- Aligned the blocked-todo reconciliation test with the debounced
subagent-lifecycle observer on main (fake timers + 100ms advance).
- Carries in-progress robomp queue/sandbox/config scaffolding from the
shared worktree (.env.example, config.py, queue.py, sandbox.py).
Kept the bare 'π' brand per owner direction: the separator between the
brand and the session label now carries the state — '>' when it's the
user's turn (idle), animated spinner frames while working, '!' when the
agent is blocked on the user. Disabled ('tui.titleState' off) renders the
pre-state 'π: label' layout. Updated the state/runtime tests to the new
contract.
Seeding additionalDirectories at launch (via --add-dir or the
workspace.additionalDirectories setting) called #rewriteAtomically on a
brand-new session manager, which materialized a header-only JSONL and a
fresh breadcrumb before any assistant output. Launching and exiting with
configured roots therefore created an empty resumable session that
--continue picked over the previous conversation.
Gated all three workspace-directory mutators behind the existing
#shouldHaveSessionFile() lazy-persistence gate (one shared helper), and
made setAdditionalDirectories a no-op when the normalized list is
unchanged so resuming large sessions no longer rewrites the whole JSONL
on every startup. Roots set before the gate is crossed land in the
header with the first durable write; added a regression test.
Gated the read.renderMarkdown opt-in at read time (details tagging) instead
of inside the renderer. The renderer gate silently flipped every
protocol-supplied text/markdown read (skill://, pr://, issue://, history://,
rule://, omp://, agent://, vault://, local://, memory://, ssh://) from the
formatted markdown cell to the raw code cell when the setting was off, which
regressed default TUI behavior. Local file tagging now happens only when the
setting is enabled, so the default render path is byte-identical to the
pre-setting behavior while opt-in previews still work end-to-end.
Also inlined the tautological isMarkdownContentPath wrapper, pinned the
widened prose-summary bypass (.mdx stays verbatim when prose summaries are
off) with a test, and documented it under Changed in the changelog.
Tested the shell-control guard against the raw command: whitespace
normalization collapsed newlines/CR before the guard ran, so
'git status\nrm file.txt' rode a 'git *' allow rule while bash executed
both lines. Honored tool-owned allow/prompt policies in yolo mode so
per-command prompt rules were no longer silently discarded under the
default approvalMode. Added precision regression tests through the real
matcher (separators, subshells, redirects, env prefixes, path/quoting
variants) that fail on the unfixed head.
Forced retains returned early with an empty incremental slice when no new
messages arrived since the last successful auto-retain, so a user-visible
/memory enqueue rebuild sent nothing and could not recover a deleted or
unmaterialized upstream document. Also removed the public modifier from the
test fake per the root AGENTS.md class-privacy rule and added a forced-retain
resend test.
#4874 only parsed weekly ?format=credits (creditUsagePercent). Unified
accounts often omit those fields or mark isUnifiedBillingUser while the
default /v1/billing payload still exposes monthlyLimit/used, so omp usage
reported "no usage data". Fall back to and merge the monthly shape.
- Credential-shaped token redaction now requires explicit opt-in via `configureCredentialRedaction` and is disabled by default, so user-supplied credential-like strings reach providers unmodified unless the host enables redaction.
- Wired the `secrets.enabled` ("Hide Secrets") setting to `configureCredentialRedaction` in the coding-agent so the pattern redaction follows the existing secret-obfuscation toggle.
- Detect bun crash exits (signals 132-139) and retry up to MAX_CHUNK_ATTEMPTS in a fresh heap.
- Add `retries` field to ChunkOutcome and surface crash retries in progress output.
- Fix test assertion expecting `stopReason: "aborted"` to use `toolUse` (aborted turns are dropped from context).
Review follow-ups (Codex on #6362, round 5):
- #computeSnapcompactRescueMaxFrames now subtracts the kept tail AFTER the
archive (plus the existing fixed-context reserves) so the budget mirrors
what #compactionCreatedHeadroom will measure, and returns 0 when not even
one frame fits — the rescue bails instead of appending a rebuild that can
never create headroom (and would wedge prepareCompaction behind its
last-entry guard once elide fixes the real tail).
- Dead-end warnings now stamp the branch's LATEST compaction entry: the
post-pass path no longer badges the entry the rescue just superseded, and
the no-preparation path badges the rebuilt entry when the rescue appended
without creating headroom.
Claude-Session: https://claude.ai/code/session_014rh4JyWFkxgMhgFaEf8VBY
Adds a login-only `zai-coding-plan` provider that runs the ZCode
"Individual Plan" browser sign-in (authorize on chat.z.ai -> token
exchange -> business login -> mint a durable `id.secret` key) and
stores the minted key under the existing `zai` provider via
`storeCredentialsAs`, so `zai`'s models and `zaiUsageProvider` apply
with no model or catalog changes. Mirrors the existing
`openai-codex-device => openai-codex` pattern.
The flow is built on `OAuthCallbackFlow` (loopback callback on port
54548, plus a paste-redirect fallback via `pasteCodeFlow`) and returns
`OAuthCredentials` with the minted key in `access`; `getOAuthApiKey`
returns it verbatim as the request bearer for `zai`. `zaiUsageProvider`
is widened to accept both `api_key` (paste) and `oauth` (sign-in)
credentials so `/usage` renders Z.AI quota for both login paths.
Strictly additive: the existing paste-key `zai` and `zhipu-coding-plan`
logins are unchanged.
Tests: full authorize -> token -> biz-login -> key-mint walk (find +
create), and `zaiUsageProvider` covering both credential types.
Switching models into a signing Anthropic endpoint while the latest
surviving assistant turn came from a different anthropic-messages
provider (e.g. kimi-code/k3) replayed that turn's foreign thinking
signature verbatim: the cross-model signature strip in
transformMessages was gated on !isLatestSurvivingAssistant and the
latest-abandoned byte-for-byte exemption was unconditional, so every
request 400'd with `Invalid signature in thinking block` and the
session wedged onto its fallback model until a fallback turn completed
and the poisoned turn stopped being latest.
The latest turn now strips signatures whose issuing provider differs
from the target provider — Anthropic's byte-for-byte rule only covers
the target provider's own latest response — while same-provider
cross-model-id switches keep their byte-for-byte latest turn (pinned
by anthropic-prefill). Foreign redacted_thinking siblings are dropped
alongside instead of riding the wire unverifiable.
Fixes#6379