- Added the `xd://` virtual device protocol (`internal-urls/xd-protocol.ts`, `tools/xdev.ts`): tools declaring `loadMode: "discoverable"` are unmounted from the request tools array and driven via `read xd://` (list/docs+schema) and `write xd://<tool>` (execute), gated by the `tools.xdev` setting (default on) and inlined into the system prompt.
- Merged the `irc`, `job`, and `launch` tools into a single `hub` tool (`tools/hub/`, `async/job-manager.ts`): messaging keeps `send`/`inbox`/`list`, job control maps to `wait`/`cancel`/`jobs`, process supervision keeps `start`/`logs`/`stop`/`restart`/`describe` with `ps`, and the unified `wait` races background jobs against peer messages; SDK `IrcTool`/`JobTool`/`LaunchTool` are replaced by `HubTool`.
- Removed the hidden `resolve` tool in favor of the `xd://resolve`/`xd://reject`/`xd://propose` resolution devices, auto-including `write` whenever a deferrable tool or plan mode is present.
- Removed the BM25 tool-discovery system: the `search_tool_bm25` tool, the `tool-discovery` module, the `tools.discoveryMode`/`mcp.discoveryMode`/`mcp.discoveryDefaultServers`/`tools.essentialOverride` settings, per-tool MCP selection, and the `mcp_tool_selection` message type.
- Unified tool presentation on `ToolLoadMode` (`essential`|`discoverable`), replacing the custom-tool `xdev?: boolean` opt-out; custom, extension, MCP, RPC host, image-generation, and TTS tools now default to `discoverable`, and added a `satisfies` predicate to `SoftToolRequirement`.
- Removed the standalone `ssh` command tool and `ssh/ssh-executor` (the `ssh://` read/write/search protocol stays), and made `--tools` address hidden built-ins.
- Updated collab-web to render `xd://` dispatches and `hub` op families, dropped the `search_tool_bm25`/`ssh`/`report-finding` renderers, refreshed tool docs and prompts, and migrated the affected tests and changelogs.
- Privatized the legacy `nextToolChoice` method to `#nextHardToolChoice` to ensure all tool-choice directives flow through the unified `nextToolChoiceDirective` entry point.
- Eliminated redundant dual entry points for fetching tool choices, which previously bypassed the soft pending-preview lifecycle.
- Updated test suites to consume `nextToolChoiceDirective` where appropriate to maintain consistency with internal agent-loop logic.
- Switch all UI components and tests from sharp box corners (`boxSharp`) to rounded ones (`boxRound`).
- Update `Theme` to re-export sharp junction symbols (tees and cross) under `boxRound` to ensure consistent divider rendering in rounded boxes.
- Remove outdated architectural notes regarding forced tool-choice queues in documentation.
- Added canonical `pi.zod` schema API exports and removed TypeBox package exports/imports.
- Migrated Tool schema typing from TypeBox to shared `TSchema`/Zod flow with legacy TypeBox compatibility.
- Updated AI provider adapters and MCP/agent builders to convert tool params through `toolWireSchema()`.
- Reworked schema validation from AJV to Zod-safe parsing with `fromTypeBox`, `toolWireSchema`, and meta schema checks.
PendingAction.apply() and reject() now receive the reason string that was
passed to resolve(). This lets custom tools surface the agent's rationale
in their apply/discard output or use it for logging.
- PendingAction interface: apply(reason) and reject?(reason)
- CustomToolPendingAction: same signatures, reject is optional
- CustomToolLoader: threads reject through when building PendingAction
- AstEditTool: accepts _reason (unused, reserved for future tracing)
- resolve.test: covers reason forwarding on apply and reject paths,
and verifies reject return value replaces the default discard message
- docs/resolve-tool-runtime.md: updated interface table, built-in
producer description, usage example, and developer guidance
- Introduce `deferrable?: boolean` on AgentTool, CustomTool, and ToolDefinition.
AstEditTool sets it to true; resolve is now injected only when at least one
active tool is deferrable (previously unconditional).
- Replace single-slot PendingActionStore (set/get/clear) with a LIFO stack
(push/peek/pop/clear). Multiple deferrable tools can stage independent
preview actions; resolve always consumes the topmost one first.
- Wire pendingActionStore through discoverAndLoadCustomTools / loadCustomTools /
CustomToolLoader so custom tools can call pushPendingAction(action) to
register a resolve-compatible pending action with label, apply callback,
optional details, and optional sourceToolName.
- Export HIDDEN_TOOLS and ResolveTool from the SDK for manual tool composition.
- Add CustomToolPendingAction type and pushPendingAction to CustomToolAPI.
- Update createAgentSession to re-inject or remove resolve after the deferrable
audit, consistent with createTools behavior.
- Add LIFO resolve test, update existing tests (set -> push, get -> peek).
- Add docs/resolve-tool-runtime.md covering PendingActionStore internals,
built-in producer example, and custom tool usage guide.