Ran deferred-submission promotion on an independent timer in addition to the empty-queue path, so a sustained ordinary queue can no longer starve a rate-limited submitter after their rolling window frees. Added ROBOMP_DEFERRED_PROMOTION_SCAN_SECONDS to tune or disable the sweep.
Fixes#5882
Stored a bounded per-login overflow backlog and promoted deferred events oldest-first as rolling-window capacity became available. Surfaced the deferred state through the dashboard contract and documented admission behavior.
Fixes#5882
- Both plan-model transition tests relied on ambient host credentials to
make anthropic models resolvable; on CI runners without keys the
plan-role reassignment and restore paths were silently skipped.
- Seeded a runtime API key via AuthStorage, matching the pattern used by
every other coding-agent session test.
Brings the per-advisor toggle, status-line glyphs, quota display, and the
failing-advisor stall/abort fix (f4c8143) onto main's rewritten advisor
runtime. Conflict reconciliation kept main's architecture (fingerprint
prefix reconciliation, host-level onTurnError recovery + fallback chains,
terminal-failure classification) and ported the branch semantics onto it:
- #failing latch: waitForCatchup resolves immediately while an advisor is
mid-failure; parked waiters wake the moment a turn fails, before any
async hook or retry sleep.
- Turn-end render containment: a formatter bug restores the cursor/prefix/
dedup snapshot and never propagates into the primary's turn-end callback
(per-advisor try/catch boundary in AgentSession).
- Quota pause: when host recovery declines a usage-limit failure, the
runtime latches quotaExhausted, requeues the batch, and notifies —
cleared only by an explicit reset.
- Hard halt after a permanent rejection or three backlog-drop cycles.
- #recoverAdvisorTurn also marks usage limits for structural errors thrown
before any assistant turn is recorded.
The reassignment test awaited a single microtask, but the role-change
listener crosses real async storage hops since per-project model roles;
it now awaits the setModelTemporary call itself. The failed-restore
test picked claude-haiku unconditionally, which no-ops plan entry when
the ambient default already resolves to haiku (as on CI); it now picks
a model that differs from the active session model.
The regenerated catalog stamps kimi-for-coding with the zai thinking
format, under which reasoning yields to a forced tool choice (#5758
review) instead of downgrading the choice: chat-completions carries an
explicit thinking {type: disabled} and the Anthropic wire keeps the
forced choice with no thinking block.
A broken advisor could hold the primary agent on the per-turn catch-up
gate for its full 30s budget while retrying, and an exception thrown from
onTurnEnd propagated into the primary's turn-end callback.
- waitForCatchup resolves immediately while the advisor is mid-failure
(new #failing latch, set at the failure catch BEFORE any async hook,
cleared on the next successful turn or reset/seed).
- Every parked waiter is woken the moment an advisor turn fails.
- The turn-end boundary isolates advisor exceptions per advisor: a
throwing advisor loses its delta, the primary and sibling advisors
continue untouched.
- A failed render (poisoned message, formatter bug) restores the delta
cursor and dedup state, so the delta is re-rendered next turn instead
of silently lost; the size probe itself is guarded and falls back to
the deferred renderer.
Reinstates the catalog regeneration (glm-4.5 reasoning/effort metadata,
refreshed pricing and limits) that the previous commit wrongly rolled
back. The three failing tests were pinned to stale upstream metadata;
they now assert the durable contracts instead: K2.7-Code stays above
the 32,768 K2-family cap and tracks the bundled reference, and K3
asserts effort-mode metadata while the wire-body test remains the
binding reasoning_effort=max contract.
A stale regenerated models.json rode the previous commit from the
shared index; it contradicted the Fireworks K2.7-Code output-ceiling
and Moonshot K3 reasoning contracts (#1849, #5756). Restored the
snapshot those tests verify; a deliberate catalog refresh should
reconcile the K3/K2.7 policies first.
The 50ms budget raced external-process spawn on cold CI runners: cancel
could fire before yes produced output, so the builtin tail flushed an
empty ring buffer (0 lines instead of 5, Linux x64 modern). 750ms keeps
the post-cancel drain scenario while outlasting spawn latency.
- v17.0.1 (#5476) rewrote the normal buffer in place per SIGWINCH, so
the terminal's own width reflow pushed wrapped fragments into native
scrollback mid-drag and resize smoothness collapsed.
- Throwaway drag frames paint on the alternate screen again; the settle
full paint fuses the buffer exit ahead of its destructive repaint.
- Kept the #5319 fixes: deferred overlay alt-exit fusing, confirmed-only
DECRPM 2026 handling, and Warp's in-place resize path.
- Reverted PR #5751 (issue #5749): continuation rows wrapped the editor
top border onto extra lines, which is unacceptable for the input frame.
- EditorTopBorder is back to a single content/width pair; narrow widths
drop right segments, shrink the path, then drop left segments.
The Duo goal bypasses transformMessages; apply the outbound credential
scrub (#5655) to the rendered ChatML transcript and latest-prompt goal,
and updated the provider test to the redaction contract.
Lands the intent of #5318 on the established generate_image.enabled
gate instead of introducing a parallel imagegen.enabled key; sessions
must opt in before the tool registers top-level or as an xd:// device.
Post-compaction auto-continuation is gated on remaining work since
#5721; an active goal keeps the continuation vehicle these #1246
regressions ride on.
Managed-timer cleanup from #5667 is now optional-called so host or test
facades implementing only the dispatch surface do not throw during
dispose; aligned the selector fallback status expectation with #5586's
role-tag casing.
Grafted the evaluator's port (ec2c1e632) onto the merged advisor
runtime: terminal provider failures classified non-retriable (and not
context overflow) drop the bounded batch after one attempt with a
single notification; fallback-chain recovery and overflow recovery
retain precedence. Includes the one-prompt regression test and tags the
rollback-retry fixture's synthetic failure as transient.
Semantic merge with #5734 (delivered-prefix reconciliation) and #5748
(fallback chains): kept the coalescing round cap and wip threading,
adopted bounded cursor-preserving maintenance resets and overflow
recovery, and gated late-arrival consumption on coalescing rounds so
both suites' backlog and preserved-updates contracts hold.