Codex review flagged that /tmp/a.png ./b shot.png slipped past the
interior-anchor guard (absolute prefixes only) and fused into one bogus
attach that swallows the paste. Add ./, ../ and .\ as second-path
anchors; bare relatives (dir/b shot.png) stay recoverable because an
interior token/ after a space is exactly the shape of a spaced
directory name (/Users/me/My Photos/shot 1.png). 4 tests pin both
sides of the boundary.
When Cursor packs toolCallStarted and toolCallCompleted into one HTTP/2
chunk, the bridge tool_execution_end (synchronous callback, fired
mid-parse) reaches the interactive controller before the streamed
toolcall_start (queued on AssistantMessageEventStream, delivered a
microtask later). The controller found no pendingTools entry, dropped
the completion, and the card created afterwards animated forever.
Two halves, each necessary:
- Hold an early todo completion in #orphanedToolCompletions and replay
it when the streamed block creates its component.
- Guard card creation from cumulative message_update frames with the
turn-scoped #toolTimelineComponents map. Without this, the update
after the replay re-lists the same toolCall block, finds pendingTools
empty again, and spawns a second, permanently pending card. This is
also why emitting a synthetic tool_execution_start from the bridge
(previous attempt, reverted) could not work.
Both maps are cleared together at the existing transcript-anchor reset
sites. The normal ordering (start first) is covered by a control test.
Two review findings on the native todo sync.
- TodoItem.dependencies is a graph the local model cannot store: rows
are keyed by content, carry no id, and hold no edges. An imported
dependent row files as plain pending and nextActionableTask then
offers work the server considers blocked. Refuse snapshots with an
edge pointing at an unfinished row; edges whose blockers already
finished constrain nothing and still mirror.
- The todo failure warning interpolated the provider error verbatim.
Collapse and truncate it at the render boundary.
Also documents two known, unfixed defects: an async cursorOnToolResult
transformer resolving after the buffer drain, and the todo card
lifecycle race. Emitting a synthetic tool_execution_start for the
latter was measured and rejected -- the completion deletes the entry it
creates, so the late streamed block adds a second card.
Disabling the Advisor from /settings persisted the setting but left the
live Advisor runtime running until the session restarted.
SelectorController.handleSettingChange had no case for "advisor.enabled",
unlike other session-managed toggles (autoCompact, steeringMode, ...), so
the change never reached session.setAdvisorEnabled — the same call /advisor
off already uses to stop the runtime immediately.
omp config list printed every configured value, including auth.broker.token,
searxng.token, searxng.basicPassword and dev.autoqaPush.token, in both the
human and --json output. Nobody asked for those specific credentials; the
command dumps everything.
Credentials are marked with a top-level credential flag rather than ui.secret,
because four of them have no settings-panel entry and so have nowhere to put a
UI-level flag. isCredential is the single accessor both the CLI and the panel
consult, so the two spellings cannot produce different behaviour on different
surfaces.
Human output shows dots. JSON omits value and marks the entry redacted instead
of substituting a placeholder, which a consumer could not distinguish from a
real value and might write back.
config get <path> is deliberately unchanged: that is an explicit request for a
single value, and masking it would break a retrieval API with no way to read
your own token back.
Disable reset-mode loops when vibe mode prevents the required session transition, so the prompt is not resubmitted into the unchanged session.
Added focused regression coverage for the blocked transition.
Fixes#6607
Blocked interactive session transitions before they reach the AgentSession vibe guard, preserving the active session and rendering the existing exit-vibe warning instead of rejecting the input callback.
Added regression coverage for new, drop, fork, and move transitions.
Fixes#6607
The whole-text-as-path fallback added in the previous commit claimed any
single-line payload starting with an absolute-path anchor, including one
holding several paths. Dragging two files at once emits
`/tmp/a.png /tmp/b shot.png`, which the segment splitter also refuses
because `shot.png` is not explicit, so the fallback fused the pair into
one unresolvable path. `handleImagePathPaste`'s ENOENT branch only
surfaces a status and — unlike its too-large and generic-error branches
— never re-pastes the text, so both paths vanished.
On `main` the bracketed route returned undefined for that payload and
fell through to a text paste, so this was a regression introduced by the
previous commit rather than behavior inherited from the clipboard route.
It is reachable by the same gesture that motivated #6578, with one more
file selected: macOS screenshot names always contain spaces.
`extractWholeTextImagePath` now rejects payloads carrying a second
absolute-path anchor after unescaped whitespace. The anchor alternation
moves into a shared `ABSOLUTE_PATH_PREFIX_SOURCE` so the leading-anchor
and second-anchor tests cannot drift apart across the POSIX, `~/`,
`file://`, UNC and Windows-drive families. Escaped whitespace is exempt,
since the escape is the terminal asserting the space belongs to the path.
Guarding the shared helper rather than the bracketed caller also settles
`extractImagePathFromText`, whose JSDoc already claimed multi-path text
falls through to a text paste while the fallback leaked around it.
Ambiguous input — a directory whose name ends in a space, as in
`/tmp/odd dir /sub/x.png` — is treated as multi-path and pastes as text:
a text paste loses nothing, a bogus attach loses everything.
11 tests added covering each anchor family, tab separation, the
escaped-space exemption and the unchanged splitter-success path.
The bracketed-paste (drag-drop) image route required every whitespace-split
segment to look path-like, so a raw macOS screenshot path (spaces unescaped,
per the attachment convention terminals implement) degraded to literal text.
Extract the keybind route's whole-text-as-path pass into a shared helper and
apply it when the segment splitter fails; route the bracketed extractor
through the stripped-marker one so both share identical detection.
Fixes#6578
handlePlanApproval and the ACP rejection path selected a resolved draft that could differ from PlanModeState.planFilePath but never updated the state, so a refine turn was rebuilt by #buildPlanModeMessage() from the stale path. Both paths now promote the reviewed path into plan-mode state.
Fixes#6569
While a provider error is pinned in the banner above the editor the inline transcript block is suppressed, so the prior guard skipped re-rendering on Ctrl+O and the full body stayed unreachable until the next turn.
- Track whether the message carries a truncatable error regardless of pinning, so setExpanded re-renders while pinned.
- Render the inline error block in full when expanded even while pinned; keep it suppressed only while pinned and collapsed.
- Disable the streaming fast path whenever the inline error block is drawn.
Fixes#6555
New live, rebuilt, and transcript-builder assistant components now inherit the active tool-output expansion state before provider errors render.
Added regression coverage for an error arriving after expanded mode was already enabled.
Fixes#6555
Turn-ending provider errors rendered inline through
AssistantMessageComponent#appendErrorBlock, capped at 8 lines with no
setExpanded method, so isExpandable filtered the component out of the
Ctrl+O tool-output expansion and the truncated tail was unreachable in
the live TUI (full text was persisted but not shown).
- Add setExpanded to AssistantMessageComponent; when expanded the error
block renders the full body (tabs replaced, blank lines preserved,
Text word-wraps to width).
- Collapsed view appends a dim "+N more lines (Ctrl+O to expand)" hint so
the truncation and its remedy are discoverable.
- Only re-render on toggle when the last render produced a truncatable
error block, so expansion skips ordinary turns.
Fixes#6555
The rebuild dedup dropped any preserved pendingTools component whose toolCallId
had a persisted toolResult. A background task's initial async.state=="running"
result is persisted while EventController#handleToolExecutionEnd deliberately
keeps its component in pendingTools so a later tool_execution_update/_end can
settle it. Dropping that still-live handle stranded those updates on the running
snapshot. Only terminal results are now owned by the replay; running async
handles stay preserved. Added a regression covering the running-task case.
rebuildChatFromMessages preserves the live pendingTools components across its
clear+replay so streaming keeps routing into them. That preservation assumed
every pending-tool component was still dangling (its result outside
state.messages). Once a tool's result had landed in the session entries while
its component still lingered in pendingTools (a rebuild racing the
tool-completion event, or a background/displaceable snapshot), the replay
reconstructed the completed block from the persisted toolResult AND the
preserved live component was re-appended, so the same tool block rendered twice.
Resolved tool calls are now dropped from the preserved live set and owned by the
replay; only genuinely in-flight (dangling, replay-stripped) calls are preserved.
Fixes#6516
- Large-paste menu now saves pastes as local://paste-N.md instead of
local://attachment-N, giving the artifact a markdown extension and a
clearer name.
computeNonMessageBreakdown estimated Skills tokens from the unfiltered
session.skills registry and subtracted that from the first system-prompt
block, which only ever contained the rendered (filtered) skills. Hidden
explicit-only skills (hide/disable-model-invocation) and all skills when
the read tool was absent inflated Skills and clamped System prompt to 0.
Add a renderedSkills helper mirroring buildSystemPrompt's filter and use
it for the Skills estimate so the category split matches the provider
prompt.
Fixes#6498
- Add `CodexAttestationProvider` hook and `getCodexAttestationHeader` resolver that gates on ChatGPT-OAuth credentials.
- Integrate attestation into WebSocket transport, SSE event stream, and OpenAI compaction requests.
- Wire `setCodexAttestationProvider(generateCodexAttestation)` in model-registry init for OAuth sessions.
- Added `LIVE_DELEGATION_MESSAGE_TYPE` constant and delegation message handling for voice sessions.
- Implemented turn-based transcript coalescing with user and assistant turn counters.
- Added transcript display row with normalized rendering in the live visualizer.
- Refactored controller to send delegation messages via `sendCustomMessage` with configurable frame styling.
- Removed microphone permission error reporting from silence detection logic.
- Switched from `miniaudio` to `maudio` Rust crate and added `AudioCapture` and `AudioPlayback` native classes.
- Removed browser-side audio infrastructure including Web Audio API, audio worklet processor, and WebRTC runtime.
- Migrated STT recorder and transcriber modules to use native `AudioCapture` with callback-based streaming.
- Replaced streaming audio player with native `AudioPlayback` that writes PCM directly without TypeScript intermediaries.
- Removed ffmpeg, wav, and platform-specific playback commands from the audio toolchain.
- Extracted #formatToolExecution into a standalone formatDefaultToolExecution module.
- Updated xdev renderXdevCall and renderXdevResult to use the default card when no mounted renderer exists.
- Added fallback rendering that shows tool label, args, and output with appropriate theming.
- Added integration test verifying generic card renders for mounted tools without bespoke renderers.
- Add `pinSessionOAuthAccount` storage method and active account flag to the auth storage API.
- Introduce session account selector component, controller logic, and interactive mode delegation.
- Implement the `/session pin` builtin slash command with text listing and account pinning capabilities.
- Add unit tests covering session account selection, component navigation, and command handling.
Scheduling agent.continue() inside navigateTree started a post-prompt
task before the interactive /tree handler rebuilt its transcript, so a
fast provider's agent_start/turn_start could render against the stale
pre-rebuild UI and then be clobbered by renderInitialMessages.
navigateTree now reports the commit via askReanswerCommitted instead of
resuming, and SelectorController.showTreeSelector calls the new
AgentSession.resumeAfterAskReanswer() only after renderInitialMessages +
reloadTodos, so the resumed turn always renders against the rebuilt
transcript.
Addresses chatgpt-codex-connector review on #6484.
Fixes#6483
requestRender(true) only queues the paint via setImmediate; calling
prewarm() synchronously afterwards put the worker spawn syscall ahead
of the render callback in the same loop turn. Schedule the prewarm
with its own setImmediate (FIFO after the render callback) so the
first startup frame paints before the subprocess spawns.
The first interactive submit fired session.generateTitle() before
startPendingSubmission() painted the optimistic user row, and
tinyTitleClient.generate() spawned the local tiny-title subprocess
synchronously in #ensureWorker() before its first await. With a local
providers.tinyModel configured, subprocess-spawn latency therefore landed
ahead of the first frame, stalling the first prompt.
Paint the pending row before starting titling, and prewarm an idle,
unref'd worker at TUI startup via a no-op ping (no model load) so the
first submit reuses a live subprocess.
Fixes#6462
- Added `src/live/` subsystem with WebRTC transport, protocol parser, session controller, and headless Chromium audio injection.
- Added `LiveVisualizer` component with phase states, transcript display, and animated waveform rendering.
- Added `/live` slash command and `LiveCommandController` to toggle live voice sessions.
- Suppressed local TTS via `vocalizer.suspend()` during live mode to prevent audio conflicts.
- Added live-instructions and agent-final-message prompts for agent messaging context.
- Added `protocol.test.ts` covering event parsing, chunking, and context message construction.
- Pinned displaceable snapshots like hub waiting polls and todo lists to the viewport during active execution.
- Prevented unpinned spinner ticks from repeatedly committing mutating rows to native scrollback and force-sealing blocks.
- Extracted internal handlers and logic from AgentSession into dedicated runner, guard, and coordinator modules.
- Created standalone modules for bash execution, evaluation runners, IRC bridging, and prewalk coordination.
- Established dedicated session components for tracking stats, todos, streams, and retry fallback chains.
- Preserved existing session behavior while significantly reducing monolithic class size and complexity.