Brings the per-advisor toggle, status-line glyphs, quota display, and the
failing-advisor stall/abort fix (f4c8143) onto main's rewritten advisor
runtime. Conflict reconciliation kept main's architecture (fingerprint
prefix reconciliation, host-level onTurnError recovery + fallback chains,
terminal-failure classification) and ported the branch semantics onto it:
- #failing latch: waitForCatchup resolves immediately while an advisor is
mid-failure; parked waiters wake the moment a turn fails, before any
async hook or retry sleep.
- Turn-end render containment: a formatter bug restores the cursor/prefix/
dedup snapshot and never propagates into the primary's turn-end callback
(per-advisor try/catch boundary in AgentSession).
- Quota pause: when host recovery declines a usage-limit failure, the
runtime latches quotaExhausted, requeues the batch, and notifies —
cleared only by an explicit reset.
- Hard halt after a permanent rejection or three backlog-drop cycles.
- #recoverAdvisorTurn also marks usage limits for structural errors thrown
before any assistant turn is recorded.
- Reverted PR #5751 (issue #5749): continuation rows wrapped the editor
top border onto extra lines, which is unacceptable for the input frame.
- EditorTopBorder is back to a single content/width pair; narrow widths
drop right segments, shrink the path, then drop left segments.
Cherry-picked 69c9fe8d4; resolved terminal.ts against the newer
onPrivateModeReport signature and unioned appearance tests with the
Windows Terminal polling regression.
Resolved against the newer RpcInputDispatcher loop: kept serial dispatch
and shutdown coordination, replaced only the readJsonl generator with
line-based reads and a per-line parse-error response frame.
Resolved plan-mode exit overlap with #5662 (kept restore/rollback
structure, routed pending-switch clearing through
clearPendingPlanModelSwitch) and unioned additive test blocks with
#5672/#5662.
Extension/SDK/RPC registerTool defaulted an omitted loadMode to
"discoverable". A UI-only re-register of an essential built-in
(read/write/bash/edit/glob) then became discoverable and, with tools.xdev
on, was unmounted from the top-level schema. read/write dropping also
broke the xd:// transport (read xd://, write xd://<tool>), leaving the
model with no callable coding essentials.
- Add defaultLoadModeForToolName: omitted loadMode resolves to "essential"
for known essential built-in names, "discoverable" otherwise.
- Apply it at all four adapter boundaries (extension wrapper, custom-tools
wrapper, sdk customToolToDefinition, rpc normalizeHostToolDefinitions).
- Transport invariant: read/write never mount under xdev regardless of
loadMode (they carry the transport).
- Regression test covering the demotion, transport invariant, and a drift
guard tying the essential-name set to the tool classes.
Fixes#5764
- Applied the interactive shutdown budget to normal and error print-mode disposal.
- Added regression coverage for bounded mnemopi consolidation.
Fixes#5753
Decoupled fullscreen alternate-screen rendering from terminal mouse capture.
Disabled pointer tracking for Plan Review so terminals retain native selection.
Fixes#5711
Removed the 24-column cap from account cells so wide terminals can show full disambiguating labels.
Kept usage bars independently capped and added regression coverage for same-email organization accounts.
Fixes#5701
The /usage show "in use by this session:" marker took only the bare
email from OAuthAccountIdentity, so two same-email Anthropic credentials
in different orgs were indistinguishable. Route the label through a
shared formatActiveAccountLabel that suffixes the active org, matching
the account list and login-success surfaces.
Fixes#5691
Moved #hidePlanReview from after the model restore to immediately before the synthetic execution dispatch, past the awaited sessionManager.setSessionName. Hiding earlier restored editor focus while the async title write was in flight, so operator keystrokes could submit a normal turn ahead of the approved execution turn and reorder it.
Fixes#5688
The stale-buffer flicker fix (68f84d7c20, #5319) moved #hidePlanReview out of the picker's synchronous finish() into closePlanReview(), reached only after #approvePlan returns. #approvePlan awaits session.prompt of the synthetic plan-approved turn, which blocks for the whole run, so the fullscreen plan-review overlay stayed mounted while work proceeded underneath.
Hide the overlay inside #approvePlan after the async transcript rebuild (exitPlanMode/compaction, tool and model restore) completes but before the blocking dispatch. #hidePlanReview is idempotent, so the caller's trailing closePlanReview() stays a safe no-op, and #5319's stale-buffer guard is preserved.
Fixes#5688
- Routed automatic first-input and replan title requests through AgentSession lifecycle cancellation.
- Propagated disposal aborts to online provider and local tiny-model title generation.
- Added a regression test proving an in-flight title request settles when disposal begins.
Fixes#5666
Extension-scheduled setInterval/setTimeout/detached callbacks ran outside
the handler-dispatch try/catch, so a throw surfaced as a process-level
uncaughtException and the global postmortem handler tore down the whole
session instead of isolating the misbehaving extension.
- Added ManagedTimers backing sanctioned ctx.setInterval/setTimeout/clearTimer:
callbacks run with handler-dispatch isolation (throw/rejection logged and
routed through onError), handles are unref'd, and all are cleared on
session_shutdown.
- Wired the helpers into ExtensionRunner.createContext and the runner-less
command-context fallback; onSession now inherits the runner context.
- Documented in-process no-isolation behavior and the managed timers in
docs/extensions.md and docs/skills/authoring-extensions.md.
Fixes#5664