Move the dead-end rearm probe below the mid-run turn-persistence barrier so prepareCompaction sees the just-finished assistant and tool result.
Delay message-end persistence in the regression and require compaction at the second tool boundary, before another provider request can be sent.
Fixes#7151
The dead-end mark parked the live tool-loop context permanently, but the array keeps growing: a later smaller tool result can move the oversized turn to the summarizable side. Recheck prepareCompaction each boundary and re-attempt once a cut point appears, instead of suppressing until provider overflow.
Added a regression proving maintenance re-attempts once a cut point becomes available.
Fixes#7151
Remember no-progress mid-turn compaction results for the live agent-loop context so later tool boundaries skip identical rescue work. The weak context key naturally resets for the next user turn.
Added a scripted regression covering one warning and one attempt per oversized tool-loop turn.
Fixes#7151
macOS Terminal.app consumes Option for character composition, so Alt+Up
never reaches the app and the dequeue is unreachable there. Bind Shift+Up
alongside it -- Shift is not intercepted, and the key was unbound in the
input path.
The three overlay handlers that already use shift+up for fast scroll
(scroll-view, model-hub, log-viewer) match keys directly rather than
through the manager, so they never see this binding.
Both default tables move together: the registry in config/keybindings.ts
and DEFAULT_ACTION_KEYS in custom-editor.ts, which silently shadows the
registry when they disagree.
Appending builtinCredentialSecretEntries() unconditionally made every
secrets.enabled session carry a regex obfuscate entry, so
secretEntriesNeedPlaceholderKey was always true and startup always
created secret-placeholder.key — nullifying the replace-only/no-secret
key-avoidance path and failing headless runs on an unwritable config
root for a feature they never use.
Only configured entries now force startup key creation. The built-in
credential pattern matches dynamically, so SecretObfuscator accepts a
key provider resolved once on the first actual credential match, via
the new getSecretPlaceholderKeySync (never throws: degrades to a
process-ephemeral key with a warning when the key file is unwritable).
Also moves both CHANGELOG entries from the released 17.1.7 sections to
[Unreleased].
- The snapshot dir was one fixed name under the shared `os.tmpdir()`,
created 0700 because the script inlines env-var values referenced by
captured functions (#3470). The first account to run omp owns it, so on
a box where a second Unix account runs omp every bash tool call died
with `EACCES: permission denied, open
'/tmp/omp-shell-snapshots/snapshot-bash-<uuid>.sh'`.
- `recursive: true` swallows EEXIST and `mode` is ignored for an existing
dir, and the defensive `chmodSync` fails EPERM on a foreign-owned dir
and was already swallowed, so the code walked straight into a dir it
could not write.
- `mkdirSync` and the pre-create `writeFileSync` both sat outside any
try/catch, so the error escaped `getOrCreateSnapshot` into
`executeBash`. Nothing is cached on failure, so it repeated for every
command instead of degrading once.
- Scope the dir per uid (`omp-shell-snapshots-<uid>`) and guard both
filesystem calls: an unusable dir now logs at debug and returns `null`,
which callers already handle as "run without a snapshot".
A before_agent_start extension can replace the base system prompt after the
mount notice was consumed. Catalog-backed additions were then marked
announced and suppressed even though the provider request no longer contained
the catalog.
Reserve the notice's pre-user message position, wait until the extension has
selected the final prompt, and suppress catalog-backed additions only when no
per-turn replacement dropped the base catalog. Explicit replacements retain
the mount notice as the device-discovery channel.
Fixes#7139
Marking rebuild-exposed devices announced (and deleting them from the pending
delta) at rebuild time broke add/remove coalescing: a device mounted by
deferred discovery then unmounted before the first user prompt would leave the
device marked announced with the add already gone, so the unmount produced a
spurious "No longer mounted" notice for a device the model never saw.
Record the catalog the current base prompt exposes in #basePromptXdevNames and
apply the suppression in takePendingXdevMountNotice at delivery instead. The
pending delta is left untouched by rebuilds, so #notifyXdevMountDelta still
cancels an undelivered add against a later remove.
Fixes#7139
On a fresh session with deferred MCP discovery the post-discovery prompt
rebuild renders the full mounted xd:// device catalog, yet the pre-user
xdev-mount-notice re-listed the same names because announcement tracking was
never updated by the rebuild. This double-billed the entire mounted MCP
inventory into the first model request.
rebuildSystemPrompt now reports the catalog it rendered via
BuildSystemPromptResult.xdevCatalogNames, and applyActiveToolsByName folds
those devices into the announced-mount baseline (marking them announced and
dropping them from the pending delta). Notices for mount changes the rebuild
did not expose, and all unmount notices, remain intact.
Fixes#7139
Env-driven OTLP trace export built its resource from only service.name,
so OTEL_RESOURCE_ATTRIBUTES entries were silently dropped and backends
that attribute spans via resource attributes never received them.
Merge the vendored envDetector into the resource, which parses
OTEL_RESOURCE_ATTRIBUTES (percent-decoded, per spec) with OTEL_SERVICE_NAME
taking precedence for service.name.
Fixes#7134
The artifact spill wrapper dropped the read truncation metadata, so a
spilled oversized read lost its next-offset pagination hint, and an
artifact:// read of an already-spilled result was spilled a second time.
Preserve the existing truncation metadata and skip re-spilling artifact
reads.
- Wrap status line path segment labels and worktree names in file hyperlinks.
- Apply hyperlink generation using the project directory and rendered path text.
- Add the `app.live.toggle` keybinding defaulted to `Ctrl+L` to start or stop live voice mode.
- Remap the default display-reset action (`app.display.reset`) from `Ctrl+L` to `Alt+L`.
- Update the live visualizer to listen for stop keys so the toggle chord terminates active sessions.
- Replaced legacy `SWAP`, `INS`, and `PASTE` commands with unified `PUT` and `CUT` hunks across parser, grammar, tokenizer, and test suites.
- Added support for named registers and span paste operations in clipboard and block execution logic.
- Implemented indentation repair and enhanced gap locator formatting for improved patch resilience.
- Updated documentation, system prompts, and session analysis scripts to reflect the new syntax and header shapes.
DuckDuckGo does not parse after:/before: operators, so the provider relies
on the shared lenient post-filter to enforce them. But parseHtmlResults()
discarded the ISO timestamps DuckDuckGo now emits per result row, so every
source was undated and passed the date filter unconditionally.
Extract the timestamp span into publishedDate/ageSeconds so
applyQueryConstraints can honor the requested window.
Fixes#7115
Followed DuckDuckGo's returned continuation form until the requested result limit is satisfied, preserving deduplication across pages and the existing search deadline.
Added regression coverage for continuation field submission and 20-result collection.
Fixes#7116
callDuckDuckGoHtml now parses params.query once when parsedQuery is absent and uses that structured view for both q and kl. Direct searchDuckDuckGo/DuckDuckGoProvider.search calls no longer strip lang: from q while defaulting kl to us-en.
Fixes#7110
Replaced unrestricted locale component swapping with DuckDuckGo's documented kl allowlist and explicit aliases for provider-specific codes such as jp-jp, kr-kr, tw-tzh, and uk-en. Unsupported locale combinations now fall back to the existing us-en default instead of sending invalid kl values.
Expanded regression coverage for Japanese, Korean, Traditional Chinese, and unsupported region-language combinations.
Fixes#7110
callDuckDuckGoHtml hardcoded kl=us-en and never read parsedQuery.lang, so
the shared lang: directive was silently discarded — unlike the Perplexity
and SearXNG providers, which map it. Distinct locales collapsed to the same
request.
Added localeToKl mapping the parsed language-region locale onto DDG's
region-language kl code (swapping components, gb->uk alias), falling back to
us-en for language-only, malformed, or absent locales.
Fixes#7110
Address Codex review on #6881. Retraction of never-run tool cards no longer runs eagerly at message_end: only a TTSR rewind (known via isTtsrAbortPending) retracts there. A terminal error/abort lets agent-loop's synthetic tool_execution_end settle each card in place so the failure stays visible, and an auto-retry removes those synthetic-settled cards only when auto_retry_start actually supersedes the turn.
Also settle a held server-resolved (Cursor/todo) completion after a mid-stream tool-call id re-key, so the migrated card is not stranded pending.
Fixes#6879
editor's prefill is the actual document being edited, not a placeholder
like input's — the interactive (hook-editor.ts) and RPC implementations
set it verbatim on any truthy value. Trimming before the presence check
silently dropped whitespace/blank-line prefill content from the ACP
elicitation schema, so a client-side form opened empty and accepting it
could not reproduce the extension's supplied indentation.
Now only a genuinely empty string omits `default`; any other prefill,
including whitespace-only, passes through unchanged.
The factory-level doc comment still listed editor among the non-elicitation
surface that 'remains stubbed', contradicting the elicitation bridge added
in ec3144860. Reflows the sentence without changing its meaning otherwise.
createAcpExtensionUiContext stubbed editor as a hardcoded no-op
(async () => undefined), so free-text elicitation requests from
/review's custom-instructions branch and the ask tool's custom-input
path never reached the client and silently resolved to undefined.
Wire editor through the existing elicitFromAcpClient bridge used by
select/confirm/input, using a {type: "string"} schema with default
set to the prefill text when non-blank.
Verified against a real stdio JSON-RPC transport via acp-probe: the
elicitation/create request now fires with the expected schema and
round-trips the accepted value back to the prompt without hanging.
Adds matching unit test coverage in acp-agent.test.ts mirroring the
existing select/confirm/input bridge tests (prefill->default mapping,
whitespace-prefill omits default, decline/cancel->undefined, no-form
fallback).
- Captured the prompt generation before an IRC wake and passed it to the post-prompt recovery wait.
- Stops the wait from following a successor turn once an abort supersedes the wake, so the wake monitor finalizes promptly instead of misattributing successor progress.
Fixes#7105
- Extracted the shared attachIrcWakeTurnMonitor from the executor reviver closure.
- Installed it in the persisted cold-revive path, forwarding the top-level event bus.
- Covered that a resumed process's parked subagent emits wake lifecycle frames.
Fixes#7105
- Kept IRC run monitors attached through post-prompt retry and continuation recovery.
- Flushed the final deferred agent_end before terminal lifecycle emission.
- Covered empty-stop retry ordering for RPC event subscribers.
Fixes#7105
- Monitored autonomous IRC wake turns with the task executor lifecycle and progress channels.
- Preserved monitoring after idle-TTL parking and session revival.
- Covered RPC subscriptions for both idle and parked keep-alive agents.
Fixes#7105
A bare ctx.invokeTool(params) passed undefined for both signal and onUpdate,
so a wrapper that simply delegates did not stop the native tool when the
outer call was aborted, and native progress updates were dropped unless every
wrapper forwarded them by hand.
createContext now takes the delegation wiring as one named object and binds
the wrapper's own signal and onUpdate as defaults for the delegated call, with
explicit invokeTool options still taking precedence. Grouping toolName, depth,
context, signal, and onUpdate together also keeps the signature readable now
that delegation carries five inputs.
Tests: the delegated native call receives the outer signal and onUpdate,
explicit options override them, invokeTool is absent when no native built-in
of that name exists, and recursion stays bounded per call chain.
The delegated native call built a fresh AgentToolContext with no toolCall
metadata. Native tools read that: write/edit derive LSP batch flushing from
context.toolCall, and computer uses provider metadata plus
providerSafetyApproved for the required screenshot/safety acknowledgement, so
wrapping those tools lost batching and dropped provider result metadata.
Thread the caller's own context (the one the re-registered tool received)
through RegisteredToolAdapter.execute and createContext into invokeNativeTool,
and reuse it for the native call instead of a bare getContext(), falling back
to a fresh session context only when the caller had none.
Addresses PR review. The initial version put invokeTool on AgentToolContext
via ToolContextStore, but the extension execute path (RegisteredToolAdapter)
builds its own ExtensionContext and never saw it, so the documented
registerTool wrapper use case did not work. It also allowed arbitrary
cross-tool targets (bypassing the target's approval policy), used a
session-global recursion counter that tripped on concurrent independent
delegations, and missed discoverable built-ins that xdev partitioning moves
out of the tool array.
Rework:
- Move invokeTool onto ExtensionContext, and bind it in RegisteredToolAdapter
to the tool's own name, so a re-registered built-in actually receives it.
- Make delegation same-tool only: invokeTool takes just (params, options) and
runs the native built-in of the caller's own name. It cannot reach an
arbitrary target, so it cannot escalate past the approval already granted
for the call, and the native call is not re-gated.
- Track recursion depth per call chain (threaded through invokeNativeTool and
createContext) instead of session-global state, so concurrent delegations
do not interfere.
- Seed the native resolver from the xdev registry when present (it retains
discoverable built-ins like browser), else the built-in registry.
Replaces the ToolContextStore-level unit test with an end-to-end test that
registers a built-in wrapper through the extension/session path and asserts
the native tool runs the wrapper's delegated input.
A tool's execute context now carries invokeTool(name, params, options?),
which runs the native built-in of `name` and returns its result. A tool
that re-registers a built-in (e.g. wrapping write to add logging or a
policy check) can delegate to the original instead of reimplementing it.
The native implementation is captured before extension re-registration
replaces the registry entry and before the ExtensionToolWrapper pass, so
invokeTool reaches the unwrapped native execute: it does not recurse into
the caller's own wrapper, and it inherits the caller's already-granted
approval rather than re-running the gate. Delegation depth is guarded
against accidental self-recursion, and it resolves to undefined when no
native tool of that name exists.
Wired through ToolContextStore with a lazy native-tool resolver, so it is
coding-agent-only (no agent-loop change) and sees the fully-assembled
built-in set at call time.
- Bootstrapped extension providers before model selection in both commit pipelines.
- Loaded project-local settings consistently in the legacy pipeline.
- Added regression coverage for explicit and role-based extension models.
Fixes#7099