# leeroy-wip manual review queue (oldest → newest)

Generated: 2026-01-24
Source: docs/commit-audits/happy/leeroy-wip.commit-analysis.md

Commits flagged for manual review: 71

## Bucket counts

- `codex`: 9
- `cli`: 7
- `sync`: 5
- `i18n`: 4
- `new-session`: 4
- `claude`: 3
- `expo-app`: 3
- `secrets`: 3
- `tools`: 3
- `ui`: 3
- `agent-input`: 2
- `auth`: 2
- `permission`: 2
- `profiles`: 2
- `resume`: 2
- `server`: 2
- `app`: 1
- `crypto`: 1
- `experiments`: 1
- `fork`: 1
- `happy-cli`: 1
- `new`: 1
- `pr107`: 1
- `reducer`: 1
- `rpc`: 1
- `security`: 1
- `server-light`: 1
- `settings`: 1
- `terminal`: 1
- `tmux`: 1
- `typecheck`: 1

## Queue

Each entry is: `index date short-sha bucket — subject — reasons`

- 001 2026-01-17 58528a7c37d3 `crypto` — chore(crypto): patch react-native-libsodium — YES (safety/security-sensitive area)
- 004 2026-01-17 4890a471df31 `auth` — fix(auth): harden tokenStorage web persistence — YES (safety/security-sensitive area)
- 005 2026-01-17 4adc41d92af0 `sync` — feat(sync): add permission mode types and mapping — YES (safety/security-sensitive area)
- 017 2026-01-17 65bae55a0b61 `i18n` — refactor(i18n): separate translation types and content — YES (diff summary skipped (large change (+1756/-1006)))
- 018 2026-01-17 2993b5c860ff `new-session` — fix(new-session): restore standard modal flow — YES (diff summary skipped (large change (+3142/-1629)))
- 019 2026-01-17 9e08047d2478 `profiles` — fix(profiles): harden routing, grouping, and editing — YES (diff summary skipped (large change (+1319/-857)))
- 020 2026-01-17 8d9f56e85e5a `ui` — refactor(ui): unify list selectors and modal primitives — YES (diff summary skipped (too many files (28)); safety/security-sensitive area)
- 022 2026-01-17 2d4675a5d051 `agent-input` — fix(agent-input): use compact permission badges — YES (safety/security-sensitive area)
- 027 2026-01-18 7899bbd8433e `profiles` — feat(profiles): add API key requirements flow — YES (safety/security-sensitive area)
- 028 2026-01-18 0023ba1ea5aa `i18n` — refactor(i18n): update translations and tooling — YES (diff summary skipped (large change (+2913/-143)))
- 033 2026-01-18 daa0b4527d7f `new-session` — feat(new-session): add api key selection and wizard extraction — YES (diff summary skipped (large change (+1719/-1116)))
- 036 2026-01-18 97ca69e0a735 `i18n` — refactor(i18n): replace remaining UI literals — YES (safety/security-sensitive area)
- 038 2026-01-18 7976b877259c `experiments` — feat(experiments): gate Zen, file viewer, and voice auth flow — YES (safety/security-sensitive area)
- 039 2026-01-21 6ed379f82c34 `ui` — refactor(ui): add modal + popover overlay primitives — YES (diff summary skipped (too many files (43)))
- 040 2026-01-21 f0787de5308e `sync` — feat(sync): add secrets + terminal settings primitives — YES (diff summary skipped (too many files (60)); safety/security-sensitive area)
- 041 2026-01-21 66ee1eaf88a6 `secrets` — feat(secrets): add secrets management + requirement resolver — YES (diff summary skipped (too many files (29)); safety/security-sensitive area)
- 043 2026-01-21 bc779e4f7909 `new-session` — refactor(new-session): integrate secrets + terminal spawn options — YES (safety/security-sensitive area)
- 049 2026-01-21 2e956f32f220 `new` — fix(new): keep pick screens above iOS modal — YES (safety/security-sensitive area)
- 057 2026-01-21 ff7bec72358f `secrets` — fix(secrets): tighten callback deps and fix indentation — YES (safety/security-sensitive area)
- 058 2026-01-21 1bb65f5dd494 `new-session` — fix(new-session): avoid stuck secret requirement modal guard — YES (safety/security-sensitive area)
- 060 2026-01-22 bb09f91de715 `settings` — fix(settings): keep valid secrets when one entry is invalid — YES (safety/security-sensitive area)
- 061 2026-01-22 765423af52b4 `agent-input` — fix(agent-input): cycle permission mode from normalized state — YES (safety/security-sensitive area)
- 063 2026-01-22 2ed3100311c7 `secrets` — fix(secrets): hide values when using secret vault — YES (safety/security-sensitive area)
- 064 2026-01-22 e5848c480522 `ui` — fix(ui): harden overlays and permission cycling — YES (safety/security-sensitive area)
- 065 2026-01-13 69fdcff96a4c `sync` — fix(sync): restore session permission mode from last message — YES (safety/security-sensitive area)
- 066 2026-01-13 9b499c5dccce `sync` — fix(sync): persist permission mode timestamp for restart-safe arbitration — YES (safety/security-sensitive area)
- 067 2026-01-13 def8852509d0 `sync` — fix(sync): persist permission mode reliably across devices — YES (safety/security-sensitive area)
- 069 2026-01-06 c06b6202b5d4 `expo-app` — Add copy-to-clipboard button to message blocks — YES (non-Conventional-Commits subject)
- 072 2026-01-21 82d74454c3c4 `typecheck` — fix(typecheck): restore permission imports and Popover web styles — YES (safety/security-sensitive area)
- 086 2026-01-13 86330e263595 `security` — fix(security): redact spawn secrets from daemon logs — YES (safety/security-sensitive area)
- 089 2026-01-13 ef418bc4dda3 `pr107` — fix(pr107): redact profile secrets in doctor + align tmux tmpDir — YES (safety/security-sensitive area)
- 096 2026-01-15 2973f7fe6861 `codex` — fix(codex): harden MCP command detection — YES (safety/security-sensitive area)
- 099 2026-01-15 c52227082c2b `tmux` — fix(tmux): correct env, tmpdir, and session selection — YES (safety/security-sensitive area)
- 113 2026-01-21 51782fdbfbcd `codex` — test(codex): reset transport instances between tests — YES (safety/security-sensitive area)
- 124 2026-01-13 8b88dcd73d40 `claude` — fix(claude): carry permission mode across remote/local switches — YES (safety/security-sensitive area)
- 125 2026-01-13 8f0e10c9428b `claude` — fix(claude): publish permission mode in session metadata — YES (safety/security-sensitive area)
- 126 2026-01-13 ffad20faa406 `cli` — fix(cli): publish permission mode for codex/gemini sessions — YES (safety/security-sensitive area)
- 137 2026-01-12 68a6ba4bc244 `fork` — feat(fork): enable Codex inactive-session resume via codex-reply — YES (safety/security-sensitive area)
- 140 2026-01-22 9c40c54018c2 `cli` — Revert "fix(tools): support Windows arm64 tool unpacking" — YES (non-Conventional-Commits subject; revert commit)
- 141 2026-01-22 ab35b47ff699 `resume` — fix(resume): make inactive resume reliable; gate Codex resume — YES (multiple major areas: cli, expo-app; safety/security-sensitive area)
- 144 2026-01-22 0140ae276869 `codex` — refactor(codex): install mcp resume server via install-dep — YES (multiple major areas: cli, expo-app; safety/security-sensitive area)
- 146 2026-01-22 e1deb6db8ddb `codex` — refactor(codex): add dep-status and drop codex-resume RPCs — YES (multiple major areas: cli, expo-app)
- 148 2026-01-22 8bebf04aca92 `cli` — refactor(cli): modularize capabilities and env preview — YES (diff summary skipped (large change (+1296/-908)); safety/security-sensitive area)
- 150 2026-01-22 a5cac698f15b `cli` — feat(cli): harden session queue, switching, and lifecycle — YES (safety/security-sensitive area)
- 151 2026-01-22 3fc704424e8d `app` — feat(app): add pending queue, discard markers, and capabilities — YES (diff summary skipped (too many files (44)))
- 156 2026-01-22 8c16ee8f9cef `auth` — fix(auth): surface auth failures and gate unauth routes — YES (safety/security-sensitive area)
- 158 2026-01-22 3b3609fed434 `rpc` — fix(rpc): add structured code for missing RPC methods — YES (multiple major areas: expo-app, server)
- 160 2026-01-22 7fbe1f1cc727 `permission` — fix(permission): avoid no-op permissionModeUpdatedAt bumps — YES (safety/security-sensitive area)
- 162 2026-01-22 ee0bec2a0b90 `resume` — Delete INACTIVE_SESSION_RESUME.md — YES (non-Conventional-Commits subject)
- 165 2026-01-23 8b3f39f22664 `cli` — feat(cli): add interaction.respond for AskUserQuestion — YES (safety/security-sensitive area)
- 166 2025-12-24 ed4bc007308a `codex` — feat: add execpolicy approval option for Codex — YES (safety/security-sensitive area)
- 167 2025-12-24 78adc9c58811 `codex` — feat(codex): support execpolicy approvals and MCP tool calls — YES (safety/security-sensitive area)
- 168 2026-01-22 9dfa09bef8d8 `i18n` — fix(i18n): add Codex execpolicy button text — YES (safety/security-sensitive area)
- 169 2026-01-22 559d39da116d `reducer` — fix(reducer): keep permission messages idempotent — YES (safety/security-sensitive area)
- 171 2026-01-19 d06d5a833f8e `claude` — Add signal forwarding to claudeLocal.ts — YES (non-Conventional-Commits subject)
- 174 2025-12-24 e956463db3e2 `codex` — fix: use runtime execPath for MCP bridge — YES (safety/security-sensitive area)
- 175 2026-01-23 f0a7d8d0b40c `codex` — fix(codex): use mcp tool call id for approvals — YES (safety/security-sensitive area)
- 176 2026-01-22 da620b6865ad `server` — feat(server): add full/light flavors with sqlite migrations — YES (diff summary skipped (too many files (38)))
- 183 2026-01-23 46186162ae14 `happy-cli` — test(happy-cli): fix timer cleanup and MCP schema mocks — YES (safety/security-sensitive area)
- 208 2026-01-23 61a18ac95e17 `tools` — fix(tools): require permission id for ExitPlanMode actions — YES (safety/security-sensitive area)
- 209 2026-01-23 5b36c9bf91c1 `tools` — test(tools): avoid null permission in ExitPlanToolView tests — YES (safety/security-sensitive area)
- 211 2026-01-23 55428fb0253c `tools` — fix(tools): alert when AskUserQuestion permission id is missing — YES (safety/security-sensitive area)
- 212 2026-01-23 dc6955f88abd `terminal` — fix(terminal): prevent sessionId path traversal in attachment info — YES (safety/security-sensitive area)
- 226 2026-01-23 c461ed1cb4ef `permission` — feat(permission): add permission mode option helpers — YES (safety/security-sensitive area)
- 228 2026-01-23 523989b4de8e `server-light` — fix(server-light): avoid master secret race — YES (safety/security-sensitive area)
- 237 2026-01-23 241f0ae24b1d `cli` — test(cli): prevent legacy sessionId path traversal — YES (safety/security-sensitive area)
- 238 2026-01-23 a1e4a6dd3fbd `cli` — fix(cli): block legacy sessionId path traversal — YES (safety/security-sensitive area)
- 241 2026-01-23 1464402758bf `codex` — fix(codex): preserve falsy MCP tool results — YES (safety/security-sensitive area)
- 247 2026-01-23 24b607abfa07 `server` — Refactor schema sync and centralize Prisma types — YES (non-Conventional-Commits subject; diff summary skipped (too many files (29)))
- 248 2026-01-23 bf3027799623 `expo-app` — Set EXPO_UNSTABLE_WEB_MODAL env var in Expo scripts — YES (non-Conventional-Commits subject)
- 249 2026-01-23 c803115dcbdc `expo-app` — Improve postinstall script for symlinked paths and patching — YES (non-Conventional-Commits subject)
