- Added `tools.artifactHeadBytes` and `tools.outputMaxColumns` settings with defaults in `SETTINGS_SCHEMA`.
- Expanded `OutputSink` with `headBytes`/`maxColumns` and middle truncate logic with elision markers and tracking.
- Updated output-meta to resolve sink settings, emit truncation metrics, and use `truncateMiddle` for spills.
- Integrated head and column limits into JS/Python/Bash/SSH/read output flows, with `:raw` skipping read truncation.
- Documented new output middle-elision and column-cap behavior in `CHANGELOG.md`.
- Added truncation tests for `OutputSink`, `truncateMiddle`, and read-tool line handling.
- BashTool dispatches execution through the client bridge terminal channel when a bridge is present, falling back to local PTY otherwise
- ReadTool and WriteTool gate filesystem access through ACP permission checks
- Exports new tool wiring in the tools barrel
- Hardened `parseUrl` to decode each internal segment and reject empty, `.` or `..` segments.
- Added `AbortSignal` propagation through `ReadTool` into internal URL resolution to honor cancellation.
- Adjusted markdown rendering in `read` output so raw selector reads bypass markdown formatting.
- Aligned `conflict://` help text in `read`/`write` with URI read-path examples for scope conflicts.
- Updated event-controller read-tool streaming handling to wait for a parseable target before routing tool calls, avoiding early component binding for unresolved arguments.
- Allowed internal-URL read calls to bypass the regular read grouping path and fall through to direct tool execution.
- Adjusted read tool rendering to honor the computed `expanded` flag for completed output instead of forcing expanded output.
- Fixed `issue://owner/diff` and `pr://owner/diff` parsing so they resolve to issue and PR list outputs.
- Fixed `pr` short-form parsing by requiring `scheme==='pr'` and a numeric host before `diff` matching.
- Fixed PR unified-diff parsing to decode quoted header paths and count `----`/`++++` hunk lines as one deletion/addition.
- Fixed `read` error rendering to emit status blocks with cleaned, range-aware, tab-normalized lines.
- Stopped `github-cache` from chmod-ing existing parent directories, preserving pre-existing permission modes.
- Added readArgsTargetInternalUrl in the read tool group component to detect targets handled by InternalUrlRouter from path or file_path arguments.
- Updated event-controller and UI helper read rendering paths to skip grouping read tool calls when those arguments target internal URLs.
- Passed session cwd and settings into internal URL resolution in read.ts and added tests for internal versus non-internal target detection.
- Added `:conflicts` and `read conflict://<N>`/`read conflict://<N>/<scope>` support and rejected wildcard conflict reads.
- Added bulk conflict resolution via `write({ path: "conflict://*", ... })` across files with per-file grouping.
- Expanded conflict detection to scan files up to 10MB, track insertion-ordered history, and report full `X of Y` summaries.
- Reworked `spliceConflict` to match marker blocks by content, fixing shifted or stale block splicing.
- Added coverage for wildcard parsing, scoped reads, prepended-line splices, relocation, and warning assertions in detect/integration tests.
- Added `ConflictScope` parsing for `conflict://<N>/<scope>` with `ours`, `theirs`, and `base` validation.
- Added `read` support for full and scoped conflict URIs, rendering regions via `#readConflictRegion` with preserved formatting metadata.
- Added conflict-count and error handling in read results, including `Conflict #N not found` responses.
- Added `write`-path rejection for scoped conflict URIs, returning `ToolError` before lookup to enforce read-only behavior.
- Added unit and integration tests for scope parsing, conflict rendering, and read/write conflict error scenarios.
- Added conflictCount metadata and warning badge output to read results for files with unresolved conflicts.
- Added conflict detection parsing with strict marker matching and session-scoped conflict IDs.
- Added write-path conflict resolution for `conflict://N` using token expansion and marker validation before splicing.
- Added unit and integration tests for conflict scanning, history lifecycle, URI validation, and workflows.
- Added process-wide singleton instances for InternalUrlRouter, AsyncJobManager, and MCPManager.
- Changed internal URL protocols to resolve through registered sessions and scan all active roots/datasets for matches.
- Refactored agent, artifact, memory, rule, skill, jobs, and mcp handlers to use shared manager and rule/skill state.
- Removed per-session protocol/tool wiring and switched tests to initialize and reset global singleton state.
- Added immutable metadata to protocol handlers and had the router copy each handler's setting onto resolved internal resources.
- Updated read and search tools to honor `resource.immutable`, and made search suppress hashline anchors only for immutable source paths while preserving them for mutable files.
- Expanded internal URL tests to cover mutable local resources and mixed immutable/mutable search input hashline behavior.
- Extended splitPathAndSel to detect compound selectors that combine a line range with `raw` in either order.
- Updated read selector parsing to support `:lines:raw` and `:raw:lines` selectors and propagate raw-mode handling through internal URL, archive, and notebook paths.
- Added tests covering compound selector syntax and confirming it returns verbatim content without anchors or line-number prefixes.
- Extended file-display resolution to accept an immutable flag and suppress hashline anchors when immutable sources are requested.
- Plumbed immutable propagation through ReadTool and SearchTool so internal URL reads and searches pass that context.
- Added a regression test confirming artifact:// search output no longer includes hashline anchors.
- Added `listWorkspace` native binding and API types, exporting bounded workspace trees with AGENTS.md candidates.
- Reworked `buildWorkspaceTree` and `buildDirectoryTree` to call `listWorkspace` with 5s timeout defaults.
- Replaced startup AGENTS.md discovery with workspace-tree-only scanning and removed legacy AgentsMdSearch session plumbing.
- Updated `WorkspaceTree` and system prompt context to expose `agentsMdFiles` and aligned tests/changelog expectations.
- Added `./hashline` package exports and redirected callers to the new hashline entrypoint.
- Moved hashline logic out of `edit/` to `src/hashline` and removed `edit/modes/hashline`/`edit/line-hash` paths.
- Added hashline parsers, anchors, types, and diff helpers with stricter input and mismatch validation.
- Implemented preflight and cache-recovery execution flows to reapply edits and handle stale anchor mismatches.
- Documented the hashline API relocation as breaking changes in `CHANGELOG.md`.
- Implemented hashline stale-anchor recovery using cached reads and a 3-way merge fallback.
- Updated hashline execution and preflight checks to retry mismatched anchors through cache recovery.
- Added file-read cache support with per-session LRU snapshots and contiguous/sparse record APIs.
- Integrated read and search tools with the shared cache to record candidate lines for recovery.
- Added tests for stale-anchor recovery flows and FileReadCache session, null, overlap, and eviction behavior.
- Expanded read tool range calculations to include optional leading and trailing context lines around user-requested offsets and limits.
- Added shared context range expansion logic so line-slice and streaming reads return anchor-safe windows while preserving existing truncation behavior.
- Updated read-tool tests to assert boundary-offset, limit, and combined offset-limit reads now include the expected ±3 lines of context.
- Removed the read CLI argument and tool schema field so read requests no longer accept custom timeouts.
- Updated URL read handling to stop forwarding timeout values and execute URL reads without a timeout parameter.
- Standardized URL read fetching to a fixed 30-second timeout and dropped timeout metadata from URL call rendering.
- Added `.ipynb` detection and editable-cell conversion utilities, including merge/serialize helpers in `edit/notebook`.
- Rerouted hashline, patch, and replace edit flows, plus read/write paths, through notebook-aware helpers before persistence.
- Removed the dedicated `notebook` tool, its schema flags, renderer, and built-in registration/settings checks.
- Updated notebook read behavior, docs, and tests so `.ipynb` reads return editable `# %%` cells and edits reserialize to JSON.
- Added optional `loadMode` and `summary` fields to `AgentTool` and related type declarations.
- Added `loadMode` and `summary` metadata to built-in tool classes for discoverable/essential behavior.
- Replaced `BUILTIN_TOOL_METADATA` with per-tool fields in discovery code paths.
- Updated `search_tool_bm25` and discovery indexing to use each tool's `summary` text.
- Updated discovery tests to validate tool `loadMode` and summary completeness.
- Added a new `read.summarize.prose` setting to control markdown and plain-text read summaries.
- Updated the read tool to skip summarization for prose files unless that setting is enabled.
- Added coverage for default and enabled markdown read-summary behavior.
- Converted systemPrompt APIs and state types to ordered `string[]` across agent, AI, and coding-agent surfaces.
- Added `normalizeSystemPrompts` and applied it to context normalization before building provider request payloads.
- Updated AI providers to emit separate normalized prompt blocks/messages instead of a single merged system prompt.
- Removed dedicated `projectPrompt` state and remapped that context into system-context buckets in session, dump, and token accounting.
- Aligned tests and changelogs to pass and assert `systemPrompt` as arrays with ordered prompt semantics.
- Added DirectoryTree, DirectoryTreeOptions, and buildDirectoryTree exports for configurable tree rendering.
- Changed read tool directory output to use buildDirectoryTree with depth and exclusion limits.
- Added read.summarize settings and summary-mode parseable read output behavior when no selector is used.
- Added tests for truncated root/child listings and hidden or excluded entry filtering.
- `is_elidable_kind` now treats more AST kinds as elidable for TypeScript, Rust, and Java.
- Added summary tests for interface and class bodies in TypeScript, Rust, and Java.
- Merged brace-boundary read summary spans into a single `..` line-range representation.
- Grouped adjacent groupable nodes and emitted elision spans only after grouped runs met thresholds.
- Normalized end-line rows at column 0 and extended import-like groupable-kind rules across languages.
- Updated read-summary tests and added changelog notes for merged brace-pair `{ .. }` output behavior.
- Updated read schema, path utilities, and dispatch to parse selectors from :raw/:L suffixes on path, removing standalone sel usage.
- Changed truncation/error notices to continue with :<nextOffset> and :1 guidance for read and sqlite pagination.
- Added summarizeCode support with tree-sitter summaries, read.summarize settings, and N-API Summary types/exports.
- Added tests and docs updates for path-embedded selectors, summary behavior, and explicit raw/offset SQL/read cases.
- Added inline hashline parse and apply support for `<` prepend and `+` append operations with prefix+suffix edits.
- Added fail-fast behavior to reject inline modify ops combined with delete or replace on same line.
- Renamed HASHLINE_* and mode symbols to HL_* in prompt tooling, read/search checks, and prompt templates.
- Standardized separators to `PI_HL_SEP`/`HL_EDIT_SEP` and fixed `HL_BODY_SEP='|'`, updating parser formatting behavior.
- Updated benchmark subtype constants and python cleanup test setup to use HL_* values and AgentRegistry mock failure injection.
- Added compact Lark grammar processing and applied it to OpenAI custom-format tools before conversion.
- Reworked atom mode into `---PATH` compact commands with new grammar, parser, and rm/mv file operations.
- Updated `hline`/`href`/`hrefr` helper behavior and hashline mismatch guidance using shared anchor state.
- Standardized path formatting with `formatPathRelativeToCwd` across LSP, prompts, and edit/search/write tools.
- Added benchmark run-path handling, including `.gitignore` runs mapping, absolute reports, and safer snapshot output.
- Added tests for compact grammar payloads, atom parsing/execution, renderer streaming, and path-list outputs.
- Increased the default `read.defaultLimit` configuration from 300 to 500.
- Computed a dynamic read byte budget in `ReadTool` as `max(50KB, maxLinesToCollect * 512)` so larger line limits are not clipped by the fixed 50KB cap.
- Updated truncation and hashline checks to compare against the new dynamic budget instead of `DEFAULT_MAX_BYTES`.
- Replaced `AgentTool` `nointent` and `deriveIntent` with a unified `intent` option that supports `omit`, `optional`, `require`, or a callback function.
- Updated agent tool schema injection and execution paths to inject `_i` as required/optional/omitted and to derive intent through the new `intent` callback.
- Aligned atom-edit tests with the updated default sed behavior (`g` now off by default and explicit `g: true` for global replacement).
- Added `nointent` and `deriveIntent` to `AgentTool`, and made intent-schema injection honor `PI_NO_INTENT` plus per-tool opt-outs.
- Updated tool execution and streaming UI handling to derive a fallback intent when `_i` is absent, without aborting on derivation failures.
- Marked several coding tools as `nointent` and added `deriveIntent` callbacks where needed, then relaxed prompt language to indicate intent is present on most tools.
- Updated `read` selector parsing for file and URL reads to accept optional leading `L` and `+` count-style ranges.
- Adjusted truncation notices and schema/help text to emit and suggest `sel` offsets without the `L` prefix, including continuation and suggestion messages.
- Updated hashline/output parsing and related tests to recognize the new `sel` formatting in truncation notices.
- Updated atom edit location parsing to treat "$" as a file-wide target for prepend, append, and sed, and rejected "^" as a supported locator.
- Added a new sed_file operation that runs line-wise substitutions across the full file, preserving ordering and trailing-newline semantics while failing when no lines match.
- Removed per-entry path overrides from atom resolution and made read selector parsing return "none" for unrecognized selectors to defer handling to specialized readers.
- Removed `pi-natives` chunk language classifier modules and all core chunk subsystems (kind, state, render, edit, resolve).
- Removed chunk-mode CLI/read/edit entrypoints, including `read` command and chunk mode registration/prompt tooling.
- Removed chunk selectors from `read` and `grep` tools, switching behavior to raw/L-range handling.
- Fixed poll wait parsing to keep defaulting to `30s` when the provided value is empty.
- Added `sed` atom editing with `g`, `i`, and `F` flags, path/anchor parsing, and conflict handling updates.
- Changed hashline and grep/read output to `LINE+ID|content` with `>` match prefixes and `:` context prefixes.
- Fixed atom anchor parsing for path-qualified locs, hyphenated single anchors, and content hints after `|` or `:`.
- Updated prompts, changelog, and tests to document and validate the new hashline and `sed` formats.
- Added `HASHLINE_CONTENT_SEPARATOR` and switched hashline formatting to colon separators across hashline helpers.
- Updated hashline prefix regexes in `edit/modes/hashline.ts` to require `:` and stop accepting tab separators.
- Updated `read.ts` and `write.ts` hashline prepending/stripping to match `LINE+ID:` content prefixes.
- Updated `match-line-format.ts` and hashline read-mode docs to document and emit `LINE+ID:content` lines.
- Changed hashline/atom parsing to require full `line+suffix` anchors and emit full-anchor guidance on failures.
- Updated atom/hashline prompt docs, `atom.test.ts`, and changelog entries to require exact full anchors like `160sr`.
- Added preformatted `displayContent` for read/grep/ast tools and switched renderers to prefer it in TUI output.
- Updated mismatch and grep/ast renderers to show context with `*` markers and gutter lines, removing legacy helpers.
- Expanded hashline and chunk bigram tables to 647 entries and moved chunk checksums to a 40-item namespace.
- Changed hashline anchors from `LINE#ID`/`:` to concatenated `LINEID`\t forms across parsing and tool outputs.
- Removed line-number padding and routed diff/read/grep/renderer output through raw numbers, tabs, and `toDisplayLine` formatting.
- Renamed atom ops to `pre`/`post`, removed `ins`, and updated schemas, prompts, and tests for new insertion behavior.
- Added `examples` support to `StringEnum` schemas and propagated it to tool metadata.
- Added concise descriptions and example values across coding-agent tool schemas for clearer guidance.
- Documented the new StringEnum examples capability in `packages/ai/CHANGELOG.md`.
- Cast `real` to `HASHLINE_BIGRAMS` elements in `staleBigramFor` test setup.
- Added raw read output propagation so read/archive commands bypass anchors, line numbers, and chunk formatting.
- Fixed atom/hashline editing by tightening hashline prefixes and applying grouped anchor edits in stable order.
- Hardened chunk parsing and path handling by using `bigram_end` checks and resolving edit paths via shared `args.path` fallback.
- Updated path-related behavior for chunk, replace, patch, and hashline previews to honor optional edit paths.
- Removed mode-level param validators and replaced them with runtime handling, then removed obsolete validation tests.
- Aligned hashline and chunk token handling to `HASHLINE_BIGRAMS` in `computeLineHash` and parsing regexes.
- Removed hashline file-level `move`/`delete` options from schemas and execution so edits are in-place updates only.
- Hardened hashline prefix parsing to reject non-bigram IDs, preventing false stripping of `#` comment lines.
- Updated `read()`/prompt wording so raw reads skip prefixes and examples now show anchors like `123#th`.
- Updated hashline chunk tests for new `HASHLINE_BIGRAMS` IDs and replaced stale hash constants.
- Canonicalized file and CLI defaults from `read` to `open` across tool registration and prompts.
- Added `resolveToolAlias()` and applied alias-normalized tool selection so legacy `read` maps to `open`.
- Updated runtime, UI, and export layers to treat `open` as first-class while preserving `read` compatibility.
- Renamed read prompt docs to `open.md`/`open-chunk.md` and refreshed system guidance to recommend `open`.
- Updated tool-related tests and expectations from `read` to `open` (including test fixtures and aliases).
- Added SQLite path parsing and candidate validation for `.sqlite`, `.db`, `.db3`, and `.sqlite3` targets in read/write flows.
- Added SQLite read operations for table lists, schema views, row lookups, paginated queries, and raw SELECT mode.
- Added SQLite write operations for insert, update-by-key, and delete-by-key using JSON5 row payloads.
- Updated selector routing to validate SQLite headers and fall back to normal file reads/writes when not databases.
- Secured read mode by enforcing query validation to block destructive SQL execution on SQLite inputs.
- Migrated language classifiers from imperative methods to declarative semantic rule tables with ClassifierTables and StructuralOverrides.
- Extracted node shape analysis into dedicated shape module with field priority constants and helper functions for AST traversal.
- Added schema module with language-aware node metadata and thread-local language context management.
- Centralized environment variable parsing across codebase using $flag(), $envpos(), and isBunTestRuntime() utilities.
- Added PI_CHUNK_AUTOINDENT configuration to control indentation normalization in chunk read/edit operations.
- Enhanced system prompt with instruction priority, output contract, tool persistence, and completeness guidelines.