- Stubbed `isSettingsInitialized` to false so crest timing stays deterministic.
- Replaced magic timestamp with named `CLASSIC_CREST_VISIBLE_MS` constant.
- Replaced manual settings callback sets with a shared `SettingSignal` that snapshots listeners and skips over individual callback failures.
- Updated `provider.appendOnlyContext`, `statusLine.sessionAccent`, and `hindsight` hook dispatch to use the new signal and added a Settings test confirming a throwing append-only listener does not stop other listeners.
- Adjusted the duplicate-tool-results regression test to handle `tool_calls` being absent before mapping IDs.
- Added reconstructed SSE event emission for OpenAI, Azure, and Anthropic streams.
- Added raw SSE text to debug report bundles, including raw-sse.txt output.
- Included dropped-record metadata in raw SSE text when events were trimmed.
- Updated raw SSE and sse-debug tests for observer-based capture and safety checks.
- Cached setting path segments and memoized `Settings.get()` results, clearing caches on updates.
- Triggered session-name and session-accent callbacks only when effective values changed, with error-safe dispatch.
- Memoized status-line and interactive accent resolution with cache invalidation on settings/theme/session changes.
- Added regression tests for keybinding precedence, status-line, settings, and accent cache behavior.
- Built canonical and alias key maps for action/custom handlers and rebuilt them on changes.
- Preserved the first handler when custom key alias collisions occurred during rebuilds.
- Exported canonicalKeyId and addKeyAliases from keybindings for external use.
- Updated classic shimmer to compute band position from elapsed time at 30 cells per second instead of a fixed sweep duration.
- Updated KITT shimmer to use fixed-speed ping-pong motion over the same 2xrange cycle so round-trip timing scales with message length.
- Adjusted `LspTool` to retry only zero/decl-only references with two 250ms waits for project-aware servers.
- Removed raw-mode GitHub repo README API fallback in `read`, so `:raw` now renders the page directly.
- Replaced regex heuristics in `isImagePlaceholderAnswer` with a fixed normalized placeholder set.
- Coalesced concurrent JS and Python reset requests by awaiting in-flight promises instead of throwing.
- Aligned non-reset execution calls to wait for in-progress resets before running on a recreated session.
- Ensured eval LLM calls always include a non-empty system prompt to avoid 400s.
- Aligned eval tool docs with session spawn policy by omitting agent() when spawns are disallowed.
- Added regression coverage for default system prompts and spawn-aware agent() description behavior.
- Updated `packages/coding-agent/src/eval/py/prelude.py` to accept positional `offset` and `limit` in `read()`.
- Added regression coverage in `packages/coding-agent/src/eval/py/__tests__/prelude.test.ts` for positional read signatures.
- Applied `opts.viewport` on reusable tabs in `tab-supervisor.acquireTab` before conditional `tab.goto`.
- Skipped `runInTabWithSnapshot` on tab reuse when no viewport or URL change was requested.
- Changed `tab.extract` to return `Promise<string>` and throw on missing or empty Readability content.
- Redacted `user:pass@` from tab URLs returned in observations to avoid leaking credentials.
- Documented `tab.extract(format)` to return markdown/text and throw when no readable content exists.
- Updated sendRequest timeout handling to use explicit timeoutMs, then AbortSignal deadlines, else 30s fallback.
- Normalized getServersForFile matching to accept both `.ts` and `ts` for extension routing.
- Expanded references retry logic to handle thin results with progressive backoff before giving up.
- Filtered rename_file fanout to servers matching source/destination extensions only.
- Updated status output to separate configured servers from started clients with readiness labels.
- Added regression tests for timeout ownership, extension filtering, and status readiness reporting.
- Added `:raw` repo-root resolution via GitHub API `/readme` for decoded markdown.
- Preserved fallback to default raw HTML rendering when the README payload was unusable.
- Added regression coverage for successful README decoding and fallback behavior.
- Set `FindTool` to disable recursive glob traversal so `dir/*` stays shallow.
- Added `parseSearchPathPreferringLiteral` to prefer literal paths like `apps/[id]/page.tsx` when they exist.
- Updated `resolveToolSearchScope` to reject external URLs with a clear `read` usage error.
- Expanded plan-mode sandbox checks to allow absolute paths inside the local artifact root.
- Accepted nullable `skip` in `searchSchema` and treated it as 0 in `SearchTool` pagination logic.
- Added oversized-file detection for explicit search targets to warn when native grep's 4MB cap may hide matches.
- Clarified archive-member error guidance to read `<archive>:<member>` content directly before re-grepping.
- Propagated `schemaOverridden` from `YieldTool` into executor `YieldItem` metadata.
- Bypassed schema validation on override or schema-builder errors and kept payload output with success exit.
- Emitted `SUBAGENT_WARNING_SCHEMA_OVERRIDDEN` so accepted override results no longer surface as `schema_violation`.
- Expanded Codex placeholder detection to match common image-reference phrases and punctuation.
- Raised `codex` provider failure when final and streamed text are placeholders and no sources exist.
- Dropped placeholder prose from returned answers while preserving citation sources.
- Reworked running-task rendering so shimmer animation is applied to descriptions instead of IDs.
- Added accent coloring for the separator and description text to keep the status line formatting consistent.
- Added first-party-first provider priority defaults for model ranking.
- Consolidated model resolution to use getModelMatchPreferences from session settings.
- Prioritized providerPriorityRank ahead of usage rank when picking preferred models.
- Added second-pass fallback to default-model or API-key-valid matching order.
- Tracked each role assignment with an `autoSelected` flag to distinguish inferred defaults from configured models.
- Resolved unconfigured known roles from `pi/{role}` candidates in `#loadRoleModels` and marked them as auto-selected defaults.
- Added a selector test verifying unconfigured models render `[SMOL auto]` and `[SLOW auto]` badges.
- Added `getCredentialOrigin` and `getEnvApiKeyName` to classify auth source.
- Surfaced provenance tags in the `/login` and `/logout` provider picker.
- Made the picker search filter match credential origin and env var name.
- Added coverage for credential-origin precedence and env naming.
- Handled local resumes with missing source CWD by prompting to move and reopening sessions.
- Shared missing-CWD relocation logic between local and global resumes for consistency.
- Added regression test for local explicit-session-dir resumes and session-header cwd updates.
- Tracked kitty-dot payload listings to emit BEL-terminated OSC5522 responses.
- Updated non-kitty-dot writes to include mime in metadata and drop ST terminator.
- Adjusted enhanced-paste tests to assert BEL terminator and metadata formatting.
- Updated startup handling so `applyStartupCwd` now re-syncs `parsed.cwd` to the resolved absolute project directory after `setProjectDir` runs.
- Adjusted the CLI cwd tests to verify a relative `--cwd` argument is normalized to an absolute path and does not double-resolve against the new process cwd.
- Added an interrupt state in EventController to switch the working label to `Interrupting...` and suspend intent-driven updates until the turn resets.
- Called `notifyInterrupting()` from streaming-interrupt paths in InputController and exposed it on InteractiveModeContext so Esc acknowledgement shows immediately while tools tear down.
- Added tests to verify loader acknowledgement, freeze of late intent updates during interruption, and label updates resuming on the next agent start.
- Changed the `github-copilot` service provider to resolve credentials only from `COPILOT_GITHUB_TOKEN`.
- Updated CLI extra help text to document `COPILOT_GITHUB_TOKEN` as the GitHub Copilot environment variable.
- Reworded environment variable docs to reflect the revised Copilot/GitHub token usage and order.
When a session's working directory is moved or renamed (e.g. `git worktree
move`), the session file stays under the old cwd-encoded bucket while the new
directory is empty. Resuming was lossy:
- `--continue` rejected the terminal breadcrumb purely on cwd mismatch and then
found nothing in the new bucket, silently starting a fresh empty session.
- cross-project `--resume <id>` only offered to *fork* (duplicate) the session
into the new directory, forcing manual id selection and leaving a stale copy.
Detect relocation via the strong, low-false-positive signal "recorded cwd no
longer exists on disk" and re-root in place with the existing `moveTo()`:
- `continueRecent` re-roots the terminal's last session into the current
directory when its recorded cwd is gone and the new location has no sessions
of its own (otherwise behavior is unchanged). `readTerminalBreadcrumb` is
refactored into `readTerminalBreadcrumbEntry` returning the raw cwd +
session file so callers can interpret a cwd mismatch.
- cross-project `--resume <id>` offers "Move (re-root)" instead of fork when the
source directory is gone; a still-existing different project still forks.
Tests: continue-relocation (re-root on move, no-hijack on plain cd, prefer
local recent) and cross-project move-vs-fork routing.
`finalizeSubprocessOutput` always spliced collected `report_finding`
entries onto a top-level `findings` array regardless of the active output
schema. A caller-supplied schema with `additionalProperties: false` and
no `findings` property would accept the raw payload in-tool (via the
`yield` validator, which only sees the pre-injection data) but then fail
post-mortem validation — emitting `schema_violation: findings: must not
be present` and propagating as a fatal `RuntimeError` through
`agent-bridge.ts` and the eval Python/JS preludes, collapsing the entire
workflow cell along with any prior successful subagent work.
`normalizeCompleteData` now takes the resolved validator and only
performs the injection when the augmented candidate validates. When the
schema rejects it, the raw payload is returned instead — which the in-
tool yield validator already accepted, so the lockstep guarantee
documented at the top of `output-schema-validator.ts` is honored.
Findings remain visible via the agent progress stream and JSONL
artifact, so no information is dropped when injection is suppressed.
Both finalize call paths (yield-success and no-yield fallback) now share
the single validator build instead of constructing it twice, and the
yield-path schema_violation branch is now reached only via the
explicit malformed-schema check, never via spurious findings rejection.
Fixes#2070
MCPTool and DeferredMCPTool now declare approval = 'write' instead of
implicitly defaulting to 'exec'. Without this, the approval system
requires user confirmation for every MCP tool call in non-yolo modes,
but the confirmation prompt never renders in the TUI while streaming,
causing the agent to hang indefinitely.
Also propagate the approval property through customToolToDefinition()
in sdk.ts, which was silently dropping it during CustomTool ->
ToolDefinition conversion.