The advisor-watchdog.md slash-command table described /advisor,
/advisor on, and /advisor off as toggling the persisted advisor.enabled
setting. Commit 3c5e32f21b made the toggle session-local: setAdvisorEnabled
mutates only the in-memory #advisorEnabled field and writes nothing to
config.yml. Corrected the three rows to describe the session-scoped
override.
Fixes#6128
One ChatGPT email can hold several workspaces (a personal Plus/Pro plan
plus Team/Enterprise seats), each with its own workspace-scoped OAuth
token and independent limit pools. Codex credentials were deduped by
bare email, so logging into the second workspace silently replaced the
first, and usage reports from the two pools merged into one row.
- capture the workspace (chatgpt_account_id) as orgId at login, with
the plan type as its display label; token refreshes never rewrite it
- key openai-codex credential identity as email + org via the existing
org-scoped machinery; legacy email-keyed rows are claimed in place by
the first workspace-scoped login, and workspace-less credentials
never clobber workspace-scoped rows
- exclude the org-mirroring account base from same-org row claims so
two members of one workspace (shared chatgpt_account_id) keep
separate rows
- partition usage-report dedupe by workspace and require every shared
identity dimension to agree when reconciling codex usage blocks
Fixes the openai-codex half of #2966 (anthropic half shipped in #5170);
also covers the #633 scenario.
Added TCP server transport for vscode-js-debug and recursively handled startDebugging requests, breakpoint synchronization, active child routing, and tree cleanup.
Fixes#5984
The normal-yield conclusion claimed a blocked steer is always preserved as a card. During the advisor.immuneTurns cooldown, resolveAdvisorDeliveryChannel returns aside and the note rides the YieldQueue to the next step boundary, not a card. Qualified the conclusion to separate the card cases from the aside downgrade.
Clarified that plan mode preserves every would-be advisor steer, including live-streaming notes, because only user-driven turns converge on ask/resolve.
Documented that ACP bridges deferring agent-initiated turns preserve idle advice unless the bridge allows those turns, while advice can still steer an already-streaming turn.
Updated the severity table and changelog to make all delivery statements conditional on these session and client constraints.
The severity table listed `concern` as unconditionally interrupting and the
prose claimed a normal yield can always steer/resume the agent. Neither holds
once the primary ends with a terminal text answer and no queued work: per #4840
`resolveAdvisorDeliveryChannel` preserves a late `concern` as a passive card
rather than waking the agent to restate completion, while a `blocker` still
steers a triggered turn (#5628).
Documented the streaming-vs-idle split and the terminal-answer carve-out so the
observed idle delivery reads as intended behavior.
Fixes#5913
Loaded a platform-delimited (: on Unix, ; on Windows) path-list of settings overlays from PI_CONFIG_FILES before explicit --config overlays, so wrapper-based setups can inject settings without argv surgery.
Dropped the earlier global --config extraction as too risky; --config remains a launch/acp/models flag as before.
Fixes#5685
Logged one actionable warning per LiteLLM management base when rich metadata discovery fails, while keeping missing 404 routes silent.
Documented metadata-route permissions and covered forbidden versus absent endpoints.
Fixes#5801
- v17.0.1 (#5476) rewrote the normal buffer in place per SIGWINCH, so
the terminal's own width reflow pushed wrapped fragments into native
scrollback mid-drag and resize smoothness collapsed.
- Throwaway drag frames paint on the alternate screen again; the settle
full paint fuses the buffer exit ahead of its destructive repaint.
- Kept the #5319 fixes: deferred overlay alt-exit fusing, confirmed-only
DECRPM 2026 handling, and Warp's in-place resize path.
Added an opt-in viewport-pinned live-region policy and propagated it through transcript composition for in-flight vibe_wait TV walls.
Pinned mutable wall frames now repaint virtually until finalization, while append-only live regions retain their existing frozen-snapshot behavior.
Fixes#5777
Extension-scheduled setInterval/setTimeout/detached callbacks ran outside
the handler-dispatch try/catch, so a throw surfaced as a process-level
uncaughtException and the global postmortem handler tore down the whole
session instead of isolating the misbehaving extension.
- Added ManagedTimers backing sanctioned ctx.setInterval/setTimeout/clearTimer:
callbacks run with handler-dispatch isolation (throw/rejection logged and
routed through onError), handles are unref'd, and all are cleared on
session_shutdown.
- Wired the helpers into ExtensionRunner.createContext and the runner-less
command-context fallback; onSession now inherits the runner context.
- Documented in-process no-isolation behavior and the managed timers in
docs/extensions.md and docs/skills/authoring-extensions.md.
Fixes#5664
- Added the `xd://` virtual device protocol (`internal-urls/xd-protocol.ts`, `tools/xdev.ts`): tools declaring `loadMode: "discoverable"` are unmounted from the request tools array and driven via `read xd://` (list/docs+schema) and `write xd://<tool>` (execute), gated by the `tools.xdev` setting (default on) and inlined into the system prompt.
- Merged the `irc`, `job`, and `launch` tools into a single `hub` tool (`tools/hub/`, `async/job-manager.ts`): messaging keeps `send`/`inbox`/`list`, job control maps to `wait`/`cancel`/`jobs`, process supervision keeps `start`/`logs`/`stop`/`restart`/`describe` with `ps`, and the unified `wait` races background jobs against peer messages; SDK `IrcTool`/`JobTool`/`LaunchTool` are replaced by `HubTool`.
- Removed the hidden `resolve` tool in favor of the `xd://resolve`/`xd://reject`/`xd://propose` resolution devices, auto-including `write` whenever a deferrable tool or plan mode is present.
- Removed the BM25 tool-discovery system: the `search_tool_bm25` tool, the `tool-discovery` module, the `tools.discoveryMode`/`mcp.discoveryMode`/`mcp.discoveryDefaultServers`/`tools.essentialOverride` settings, per-tool MCP selection, and the `mcp_tool_selection` message type.
- Unified tool presentation on `ToolLoadMode` (`essential`|`discoverable`), replacing the custom-tool `xdev?: boolean` opt-out; custom, extension, MCP, RPC host, image-generation, and TTS tools now default to `discoverable`, and added a `satisfies` predicate to `SoftToolRequirement`.
- Removed the standalone `ssh` command tool and `ssh/ssh-executor` (the `ssh://` read/write/search protocol stays), and made `--tools` address hidden built-ins.
- Updated collab-web to render `xd://` dispatches and `hub` op families, dropped the `search_tool_bm25`/`ssh`/`report-finding` renderers, refreshed tool docs and prompts, and migrated the affected tests and changelogs.
Documented both accepted scope encodings: a comma-separated YAML scalar and a YAML sequence. Added prose, thinking, block-list, and tool/path examples, plus an explicit warning that adjacent quoted scalars are invalid YAML. Updated malformed-frontmatter fallback semantics to match the fix in PR #5489.
Fixes#4796
- Updated prewalk gating in `AgentSession` to key the todo gate on active tools instead of registry presence, so deactivated todo tools no longer block prewalk handoff.
- Changed subprocess tool filtering so `todo` is stripped for normal subagents but retained when prewalk is armed, and propagated the prewalk state through tool-session setup.
- Added regression tests for restricted active-tool slates and prewalk/non-prewalk subagent tool propagation to verify todo is handled correctly in each case.
- Added schema and type updates for task-agent fields and model resolver settings.
- Extended discovery helper logic to carry resolved task-agent metadata through execution setup.
- Updated task/agent registration and execution paths to use the new capability/field data.
- Expanded test coverage for agent-field parsing, model resolution, and executor prewalk behavior.
The agent:// path segment was always treated as a jq JSON-extraction key
against <parent>.md, so agent://Parent/Child loaded Parent.md and applied
.Child instead of resolving the nested child capsule Parent.Child.md. A
precise-planner reading its own scout child therefore got Not found.
The slash is now a hierarchy separator first: agent://Parent/Child resolves
Parent.Child.md (subagent children are allocated as dot-qualified ids). It
falls back to JSON extraction only when no nested output matches the path;
the ?q= query form is always extraction.
Fixes#5238
- Replaced legacy `pi/` role alias prefix with canonical `@` syntax across model resolution, documentation, and tests.
- Added support for bare `*` default alias and multiple alias prefix detection with custom role resolution in `resolveConfiguredRolePattern()`.
- Enhanced thinking suffix parsing to accept unambiguous abbreviations (minimum 2 characters) for effort and level selectors.
- Extended `resolveCliModel()` and `filterAvailableModelsByEnabledPatterns()` to accept settings parameter for role alias resolution from `--model` flag.
- Added a configuration setting `launch.enabled` to control the availability of the project-scoped launch tool.
- Integrated the setting into the bash tool and tool registry to conditionally enable or disable the launch functionality.
- Updated documentation and settings schema to include the new toggle.
- Introduced a project-scoped `launch` tool to orchestrate long-running services, debuggers, and watchers with persistent execution capabilities.
- Implemented a robust daemon broker with Unix/Windows IPC transport that manages process lifecycles, readiness monitoring, and automatic log rotation.
- Added detached process support to ensure services persist independently of the main application lifecycle, including recovery and cleanup mechanisms.
- Updated the `bash` interceptor to prioritize the new `launch` tool for background processes and provided comprehensive documentation for lifecycle and signal handling.
- Implemented model-specific keys and provider wildcards for `retry.fallbackChains` with updated resolution logic.
- Added interactive fallback chain management in the model roles UI, including support for reordering and editing.
- Improved fallback chain specificity rules and added comprehensive validation with startup warnings.
- Fixed mouse interaction alignment and hover state coordinate mapping in the roles view.
- Removed the bash command fixup system and associated logic from both the Rust and TypeScript components.
- Deleted the redundant fixup module and its exported implementations.
- Updated technical documentation and configuration settings to reflect the removal of pre-execution bash command rewriting.
- Enabled granular task execution by allowing batches to interleave blocking items with non-blocking async background spawns.
- Updated task orchestration to support simultaneous inline result collection and persistent background job tracking.
- Improved agent visibility in the job tool by reporting running subagents even when not explicitly linked to a backing job ID.
- Enhanced terminal state handling to prevent premature tool block closures while async background operations remain active.
One Anthropic account email can hold multiple organizations (a Team seat
plus a personal Max plan), each with its own org-scoped OAuth token and
independent 5h/7d limit pools. Credentials were deduped by bare email, so
logging in with the second subscription silently replaced the first, and
usage reports from the two pools merged into one row with mixed numbers.
- capture organization uuid/name at login (token exchange response, with
a claude_cli/bootstrap fallback); token refreshes never rewrite it
- key anthropic credential identity as email + org; a legacy email-keyed
row is claimed in place by the first org-scoped login with the same
email, and org-less credentials never clobber org-scoped rows
- partition usage-report dedupe and the per-credential usage cache by
org so the two subscriptions' limit pools stay distinct for rotation
- show the organization in omp usage (redaction-safe) and name the
stored account/org in the login success message
- Renamed task wire fields, replacing `assignment` and `description` with `task` and `name` while removing `role` references.
- Implemented automated task UI label generation using a tiny model to replace manual role descriptions.
- Updated task execution and rendering logic to support per-item agent resolution and dynamic badge display.
- Migrated schemas, prompts, and test suites to enforce the new flat task structure and agent-centric policy.
Aligned the context promotion documentation with the explicit contextPromotionTarget runtime behavior and the false default in settings-schema.
Fixes#5163
- Added six new search providers (Bing, Yahoo, Ecosia, Startpage, Mojeek, and Public) to expand coverage and parallel search capabilities.
- Implemented a unified `browserFetch` utility with headless-browser fallback and randomized Chrome profiles to improve scrape reliability.
- Integrated automated bot-defense mechanisms including CAPTCHA detection, ALTCHA proof-of-work, and homepage-token flows.
- Fixed hanging search CLI commands by ensuring proper closure of AuthStorage connections.
Loaded default custom model configuration from models.yaml when models.yml is absent while preserving yml precedence over yaml and legacy json migration.
Fixes#5145
- Removed the `plan` agent definition and associated prompt file from bundled agents.
- Updated documentation to reflect the removal of `plan` from available subagents.
- Cleaned up related tests to remove references to the deprecated agent.