The CI harness exports PI_TEST_RUNTIME=1, which the wrapper subprocess
inherited; isBunTestRuntime() then suppressed unref in the worker client
and deterministically kept the wrapper alive until the test timed out.
Override PI_TEST_RUNTIME=0 in the wrapper env and restore the 10s bound.
- Updated sdk-tool-activation expectations for 386385f18b: sessions
without a granted write tool keep extension/SDK tools top-level and
allocate no xd:// state instead of auto-granting write.
- Raised the unref'd-worker parent-exit repro to a 30s timeout; the 10s
ceiling SIGTERMed the wrapper (exit 143) on shared-core CI runners.
386385f18b made xd:// mounting require both granted transport halves and
stopped auto-granting write; a read-only session now surfaces deferred
MCP tools top-level. The test still encoded the old auto-grant contract.
- Implemented new shell builtins including `top`, `pgrep`, `pkill`, `pidwait`, and `kill`.
- Added a cross-platform process snapshot module supporting Linux, macOS, and Windows.
- Extended job and process handling utilities with process iteration and handle termination methods.
- Replaced test mutex locks with thread-local counters to prevent test races in the minimizer engine.
- Parsed OpenRouter reasoning effort ladders and defaults during discovery.
- Preserved explicit thinking metadata from models.yml patches.
- Regenerated the catalog and covered both regression paths.
Fixes#7307
- Make over-context models selectable in the model picker by graying them instead of disabling them.
- Trigger automatic session compaction with the current model prior to switching when an over-context model is chosen.
normalizeGeneratedTitle only guarded emptiness and the none sentinel, so
when the tiny title model ignored the titling task and answered the first
user message, its full one-line reply became the session title verbatim.
Bound accepted titles to 80 chars / 12 words and return null past that,
deferring titling to the next user turn. Both the online and local-worker
paths funnel through this normalizer, so both are covered.
Fixes#7303
- Prevent xdev state allocation and tool mounting in sessions lacking a write tool.
- Expose discoverable tools top-level instead of auto-granting write transports.
- Change the default MCP JSON-RPC request ID format from snowflake strings to sequential integers.
- Update server configuration schema, connection equivalence checks, and tests to reflect the new integer default.
Routed direct custom-message conversion through the collab steering transform so side requests and compaction see the same enveloped user turn as primary requests.
Extended the regression test to exercise convertToLlm without transformContext.
Converted user-attributed collab prompt frames to prioritized user messages only on the model-facing path, preserving guest details in persisted transcript frames.
Added regression coverage for the provider role, steering envelope, and retained guest attribution.
Fixes#7288
The compiled registry enumerated each `exports` wildcard with a single-level
glob and explicitly skipped any key containing a slash, so a nested subpath
like `slash-commands/helpers/active-oauth-account` never entered the bundled
registry. Node matches `*` across `/`, so that import is legitimate: it
resolves from source, then falls through to `Bun.resolveSync` inside a
compiled binary and dies under bunfs. Reproducible on the published 17.2.1
binary with a real extension (`quota-hud.ts`).
Enumeration is now recursive, with every path segment held to the same
private/hidden rules as the leaf, so a `.private/` or `_internal/` directory
is no more exported than a private file. Directory index modules stay
excluded: `./x/*` must not serve `x/y` from `y/index.ts`, which Node would
not resolve either.
The move fence intentionally defers a flushSync landing in the rename window; full synchronous durability there is incompatible with orphan-avoidance for a rename-based, Windows-safe move. Document the caveat honestly instead of implying parity with the in-place rewrite path.
Refs #7270
The move fence bumped #diskEpoch, which no-oped any disk task already queued at the prior epoch (e.g. a header-only ensureOnDisk materializing rewrite), losing explicitly materialized ACP/draft sessions. Gate the append hot path on #sessionFileRelocating instead of a fresh epoch, so prior disk work still drains.
Fixes#7270
A fenced append followed by a Ctrl+C flushSync in the post-rename, pre-repoint window rewrote the full body to the old path, recreating the orphan. Sync rewrites now defer while the session file is relocating.
Fixes#7270