- Implemented case-insensitive normalization for bot logins to handle mention handles and `[bot]` suffixes consistently.
- Added support for `ROBOMP_MAINTAINER_LOGINS` to allow authorized non-owner users to execute implementations.
- Refined authorization logic to distinguish between personal repository owners and organizational accounts.
- Updated documentation and added comprehensive tests to verify authorization handling across tasks, workers, and directive processing.
- Updated configuration to strip the '@' prefix from bot login names.
- Granted personal repository owners authorization to trigger implementations regardless of their GitHub author association.
- Included authorizes_impl field when attaching threads to directives.
- Added a test case to ensure the author authorization flag is preserved during directive hydration.
- Introduced `web-palette.ts` to implement the collab-web pink/purple brand identity for HTML exports.
- Updated `generateThemeVars` to support a `palette` option, allowing users to choose between the brand-web aesthetic and a specific TUI theme.
- Configured public exports and the share-viewer script to default to the brand-web palette rather than inheriting the user's terminal theme.
- Refactored `AgentSession.exportToHtml` to align with the new branding defaults while allowing for per-export theme overrides.
- Adjusted `dark.json` background values to ensure better visual consistency across internal surfaces.
Trimmed stored image_generation_call output items before replaying OpenAI Responses native history so provider-only fields like action no longer leak into the next input array.
Added a regression test covering the proxy-rejected replay shape.
Fixes#3201
- Implemented `waitForSelector` and `waitForNavigation` methods in the browser tool API.
- Introduced per-operation fail-fast budget management with dynamic timeout clamping.
- Added validation for selector engines to reject unsupported Playwright-only platform features.
- Standardized error handling to provide descriptive, named timeouts for stalled browser operations.
- Updated model detection to exclude WebP format for Codex-based providers, which do not support it.
- Forced the image resize pipeline to encode to PNG or JPEG for incompatible models to resolve transmission errors.
- Added test coverage to verify that WebP images are re-encoded when using the Codex Responses backend.
- Added extended idle timeouts for Xiaomi MiMo Pro and Alibaba Coding Plan models.
- Updated the stream timeout logic to support these providers, preventing premature stream termination due to long pre-event stalls.
Fixes#1770
- Included the timeout option in the initialization object when prepareInit is absent.
- Ensured that custom timeout settings are preserved for long-running streams instead of being silently dropped.
Fixes#2422
Added clearOptimisticUserMessage and replaceOptimisticUserMessage stubs to the EventController message_start test double so the optimistic-submission case no longer throws when the controller reconciles the signature.
Fixes#3199
Skipped optimistic replacement when a user message_start matches another recorded local submission, preserving the pending prompt bubble until its own expanded event arrives.
Added coverage for the queued-message drain race between startPendingSubmission and prompt dispatch.
Fixes#3199
Updated optimistic replay to track the replacement component handles created during transcript rebuilds, so expanded slash prompts still replace the raw replayed message.
Extended the regression test to cover the rebuild window called out in review.
Fixes#3199
Replaced raw optimistic slash-command transcript entries with the canonical user message emitted by AgentSession when prompt expansion changes the text.
Added coverage for prompt-template expansion reconciliation so the transcript keeps one expanded user message.
Fixes#3199
When the user set `providers.tinyModel` to a local key, `generateSessionTitle`
still raced local against the online `smol` path with a 10 s timeout and
silently fired the online request whenever the local worker returned `null`
(unknown key, model not downloaded, transformers.js failure). The online path
resolves the `smol` role through `priority.json` (haiku → flash → mini → …);
with an `OPENROUTER_API_KEY` picked up from env, that silently billed
OpenRouter without consent.
Drop the race entirely for local choices: honor the user's setting, log a
warning on local failure, leave the session untitled. The `raceFirstNonNull`
helper and `TITLE_LOCAL_FALLBACK_DELAY_MS` had no other consumer and are
removed; the obsolete \"silently bills online when local fails\" tests are
flipped into regressions that lock the no-fallback contract, including the
unknown-key path (e.g. \"ollama:gpt-oss\") which previously also leaked
straight through to the online billing path.
Fixes#3187
Upgraded installs can carry an Umans model cache written before the
GLM via-handoff catalog correction. If dynamic discovery is skipped or
fails, resolveProviderModels merges cache rows over the corrected static
catalog; mergeDynamicModel preserves image support when either side has
it, so a stale cached ["text", "image"] GLM row can re-add native image
support until the next successful refresh.
Add a provider-scoped cache drop hook for model ids whose cached rows
are unsafe across static fingerprint changes, opt Umans into it for
`umans-glm-5.1` and `umans-glm-5.2`, and cover the offline stale-cache
upgrade path with a regression test.
Fixes#3184
`umans-glm-5.1` / `umans-glm-5.2` advertise themselves on the Umans
`models/info` endpoint with `supports_vision: "via-handoff"`. That
sentinel means image inputs are routed through a separate vision
handoff pre-analysis step; the GLM endpoint itself rejects raw image
blocks with `400 This model does not support image inputs`.
`umansSupportsVision` was returning `true` for any non-empty string,
so dynamic discovery mapped the GLM models to `input: ["text",
"image"]` and the agent sent images straight to GLM. The bundled
`umans-glm-5.1` / `umans-glm-5.2` rows in `models.json` carried the
same stale `["text","image"]` from a previous regen.
- Tighten `umansSupportsVision` to `value === true`; document the
sentinel contract.
- Correct the two bundled rows to `input: ["text"]` so the vision
handoff path runs.
- Add resolver- and bundle-level regression tests that cover
`supports_vision: "via-handoff"` alongside the native-vision
`umans-coder` case.
Fixes#3184
Mapped OpenCode MCP array commands to stdio command plus args and accepted environment as the provider-native env key.\n\nAdded regression coverage for array command normalization, environment mapping, env fallback, and empty args omission.\n\nFixes #3180
- sdk-mcp-discovery: `find` became an essential tool (2eef88978), so it can no longer be hidden/rediscovered under `tools.discoveryMode: all`. Switch the discoverable-tool assertions to `search` (still `loadMode: discoverable`).
- agent-session-concurrent: the agent loop now drops tool calls that never reached `toolcall_end` from an aborted turn (0890b2be6, partial args are unsafe to replay). Emit `toolcall_end` before the TTSR rule-driven abort so the labeled placeholder result is minted.
- Implement ID-based guards for Codex WebSocket frames to reject stale or unauthorized interleaved frames from previous turns.
- Check sequence numbers within Codex responses to detect and handle out-of-order frame delivery.
- Restrict tool result consumption to occurrences appearing after the associated tool call, preventing the reuse of orphaned results from earlier conversation turns.
- Fixed streaming output being lost from native scrollback when an unstable "barrier" block preceded it.
- Adjusted the engine commit logic to ensure all scrolled-off content reaches history, treating the `windowTop` as the persistent commit floor.
- Updated the committed-prefix logic to perform range-aware auditing, ensuring forced-overflow rows are accurately re-anchored rather than dropped upon barrier finalization.
- Inlined the temporary model status formatting logic directly into the controller.
- Removed the unused `formatTemporaryModelStatus` utility function and its associated test.
- Refactored committed prefix auditing into distinct byte-stable, durable, and forced-overflow zones.
- Integrated a hard scan detector and refined boundary management to prevent data loss during commit-unstable barrier shifts.
- Implemented robust regression testing via the streaming-scrollback-defer harness to verify frame continuity.
- Updated audit logic to independently manage boundaries, ensuring forced-overflow rows remain correctly finalized.
- Update `shouldRetry` to treat `EISDIR` and `ENOTDIR` as terminal errors, preventing unnecessary retries when encountering Git reference directory conflicts.
- Add a test suite to verify graceful resolution of branches in scenarios where a packed ref conflicts with a directory path in the filesystem.