- Updated eager compaction and plan reference tests to track call indices and task delegation markers instead of text strings.
- Removed obsolete context message marker checks, vibe mode assertions, and prompt gating test cases.
- Simplified prewalk, workflow, and Gemini instruction test expectations across agent modules.
- Removed the system prompt personality test suite entirely.
- Added Google provider thinking configuration parameters and force-reasoning-off controls.
- Implemented MCP SSE stream resumption using Last-Event-ID and `SSEResumeError`.
- Added support for TAR old-GNU sparse extension blocks, path length checks, and archive entry overrides.
- Restricted external thinking support to specific models and added semver fallback parsing.
showHookCustom hardcoded the overlay geometry and never read
overlayOptions/onHandle, which regressed the v0.45.6 API (PR
badlogic/pi-mono#667). Forward overlayOptions to showOverlay (keeping the
full-cover defaults as fallback), invoke onHandle with the returned
OverlayHandle, widen the options type via a shared ExtensionCustomOptions,
and re-export OverlayHandle/OverlayOptions from the extension API.
Key hints resolved modifier tokens through a static, platform-agnostic label map with no `super` entry, so on macOS the shipped `super+v` paste default rendered 'Super+V' (no such key on a Mac) and `alt` always rendered 'Alt' instead of 'Option'. The static /hotkeys navigation rows were hardcoded with macOS 'Option'/'Cmd' names on every platform, so Linux/Windows users saw 'Cmd+Left'.
Modifier labels are now platform-aware: on darwin `alt` renders 'Option' and `super` renders 'Cmd'; every other platform keeps 'Alt'/'Super'. The platform is resolved through a single seam (setKeyHintPlatform/keyHintPlatform) mirroring the TUI's setKittyProtocolActive, keeping hint output deterministic in tests without mutating process.platform. The static /hotkeys rows use the same convention and drop the macOS-only Cmd line-start/end fragments (which map to no binding) off darwin.
Fixes#8235
The existing assertion encoded the exact behaviour #8030 reports as the bug:
it required that no `133;C` ever be emitted, which is what leaves Ghostty's
sticky `.input` cursor semantic latched for the rest of the session.
Rewrite it around the property the fix actually guarantees. The marker must
now be present, but it must be immediately followed by `133;D;0` and appear
exactly once per bubble, so the command zone is opened and closed within the
same render and later assistant/tool output is still never grouped under the
submitted prompt. That was the real concern behind the original assertion,
and it is now checked directly rather than by proxy.
Refs #8030
- Gated model-issued approval dialogs on the TUI tool preview lifecycle.
- Finalized edit arguments before waiting for the asynchronous diff.
- Added regression coverage for both the preview gate and approval ordering.
Fixes#7957
- A provider-supplied retry-after now bypasses the transient rate/concurrency
heuristic window instead of being overridden by it (regression from the
subscription-cap retry change).
- Updated event-controller/ui-helpers test doubles for provenance-gated
renderer selection (hasBuiltInTool), aggregated retryErrors on
auto_retry_end, and Bedrock override compat gaining streamIdleTimeoutMs.
The handoff catch in session-handoff.ts and the /handoff handler in
command-controller.ts mapped any error named AbortError to "Handoff
cancelled" regardless of whether the handoff signal was actually
aborted. Providers throw name-AbortError errors on non-user conditions
(stalls, idle timeouts, nested resolution failures), so a genuine
generation failure surfaced as a user cancellation and hid the cause.
Only report "Handoff cancelled" when handoffSignal.aborted is set;
re-throw the real error otherwise. The controller now trusts the
normalized "Handoff cancelled" message and drops its own AbortError
check so re-thrown provider failures render as "Handoff failed: ...".
Fixes#7903
Seven session entry types — title_change, credential_pin, mode_change,
service_tier_change, ttsr_injection, reset_boundary and session_init —
fell through #getEntryDisplayText's default branch to the empty string,
and none of them were in the default view's hidden set. Each one drew as
a bare bullet: a row you cannot read, cannot identify and cannot explain
the gap it leaves in the thread.
Hide them in the default and no-tools views, alongside the settings
entries they resemble, and give every one of them a label for `all`
mode. The default branch now falls back to the entry type rather than
the empty string, so a type added later degrades to a dull row instead
of an invisible one. Service tier renders its per-family map, and says
"(default)" when the tier was cleared instead of printing null.
- Routed session tool provenance through live and rebuilt transcript render paths.
- Kept same-named extension tools on the generic renderer while preserving native tool rendering.
- Added regression coverage for an external recall result collision.
Fixes#7770
After the fullscreen Plan Review closed on approve-and-execute, the
conversation view stayed blank while the plan ran. The propose write's
tool_execution_end handler runs inside EventController's serialized
dispatch chain and awaited handlePlanApproval, which awaits session.prompt
for the entire execution turn, so every later agent_start/message_start/
tool/message_update event queued behind it until the run finished.
Detach the approval dispatch so the dispatch link settles immediately and
the execution turn's events render live. Follow-up to #5688, which only
moved the overlay close before the still-blocking dispatch.
Fixes#7684
Reaching the `isTerminal === false` branch means the superseded-turn guard
above it already passed, so `session.isStreaming` is false: a command
issued from that point mounts immediately while panels queued earlier in
the turn stay in `#pendingCommandOutput` until some later terminal
agent_end. Newer output rendered ahead of older, and the queued panel
could strand for minutes on an async fan-out that keeps settling
non-terminally.
Flush there too. The transcript is quiescent at a settle, which is the
condition #4806 wanted, and the notice now says "until the agent pauses"
rather than promising the current turn.
Added the no-op setter to lightweight print-mode session mocks so text-mode runs without a submitted prompt no longer throw at the final commit call.
Fixes#7625
- Introduce `@oh-my-pi/omptype` as a new ArkType-compatible schema validation package featuring a lazy JIT runtime, JSON Schema emission, and compatibility adapters.
- Replace `arktype` across workspace packages and test utilities with `@oh-my-pi/omptype`.
- Add benchmark suites, tests, and documentation for the new validation engine and adapters.
- Update workspace build, test runner, and release configurations to include the new package.
Reserve the plain b shortcut only after /btw has a completed answer or a branch is already pending. Running, empty, aborted, and failed panels now leave the key for the composer, while completed-but-refused branches still consume it with an explanation.
Fixes#7474
Branched session files preserve entry ids, so leaf-id equality alone let a stale /btw answer promote into a different loaded session. Capture the originating session id at /btw start and require it to match at both the controller gate and every branchFromBtw checkpoint.
Fixes#7474
- Passed the authorized leaf through the branch executor and revalidated it before rewriting history.
- Refused promotion during active turns and bounded post-prompt drains.
- Consumed unavailable branch keys while showing pending and refusal state in the panel.
Fixes#7474
- The 'N tool calls elided' replay placeholder leaked tool activity while
display.hideToolActivity was on; it is now a visibility-aware component
wired into both the hotkey and /settings toggle paths.
- Added replay + live-reveal regression coverage.
The isTerminal:false early-return skipped #finishAgentEnd, the only site
that flushes a deferred plan-mode model switch, so an automatic continuation
(async wake) ran on the old model/thinking level until the terminal settle.
Flush the pending switch on the non-terminal branch before returning; the
title/loader teardown stays deferred to the terminal agent_end.
EventController.#handleAgentEnd guarded only on session.isStreaming, so a
non-terminal agent_end (isTerminal:false, emitted while an async job will
re-wake the loop) flipped the terminal title to idle and tore down the
working loader while a /vibe worker or async bash job was still running.
Early-return on event.isTerminal === false, matching the guard every other
agent_end consumer already applies; the later terminal agent_end performs
the normal teardown.
Fixes#7386