Resolved plan-mode exit overlap with #5662 (kept restore/rollback
structure, routed pending-switch clearing through
clearPendingPlanModelSwitch) and unioned additive test blocks with
#5672/#5662.
The Responses-Lite rewrite moves tools into an `additional_tools` developer
input and deletes top-level `tools`, but preserved a forced top-level
`tool_choice` (e.g. `{ type: "web_search" }`). With no top-level tools to
validate against, the ChatGPT Codex endpoint rejected the request with
`HTTP 400 Tool choice '…' not found in 'tools' parameter`, and web search
silently fell back to Gemini.
`applyCodexResponsesLiteShape` now sets `tool_choice: "auto"`, matching
codex-rs `build_responses_request`. Classic (non-Lite) Responses requests
keep their forced choice since top-level `tools` remains present.
Fixes#5771
The Kimi web-search adapter posts to the Kimi Code endpoint
(api.kimi.com/coding/v1/search) but resolved and advertised Moonshot
Open Platform credentials (moonshot provider, MOONSHOT_API_KEY,
api.moonshot.ai). Those are a different credential system, so a valid
Open Platform key was rejected with 401 and the preferred provider
silently fell back to another engine.
resolveKey() and isAvailable() now use kimi-code credentials only
(explicit MOONSHOT_SEARCH_API_KEY / KIMI_SEARCH_API_KEY overrides or a
stored kimi-code login), and the missing-credential error and provider
metadata name the Kimi Code requirement.
Fixes#5762
Answered unconfigured workspace/configuration sections with the spec-required null value and covered the Roslyn post-initialization pull path.
Fixes#5745
fs.realpath throws EISDIR on Windows drive roots (e.g. R:\), but
canonicalProjectDir in launch/presence.ts and launch/client.ts only
recovered ENOENT, aborting startup. Both now fall back to path.resolve()
on EISDIR, matching the existing ENOENT handling.
Fixes#5708
- restored capability reset import in agent-session refreshSkills
- fixed renamed credential entry reference in auth-storage org fields
- aligned xai web-search fetch mock and refresh-race test with current typings
The new isParking/has checks consulted the global lifecycle for every send, so a custom-registry IrcBus (which falls back to the global manager) could gate a live recipient on unrelated global park state for the same id. Add AgentLifecycleManager.manages(registry) and apply the mid-park/adopted gate only when the lifecycle owns this bus's registry; the parked-status path (read from the bus's own registry) is unchanged.
Fixes#5633
Replaced all three newly added manual Promise constructors with Promise.withResolvers<void>(), matching the package promise convention without changing the race coverage.
Fixes#5633
park() detached the live session only after session.dispose() resolved,
so during the dispose window the registry still exposed ref.session at
idle status. Concurrent ensureLive()/hub-send handed out or injected into
the dying session, reporting success while the message was dropped once
detach committed.
- Replace the #parking Set guard with a #parks map of in-flight park state
that is cancelable until the session is detached.
- park() now yields a cancel window, then detaches + flips status to
parked BEFORE dispose(), and coalesces concurrent park calls.
- ensureLive() cancels a pre-detach park (keeps the live session) or waits
for detach+dispose then performs one coalesced revive; never returns a
disposing session.
- release()/dispose() drain any in-flight park; the idle re-arm skips while
a park owns the transition.
- IrcBus.send() gates parkable recipients through ensureLive and derives
the revived receipt from session identity, so receipts/unread counts
reflect actual delivery.
Fixes#5633
expandPath's leading-colon strip only fired before POSIX prefixes
(`/`, `~/`, `./`, `../`), so Windows-mangled inputs like `:C:\repo\file`
or `:.\src` slipped through and path.resolve treated them as relative
children of cwd. The omp grep subcommand is the Windows grep path, so it
hit the common Windows form of the same bug.
Broaden the lookahead to admit `\` separators, `.\`/`..\` relatives, and
drive-letter absolutes (`[A-Za-z]:`). Add expandPath regression tests
for the Windows forms and the bare-token non-strip cases.
Fixes#5624
The `omp grep` subcommand resolved its path argument with a bare
`path.resolve` in `runGrepCommand`, bypassing `expandPath`. The
leading-colon strip from #5529 never fired, so `:/abs/path` was
mangled into `<cwd>/:/abs/path` and failed to resolve.
Route the path arg through `expandPath` so it inherits the leading-`:`
strip plus `@`-prefix, tilde, and unicode-space normalizations, matching
`read`/`edit`/in-agent `grep`.
Fixes#5624
- Routed native xAI Responses search through configured provider base URLs and headers.
- Kept endpoint credentials coupled and rejected official OAuth tokens for custom endpoints.
- Added proxy routing and credential-leak regression coverage.
Fixes#5599
- Updated schema and runtime paths to use `dev.autoqaConsent` and `todo.remindersMax`, including auto-QA consent reads/persistence and todo reminder limit checks.
- Adjusted settings expectations so obsolete BM25-discovery keys were dropped on load and `tools.xdev` now kept its default unless explicitly set.
- Added/updated tests for the setting key migration and refreshed issue-consent flows, plus a new `refreshMCPTools` test for steered `xdev-mount-notice` updates without prompt rebuilds.
- Added the `xd://` virtual device protocol (`internal-urls/xd-protocol.ts`, `tools/xdev.ts`): tools declaring `loadMode: "discoverable"` are unmounted from the request tools array and driven via `read xd://` (list/docs+schema) and `write xd://<tool>` (execute), gated by the `tools.xdev` setting (default on) and inlined into the system prompt.
- Merged the `irc`, `job`, and `launch` tools into a single `hub` tool (`tools/hub/`, `async/job-manager.ts`): messaging keeps `send`/`inbox`/`list`, job control maps to `wait`/`cancel`/`jobs`, process supervision keeps `start`/`logs`/`stop`/`restart`/`describe` with `ps`, and the unified `wait` races background jobs against peer messages; SDK `IrcTool`/`JobTool`/`LaunchTool` are replaced by `HubTool`.
- Removed the hidden `resolve` tool in favor of the `xd://resolve`/`xd://reject`/`xd://propose` resolution devices, auto-including `write` whenever a deferrable tool or plan mode is present.
- Removed the BM25 tool-discovery system: the `search_tool_bm25` tool, the `tool-discovery` module, the `tools.discoveryMode`/`mcp.discoveryMode`/`mcp.discoveryDefaultServers`/`tools.essentialOverride` settings, per-tool MCP selection, and the `mcp_tool_selection` message type.
- Unified tool presentation on `ToolLoadMode` (`essential`|`discoverable`), replacing the custom-tool `xdev?: boolean` opt-out; custom, extension, MCP, RPC host, image-generation, and TTS tools now default to `discoverable`, and added a `satisfies` predicate to `SoftToolRequirement`.
- Removed the standalone `ssh` command tool and `ssh/ssh-executor` (the `ssh://` read/write/search protocol stays), and made `--tools` address hidden built-ins.
- Updated collab-web to render `xd://` dispatches and `hub` op families, dropped the `search_tool_bm25`/`ssh`/`report-finding` renderers, refreshed tool docs and prompts, and migrated the affected tests and changelogs.
- Simplified `bash` guidance to tighten allowed command patterns, pipeline limits, and launch-based process handling.
- Reworked `browser` instructions into grouped helper sections while preserving selector restrictions and key action semantics.
- Harmonized `eval`, `irc`, `read`, and `todo` prompt wording around state reuse, messaging, selector formats, and task operations.
- Added schema and type updates for task-agent fields and model resolver settings.
- Extended discovery helper logic to carry resolved task-agent metadata through execution setup.
- Updated task/agent registration and execution paths to use the new capability/field data.
- Expanded test coverage for agent-field parsing, model resolution, and executor prewalk behavior.
- Removed `selector`/`sel` arguments from read and grep tool schemas and related execution arg handling.
- Reworked read and grep path processing to parse line selectors from `path` suffixes instead of separate fields, including inline range propagation.
- Updated delegation and execution call paths (including JS/Python preludes and executor tests) to pass selectors embedded in `path`.
- Updated read/grep prompt docs and changelog for the breaking inline-selector API, and removed obsolete selector-specific tests and expectations.
Some models intermittently prefix an otherwise-valid path with a leading
`:` (e.g. `:/abs/path`, `:../rel`). read/edit/grep hard-failed because
resolveToCwd left the colon intact and resolution missed the real file.
The #4618 literal-preferring probe cannot recover it: the literal
`:/abs/path` does not exist on disk, so the peel proceeds to an empty
path.
Strip the mangled prefix in expandPath — the shared resolution funnel for
read (resolveReadPath), grep (resolveToolSearchScope), and edit
(resolvePlanPath) — mirroring the existing @-prefix normalization. The
lookahead only fires before `/`, `~/`, `./`, or `../`, so selector-shaped
tokens like `:raw` are untouched.
Fixes#5508
Threw ProviderHttpError from generateOpenAIHostedImage so a failing active OpenAI/Codex image call records the failure and continues the provider fallback chain instead of aborting the tool call.
Fixes#5218
GitHub rejects the aggregate PR diff endpoint with HTTP 406 once the diff
exceeds 20,000 lines, which made `fetchPrDiffFresh` throw and aborted the
entire /review workflow. Detect the 406 (diff-too-large) specifically and
fall back to the paginated per-file endpoint, reassembling a synthetic
unified diff. Files whose patch is omitted (binary or too large) stay
visible with an explicit marker instead of being dropped.
Fixes#5350
Normalized optional since and until values before enforcing code-search date restrictions.
Covered empty placeholders, real date bounds, and successful validated searches.
Fixes#5370