- Restored formatDimensionNote bracket form '[Image: original WxH, displayed at WxH. Multiply coordinates by S to map to original image.]' that tests assert. The Bun 1.3.14 refactor regressed it to a less informative 'Image resized from …' line.
- Broadened bash-sixel-render multi-line styling assertion to accept both truecolor (38;2;) and 256-color (38;5;) SGR runs so CI runners with TERM=dumb don't fail. The contract being tested — every line carries its own SGR — is independent of color depth.
- Updated @inquirer lockfile entries to newer releases for core, prompts, and related prompt packages, including updated dependency ranges and integrity hashes.
- Expanded minimumReleaseAgeExcludes in bunfig.toml by adding bun-types to the excluded package list.
- Updated BashTool's leading `cd` regex to stop matching newline characters so cwd extraction only applies to a single-line `cd ... &&` prefix.
- Added a regression test for multiline commands with a later-line `&&` to ensure each line of the script executes normally.
- Added a new formatBashCommandLines helper that syntax-highlighted each command line and applied the dim prefix only to the first line.
- Updated the shell renderer to emit command output as line-based entries instead of a single dimmed string.
- Extended the bash renderer test to verify multi-line commands keep ANSI styling on every rendered line.
- Removed local `abortableSleep` in favour of Node's built-in `scheduler.wait` from `node:timers/promises`.
- Consolidated per-provider retry/fetch loops into a shared `fetchWithRetry` utility in `packages/utils`.
- Moved `extractHttpStatusFromError`, `isRetryableError`, and related helpers out of `packages/ai` into `packages/utils`.
- Deleted `extractRetryDelay` in favour of `extractRetryHint` with unified header and body parsing.
- Raised the Bun minimum version to >=1.3.14 across package metadata, install scripts, and changelog notes.
- Removed the Photon native image pipeline and added SIXEL-based `sixel` support in pi-natives.
- Migrated coding-agent image handling and resizing to `Bun.Image`, including updated tests and a JPEG quality bump to 80.
- Added HTTP/2 fetch bootstrap with HTTPS-only fallback and updated Bun build flags for autoload suppression/`--keep-names`.
The OutputSink now keeps a head budget (tools.artifactHeadBytes, default
20 KB) in addition to the tail spill window, so outputBytes can legally
reach head + tail + marker overhead. The multi-million line test still
asserted the pre-elision tail-only bound and started failing on CI.
- Changed multi-file search paging to skip whole files and page results in file windows.
- Added per-file match caps, round-robin file selection, and new file-limit truncation reporting.
- Replaced match/result limit metadata with fileLimitReached and perFileLimitReached.
- Lowered read.defaultLimit default to 300 with 1 lead and 3 trailing context lines.
- Replaced the search skip test with file-pagination coverage and added per-file cap tests.
- Added session-stats analytics tooling to classify searches, detect repeats, and render relevance plots.
- Updated read range expansion to use 1 leading and 3 trailing context lines.
- Changed read.defaultLimit from 500 to 300 in settings defaults.
- Updated read docs and tests to reflect the asymmetric context line behavior.
- Added read-selector analyzers and replay simulators to evaluate coverage and savings.
- Added plotting tools that output new session-stats PNG dashboards from local usage data.
- Added `getPriorityPremiumRequests` and used it in OpenAI and OpenAI Codex providers to increment `usage.premiumRequests` when `serviceTier: "priority"` was sent.
- Combined Copilot and priority premium counts in OpenAI completions and responses usage parsing so emitted usage uses the merged premium total.
- Updated stats parsing/backfill to re-read `service_tier_change` entries and UPSERT only `premium_requests`, so historical sessions pick up priority traffic without mutating other metrics.
- Added `tools.artifactHeadBytes` and `tools.outputMaxColumns` settings with defaults in `SETTINGS_SCHEMA`.
- Expanded `OutputSink` with `headBytes`/`maxColumns` and middle truncate logic with elision markers and tracking.
- Updated output-meta to resolve sink settings, emit truncation metrics, and use `truncateMiddle` for spills.
- Integrated head and column limits into JS/Python/Bash/SSH/read output flows, with `:raw` skipping read truncation.
- Documented new output middle-elision and column-cap behavior in `CHANGELOG.md`.
- Added truncation tests for `OutputSink`, `truncateMiddle`, and read-tool line handling.
- Updated the TUI shutdown slash command handler to return a `SlashCommandResult` instead of `void`.
- Returned `commandConsumed()` after clearing the editor and invoking runtime shutdown.
- Imported `SkillPromptDetails` as a type in the input controller message imports.
- Zed dispatches RPC responses and notifications on separate async tasks, so `setTimeout(0)` lost the race against the session registration handler.
- Dropped `available_commands_update` left the slash-command palette empty (#1015; zed-industries/zed#55965).
Collapses the parallel slash-commands/acp-builtins/ tree (28 files,
~1850 LOC) into one entry per command in builtin-registry.ts. Each
SlashCommandSpec has an optional 'handle' for the text-mode path used
by both TUI and ACP, and an optional 'handleTui' override for
selector/wizard UX. The two dispatchers (executeBuiltinSlashCommand
and executeAcpBuiltinSlashCommand) walk the same registry; the TUI
dispatcher synthesizes a SlashCommandRuntime from ctx when adapting
'handle', and the ACP dispatcher requires 'handle' and skips TUI-only
entries.
Helpers used by both dispatchers move under slash-commands/helpers/.
Behavior, dispatcher entry points, and test fixtures are unchanged;
all 62 ACP builtin tests and 19 TUI slash-command tests pass.
Addresses codex P2 review feedback on #1015:
- getMcpConfiguredServers (powers /mcp list, /mcp test, /mcp resources,
/mcp prompts): iterate project config first so when the same server
name is defined in both scopes the entry shown matches the one the
runtime actually loads. Matches discovery/builtin.ts where the loader
pushes project paths before user paths and capability dedupe is
first-wins.
- handleEnableDisableCommand (/mcp enable, /mcp disable): check the
project file before the user file so toggling a duplicated name flips
the effective entry. Previously '/mcp disable foo' reported success
while the active project foo stayed enabled.
Addresses the codex review comments on #1015 plus a sweep of adjacent
ACP conformance gaps surfaced while wiring them up.
Tool call + diff metadata
- acp-event-mapper: thread session cwd through and resolve every
`ToolCallLocation` (initial args, in-flight updates, result details)
to absolute paths against it; ACP requires absolute paths for
client-side file mapping.
- edit/modes/patch: emit the destination path for moves in the diff
result so post-edit "open file" actions land on the new file.
Permissions
- agent-session: pass cwd into `extractPermissionLocations` and resolve
raw `path`/`file`/etc. fields against it before sending
`session/request_permission`.
- agent-session: gate the permission wrapper on
`bridge.capabilities.requestPermission && bridge.requestPermission`,
matching the read/write/bash capability+method pattern.
acp-agent
- `authenticate`: validate `methodId` against the methods advertised by
`initialize` and reject anything else, so malformed clients fail fast.
- `setSessionConfigOption(MODE_CONFIG_ID)`: also emit
`current_mode_update` so clients tracking `modes.currentModeId` see
the same transition `session/set_mode` would produce.
- Pass `runtime.notifyConfigChanged` to builtins; emit
`available_commands_update` from a shared `reloadPlugins` helper
reused by `/reload-plugins`, `/marketplace`, and `/plugins`.
- prompt resource handling: route `resource` content with `image/*`
MIME into the `images` array instead of dropping it as an opaque
blob; non-image blobs still fall back to the URI placeholder.
- pass session cwd to the event mapper.
Builtins
- model: call `runtime.notifyConfigChanged()` after a successful
`setModel` so the ACP config selector reflects the new model
immediately.
- mcp: redact query strings and userinfo from MCP server URLs before
emitting them in `/mcp list` (prevents leaking `?exaApiKey=…` style
secrets); wire `manager.setAuthStorage(...)` before `prepareConfig`
in `/mcp test|resources|prompts` so OAuth servers can refresh tokens.
- ssh: reject non-integer `--port` values via a `^\d+$` guard instead
of silently coercing through `Number.parseInt`; list project hosts
first and dedupe user-scope duplicates to match capability-loader
precedence.
- export: reject clipboard aliases (`--copy`, `clipboard`, `copy`)
before passing them to `exportToHtml` as a filename.
- compact / force / move / browser: surface underlying failures via
`usage(errorMessage(...))` instead of letting them crash the command.
- session save|delete: route through the active SessionManager so the
persist writer is consulted and stale storage references are removed.
- marketplace / plugins / reload-plugins: call `runtime.reloadPlugins()`
on install/uninstall/upgrade and enable/disable so slash command
registries and command lists refresh consistently.
- shared.usage: make async and `await runtime.output(...)` so
`sessionUpdate` text is never dropped or reordered.
- types: document the new `reloadPlugins` and `notifyConfigChanged`
runtime hooks.
bash tool
- Use a shared `fireKill()` from the abort listener so `session/cancel`
terminates the remote command immediately instead of waiting for the
next `currentOutput()` round trip.
- Race `currentOutput()` against the abort signal so a stuck
`terminal/output` RPC cannot delay cancellation.
- Kill the terminal before reading final output on timeout so a slow
output read cannot let a timed-out command keep running past the
enforced timeout.
Tests
- acp-agent.test: extend the existing config-option assertions to
verify both `model` and `thinking_level` changes emit
`config_option_update` notifications scoped to the right session.
- acp-builtins.test: cover `/model` emitting both
`notifyTitleChanged` and `notifyConfigChanged`; lock in the parsed
`mcp add` / `ssh add` call shapes so future arg-parser regressions
fail the test instead of silently writing different configs; add a
`reloadPlugins` stub plus a typed `notifyConfigChanged` slot to the
shared test runtime factory.
- acp-stdout-hygiene.test: drain stderr in parallel and assert no
JSON-RPC frame leaks onto it; terminate the spawned process so the
stderr pump resolves deterministically.
CHANGELOG: itemize the above under `[Unreleased] > Fixed`.
CI
- bun run check: clean (TS + Rust)
- bun run test: 4128 pass / 689 skip / 0 fail (TS); 252 pass / 0 fail
(Rust nextest)
- bun run ci:test:smoke: --version / --help / `stats --help` all OK
- EditTool now carries oldText/newText in per-file results for patch, replace, and multi-file aggregation paths
- Renderer updated to display diff content for all edit modes
- Enables downstream consumers (ACP event mapper, TUI) to render accurate diffs
- BashTool dispatches execution through the client bridge terminal channel when a bridge is present, falling back to local PTY otherwise
- ReadTool and WriteTool gate filesystem access through ACP permission checks
- Exports new tool wiring in the tools barrel
- Adds omp acp subcommand that launches the agent as an ACP stdio server
- Registers the subcommand in the CLI dispatcher
- Threads terminal-auth args and ACP flags through the launch and main orchestrators
- Exports AgentSession on the public SDK surface
- Updates skills loader to support skill→slash-command conversion and prompt injection
- Updates input-controller to dispatch ACP built-in slash commands
- Adds create/resume/list/page session lifecycle handling to AcpAgent
- Implements mode switching (default vs. plan), MCP server configuration, and model/thinking config negotiation with the connected client
- Routes incoming ACP connections to AgentSession via the new ClientBridge
- Introduces ClientBridge — the abstract boundary between AgentSession and external clients (ACP, TUI), defining terminal handle and permission request contracts
- Adds ACP permission gating in AgentSession for destructive tools (bash, edit, write, ast_edit): allow-once, reject-once, allow-always with caching
- Wires todo tracking, model cycling/retry-fallback chains, and auto-compaction into the session lifecycle
- Flattened newlines and tabs in summary explanations before generating the review preview text, and trimmed the extracted sentence before truncating.
- Sanitized finding titles during render by normalizing tabs/newlines to spaces after stripping priority prefixes.
- Deferred initialize to flush queued credential_disabled events via queueMicrotask and event splicing.
- Added tests for pre-initialize credential_disabled emissions and onError propagation of handler failures.
- Replaced auth credential disable flow with CAS checks in #tryDisableAuthCredentialIfMatches and matching SQL statement.
- Retried OAuth getApiKey after disable failures; added peer-rotation race test for fresh token and active credential retention.
- Updated CHANGELOG for deferred microtask flushing plus eval import renames and diff URL/quoted-path parsing fixes.
- Updated the task tool output to list newly started background jobs by live task id with optional descriptions.
- Extended the async task prompt guidance to distinguish IRC-enabled versus standard coordination and cancellation behavior.
- Added guard for ASTs with no body and trimmed trailing EmptyStatement nodes before final-expression capture.
- Exposed wrapCode via context-manager export for external JS import-rewrite callers.
- Added regression test asserting final-expression wrapping when trailing semicolons follow await.
- Handled structured-clone failures in JsRuntime.display by falling back to text output.
- Added regression coverage for non-structured-cloneable JS display output.
- Hardened `parseUrl` to decode each internal segment and reject empty, `.` or `..` segments.
- Added `AbortSignal` propagation through `ReadTool` into internal URL resolution to honor cancellation.
- Adjusted markdown rendering in `read` output so raw selector reads bypass markdown formatting.
- Aligned `conflict://` help text in `read`/`write` with URI read-path examples for scope conflicts.