • Fix Monday account linking and token refresh failing with an invalid OAuth resource request.
  • Reduce unexpected web logouts with 30-day sessions and reliable rolling renewal that updates both the browser cookie and database expiry.
  • Settings stop repeatedly retrying failed model saves, restore saved values when available, and show a clear error. Saved Slack automation destinations remain visibly selected, and the Pull request delivery selector has an accessible name.
  • Include all server-local-day pull requests in PR analytics on non-UTC deployments, matching task and cost reporting.
  • Clarify that Roomote should not assign people work or commit them to plans without authorization, while remaining proactive about its own authorized work.
  • Include the running build's commit SHA and deployment label alongside the release version in assistant prompts, explicitly reporting unavailable commit metadata as unknown.
  • Brain-enabled host backups fail clearly when the index database cannot be checked, rather than reporting success with a potentially incomplete backup.
  • Stable sandbox workers can be selected through the release-list fallback when GitHub blocks tag lookup.
  • Make Doctor warn about whitespace-only Slack and Microsoft authentication configuration instead of reporting it as configured.
  • Update qs to 6.16.0 to address denial-of-service and array-limit-bypass vulnerabilities in query and form parsing dependencies.

mrubens and others added 30 commits September 4, 2026 23:36
Co-authored-by: Matt Rubens <2600+mrubens@users.noreply.github.com>
… Zen (#2245)

Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: @daniel-lxs <57051444+daniel-lxs@users.noreply.github.com>
Co-authored-by: @daniel-lxs <57051444+daniel-lxs@users.noreply.github.com>
Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: @daniel-lxs <57051444+daniel-lxs@users.noreply.github.com>
…2260)

Co-authored-by: @daniel-lxs <57051444+daniel-lxs@users.noreply.github.com>
* feat: session wakeups let a Fast Session schedule a message to itself

Add the manage_wakeups Fast native tool (create, list, get, cancel) backed by
a session_wakeups table. A wakeup is a durable row plus one delayed BullMQ job;
when it fires, a scheduled_wakeup platform event is admitted into the
conversation's existing parent-event inbox and runs as a normal turn with the
full history in context. Occurrences are claimed with a compare-and-set on
next_run_at, so duplicate jobs cannot double-fire, and a 60s recovery sweep
re-adds hints for due rows. One-shot wakeups always reply; recurring ones
stay quiet unless notable and retire after five consecutive failed turns.
Archiving a Session cancels its wakeups.

* fix: make session wakeup creation resilient to model placeholders and BullMQ job ids

- BullMQ rejects custom job ids containing ':'; use '-' between the wakeup
  id and occurrence time so delayed fire jobs actually enqueue.
- Strip empty strings, null, 'none'-style placeholders, and non-positive
  caps from manage_wakeups arguments before validation. Models fill every
  optional field, and each strict rejection cost a retry.
- A once schedule ignores stray maxRuns/until and prefers inMinutes when a
  computed 'at' is sent alongside it, instead of failing.

* refactor: take the wakeup schedule as one string instead of a structured union

Models fill every optional structured field with placeholders, and each
rejected placeholder cost a retry. The tool now takes a single required
schedule string ("in 20m", "at <iso>", "every 10m x3", "every 10m until
<iso>", "cron 0 9 * * 1-5 America/New_York") parsed server-side into the
same stored schedule. This removes the discriminated union and the
maxRuns/until fields from the tool surface; the create action is now name,
prompt, schedule, and an optional reportPolicy.

* fix: honour cancellation for already-admitted wakeups and cap high-frequency cron

- Delivery of a scheduled_wakeup event now re-reads the row and skips when
  the wakeup was cancelled or failed after its occurrence was admitted, so
  cancel and archive keep their guarantee even against an in-flight event.
  A row that completed at claim time (one-shot or final run) still runs.
- Cron schedules are held to the same tight-interval cap as intervals by
  sampling the gap between upcoming occurrences; "cron * * * * *" now needs
  "x<count>" or "until <iso>", which the cron grammar accepts alongside an
  optional timezone.

* fix: keep the wakeup schedule parser linear and the cron gap helper private

The parser already collapses whitespace and the contract caps the string
length, so the patterns use literal single spaces instead of \s+ runs that
CodeQL flagged as polynomial. estimateCronMinGapMinutes is only used inside
the schedule module.

* fix: never deliver a wakeup into an archived Session

Archiving cancels a Session's wakeups, but that cancellation is best-effort
after the archive itself. Delivery now also checks the Session and skips a
scheduled_wakeup whose Session is archived, so a failed cancellation cannot
make an archived Session speak.

* fix: revalidate a wakeup right before it replies

A cancel or archive that lands while the wake turn is generating must still
win. The wakeup turn's postReply is now guarded: it re-checks the wakeup row
and the Session immediately before posting, drops the reply if either was
superseded, and aborts the turn's signal so no further tool calls run. The
next drain of the event settles it as skipped.

* fix: serialize session wakeup creation and enforce the active cap

* fix: deduplicate wakeup schedules independent of JSONB key order

* fix: preserve relative reminder identity across create retries

* fix: serialize session archival with Fast reply delivery
Co-authored-by: Roomote <roomote@roomote.dev>
…urns (#2183)

* [Fix] Reactions and platform events no longer supersede parked Fast turns

Every inline admission discarded the conversation's older pending inline
rows on the assumption that a newer human message stands in for the earlier
request. #2156 routed emoji reactions and web platform events through the
same path, so a reaction while a turn was parked for a retry, or waiting to
resume after an interruption, silently dropped that turn and turned its
retry notice into an interruption message.

Only typed human messages supersede now. The next-turn and settle reconciles
also leave a retry notice alone while another durable row for the
conversation is still pending, so the resumed run edits it into the answer
instead of posting beside a false interruption.

* Keep the expired-lease sweep as the backstop for stalled hand-offs

The pending-row guard now counts only a live claim or a scheduled retry on
the expired-lease path, so a released or expired row whose queue wakeup
never runs cannot leave a stale retry notice active forever.

* Re-run review

---------

Co-authored-by: Matt Rubens <2600+mrubens@users.noreply.github.com>
…2274)

* fix: durably accept Session messages while working

* fix: deliver Slack follow-ups to bound Sessions while working

Use the canonical Fast Session binding for inbound delivery before applying thread-history heuristics. Preserve linked-user authorization and existing queue behavior. Remove the earlier web and independent SDK changes from this PR's net scope.

* fix: queue Fast follow-ups across response closeout

Stop exposing detached promptAsync steering without an owned completion contract. Preserve follow-ups for the existing durable whole-turn queue and leave child-task steering unchanged. Replace the earlier unrelated Slack routing scope with provider and closeout regression coverage.

---------

Co-authored-by: @daniel-lxs <57051444+daniel-lxs@users.noreply.github.com>
…accepted (#2277)

* fix: keep automation suggestions in their session and Slack thread

* fix: bind automation reports to their canonical session

* fix: recover report session binding on submission retries

---------

Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: @daniel-lxs <57051444+daniel-lxs@users.noreply.github.com>
* fix: restore signed PR images in merge announcements

* fix: bound merge image parsing and escape HTML fixtures

---------

Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
roomote-roomote Bot and others added 16 commits September 7, 2026 16:43
* improve: let agents choose useful visual proof

* fix: keep visual proof coverage tied to the stated claim

---------

Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
…ies (#2339)

* feat: allow authorized task writes across active repositories

* fix: limit environment repository change to GitHub write scope

---------

Co-authored-by: @daniel-lxs <57051444+daniel-lxs@users.noreply.github.com>
)

* feat: show Discord and Telegram typing during parent turns

* fix: reassert Discord typing after parent replies

---------

Co-authored-by: @daniel-lxs <57051444+daniel-lxs@users.noreply.github.com>
* feat: deliver native Slack videos from Fast replies

* fix: gate Slack video uploads on accepted replies

* fix: use link-only fallback for Slack video uploads

* test: isolate SDK suites that mutate global Slack state

---------

Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: Roomote <roomote@roomote.dev>
Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
)

Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
Co-authored-by: Roomote <roomote@roomote.dev>
Co-authored-by: @mrubens <2600+mrubens@users.noreply.github.com>
@mintlify

mintlify Bot commented Sep 8, 2026

Copy link
Copy Markdown

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
roomote 🟢 Ready View Preview Sep 8, 2026, 1:03 PM

💡 Tip: Enable Automations to automatically generate PRs for you.

@roomote-community

roomote-community Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

No code issues found. See task

  • packages/sdk/src/server/lib/session-wakeups.ts:128 - A cancelled wakeup can still execute after its event is persisted but before the row claim succeeds. — dismissed: delivery rechecks wakeup state before the turn and before posting a reply.

Reviewed 76073d8

await enqueueFastAgentParentEvent({

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A cancellation can win between this durable event admission and the compare-and-set claim below. In that interleaving, cancelSessionWakeup marks the row cancelled, claimSessionWakeupFire returns null, but the already-persisted parent event is still drained because the parent-event queue does not re-check the wakeup state. The cancelled reminder therefore still runs once, contradicting the cancellation contract. Make admission and cancellation mutually observable (or discard scheduled-wakeup events whose row is no longer active) before delivering the turn.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-evaluated this specific interleaving on repaired head 76073d83938a3727b1324b547a79bcf3839454a8 (its file tree is identical to the original candidate). Admission still precedes the compare-and-set claim, but delivery does re-read authoritative wakeup state: isScheduledWakeupDeliverable rejects cancelled/failed rows, and deliverFastAgentParentEventWithLock returns skipped before creating a turn. The reply guard also rechecks before posting (lines 2321–2338).

Existing post-admission and mid-turn cancellation tests passed during resolution preparation (3 focused tests passed; the identical tree was verified after CI reconciliation). This contradicts the finding's premise that the queued event is delivered without rechecking cancellation. A stale durable event may still be drained, but that is not the claimed extra reminder execution when cancellation has already won.

No runtime change is proposed for this stated interleaving. Leaving the thread unresolved for review confirmation rather than labeling it fixed or silently dismissing it. If a distinct race survives the delivery check, the next step is a targeted reproduction of that precise ordering, not broadening this ancestry-only release repair.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed. The prior finding was incorrect: scheduled wakeups are revalidated before the turn starts and immediately before a reply posts, so cancellation after event admission does not produce the claimed reminder execution. Retracting it.

Reviewed resolution: 3ada941
Review PR: #2355
@roomote-roomote

roomote-roomote Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

CI reconciliation applied and verified

Reconcile Release Candidate run 34248498484 successfully pushed the approved reconciliation, then failed its post-push PR metadata check with Closed or mismatched PR for release/v1.4.0. This comment records the verified result without rerunning stale inputs or implying the push rolled back. The run remains failed; the candidate update is complete.

  • Original frozen candidate: 16cc5395fe80bfa450b02fab27f44f5cfe79c09d
  • Pinned production main: 08dd507f504493981bc5718d6e9a5cb256b5300e
  • Independently approved resolution: 3ada94108bf19afc8ede49ea05cf7394c28cb4fa in [Chore] Review pinned v1.4.0 reconciliation (do not merge) #2355
  • Actual CI candidate head: 76073d83938a3727b1324b547a79bcf3839454a8
  • Verified tree: a5e7adb461fbbf991f4df2844ed519ea16b43bb8, byte-identical to both the reviewed resolution and frozen candidate

The new head has exactly the original candidate and pinned main as parents. GitHub reports it conflict-free (MERGEABLE). CI, Docs, CodeQL, and Roomote code review all passed on this exact head; optional Mintlify Deployment and codesmith checks were skipped. The original reviewer retracted the wakeup finding after verifying the existing delivery and reply guards; the canonical summary reports no code issues. The historical thread remains unresolved, rather than being mislabeled as fixed by this ancestry-only change.

GitHub still reports REVIEW_REQUIRED / BLOCKED: resolution approval is not approval to promote this PR. Neither PR was merged, main remains pinned above, no v1.4.0 tag exists, and no publication or deployment was initiated. A later tooling improvement can make post-push metadata recovery tolerate GitHub consistency delays; the exact cause of this one transient mismatch has not been established.

@mrubens
mrubens merged commit fba2324 into main Sep 8, 2026
19 checks passed
@mrubens
mrubens deleted the release/v1.4.0 branch September 8, 2026 16:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants