review_task/continue_merge on a planning parent always leaves conflicts in the tree, and the UI auto-opened the resolver on every PlanningMergeConflict broadcast regardless of who started the merge -- so a running Claude session resolving a unit-merge conflict could race a human editing the same shared checkout in a resolver window neither of them asked for. PlanningMergeOrchestrator.StartAsync now takes an externallyDriven flag (set by ExternalMcpService's MCP-driven review_task path, left false for the UI's ApproveReview) that rides along on the PlanningMergeConflict broadcast. The UI only auto-opens the resolver when it's false; otherwise it shows a persistent banner with a manual "Open resolver" button, cleared on PlanningMergeAborted/PlanningCompleted. A new GetActiveExternalConflictsAsync query (checked against GitService.IsMidMergeAsync rather than the in-memory flag alone) lets the UI resync the banner on reconnect instead of trusting a one-shot broadcast that isn't replayed after a restart. The childless single-task conflict path was checked and needed no change -- it only broadcasts the generic TaskUpdated, never PlanningMergeConflict.
Explore-notes
Distilled, reusable maps of complex subsystems, produced by deep code exploration. The goal: stop re-exploring the same subsystem from scratch in every new session.
These sit between the CLAUDE.md files and the code:
- CLAUDE.md — high-level orientation, hand-maintained, always-loaded.
- explore-notes — deeper subsystem detail (flows, who-calls-whom, invariants) that is too fine-grained for a CLAUDE.md but stable enough to be worth caching. Read on demand.
- code — the only source of truth.
Index
| Note | Covers |
|---|---|
| worker-task-pipeline | TaskRunner end-to-end: config resolution, worktree, CLI invocation, streaming, commit |
| usage-monitoring | OAuth usage endpoint, gate, throttle, per-run token accounting, usage pill/modal |
| external-mcp | The claudedo MCP tool surface + its two test-enforced conventions |
| review-merge | Approve=merge-unit, verify gate, MergeCommit/revert, diff stack, conflict resolver |
| conpty-sessions | Interactive/planning/list-handler launch specs + the arg-flattening gotcha |
| installer-preflight | CLI version/login/auto-mode research, the ExecutableResolver/shim root cause, and the Installer's Checks/+SystemCheckPage implementation status |
Rules
- Only stable structure. Flows, responsibilities, entry points, invariants, relative file paths. No line numbers, no exhaustive symbol dumps — those rot fastest.
- Verify before trusting. A note is a starting map, not authority. Always confirm against current code before acting on it. Each note records the commit it was verified against so you can diff for drift.
- Not a substitute for CLAUDE.md. If a fact belongs in orientation, put it there.
Header every note must carry
> **Explore-note — verify before trusting.** Distilled map of a subsystem, not authoritative.
> Last verified against commit `<short-hash>` (<date>).
> Drift check: `git log --oneline <short-hash>..HEAD -- <paths this note covers>`
> Stable structure only (no line numbers). See docs/explore-notes/README.md.
Workflow
- Before deep-exploring a subsystem, check for a matching note here and read it first; explore only to fill gaps or confirm.
- After a deep explore, distill the durable findings into a new/updated note and bump its "verified against" commit line.
- If the drift check shows the covered paths changed a lot since the verified commit, treat the note as suspect and re-verify the parts you rely on.