The runner stacked two independent parallelism knobs: OMP_TEST_CONCURRENCY
spawned N `bun test` processes while each process ran its own --parallel=M
test files, so the workspace bucket put 4 x 8 = 32 files in flight on a
4-core runner. bun's per-test timeout is wall-clock, so CPU-starved suites
crossed the 5s default and failed at random - mnemopi's sqlite/CLI files
tripped a different pair every run.
- TestCommand now carries a `parallel` request instead of baking the flag
into argv; the dispatcher resolves it against one shared budget
(availableParallelism x 2, split by the live pool width) so total
in-flight files track the machine. A chunk that runs alone still gets
its full requested width, leaving the sequential CI path unchanged.
- Raised the per-test timeout to 30s (OMP_TEST_TIMEOUT to override).
Suites here build real SQLite schemas and spawn CLIs, already running
1-4s per case on a quiet runner; the 10-minute chunk watchdog stays the
backstop for an actual hang.
- --dry-run now resolves the same budget, so it prints the argv a real run
would use, and the pool header reports cores plus the granted width.
- Dropped the dead `{ smol: true }` argument: workspaceTestCommand never
accepted it, and this file's own findings say a smaller heap makes bun
1.3.14's GC crash more often, so it should not be wired up.
- 28 symbols across discovery, mcp header policy, agent-hub projection and
rendering, the agent registry, shell tokenizing and changelog comparison
were exported but referenced only inside their own module; they are now
module-private, shrinking the deep-import surface.
- Kept AGENT_PLUGIN_MANIFEST_SCHEMA, AGENT_PLUGIN_MCP_SCHEMA,
parseAgentPluginManifest, clearAgentPluginRootCache and mergeMCPHeaders
exported: each is a seam for tests that defend real parsing or header
precedence behavior.
- Nothing reachable from an explicit exports entry or public barrel changed.
- src/lsp/index.ts is the explicit ./lsp package entry, yet held 2821 lines of
warmup, config caching, diagnostics, external build-command workspace
diagnostics, the writethrough batching subsystem and the LspTool class.
- Those are now servers, diagnostics, workspace-diagnostics, writethrough and
tool modules; index.ts is 22 lines and re-exports the same public surface.
- configCache and writethroughBatches remain single instances and every tuned
diagnostics timing constant moved verbatim.
- Moved the module-level machinery that sat in front of the ModelRegistry
class into model-config-values, model-patch, custom-models and
model-provider-discovery; model-registry.ts drops 646 lines.
- commandValueCache and its negative-cache TTL stay single instances, so the
execSync storm the cache exists to prevent cannot return.
- The setCodexAttestationProvider import-time side effect stays in
model-registry.ts. The class itself was left alone: its private state is
shared across the methods, so splitting it is not a straight move.
- theme.ts mixed symbol presets, JSON schema, color math, the Theme class,
loading, global state, appearance handling and TUI adapters in 3171 lines.
- Symbols, schema, color, theme-class, loader and tui-adapters are now
siblings; theme.ts keeps global state, the watcher, appearance handling and
HTML export at 745 lines, with all 44 exports intact.
- Left appearance and export-colors in place: both read private mutable
auto-theme state, so extracting them would have required new exported
internals or DI rather than a straight move.
- Separated deterministic replacement generation, placeholder derivation,
placeholder-range scanning and message-tree transforms out of the 2647-line
module; obfuscator.ts now holds the types and SecretObfuscator.
- ephemeralPlaceholderKey stays a single instance and both global regexes stay
beside the code that resets their lastIndex, so placeholder stability and
the security argument in the moved comments are preserved verbatim.
- Repointed every importer at the real modules rather than leaving a re-export
shim; the public ./secrets barrel exports the same 15 names as before.
- gh.ts held wire types, search, Actions run-watch, PR checkout/push/create,
PR diff parsing and view fetch/format in 3958 lines.
- Split into gh-types, gh-search, gh-run-watch, gh-pr-checkout, gh-pr-diff,
gh-view and a gh-common module holding the shared primitives and the single
process-lifetime default-repo memo pair; gh.ts is now 246 lines.
- All 22 exports stay on gh.ts because tools/index.ts star-exports ./gh, so
the issue:// and pr:// protocol handlers needed no edits.
- ReadTool mixed plain-file reading with archive, sqlite, pdf-image, summary,
selector, formatting and renderer concerns in one 3763-line module.
- Each now owns a sibling module; read.ts drops to 2020 lines and keeps its
public exports, including the readToolRenderer re-export required because
tools/index.ts star-exports ./read through the explicit ./tools entry.
- The pdfImageExtractions map and summaryParseCaches WeakMap stay single
instances; execute() was deliberately left intact.
- builtin-registry.ts held a 2341-line array of every command spec with its
handler inlined, plus the autocomplete builders and the TUI dispatcher.
- Specs moved verbatim into modes, collaboration, session, lifecycle,
marketplace and control modules; completions moved to builtin-completions.
- builtin-registry.ts is now a 174-line composition/dispatch module and keeps
all 16 exports. Command order is unchanged, which matters because it drives
autocomplete ordering and BUILTIN_SLASH_COMMAND_DEFS.
- Python, Ruby and Julia each carried their own copy of the same session
maps, acquire/reset/replace/dispose lifecycle and executeOnSession; one
generic registry now owns it, parameterized by a per-language descriptor.
- Julia additionally re-implemented seven executor-base helpers locally; those
copies are gone and executor-base gained sparse managed-env and timeout
resolver hooks so Julia's differing behavior survives unchanged.
- All twelve exported entry points keep their names and signatures.
- Added one internal generic builder covering the repeated apiKey/baseUrl
resolution, bundled reference map, providerId and fetchDynamicModels closure.
- Migrated openai, cerebras, novita, aimlApi, alibabaCodingPlan, venice,
baseten and moonshot, and routed createSimpleOpenAICompletionsOptions
through it; deleted the duplicate responses-side helper.
- Preserved fetchDynamicModels key PRESENCE per site, since the apiKey spread
guard omits the key entirely rather than setting it undefined.
- Deleted usage/shared.ts's duplicate toNumber; every consumer in the directory
now resolves the single catalog implementation.
- Promoted HOUR_MS, DAY_MS, WEEK_MS, parseIsoTimestamp, parsePositiveTimestamp
and usageStatus into usage/shared.ts and dropped the local copies.
- Left the epoch coercers, status thresholds and base-url normalizers alone:
they disagree on the 1e12 boundary, non-positive values and warn levels, so
merging them would change reported usage.
- Nine providers reimplemented createApiKeyLogin's exact prompt/trim/abort flow
verbatim; they now call the existing helper instead.
- Extended ApiKeyLoginConfig with optional authUrl/instructions and an
emptyKeyFallback so the local-server family (llama.cpp, vLLM, LM Studio)
collapses onto the same helper without changing observable behavior.
- Left ollama, ollama-cloud, nvidia, qwen-portal, github-copilot and both
alibaba flows hand-written: their error classes, messages or callback
ordering differ, so migrating them would change observable behavior.
clippy-strict (nursery redundant_pub_crate, -D warnings) rejects pub(crate)
items inside the crate-private device module; plain pub is equivalent there.
Applied across all platform backends since CI only lints the linux cfg.
- Replaced the miniaudio dependency with custom OS audio device abstractions and backends.
- Implemented platform-specific audio playback and capture for macOS (Audio Queue), Windows (WASAPI), and Linux (PulseAudio/ALSA).
- Added a fallback stub backend returning errors for unsupported platforms.
- Updated audio stream handling with reliable fill guard wakeups and streamlined rate validation.
- zune-jpeg 0.5.15 (image 0.25's JPEG decoder) cannot compile with its
non-default log feature off: zune-core's no-log warn! stub is not
expression-safe. A feature-activation-only workspace dep on
zune-jpeg { features = ["log"] } fixes the cold build; log stays 0.4.33.
- model-registry-default-config's local ModelSnapshot type gains the optional
streamIdleTimeoutMs the Bedrock watchdog compat now emits.
- The two-child fs.watch/poll choreography deadlocked under parallel test load
(runner killed a dangling probe); the PID-namespace pruning test still covers
the multiprocess audit/rotation file contract.
- A provider-supplied retry-after now bypasses the transient rate/concurrency
heuristic window instead of being overridden by it (regression from the
subscription-cap retry change).
- Updated event-controller/ui-helpers test doubles for provenance-gated
renderer selection (hasBuiltInTool), aggregated retryErrors on
auto_retry_end, and Bedrock override compat gaining streamIdleTimeoutMs.
Preserved zero-width readiness and wait matches across the daemon wire protocol, and isolated malformed completion events from unrelated pending RPCs.
Fixes#7908
Added the upstream unregisterProvider lifecycle to queued and initialized extension runtimes. Provider removal now clears runtime model/auth state before replacement, while failed factories restore the prior registration queue.
Fixes#7914
An interrupted fastembed model download leaves <cacheDir>/<model>/ with
sidecars and a truncated model.onnx_data but no model.onnx. Upstream
retrieveModel short-circuits on the existing dir (and reuses a leftover
partial <model>.tar.gz), so FlagEmbedding.init throws "Model file not
found at .../model.onnx" every session: semantic recall silently dies
machine-wide and reconcileEmbeddingModel re-enqueues the same
never-embeddable rows on every store open.
quarantineCorruptModelFile only matched "Protobuf parsing failed", never
this partial-extraction variant. Add clearIncompleteModelCache: a
"Model file not found" init failure now removes the incomplete model dir
and the leftover partial archive (containment-guarded to a direct child
of the fastembed cache root) and retries init exactly once, so the next
attempt re-downloads cleanly and recall self-heals.
Fixes#7916
- Tracked pointer and keyboard grants from the RemoteDesktop response.
- Drained asynchronous EIS announcements after the first resumed device.
- Covered GNOME's keyboard-before-pointer ordering with a regression test.
Fixes#7926
Published per-cwd discovery snapshots to existing task tools and refreshed them from TUI, ACP, and Agent Control Center reload paths.
Added regressions for existing and future task tools across TUI and ACP reloads.
Fixes#7940
A cooldown-expiry model revert runs at a turn boundary. The user-prompt
path reverts then re-checks accumulated context against the restored
model via runPrePromptCompactionIfNeeded, but the automatic
agent.continue() path (#scheduleAgentContinue) reverted and issued the
next request with no such check. When a transient failure had fallen
back to a larger-window model and the conversation then grew past the
original model's window, restoring the primary once its cooldown expired
sent a predictably oversized request to the smaller model.
maybeRestoreRetryFallbackPrimary now reports whether it actually
switched, and the auto-continue path runs the same post-revert
context-fit maintenance (compaction/promotion) the prompt path already
runs, but only when a revert occurred.
Fixes#7952
Follow-up head of the same PR, merged after the sweep landed cf5bd72877:
bounds the consent-denied portal close inline (a nested block_on would panic)
and removes the world-readable pre-#7884 RemoteDesktop restore token.
- Runtime error now just says to download vscode-js-debug from its GitHub repo;
tarball recipe, extract path, env var, and Mason detail stay in docs/tools/debug.md.
Pre-#7884 builds wrote a world-readable RemoteDesktop restore token under $XDG_STATE_HOME/omp/remote-desktop-token during read-only calls, and nothing on the fixed tree reads, rewrites, or removes it. WaylandBackend::new now unlinks it best-effort on construction so the stale credential does not survive the upgrade.
Fixes#7884
The SelectDevices/Start/ConnectToEIS failure arm closes the RemoteDesktop session from inside runtime.block_on, so it cannot use close_session (a nested block_on panics). Bounded it with an inline tokio::time::timeout(CLOSE_TIMEOUT, ...) so a frozen xdg-desktop-portal on the ordinary denied-consent path no longer hangs the worker thread.
Fixes#7884
The handoff catch in session-handoff.ts and the /handoff handler in
command-controller.ts mapped any error named AbortError to "Handoff
cancelled" regardless of whether the handoff signal was actually
aborted. Providers throw name-AbortError errors on non-user conditions
(stalls, idle timeouts, nested resolution failures), so a genuine
generation failure surfaced as a user cancellation and hid the cause.
Only report "Handoff cancelled" when handoffSignal.aborted is set;
re-throw the real error otherwise. The controller now trusts the
normalized "Handoff cancelled" message and drops its own AbortError
check so re-thrown provider failures render as "Handoff failed: ...".
Fixes#7903