Moved RPC dialog request lifecycle into a reusable helper that emits a cancel frame targeting the original request before settling an aborted local promise.
Added coverage for remote confirmation cancellation and pending-request cleanup.
Render the Advisor spend next to the primary-model cost as `$2.67 (sub) + $0.41 (adv)`, leaving the status line unchanged until an Advisor cost exists.
Record the cost from finalized advisor `message_end` events in a per-session ledger instead of deriving it from the live advisor transcript, so an in-session compaction or any other history rewrite no longer resets the reported spend. The ledger is cleared for a new session and once a different-session switch commits, and survives a switch that rolls back.
Replaced the scoped UI object spread with a delegating proxy that binds inherited methods to the original context while overriding only abort-capable dialogs.
Extended watchdog coverage with a prototype-backed notification method matching RPC UI contexts.
Attached the session-stop abort listener and rechecked cancellation before invoking extension work, preventing synchronous ctx.abort() calls from being missed.
Added deterministic coverage for a handler that aborts and then waits on non-UI work.
Forwarded confirmation dialog options in the interactive TUI and scoped extension UI dialogs to each handler watchdog signal.
Added regressions for direct confirmation cancellation and fail-closed tool-call timeout cleanup.
Fixes#6805
- Keep terminal working titles static with a colon separator on Windows instead of scheduling animated spinner updates.
- Update terminal title builder and state machine to check the platform and bypass timer intervals on win32.
- Deduplicate terminal title writes globally across all platforms.
- Adopt `SetConsoleTitleW` via `bun:ffi` for Windows terminal updates instead of OSC writes.
Four levers on top of the green pipeline:
- kata jobs pass --remote_download_toplevel, so fully cache-hit builds
stay metadata-only instead of pulling every intermediate artifact from
bazel-remote (the bulk of the previous 6-minute TS-only main runs).
- the xwin MSVC splat caches its ~1GiB CDN payload on the runner-cache
PVC (OMP_XWIN_CACHE_DIR), instead of re-downloading per ephemeral pod.
- main-push rust jobs export their bazel disk cache to the GitHub cache
(once per lockfile change, shared linux scope). GitHub only shares
default-branch caches across PRs, and main runs on kata where
actions/cache never saved — so every fresh PR was building cold.
- TS-only pull requests skip Rust validation entirely (gh pr diff path
gate); their test jobs restore addons from the main-exported cache.
Export runs disable top-level-only downloading: remote hits would
otherwise export action entries whose blobs were never materialized.
- Cleared the retained soft-requirement lifecycle alongside the deferred
hard choice: clearDeferredToolDirectives() owns both, is called from
clearAllQueues/reset and session-scoped tool-state cleanup, with a
regression covering reminder re-injection after a queue clear.
- Allowed void-returning pre-model gates via the named AgentBeforeModelCall
type and normalized gate results in the loop and Agent dispatcher.
- Documented that the first gate installed mid-run applies from the next
run; corrected the onToolChoiceRejected contract docs; documented the
cross-run lifetime of ToolChoiceQueue's in-flight claim.
- Removed the unused addBeforeModelContextBuild hook.
- Relocated both packages' changelog entries out of the released 17.1.4
sections into Unreleased with PR attribution, folding the never-shipped
Fixed bullet into Added and noting the input-event timing change.
Added an optional per-server languageId override and used it for both disk-backed and in-memory didOpen notifications.
Covered config loading and both document-open paths with a fake custom GDScript server.
Fixes#6800
build-bindings.ts built the failure error from captured stderr only, but
napi-rs/cargo route much of the failure detail to stdout (e.g. `cargo
metadata exited with code 101 ...`). When stderr was empty the thrown
error collapsed to a bare "napi build failed", hiding the real cause.
Attach the exit code plus tail-capped stdout and stderr sections to the
thrown error so the actionable output survives on the error object.
Fixes#6796
Gates guard 1's suppression on #dead: the disconnected path stays
best-effort, but a failed restore during a normal stop() throws as it
did before the guard, instead of silently leaving stdin in raw mode.
Claude-Session: https://claude.ai/code/session_01LTC1HNAntXEMnTYmuUpGHz
zig 0.14's cache corrupts under concurrent `zig cc` (ziglang/zig#18763):
with ~60 cc-compiling cargo build scripts running in parallel, cache
manifests end up referencing evicted objects ("failed to open
.../scanner.o: FileNotFound") and kill the build. Patch the hermetic
wrapper via single_version_override so compile-only steps (-c/-E/-S) get
private throwaway caches under the system tmp dir — cold vs warm is
~25ms for compiles, measured — while links keep the shared cache for
compiler-rt/crt reuse (~6s cold, 25ms warm) under zig's per-artifact
locking.
Moved first-wins MCP tool-name deduplication and origin-aware warnings into one shared helper used by startup extension registration, SDK custom-tool assembly, and deferred refreshes.
Added an SDK startup regression proving colliding MCP proxy tools keep the first origin instead of silently overwriting it.
Fixes#6786
The zig and xwin toolchains stage ~10k-file input trees per action;
building and async-deleting thousands of sandbox trees exhausted file
descriptors (EMFILE in unix_jni during sandbox setup). --reuse_sandbox_directories
under --config=ci removes the churn, with a raise-only ulimit guard in
the bazel-launching steps as belt and braces.
Applied the denylist and per-server enabled:false exclusions before connection-equivalence deduplication, alongside project scope, so a disabled higher-priority server can no longer shadow a differently-named equivalent enabled server and leave no connection. Parameterized LoadOptions<T> so the pre-dedup filter sees the typed item.
Fixes#6786
Applied the project-scope filter before connection-equivalence deduplication so a project server can no longer shadow a differently-named but equivalent user server and then be dropped, leaving none.
Fixes#6786
Windows Terminal identity is commonly lost across SSH and container hops,
leaving only the ambiguous raw 0x08 byte. Added the conservative
PI_TUI_RAW_BACKSPACE_IS_CTRL=1 opt-in so those sessions can map it to
ctrl+backspace without changing the default for terminals where 0x08 means
plain Backspace.
Restored the public isWindowsTerminalSession and matchesRawBackspace exports
and route the parser wrappers through matchesRawBackspace. Documented the
runtime flag and covered local WT, remote opt-in, SSH, and 0x7f behavior.
Fixes#6782
kubelet creates missing subPath mountpoint parents as root, so mounting
the PVC repository cache under ~/.cache left the directory root-owned
and broke both bazel's default output root and zig's wrapper cache
compile (AccessDenied). The mount now lives at /opt/bazel-repo-cache.
kubelet materializes /home/runner/.cache as root when creating the
omp-bazel-repo subPath mountpoint, so bazel's default output_user_root
under it fails with EACCES. Kata jobs now point output_user_root at
RUNNER_TEMP via the bazel-cache rc fragment (pods are single-job
ephemeral; toolchain/crate downloads stay on the PVC repository cache),
and the runner image pre-owns ~/.cache for the next rebake.
Deduplicated semantically identical MCP endpoints across provider-specific names while preserving provider priority and canonical direct names.
Kept the first registration on sanitized tool-name collisions and logged both origins.
Fixes#6786
- Replaced the napi-cli/cargo-zigbuild/cargo-xwin/sccache build path with
Bazel: rules_rust + crate_universe over Cargo.lock, hermetic zig cc
toolchains (linux-gnu pinned to glibc 2.17, linux-musl), host Xcode for
darwin, and a repo-local hermetic clang-cl + llvm-ml + xwin toolchain for
windows-msvc (bazel/toolchains/msvc).
- All eight shipped addons build as //:natives-<target> via the release
transition in bazel/defs.bzl (opt, thin LTO, cgu=16, stripped, canonical
.node naming); scripts/bazel-natives.ts is the single driver for local
dev and CI.
- Rust validation moved to bazel test + clippy aspects (strict workspace
policy for opted-in crates, default lints elsewhere, mirroring cargo
semantics) and the rustfmt aspect; cargo stays as the dev-iteration
surface, with brush-core/brush-builtins promoted to workspace members
and excluded from cargo dev tasks to keep their historical scope.
- CI caches through an in-cluster bazel-remote action cache (TLS + basic
auth, cluster-internal only); GitHub-hosted runners never touch the
infrastructure and use an actions/cache-backed disk cache instead.
- Deleted the hand-rolled caching machinery: ci-target-cache,
ci-native-artifact-cache, ci-build-native, native-source-hash,
find-native-artifacts, restore-linux-native, native-prewarm workflow,
ensure-* toolchain actions, and all sccache/Swatinem wiring.
- Warm native rebuilds drop from ~20 minutes to seconds; a cold client
with a warm remote cache rebuilds the linux x64 pair in ~2.5 minutes.
- Skipped extension-source reconciliation when restricted sessions intentionally load no extensions.
- Added a shared-registry regression covering the provider model, credential, and custom API.
Fixes#6783
The multi-line prompt editor matched word/line delete and yank with
hardcoded chords via matchesKey() instead of the keybindings registry,
unlike cursor motion and the single-line Input component. As a result
ctrl+backspace (a declared default of tui.editor.deleteWordBackward)
never fired and keybindings.yml remaps of deleteWordBackward,
deleteWordForward, deleteToLineStart, deleteToLineEnd, yank, and yankPop
were silently ignored in the main prompt.
Route those six actions through kb.matches(). Also re-wire the Windows
Terminal raw 0x08 -> ctrl+backspace disambiguation into the TS
matchesKey/parseKey seam (where WT_SESSION is observable), replacing the
dead matchesRawBackspace helper that no longer had any call sites.
Fixes#6782
clap consumes the -- marker before execute for the default-signal and -s/-n forms, so kill -- -10 and kill -s TERM -- -10 previously misread the negative PID as a signal. Captured post-marker operands via a dedicated last=true field and treated a preselected -s/-n signal as closing the option position.
Added a regression covering both marker-consumed forms.
Fixes#6779
Recorded per-target PID and jobspec errors while continuing through every remaining operand, then returned a non-zero aggregate status.
Added a regression with a stale PID between two live processes.
Fixes#6779
Restricted -sigspec parsing to the option position and consumed the -- end-of-options marker, so negative PIDs (process groups) and post-marker operands are signaled rather than parsed as signals.
Added a process-group regression covering kill -TERM -- -<pgid> <pid>.
Fixes#6779
Accepted numeric signal specifications, signaled every process operand, and restored SIGTERM as the default.
Added process-level regressions for multi-target SIGKILL and graceful default termination.
Fixes#6779
The "reads the emitted changelog asset when run outside the bundle directory"
probe built its bundle by shelling out to `bun build`, which cannot take a
plugin. The real `@oh-my-pi/pi-utils` and the changelog module's `../config`
import therefore stayed in the graph, and both pull in the native addon loader.
The emitted bundle called `loadNative()` at startup and resolved
`pi_natives.<platform>.node` relative to its own directory, but the probe is
written to a temp dir and run from an unrelated cwd, so that lookup cannot
succeed. Whether the test passed depended on a platform native happening to be
resolvable next to the runner.
Build it with `Bun.build()` and the same `changelog-utils-stub` plugin the
compiled-binary probe in this file already uses, extracted into one shared
helper. The subject under test is emitted-asset resolution, not native loading.
A recycled terminal pane revokes the pty. stdin EOFs, the disconnect path
runs, and stop() tries to restore raw mode on an fd that is no longer a
tty - Bun's node:tty shim throws ENOENT. That throw escaped stop() and
#markTerminalDisconnected(), preempting its own process.kill(SIGHUP), so
the process died with an uncaught exception instead of exiting 129.
Restoring raw mode on a dead fd is best-effort, matching what
emergencyTerminalRestore() already does, and the disconnect handler is
now wrapped so no teardown failure can preempt the exit.
- Enhanced CI workflows and GitHub actions to support native artifact caching and parallel builds.
- Added composite actions and scripts for computing sources, finding artifacts, and managing caches.
- Updated infrastructure documentation and runner deployment scripts with revised resource limits.
/usage, /session, /advisor status, /jobs, /changelog, /context, and
/memory view mounted their finalized panel immediately via ctx.present()
instead of ctx.presentCommandOutput(), the streaming-deferral path added in
#5427 for /tools and /mcp. When invoked mid-turn, the panel landed above a
still-growing live block and the append-only scrollback contract recommitted
it lower down, so it appeared twice in native scrollback.
Route all six large command panels through presentCommandOutput() so they
defer until agent_end, matching /tools and /mcp.
Fixes#6767
- Filter out runner-internal frames from runtime exception tracebacks to start at user code.
- Omit full tracebacks for cell syntax errors to render only the caret display with `<cell>` filename.