- Added optional `source?` field with value `'login'` to `apiKeyCredentialSchema` so snapshots accept login-sourced API keys.
- Updated CHANGELOG with a fixed entry describing the correction.
- Added a test verifying that a snapshot containing `source: "login"` passes client wire validation.
- Implemented parsing of id-prefixed wildcard keys and entries, allowing provider-specific prefixes in retry fallback configuration.
- Added logic to re-prefix failing model IDs and to match id-prefixed keys, with validation of provider existence.
- Updated settings schema description and changelog, and added tests covering the new behavior.
- Updated models.json to set maxTokens to 65536 for Kimi K2.7-Code entries.
- Adjusted openai-compat logic to use a new 65,536 ceiling for K2.7-Code while preserving the 32,768 cap for older K2 models.
- Modified tests to verify the new token limit and ensure K2.7-Code models are excluded from the older cap.
- Used the active provider session id for title credential selection.
- Covered explicit provider-session credential stickiness alongside disposal cancellation.
- Delayed reader cancellation so pipeline consumers can flush after producers are terminated.
- Kept the JavaScript watchdog behind bounded native timeout cleanup.
- Added native and executor regressions for timeout-time output draining.
Fixes#5316
- Routed automatic first-input and replan title requests through AgentSession lifecycle cancellation.
- Propagated disposal aborts to online provider and local tiny-model title generation.
- Added a regression test proving an in-flight title request settles when disposal begins.
Fixes#5666
Extension-scheduled setInterval/setTimeout/detached callbacks ran outside
the handler-dispatch try/catch, so a throw surfaced as a process-level
uncaughtException and the global postmortem handler tore down the whole
session instead of isolating the misbehaving extension.
- Added ManagedTimers backing sanctioned ctx.setInterval/setTimeout/clearTimer:
callbacks run with handler-dispatch isolation (throw/rejection logged and
routed through onError), handles are unref'd, and all are cleared on
session_shutdown.
- Wired the helpers into ExtensionRunner.createContext and the runner-less
command-context fallback; onSession now inherits the runner context.
- Documented in-process no-isolation behavior and the managed timers in
docs/extensions.md and docs/skills/authoring-extensions.md.
Fixes#5664
In plan mode the active session model is the plan-role model, but
reassigning that role through the model hub only wrote settings and
never moved the live session onto the new model — planning continued on
the model plan mode was entered with until the next entry.
Subscribe InteractiveMode to onModelRolesChanged and, while plan mode is
active, re-resolve the plan role and switch onto it (deferring to the
next turn boundary when a turn is streaming). Extract the transition
decision into a pure resolvePlanModelTransition() helper with tests.
Fixes#5657
Marked's bundled url tokenizer fired the www./http(s):///ftp:// extended
autolink after any preceding character, so a local path such as
~/meta/www.share/blog/index.dj was mangled into a http://www.share/... link.
Added an inline tokenizer extension that consumes only the scheme prefix as
literal text when it is glued to an invalid left boundary, letting genuine
autolinks at start-of-line/whitespace/*_~( fall through to marked unchanged.
Fixes#5652
- Implement `isInvalidatedOAuthTokenError` to identify specific upstream auth failures.
- Enable automatic credential rotation in `AuthStorage` and stream retries when an invalidated token is detected.
- Update `proxy.test.ts` to correctly handle `NO_PROXY` and `no_proxy` environment variables during testing.
Built-in xd:// devices are mounted before the SDK wraps registry tools in ExtensionToolWrapper, so Cursor executed them via tool.execute() without the deny/prompt approval gate that write xd:// enforces. Wrap unwrapped devices in the Cursor resolver, skipping already-wrapped dynamic mounts.
Fixes#5650
The context refresh captured the run-start model, so mid-run switches into or out of cursor-agent (retry fallback, prewalk, plan-yolo) sent the wrong tool set. Resolve supplemental tools against this.#state.model each call.
Fixes#5650
Forwarded the session xd registry into Cursor provider tool contexts.
Routed Cursor MCP execution through the mounted registry fallback and added regression coverage for built-in devices and external MCP tools.
Fixes#5650
Print-mode assistant-error/aborted exit, RPC pi.shutdown() and stdin-EOF
shutdowns, and the extension command-context shutdown() called
process.exit() before (or racing) session.dispose(), skipping the bounded
browser reaper (releaseTabsForOwner) installed in dispose(). An OMP-owned
Chromium could survive the parent and reparent to PID 1.
Route all four graceful paths through the idempotent, promise-memoized
session.dispose() and await it before the final exit. The RPC
performShutdown no longer emits session_shutdown directly (dispose() emits
it), avoiding a double emit.
Fixes#5643