#purgeSupersededDisabledRows matched disabled rows against active ones by
exact identity-key string equality, but the active-replacement path it
mirrors (matchesReplacementCredential) claims pre-org legacy rows
(`<b>` vs `<b>|org:<o>`). So a later org-scoped login of the same account
never purged the pre-org tombstone, which then rendered forever as a red
row in `omp usage` with no CLI/TUI escape. This is the OAuth half of the
class of bug #2943 fixed for api_key rows in the same function.
Reuse matchesReplacementCredential in the purge so an org-scoped login
claims and hard-deletes its pre-org tombstone, inheriting the one-way
upgrade and shared-workspace guards unchanged.
Fixes#7876
PUT ... @name with no matching capture no longer fails the patch: it
pastes nothing (a span target is still removed, i.e. it degrades to a
cut) and surfaces a warning naming the available registers. Anonymous
empty/ambiguous pastes still error. validateClipboardSequence now only
guards anonymous sequencing; applyEdits threads clipboard warnings into
ApplyResult.warnings.
Shares a saved session by id prefix or .jsonl path without launching the
agent - same encrypted upload, store selection, and share.redactSecrets
handling as the /share slash command.
Moved the obfuscator assembly (secrets.yml + env entries + built-in
credential patterns, placeholder-key minting rules, redaction-only
fallback) from createAgentSessionScoped into the secrets module so other
entrypoints can build the same obfuscator.
- New agent-plugins provider discovers packages with a root plugin.json
targeting the canonical schema (agent-plugins.org) from marketplace
installs, --plugin-dir, and configured extension roots; skills/ and
mcp.json load per spec with closed-schema validation,
${PLUGIN_ROOT}/${PLUGIN_DATA} expansion, reserved subprocess
environment, instance-keyed data dirs, and per-component isolation.
- Package-boundary containment (spec §4.1) is enforced before every
read via the new contained-path helpers, including skill:// resource
access from the read tool and bash; plugin skill files must
realpath-resolve inside the plugin root (skills carry containRoot).
- Legacy claude-plugins/omp-plugins providers yield skills and MCP
surfaces of standard-targeting roots to the new provider and skip
fatally invalid packages.
- Client-generated HTTP/MCP/authorization headers win over configured
headers case-insensitively (Agent Plugins §7.2.1) via the new
header-policy fetch wrapper used by the HTTP and legacy SSE transports.
- headerPolicy: "origin-locked" pins configured headers to the configured
URL's origin: never forwarded across cross-origin redirects, and
method-changing redirects of JSON-RPC POSTs are refused.
- envPolicy: "literal" exempts stdio env values (and origin-locked
headers) from config-value resolution: no ambient env-name lookup, no
__omp_shell("command execution, empty values preserved.")
resolveAnthropicBaseUrl() resolved the chat base URL from github-copilot,
FOUNDRY_BASE_URL, then model.baseUrl -> hardcoded api.anthropic.com, and
never read $env.ANTHROPIC_BASE_URL. The stock anthropic descriptor pins
model.baseUrl to api.anthropic.com, so the env fallback was unreachable:
gateway-scoped keys were sent to api.anthropic.com (401, credential leak)
regardless of ANTHROPIC_BASE_URL, contradicting docs and the web-search
fix in #1693.
- Chat resolver now returns ANTHROPIC_BASE_URL (after Foundry, ahead of the
official default); an explicit non-official model.baseUrl still wins.
- resolveAnthropicCustomHeaders keys off the resolved base URL so
ANTHROPIC_CUSTOM_HEADERS reach env-configured non-official gateways.
- stream.ts leaked-thinking heal exemption mirror updated to the same
effective-endpoint precedence.
Fixes#7874
Zhipu Coding Plan returns '429 已达到 5 小时的使用上限。您的限额将在 … 重置。'
(type=1308) when the 5h window is spent. The error classifier only matched
English quota phrasing, so this message classified as UNKNOWN, Flag.UsageLimit
was never set, and multi-key sessions stayed pinned to the exhausted api_key
credential instead of rotating to a sibling key.
Add CN_QUOTA_EXHAUSTED_PATTERN (达到…使用上限, 已达上限, 额度/配额…耗尽/用完,
限额…重置, 余额不足) consulted by parseRateLimitReason before the transient
branches and by matchesUsageLimitText. Treat Simplified Chinese error bodies
as informative in isOpaqueStatusBody so a plain Chinese throttle (已达到速率限制)
does not rotate credentials via the opaque-429 fallback.
The 达到…使用上限 arm requires the 使用 token, so a concurrency or rate cap
phrased as 达到…上限 (without 使用) stays in the upstream-backoff lane instead
of being misclassified as a credential-exhausting quota.
- mnemopi provider parity 'diagnose, validate, graph' does ~6.7s of real
work under bun --parallel=8 on loaded runners; raised its per-test
timeout to 30s (default 5s flaked twice in three CI runs).
- utils LRUCache updateAgeOnGet drove a 30ms TTL with real 20ms sleeps
(10ms margin); now drives performance.now() via a mocked clock, so the
contract is asserted deterministically with no wall-clock wait.
- A blank run at EOF now breaks the list without consuming the blank,
matching real marked: '- item\n\n' lexes as a tight list plus a space
token instead of a loose list whose raw includes the blank.
- Completes the 17.2.10 mid-document fix; same-marker continuation and
indented item content across blanks are unaffected.
- Added list/blank boundary token-shape tests (verified against marked
v15) since the tui incremental tests compare the lexer to itself.
- deepseek-v4-flash bakes the wire-exact [low, high, max] ladder on
every host since 736b496cc6; V4 Pro stays [high, max].
- The stale xhigh alias-filter assertions now expect the flash ladder.
- Reverted the status-line acknowledgment added for deferred panel
commands: showStatus mounts a Spacer+Text into the transcript, and any
mid-turn transcript mount re-renders rows below the growing live block,
duplicating them in native scrollback (issues #4806/#6767).
- The queue still flushes at every settle, terminal or not.
- A blank line before a non-continuing top-level line (including plain
paragraphs) now closes the list without consuming the blank, so it
always lexes as a separate space token like real marked.
- List token shape no longer depends on the follower's block type,
restoring the TUI streaming lexer's freeze invariant (lex(prefix) ++
lex(tail) == lex(full) under append-only growth).
- A list followed by a paragraph is now tight, not loose, per CommonMark.
- Classified model_not_available_for_integrator as a permanent entitlement denial instead of transient fleet skew.
- Preserved the provider response and Available models list while retaining model_not_supported fleet retries.
Fixes#7819