Field status · verified 2026-08-29

Know which boundaries belong to rc.7—and which moved in alpha.1.

This is a community-maintained rc.7 baseline with alpha.1 migration context, not an official release-health claim. Each item separates observed evidence from inference and links to the primary discussion. For current install and upgrade decisions, start with the alpha.1 source-pinned guides and verify the artifact you actually run.

Baseline
0.1.0-rc.7
Current source
0.1.2-alpha.1
Tracked
11 boundaries
Rule
Verify before workaround

Operator view

Start with the failure surface.

Linux · installHigh friction

Published CLI may lack the Linux x64 PTY prebuild.

node-pty falls back to node-gyp rebuild. A deprecation warning is not the failure; capture the first compiler error.

First evidence
prebuilds/linux-x64 does not exist
Next action
Install the native build toolchain or wait for a corrected package; do not treat local compilation as the release fix.
Primary report ↗
Session · tool runtimeData continuity

A scheduler crash can leave a permanently invalid provider transcript.

A recorded assistant tool call without its matching result can make every later turn fail with HTTP 400. A full restart was tested and did not repair a turn already closed with turn/end(error).

First evidence
insufficient tool messages following tool_calls message
Next action
Preserve and back up the session. Avoid hot-loading plugins during an active turn; do not edit persisted event sequences manually.
Primary report and validation ↗
Linux · sandboxSecurity report

Do not run the bwrap profile as privileged root.

A public report shows a root process retaining enough mount authority to remount a read-only bind as writable. The report is source-consistent but has not been independently reproduced by this handbook.

First evidence
Host writes persist after a sandboxed remount.
Next action
Treat root + bwrap as unsafe pending an upstream fix. Run unprivileged and prefer a capability-resistant isolation boundary such as Landlock or a disposable VM.
Security report ↗
Remote Web · browserEnvironment

A typed UUID failure can look like a reconnecting socket.

Typed host.describe can throw before fetch, abort its connection generation, close both event streams, and repeat connection lost.

First evidence
Insecure context, missing randomUUID, and no matching typed host.describe request.
Next action
Compare HTTPS or loopback before changing WebSocket settings; distinguish a pre-fetch throw from a server 403.
Open the incident note →
Windows · workspacePath boundary

Folder selection failures are not one bug.

Native picker worker exits, legacy junction EPERM, and CJK UTF-16 truncation have distinct evidence and fixes. Switching blindly between pickers can hide the real boundary.

First evidence
Record the picker implementation, exact path class, and complete worker error.
Next action
Use a plain disposable path while preserving the failing path and logs for upstream diagnosis.
Junction report ↗
Windows · Web HostEvidence needed

A listening port can survive while every HTTP request times out.

Report #4755 ties the first failure to message submission, but low CPU and package presence do not identify the blocking frame.

First evidence
Verified listener PID, timestamped probes, and the same main-thread frame across three private full dumps.
Next action
Capture before watchdog restart; keep dumps private and change one network, Session, or runtime boundary at a time.
Open the Windows hang runbook →
MCP · configurationUX gap

The client exists; the general-purpose settings form does not.

Configure one @deepseek-ai/dsh-mcp-client row per server through an overlay or profile patch. Discovered tools use mcp__server__tool names.

First evidence
Resolved config plus connection, discovery, and registration logs.
Next action
Trial with --patch, then merge into a profile patch. Resolve secrets from environment variables.
Open the MCP guide ↗
GitHub Copilot · authenticationSource-consistent

A valid long-lived token can still fail every streaming turn.

Copilot expects its long-lived GitHub token to be exchanged for a short-lived endpoint token. The current adapter passes the resolved credential as a highest-priority API key instead, bypassing the provider-owned OAuth flow; the UI then reduces the resulting 403 to “API key is invalid.”

First evidence
A non-streaming auxiliary call succeeds while streaming turns fail with 403 Access to this endpoint is forbidden on the same route, model, and credential.
Next action
Do not rotate or expose the credential based only on the generic UI message. Preserve the provider response and session evidence; wait for a published OAuth-exchange fix before treating this route as operational.
Root-cause report and proposed fix ↗
Preset · Cordis hostSource-confirmed

The shipped Cordis preset can collide with its own inspect providers.

tool-cordis registers process-level host inspect providers whenever the preset mounts, while the shared registry rejects a second provider with the same ID. A live preset that already owns those registrations can therefore prevent another Cordis preset from mounting.

First evidence
Host Cordis inspect provider "Service" is already registered while session.create returns agent-preset-invalid.
Next action
Use the standard preset and restart the process after changing the default. Do not make registration silently idempotent without preserving disposer ownership; the durable fix belongs at host startup or behind isolated ownership.
Reproduction and source analysis ↗
Windows 10 · sandboxCompatibility report

Restricted-token children may fail during DLL initialization.

A Windows 10 build 19041 report shows ordinary child processes intermittently exiting with 0xC0000142 under workspace-write. The implementation documents this status for incompatible console creation flags, while its restricting-SID design was verified on Windows 11 build 26200.

First evidence
Start-Process reports -1073741502 (STATUS_DLL_INIT_FAILED), the same command succeeds outside confinement, and workspace ACLs do not accumulate.
Next action
Treat this as an OS/backend compatibility boundary, not a missing permission. Preserve the build, command, creation flags, and exit code; do not add broad SIDs or silently run unrestricted. Use a disposable VM for tasks that cannot run inside this backend.
Windows 10 reproduction ↗
Workflow · subagentsCapacity report

A workflow can exhaust the heap below the default total-agent guard.

A translation run reported a fatal V8 OOM near 4 GB after approximately 480 subagents. The worker-thread engine permits up to 1000 calls by default, so that guard does not define a safe memory envelope.

First evidence
Capture peak heap, concurrent children, total children, settled children, and whether memory falls between batches.
Next action
Start with 2-4 concurrent children, use a batch-sized total ceiling, persist every batch, and stop when memory rises after settled children.
Open the bounded workflow guide →

Interpretation rule

Observed is not the same as inferred.

Observed means a report includes an exact error, event sequence, or reproducible command. Source-consistent means the reported mechanism matches the inspected implementation. Verified means a workaround was actually tested against the described failure.

This page avoids “fixed” labels until a published build and the original failure path have both been retested.

Need a route, not a list?

Find the first broken boundary.

Open the failure routerStar the handbook