- Replaced the custom MuPDF-WASM PDF extraction and rendering pipeline with the new `pdfToMarkdown` native function from `@oh-my-pi/pi-natives`.
- Removed legacy MuPDF extraction modules, WASM embedding scripts, and PDF image extraction tools.
- Added OCR warnings and browser/text redirection for unsupported PDF image reads.
- Updated native package definitions, documentation, and test suites for the new PDF inspection capability.
- Updated `RemoteAuthCredentialStore` to track broker usage accounts across snapshots and streams before account-pool filtering.
- Replaced `#countUsageAccounts` with dynamic tracking methods `#replaceBrokerUsageAccounts`, `#upsertBrokerUsageAccount`, and `#removeBrokerUsageAccount`.
- Refactored `AuthStorage.#fetchUsageCached` to accept an options object for `timeoutMs` and `forceRefresh`.
- Updated dockerignore patterns to exclude `**/.venv/` and ensure depth-agnostic `.env` secret exclusion.
- Scale usage fetch timeout dynamically in AuthBrokerClient based on the maximum account count per provider.
- Track maximum usage accounts per provider in RemoteAuthCredentialStore snapshot applications.
- Add comprehensive wire and store tests covering serialized account batch timeouts and account pool sizing.
Copilot discovery writes an authoritative cache, so online-if-uncached served the prior endpoint for the full TTL after COPILOT_GITHUB_TOKEN switched accounts. Keying the cache namespace on the credential forces fresh discovery for a new token instead of reusing a stale personal-endpoint cache.
Fixes#8507
- Switched Docker images to build native addons via cargo/napi-rs (`OMP_NATIVE_BUILD_BACKEND=cargo`) instead of Bazel.
- Updated Cargo.toml workspace members explicitly to prevent loading errors from stale directories under crates/.
- Added depth-agnostic patterns to .dockerignore files to exclude nested build outputs from Docker build contexts.
- Added OMP_NATIVE_CARGO_PROFILE environment variable to support configuring cargo profiles for addon builds.
- Added force-refresh tracking to serialize provider usage probes and prevent stale fallback re-plays after manual invalidation.
- Updated usage request handling to incorporate cache epochs and prevent stale in-flight results from overwriting new data.
- Added integration test verifying that broker invalidations correctly drop server-side last-good usage reports.
Threaded the shared 10s discovery AbortSignal into the copilot_internal/user probe so a stalled endpoint falls back to the personal host instead of hanging startup or refresh.
Fixes#8507
Shared the plan-endpoint probe between OAuth login and raw token model discovery so Business credentials route to their advertised API host.
Added regression coverage for the raw environment-token path.
Fixes#8507
- Recover dangling range separators in hunk headers as single-line ranges instead of rejecting them.
- Ensure strict rejection is maintained when a dangling separator is followed by invalid tokens.
Detected npm and Bun ownership from the bin link immediate target within each precise global node_modules root. Foreign aliases now update their resolved standalone binary without replacing the alias.
Fixes#8468
- Replaced child_process spawn with Bun.spawn in packages/coding-agent/src/utils/external-editor.ts.
- Removed the browser tab evaluation test suite from packages/coding-agent/test/tools/browser-tab-evaluate.test.ts.
formatReadHashlineHeader collapsed every relative in-workspace path to its
basename, so reading a nested file (e.g. src/settings.json) emitted
[settings.json#tag]. When a same-basename file existed at the session cwd,
a verbatim follow-up edit resolved against the cwd file; Patcher.prepare only
runs snapshot-tag path recovery when the authored path is missing, so the
valid edit was deterministically rejected with "hash is not from this
session". Keep the workspace-relative path, which names the file uniquely and
stays directly resolvable against cwd. Out-of-workspace absolute paths remain
shortened; root-level files are unchanged.
Fixes#8482
- Removed markit-converters.test.ts from packages/coding-agent.
- Updated google-gemini-cli provider to ensure antigravity version during stream execution.
- Updated antigravity discovery options to use fetcher fallback.
Resolved npm and bun bin-entry symlinks before selecting the update method, and preserved foreign aliases by replacing their standalone target.
Fixes#8468
Kept the Bun event loop live across subagent yield drains and delayed parent result flushes. Added a timer-lifecycle regression for the idle flush.
Fixes#8462
A thinking-only STOP on the daily endpoint flipped `started` via
`ensureStarted`, and the endpoint-failover catch guard gated on
`!started`, so Antigravity auto mode never requested the sandbox
endpoint and recorded a false empty-response failure for silent
Advisor turns.
Guard failover on a new `emittedVisibleContent` flag (set only when a
visible text delta or tool call is pushed) instead of `started`, so
hidden thinking no longer blocks the fallback while genuine partial
output still does.
Fixes#8480
- The b279db1790 rewrite wrapped runner.emit() in vi.useFakeTimers() and
hand-advanced the clock, but the runner registers its cap setTimeout after
more microtask turns than the test advances (emit defers the timeout
machinery to the first matching handler and hops through Bun.sleep(0)),
so the cap timer never fires, emit never settles, and fake timers also
neutralize bun's per-test timeout — the singleton/global-state CI bucket
hung silently until the 600s watchdog SIGKILL (exit 137).
- Restored the pre-refactor real-time version: it has no sleeps or polling
loops, runs the hung handlers against a 100ms cap, and asserts bounded
wall-clock plus the per-extension timeout warnings.
- Verified the full 79-file singleton bucket passes (867 tests) and the
restored file passes on Linux bun 1.3.14 in Docker.
- Restored the original 17.3.1 status-line changelog bullet (released
sections stay immutable).
- Bun's inotify-backed fs.watch permanently stops delivering events after
observing git's atomic HEAD.lock -> HEAD rename in the watched directory
(oven-sh/bun#24875), so the directory-watch fix for issue #8412 still froze
the status-line branch on Linux after the first switch; CI caught it as a
30s timeout in status-line-vcs-refresh.test.ts.
- Added git.head.watch: fs.watchFile stat-poll of the HEAD path (reftable dir
for reftable repos) with a disposer; path-based polling survives inode swaps
on every platform.
- Status line and footer now consume the helper; the footer previously bound
fs.watch to the HEAD file inode and died after one switch on all platforms.
- Dropped the FSWatcher error-listener plumbing (StatWatcher has no error
mode) and reworked the watcher lifecycle tests to the stat-poll contract;
verified the atomic-rename regression test passes on Linux bun 1.3.14 in
Docker where it previously timed out.
- Replaced time-based sleeps and polling loops with event-driven promise resolvers and fake timers across agent and tool tests.
- Migrated test suites to share in-memory auth storage and fixtures using lifecycle hooks.
- Updated catalog model definitions, metadata, and configurations.
- Stage transcript initialization inside a detached TranscriptContainer to keep existing messages visible during incremental rendering.
- Add fallback state restoration in InteractiveMode.renderInitialMessages when chat rendering is aborted or fails.
- Update render-initial-messages tests to assert that old transcripts remain visible until replacements are fully committed.
The deterministic replay oracle only models in-place resize for tmux and
direct HerdR, but an inherited PI_TUI_RESIZE_IN_PLACE=1 makes the runtime
treat every scenario as in-place and desyncs the oracle. Add the key to
the stress env patch so a developer's override cannot leak into replay.
The HerdR flicker fix routed direct HerdR panes onto the in-place
multiplexer resize path, but the randomized render-stress oracle still
modeled them as ED3 replaying direct terminals. The width-epoch ledger
now applies to any in-place-resize scenario (multiplexer + direct HerdR)
via a dedicated resizeRepaintsInPlace trait, keeping HerdR's direct
scrollback semantics intact. Adds a deterministic replay regression
(seed 0xcafed00d, 24 iterations) that fails without the oracle update.
The executable version probe added in ecb22957 ("validate Linux browser
executables") replaced the file-only check in resolveSystemChromium with
isChromiumExecutable, which spawns the candidate `--version` for every
platform. On Windows chrome.exe is a GUI-subsystem binary: `--version`
does not print to a detached stdout and can hand off to a running
instance, opening/activating the user's normal browser window, after
which the probe rejects the candidate and falls back to cached Chrome
for Testing.
Gate the spawn probe on process.platform === "linux" (its intended
platform, where non-Chromium PATH wrappers are the real risk) and trust
the executable-file check on Windows and macOS.
Fixes#8445
The win32 addon static-CRT switch enabled the static_link_msvcrt cc
feature, but audiopus_sys's bundled opus is built through the generated
CMake toolchain, which pinned CMAKE_MSVC_RUNTIME_LIBRARY=MultiThreadedDLL
(/MD) as authoritative under CMP0091 NEW. The opus objects could then
still emit /MD and pull VCRUNTIME140.dll / conflict with the static CRT
the rest of the addon links, leaving the outcome dependent on compile-
flag ordering.
Pin CMAKE_MSVC_RUNTIME_LIBRARY to MultiThreaded (static release /MT) in
the msvc toolchain.cmake so opus deterministically matches rustc's
+crt-static and the static_link_msvcrt feature.
Verified with a fully cold `bazel build //:natives-win32-x64-baseline`
(opus recompiled): the produced .node imports no VCRUNTIME140.dll and no
api-ms-win-crt-* — only core Windows system DLLs.
Fixes#8439
The shipped win32-x64 pi_natives addon linked the dynamic MSVC CRT (/MD)
and imported VCRUNTIME140.dll from the Visual C++ Redistributable, which
is absent on a clean Windows install. LoadLibrary of the extracted .node
then failed with error 126 ("The specified module could not be found"),
so omp could not start after a fresh `irm install.ps1 | iex`.
Static-link the CRT for the win32 addon: +crt-static for rustc (crate
BUILD select) plus the static_link_msvcrt cc feature enabled for win32 in
the native_addon transition, so its C deps (opus/cmake, tree-sitter,
blake3, ring) compile /MT in lock-step. The rebuilt .node imports only
core Windows system DLLs -- no VCRUNTIME140.dll, no api-ms-win-crt-*.
Fixes#8439