## Summary
Running more than one fusion process on a host (multiple dashboards/CLIs
across worktrees, all attaching `~/.fusion/fusion-central.db`) could
crash a `node` process at random — instantly, with no JS stack and
nothing in the logs. This happened 3 times in 3 days on one machine.
After this change those processes coexist without crashing.
The crash was an OS-level `SIGBUS` (`EXC_BAD_ACCESS`, `FS pagein error`
/ kernel `cluster_pagein past EOF`) inside SQLite's `walIndexReadHdr`.
In WAL mode every connection coordinates through a memory-mapped `-shm`
wal-index; on macOS/APFS, when one process resizes/rebuilds that file
during a checkpoint while another has it mmap'd, the reader faults on
the now-out-of-bounds page. A hardware memory fault can't be caught by
`node:sqlite` or JS, so the whole process dies.
The fix switches the central DB to `journal_mode = DELETE` (rollback
journal), which uses no `-shm` memory map and coordinates cross-process
access via POSIX byte-range locks instead — removing the faulting
surface entirely while keeping multi-process access. The existing
`busy_timeout` absorbs the writer serialization that DELETE mode trades
for WAL's reader/writer concurrency. Per-project DBs (`db.ts`) are
intentionally left on WAL: they're single-process-per-project and don't
hit this cross-process fault. SQLite migrates the existing WAL database
on first open (checkpoints `-wal` into the main file and removes
`-wal`/`-shm`), so there is no data loss.
## Test plan
- New regression tests in `central-db.test.ts` assert the central DB
reports `journal_mode = delete` (not `wal`) and that **no `-shm`
wal-index file is ever created** even after write traffic — i.e. the
exact faulted surface is gone.
- All 6 central-DB suites pass (221 tests); `@fusion/core` typechecks
clean.
---
[](https://github.com/EveryInc/compound-engineering-plugin)

<!-- stage-review-badge-begin -->
---
<a href="https://stagereview.app/Runfusion/Fusion/pull/1752">
<picture>
<source media="(prefers-color-scheme: dark)"
srcset="https://stagereview.app/assets/gh-open-in-stage-dark.svg">
<img src="https://stagereview.app/assets/gh-open-in-stage-light.svg"
alt="Open in Stage">
</picture>
</a>
<!-- stage-review-badge-end -->
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Improved stability when multiple dashboards or CLIs run on the same
machine.
* Switched the local database to a safer journaling mode to reduce rare
crash issues on macOS/APFS.
* Prevented creation of extra database side files during normal
operation, while keeping data durability and lock-based coordination in
place.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
- Verify the WAL->DELETE journal-mode switch instead of discarding exec()'s
result. During a rolling upgrade a lingering WAL holder blocks the exclusive
lock the switch needs, so SQLite either throws SQLITE_BUSY or no-ops and
returns "wal". Capture both outcomes and warn loudly so the residual -shm
SIGBUS surface is observable, rather than silently swallowed.
- Do not rethrow: the condition is transient and self-healing (the next start
after the last WAL holder exits migrates cleanly); hard-failing would make the
central DB unopenable during the very upgrade window it describes.
- Add a migration-path regression test (a WAL holder blocking the switch) that
the prior fresh-DB-only tests did not cover.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The central DB (~/.fusion/fusion-central.db) is opened concurrently by every
fusion process on a host. In WAL mode those connections coordinate through a
memory-mapped `-shm` wal-index; on macOS/APFS a reader takes a SIGBUS
(walIndexReadHdr / `cluster_pagein past EOF`) when another process resizes it
mid-checkpoint, killing the node process with no JS stack or log. Observed 3x
in 3 days. Switch the central DB to journal_mode=DELETE, which uses no `-shm`
mmap and coordinates cross-process access via POSIX byte-range locks instead;
busy_timeout absorbs the added writer serialization. Per-project DBs keep WAL.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
local-runtime.ts dynamically imports @fusion/engine, but it was missing from the
esbuild externals list (only @fusion/core and @fusion/dashboard were there). esbuild
followed the import and tried to bundle engine's transitive node-pty native .node
binaries, failing with "No loader is configured for .node files" — which broke every
desktop Windows EXE and macOS DMG build leg. Externalize @fusion/engine like the other
workspace packages; it resolves from node_modules at runtime.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add a GitHub issue and pull request picker that seeds new task prompts from detected remotes.
- Add remote-aware GitHub issue/PR selection to the New Task modal.
- Generate focused task descriptions for selected issues and pull requests while confirming before replacing user text.
- Style and document the compact picker and cover loading, errors, remote selection, and overwrite behavior in tests.
- Add a changeset for the published Fusion CLI package.
Files changed:
.changeset/fn-6946-github-reference-picker.md | 7 +
docs/dashboard-guide.md | 2 +
packages/dashboard/app/components/NewTaskModal.css | 53 ++++
packages/dashboard/app/components/NewTaskModal.tsx | 297 ++++++++++++++++++++-
.../app/components/__tests__/NewTaskModal.test.tsx | 199 +++++++++++++-
5 files changed, 555 insertions(+), 3 deletions(-)
Fusion-Task-Id: FN-6946
Fusion-Task-Lineage: e871827c-dfe5-4fc3-a525-c1161639d306
Mobile bottom navigation now keeps balanced horizontal spacing without disturbing existing viewport compensation.\n\n- Add tokenized inline padding to the fixed mobile nav bar while preserving ICB and safe-area behavior.\n- Cover symmetric side spacing in mobile nav CSS and component layout tests.\n- Add a patch changeset for the published CLI package.\n\nFiles changed:\n .changeset/fn-6999-mobile-nav-side-spacing.md | 7 +++++++\n packages/dashboard/app/__tests__/mobile-nav-bar-css.test.ts | 10 ++++++++++\n packages/dashboard/app/components/MobileNavBar.css | 5 +++++\n .../dashboard/app/components/__tests__/MobileNavBar.test.tsx | 8 ++++++++\n 4 files changed, 30 insertions(+)
Fusion-Task-Id: FN-6999
Fusion-Task-Lineage: 91bd2174-8e5d-4227-a035-ff621e309719
Reclaims task detail padding so inline diffs have more readable width on compact screens.
- Expand the compact Changes file list to consume detail-body padding without page overflow.
- Add mobile breakpoint coverage that matches the detail-body padding contract.
- Add regression tests for the phone-width inline diff surface and CSS rules.
- Add a patch changeset for the published Fusion CLI package.
Files changed:
.changeset/fn-6997-diff-panel-width.md | 7 ++
.../dashboard/app/components/TaskChangesTab.css | 20 ++++-
.../components/__tests__/TaskChangesTab.test.tsx | 98 +++++++++++++++++++++-
3 files changed, 121 insertions(+), 4 deletions(-)
Fusion-Task-Id: FN-6997
Fusion-Task-Lineage: a7f21c0d-89a8-430e-a84c-341a10af4a4a
Align the Quick Chat and Terminal footer launchers so they read as matching peer controls.
- Inherit the footer font and color contract for the Terminal footer launcher.
- Preserve usable hover, focus, padding, and scripts chevron behavior in the footer variant.
- Document the footer Quick Chat launcher placement and add release notes.
- Expand status bar tests to lock the shared footer launcher styling.
Files changed:
.changeset/fn-6959-footer-launcher-style.md | 7 ++
docs/dashboard-guide.md | 2 +-
.../dashboard/app/components/ExecutorStatusBar.css | 2 +-
.../dashboard/app/components/TerminalLauncher.css | 37 +++++++-
.../__tests__/ExecutorStatusBar.test.tsx | 105 +++++++++++++++++++--
5 files changed, 138 insertions(+), 15 deletions(-)
Fusion-Task-Id: FN-6959
Fusion-Task-Lineage: 539307cb-dc81-441f-8baf-8823826e2195
From the multi-agent /ce-code-review of PR #1749 (no P0/P1 correctness bugs; these
are perf, race-hardening, and convention fixes):
- P1 (perf/reliability): the workspace diff ran git subprocesses serially per
sub-repo AND per file — an N×M explosion with no aggregate cap. Add a bounded
mapWithConcurrency helper (order-preserving) and parallelize the per-file patch
loop (cap 8) and the per-sub-repo loop (cap 4). Deleted files still fetch their
patch (skipping it would drop deletes from /file-diffs and zero /diff stats).
- P2 (frontend race): GitManagerModal's workspace-detection could be clobbered by
a previous project's in-flight fetch on a rapid projectId switch / close-reopen.
Add a detectionGenerationRef guard — only the latest detection run may mutate
state; the effect cleanup bumps the generation to abandon superseded runs.
- P2 (DRY): reuse the existing parseStatusCode instead of re-inlining the
status-code mapping.
- P2 (convention): FNXC-tag the new functions/branches per CLAUDE.md.
- P3: extract DIFF_TIMEOUT_MS/FILE_DIFFS_TIMEOUT_MS constants, drop a dead
catch-assignment, note the done-fallback oldPath limitation.
Tests: order-preservation after parallelization; rapid-project-switch generation
guard (a stale workspace verdict must not suppress a new project's real error).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The Changes / Files-changed tab showed nothing for multi-repo workspace tasks:
the task-diff backend is single-repo throughout, and a workspace task has null
task.worktree/task.branch (its per-repo state lives in workspaceWorktrees), so
every path fell back to git-diff against the non-git workspace root → empty.
Backend (register-session-diff-routes): extract the single-repo per-worktree
detailed-diff into one shared helper (computeWorktreeDetailedFiles) and add a
workspace branch to BOTH /tasks/:id/diff and /tasks/:id/file-diffs that runs
before the single-repo logic: iterate sorted workspaceWorktrees, compute each
sub-repo's diff in its own live worktree against that repo's baseCommitSha (done
tasks fall back to the per-repo landed range in the sub-repo root), and aggregate
with `${repoRel}/`-prefixed paths. Single-repo behavior is byte-for-byte
preserved (renamed→modified fold retained; 58 existing diff-route tests pass).
Frontend: TaskChangesTab takes an isWorkspace prop and no longer shows the
single-repo "No worktree available" empty state for workspace tasks;
TaskDetailModal passes isWorkspace={isWorkspaceTask(workingTask)}.
Tests: backend aggregation (repo-prefixed paths + stats) and frontend rendering
of workspace changes instead of the empty state.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Opening the Git Manager on a workspace project rendered the sub-repo dropdown
correctly but ALSO toasted "Not a git repository". On open the section fetch
fires immediately with no repoPath (selectedRepo unresolved), hitting the non-git
browse-only workspace root; fetchWorkspaceRepos resolves a tick later and the
fetch re-runs against a real sub-repo. We now track workspace detection in a ref
and suppress that one benign root-race error (no repoPath + "Not a git
repository" while detection is pending or has confirmed a workspace). A genuinely
broken non-workspace project still surfaces the error: once detection settles as
non-workspace, a single guarded re-fetch re-surfaces it (no redundant fetch in
the common non-workspace path, preserving existing call-count expectations).
Tests: add the missing fetchWorkspaceRepos api mock (pre-existing gap that broke
the whole GitManagerModal suite at import), plus a positive (workspace → no
toast) and negative-control (non-workspace broken → toast) regression.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
A workspace land squash-merges each sub-repo via a clean room that first runs the
configured/inferred install (npm/pnpm/yarn). The install hard-fails by design so
merge verification never runs against an uninstalled checkout — but that let ONE
sub-repo with a manifest npm refuses to install (e.g. a corrupt `-@0.0.1`
lockfile entry rejected by npm 11) block landing every other sub-repo.
landWorkspaceTask now passes nonFatalDependencySync to landOneRepo: a clean-room
install failure is caught, logged + audited as a non-fatal degradation, and the
land proceeds (the git squash needs no installed deps; only dep-dependent
verification degrades for that repo). A real abort signal still propagates. The
single-repo land path keeps the documented hard-fail (flag defaults off).
Tests: new workspace-merger-deps-resilient asserts both the resilient workspace
land (all repos land despite install throwing) and the preserved single-repo
hard-fail. Also fix a pre-existing getTask mock gap in workspace-merger.test
(mergeAndReview reads getTask().comments) that broke 3 tests at the land step.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- dashboard: remove the "Branch needs reattachment" banner. It fired for any
in-review task with a null singular task.branch — the NORMAL state for a
workspace task (attachment is per-sub-repo worktrees in workspaceWorktrees), so
it was a permanent false positive. Genuine lost bindings are already reattached
automatically by self-healing's reconcileInReviewBranchRebind (event-driven on
move-to-in-review + sweep), so no manual user action is needed. Delete the
now-obsolete rebind-banner test + its registry entry.
- engine/self-healing: reconcileInReviewBranchRebind now explicitly skips
workspace tasks (never rebind candidates — their fusion/<id> branches live in
the sub-repos, not the non-git browse root; null root branch is healthy).
- engine/merger-ai: pre-merge prune treats an absent ai-merge search root (ENOENT)
as "nothing to prune" instead of warning on every workspace merge.
- test: add ToggleRight to the TaskDetailModal lucide mock (pre-existing gap from
FN-6880 that broke the whole suite at import).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- core/store: include workspaceWorktrees in the slim and activity-log-limited
SELECT lists (rowToTask reads it, but the explicit column lists omitted it, so
slim/limited reads dropped the field and could misclassify workspace tasks);
add regression tests for both read surfaces
- dashboard/register-git-github: validate caller-supplied repoPath in resolveGitDir
via isPathWithin containment check (path-traversal hardening for all git
endpoints); make loadWorkspaceConfig a static @fusion/core import per AGENTS.md
- dashboard/legacy: preserve repoPath in the string-form pullBranch overload
- dashboard/GitManagerModal: revalidate selectedRepo against the fetched repo list
so a stale selection can't persist across project switches
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Multiworkspace tasks could not complete due to two independent bugs:
1. task.workspaceWorktrees had no SQLite column / rowToTask mapping, so
fn_acquire_repo_worktree's updateTask write was dropped on every persist
(applyTaskPatch writes the DB-round-tripped task back to task.json). Every
later getTask returned undefined, so fn_task_done's scope verifier read {}
and blocked with "acquired no sub-repo worktrees", and isWorkspaceTask()
consumers misfired. Persist it mirroring mergeDetails (schema column + v129
migration + db-migrate + defineTaskColumn + TaskRow + rowToTask).
2. In workspace mode every task ran rooted at the shared browse-only root, and
setActiveSession registered that path keyed only by path — so a second
concurrent workspace task was rejected by the foreign-task guard
("active-session path ... is held by ..."). Give each task a task-scoped
synthetic session key (sessionRegistryPath), applied at all register and
unregister sites; the in-memory worktree Set still holds the real root.
Regression tests assert the persistence invariant across getTask/listTasks/
store-reopen and concurrent session registration across all three session
surfaces; both verified to fail without the fix.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- Add GET /api/git/workspace-repos endpoint returning sub-repo list
- Add resolveGitDir() helper: resolves repoPath query param to sub-repo dir
- Update all 34 git endpoints to use resolveGitDir for workspace targeting
- Add repoPath param to 30+ frontend git API functions
- GitManagerModal: auto-detect workspace repos on mount, show repo selector
dropdown at top of sidebar, pass selected repo to all git API calls
- Auto-select first repo when workspace mode is detected
- Repo change triggers data refetch via gitRepoPath dependency
- Align dashboard prefix validation to 1-5 chars (was 1-10) matching CLI cap
- Fix distributed-task-id.ts fallback from KB to FN (3 occurrences)
- Move taskPrefix/defaultWorkflowId persistence outside interactive-only block
so non-interactive CLI registration also gets defaults
- Wrap both TaskStore lifecycles in try/finally to guarantee close() on error
- Add POST /api/projects/detect-workspace endpoint for sub-repo scanning
- Modify POST /api/projects to accept workspaceMode + taskPrefix params
- SetupWizardModal: auto-detect sub-repos when path is entered, show
workspace mode checkbox with detected repo count, add task prefix field
auto-derived from project name
- Wire workspaceMode and taskPrefix through registration API call
- Close first TaskStore before creating second in interactive registration (P1)
- Revert defaultWorkflowId default to undefined; set explicitly in onboarding only (P1)
- Add alpha-only filter + 2-char min to interactive prefix input (P2)
- Move suggestTaskPrefix to @fusion/core, share between CLI and dashboard (P2)
- Fix suggestTaskPrefix JSDoc to match implementation (P2)
- Fix workspace detection: change workspaceMode default from false to
undefined so isWorkspaceModeExplicitlyDisabled no longer blocks
auto-detection on fresh projects (config.json was being written with
workspaceMode:false during store.init(), causing the guard to skip
detection before it ever ran)
- Derive task prefix from project name (first 2-4 chars) instead of
hardcoded 'FN' as the suggested default
- Default workflow is now builtin:coding instead of undefined
- CLI registerProjectInteractive: onboarding prompt for task prefix
confirmation after project name
- Dashboard POST /api/projects: auto-derive prefix and set default
workflow for new registrations
Address the 6 findings from the focused re-review of the hardening commit
(test-only; no production changes):
- useDashboardHealth: drop the false-confidence unmount-state assertion
(React 19 silently drops setState on unmounted components, so it pinned
nothing) and document the cancelled-guard as a React-19-untestable-via-state
invariant; keep the meaningful mount-fetch assertions.
- sseSplitIntegration: assert the onReconnect split explicitly
(mailbox onReconnect wired, approval onReconnect undefined); prove the
mailbox approval:requested handler actually refreshes (fetchUnreadCount
called); replace the magic 2x microtask drain with a deterministic waitFor.
- Extract the duplicated msg()/message() SSE-event helper to a shared
sseTestHelpers.ts (per-file vi.mock factories stay — vitest hoists them).
- useChatUnreadBadge: add a cross-project filter case for
chat:room:message:added.
Full hook suite green (1366 tests); App.test.tsx unchanged; typecheck + eslint clean.
Address PR #1739 review round 3:
- Major (coderabbit): Reorder writes so setWorkspaceModeInConfig runs
before saveWorkspaceConfig. If the config write fails, no stale
workspace.json is left behind.
- Major (coderabbit): setWorkspaceModeInConfig only treats ENOENT as
empty config (not parse errors or permission errors). Validates
settings is a plain object before merging to prevent clobbering.
Address PR #1739 review round 2:
- P1 (greptile): Auto-detection fallback now sets workspaceMode: true in
config.json so the dashboard toggle reflects the actual state.
- Major (coderabbit): Let saveWorkspaceConfig errors propagate instead of
silently returning 'existing' when the write fails. A failed write would
leave the project with no git repo and no workspace config.
Address PR #1739 review feedback:
- P1 (greptile): When workspaceMode is explicitly false in config.json,
skip the auto-detection fallback so toggling workspace mode off via the
dashboard has a lasting effect (was being re-enabled on next registration).
- CodeRabbit: node_modules exclusion test now includes a real sibling
sub-repo to prove the exclusion is the gate, not just absence of
detection.
- Add test for workspaceMode:false config.json guard.
Add workspaceMode as a first-class ProjectSettings boolean that controls
whether the project root is treated as a workspace parent (multi-repo)
or a single git repo.
- ProjectSettings type + DEFAULT_PROJECT_SETTINGS: workspaceMode?: boolean
- CLI registerProjectInteractive: when sub-repos are detected, ask the
user to confirm workspace mode instead of auto-applying
- TaskStore.updateSettings: when workspaceMode is toggled on, detect
sub-repos and persist workspace.json; when toggled off, remove it
- Dashboard SettingsModal GeneralSection: workspace mode toggle checkbox
This lets users change workspace mode per-project at any time via the
dashboard Settings or PUT /settings API.
Address PR #1739 review feedback:
- P1: Exclude node_modules, .fusion, .pi from detectWorkspaceRepos so
packages installed from git sources don't produce false-positive
workspace members.
- P2: Wrap saveWorkspaceConfig in try/catch so a write failure (permissions,
disk full) doesn't fail the current registration.
- Nitpick: Thread runner/timeout through detectWorkspaceRepos so custom-runner
callers are consistent across all code paths.
The initial fix only checked loadWorkspaceConfig, but the dashboard
POST /api/projects and `fn project add` routes never create workspace.json
(only registerProjectInteractive does). So re-adding a workspace project
through the dashboard still triggered git init because the guard saw no
workspace.json.
Add detectWorkspaceRepos as a fallback: after loadWorkspaceConfig and
isInsideGitWorkTree both miss, probe for git sub-repos. If found, persist
workspace.json and return 'existing' without running git init. This covers
all registration surfaces.