Repository navigation
Publish the first six shell.online blog posts: a Codex run, a deadline with a stop control, session summaries, who answers Claude Code's prompts, file sharing without symlink escapes, and a background Haiku 5.5 job - #313
Open
artemiia wants to merge 8 commits into
Open
artemiia wants to merge 8 commits into
artemiia wants to merge 8 commits into
Conversation
A step-by-step post for the blog: start Codex through shell, open the session on a phone, give a teammate a read-only link, keep track of several runs, and rotate the password afterwards. It is tied to the GPT-6.1 Sol release and carries its own cover artwork. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A second post for the blog: start an agent with --auto-close so the run has a hard deadline, watch it from a phone, and stop it three ways (interrupt from the phone, the app's Stop button, shell kill on the host). It is tied to OpenAI cancelling the GPT-6.1 Astra release and carries its own cover artwork. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Start named Claude Code sessions through shell, turn on the 0.25.0 session summaries with shell permissions, and read them in the app by long-pressing a session. Hooked to Claude Code 2.1.290, which lets claude attach and claude logs find a background session by name. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… shared terminal Ties Anthropic's Claude Code mods launch (2026-10-01) to shell.online's input rules: interactive versus read-only sessions, the relay's one-typist lease, observe-only MCP grants and password rotation. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ymlink widen access Ties the brig project-mount symlink advisory (GHSA-wp6x-29qx-fpr7) to shell --files and --files-root: choosing and resolving the root, what the host refuses, and what hard links still let through. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…nd stepping back in Covers starting Claude Code on Haiku 5.5 with shell, finding the session with shell list, attaching with shell attach, detaching with Ctrl-X then D, checking the run from a phone, and stopping it. Ties in Anthropic's Haiku 5.5 release of 2026-10-07. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes for the user?
The blog gets its first six posts written for shell.online itself, all by Artemii Amelin. This pull request stays open as the daily posts accumulate until it is merged; each post is its own commit.
1. How to Watch a Long Codex Run From Your Phone and Share It With a Teammate (2026-10-03)
A step-by-step guide: install
shell, start Codex through it, open the session on a phone, give a teammate a--read-onlylink, keep track of several runs withshell list,shell lsand the 0.25.0 session summaries, then rotate the password. The hook is OpenAI's GPT-6.1 Sol release on 29 September.2. How to Put a Deadline and a Stop Button on an Unattended Coding Agent (2026-10-05)
A step-by-step guide: start an agent with
--auto-closeso the run has a hard deadline, watch it from a phone, and stop it three ways (Escape or Ctrl-C from the phone, the app's Stop button,shell killon the host), with a section on what none of that undoes. The hook is OpenAI cancelling the GPT-6.1 Astra release over acting without permission and misreporting its actions.3. How to See What Each Claude Code Session Is Doing From Your Phone (2026-10-06)
A step-by-step guide: start named Claude Code sessions with
shell --name, find a session's account ID withshell ls --json, turn on the 0.25.0 session summaries withshell permissions <ID> --summaries=true, and read them in app.shell.online by long-pressing a row. It explains how shell binds a session to its Claude Code transcript (--session-idplus a SessionStart hook), what the enclave path does for other commands, and what summaries do not do. The hook is Claude Code 2.1.290 (published 5 October), which letsclaude attachandclaude logsfind a background session by part of its name.4. How to Choose Who Can Answer Claude Code's Prompts in a Shared Terminal (2026-10-07)
A step-by-step guide to deciding who can answer a Claude Code permission prompt when the session runs under
shell: you alone from a phone (an interactive session nobody else has the password for), teammates watching while you answer at the host (--read-onlyplusshell attach), or several typists. It explains the relay's one-typist rule (a 1,800 ms input lease, "Guest N is typing…", local host before browser before MCP), a watcher agent on an observe-only grant (shell mcp grant <ID> "prompt watcher" observe 900), taking input back withshell password rotate, and a callout that "Yes, and don't ask again" saves a rule to.claude/settings.local.jsonthat rotation does not remove. The hook is Anthropic's launch of Claude Code mods on 1 October, which can approve or deny permission requests and add confirmation steps.5. How to Share a Coding Agent's Files Without Letting a Symlink Widen Access (2026-10-08)
A step-by-step security guide to
shell --filesand--files-root: pick the smallest root when the session starts, resolve it withpwd -P(a root given as a symlink is followed when it is opened), what viewers see in the Files panel (256 entries per listing, 16 MiB previews, 128 MiB downloads, pull-driven 16 KiB chunks, eight requests at once, read-only links still read opted-in files), and what happens when an agent plantsln -s ~/.ssh keysinside the root (left out of listings, refused on open byos.Root). A callout warns that dotfiles such as.envand.git/configare not hidden. The "does not do" section covers hard links (which pass), the fact that the root does not sandbox the agent, mount points, and that viewers cannot write. The hook is brig advisory GHSA-wp6x-29qx-fpr7 (26 September, fixed in brig 0.3.0) and Endor Labs' write-up of it (28 September), in which an agent's symlink made the sandbox mount a host directory read-write.6. How to Run a Claude Haiku 5.5 Job in the Background and Step Back In (2026-10-09)
A step-by-step guide: start Claude Code on Haiku 5.5 with
shell --name "..." claude --model claude-haiku-5-5, find it again withshell list, attach from a local terminal withshell attach <prefix>(screen replayed on attach, the attached window owns the grid, one local terminal at a time), detach with Ctrl-X then D (shell waits 750 ms for D and forwards any other Ctrl-X sequence, so Claude Code's Ctrl+X Ctrl+E/S/K shortcuts still work; Ctrl-] is the legacy key), check the run from a phone, and stop it withshell killor--auto-close. A callout warns that Ctrl-C goes to Claude Code and a second press at an idle prompt exits it, which ends the session. It compares shell with Claude Code's ownclaude --bg/claude attach, and the "does not do" section covers attaching to an existing process, local-only attach, sleep, cost (Haiku 5.5's tokenizer counts about 30% more tokens) and crash recovery. The hook is Anthropic's release of Claude Haiku 5.5 on 7 October and Claude Code 2.1.293, which made it the default Haiku model the same day.For each post:
blog/posts.jsongains one entry. None has acanonical, so unlike the 23 imported posts these are canonical on shell.online and are listed in/blog/sitemap.xml.blog/posts/<slug>.htmlis the body, in the formatblog/README.mddescribes.public/blog/banners/<slug>.webpis the cover, a 1200×630 drawn illustration. Because it is not an SVG, the post also uses it as its social image.The branch also carries a merge of
main(8876e0e) so it stays current.Verification
Run on 2026-10-09 on the branch head (435e2f0), which is
mainat 8876e0e plus the six posts:npx vitest run tests/blog.test.ts→ 1 file, 15 tests passed.node scripts/test-landing-seo.mjs→ "Primary landing SEO, attribution, and use-case checks passed."npm run build:web→ exit 0 (only the existing chunk-size warning).cmd/shell/help.go(start, list, attach, kill, password, e2ee, platforms and reference topics),cmd/shell/attach_unix.go(detach filter, 750 ms timeout, title handling, grid following),cmd/shell/sessions_unix.go(handleAttach, the "another local terminal is attached" refusal, resize only from an attached client),cmd/shell/terminal_grid.goandcmd/shell/session_unix.go(local grid limit set on attach and cleared on detach),cmd/shell/sessions.go(prefix rules and theshell listcolumns) andcmd/shell/session_output.go(the session card).cmd/shellis unchanged between v0.25.0 andmain, so nothing described is unreleased. Claude Code flags and shortcuts were checked against the Claude Code CLI reference, interactive-mode page and CHANGELOG (2.1.293, 2.1.295); Haiku 5.5 figures against Anthropic's announcement and migration guide. Behavior was read from source, not run on a live session.Posts 1 to 5 were checked when they were added (3, 5, 6, 7 and 8 October) as described in their commits and earlier revisions of this description: blog test, landing SEO check and build passed, and their link checks reported no dead links. Today's blog test and build above cover all six posts; the earlier posts' link checks were not repeated today.
Not done: no screenshots attached.
Access and privacy
No change to authorization, terminal input, passwords, encryption, logging or stored content. The links, password fragments, session IDs and session names shown in the covers and examples are invented.
No changelog entry: these are articles, not product changes, and the changelog already records the blog itself.
Rollout
Website only. No CLI or host update, no migration, no config change. The posts are live after the next site deploy.
🤖 Generated with Claude Code