Moved first-wins MCP tool-name deduplication and origin-aware warnings into one shared helper used by startup extension registration, SDK custom-tool assembly, and deferred refreshes.
Added an SDK startup regression proving colliding MCP proxy tools keep the first origin instead of silently overwriting it.
Fixes#6786
Applied the denylist and per-server enabled:false exclusions before connection-equivalence deduplication, alongside project scope, so a disabled higher-priority server can no longer shadow a differently-named equivalent enabled server and leave no connection. Parameterized LoadOptions<T> so the pre-dedup filter sees the typed item.
Fixes#6786
Applied the project-scope filter before connection-equivalence deduplication so a project server can no longer shadow a differently-named but equivalent user server and then be dropped, leaving none.
Fixes#6786
Deduplicated semantically identical MCP endpoints across provider-specific names while preserving provider priority and canonical direct names.
Kept the first registration on sanitized tool-name collisions and logged both origins.
Fixes#6786
- Skipped extension-source reconciliation when restricted sessions intentionally load no extensions.
- Added a shared-registry regression covering the provider model, credential, and custom API.
Fixes#6783
/usage, /session, /advisor status, /jobs, /changelog, /context, and
/memory view mounted their finalized panel immediately via ctx.present()
instead of ctx.presentCommandOutput(), the streaming-deferral path added in
#5427 for /tools and /mcp. When invoked mid-turn, the panel landed above a
still-growing live block and the append-only scrollback contract recommitted
it lower down, so it appeared twice in native scrollback.
Route all six large command panels through presentCommandOutput() so they
defer until agent_end, matching /tools and /mcp.
Fixes#6767
- Filter out runner-internal frames from runtime exception tracebacks to start at user code.
- Omit full tracebacks for cell syntax errors to render only the caret display with `<cell>` filename.
- Introduce task.enableEffort setting defaulting to false to hide per-spawn effort parameters.
- Conditionally include effort in single and batch task schemas and descriptions based on the new setting.
A crashed owner's pid can be recycled by an unrelated long-lived
process, so kill(pid, 0) succeeds and the leftover sandbox was pinned
live forever, unreachable by a non-`--all` clear.
The ownership marker now records a process-instance start-time token
alongside the pid (Linux /proc/<pid>/stat field 22, other Unix via
`ps -o lstart`). A live pid whose current token no longer matches the
recorded one is a recycled pid and counts as dead; platforms that can't
report a token degrade to the prior pid-only check.
Fixes#6761
The setup window between writeIsolationOwner and isoStart left the base
dir holding only the marker file and no `m` mount, so classifyDir
returned null and scanWorktrees classified it as a stray — which a
non-`--all` clear removes, defeating the ownership guard mid-setup.
classifyDir now treats the presence of the ownership marker as a
task-isolation signal (in addition to the mount dir), so an in-progress
sandbox with a live owner is preserved throughout backend setup.
Fixes#6761
`omp worktree clear` (without `--all`) removed every task-isolation dir
under the worktree base, including sandboxes owned by subagents running
right now, and the "no live task owns it" reason was asserted from the
mere presence of the `m` mount dir with no ownership check.
`ensureIsolation` now stamps each sandbox base dir with a pid-bearing
ownership marker before the backend materialises `m`, and the worktree
scanner classifies a sandbox as live while its owning process is alive,
so `clear` reclaims only crashed leftovers.
Fixes#6761
A context rebuild that recreated the failed turn's message object made the
identity-keyed active-context removal miss, so the scheduled retry
continuation rejected the terminal assistant error message locally
("Cannot continue from message role: assistant") before any provider
request. auto_retry_end never fired, retryPromise stayed pending, and the
in-flight prompt() plus the TUI retry indicator hung until a manual
follow-up.
The retry path now strips a still-failed assistant tail positionally after
the backoff (generation-guarded, never in preserveFailedTurn mode), and a
continuation that still fails locally closes the retry saga with a failed
auto_retry_end via the new scheduleAgentContinue onError hook.
Fixes#5382
A failed async submission can restore the draft while a nested ask prompt
(note/custom answer) is open, re-blocking the input guard; restoreAskDialog
mounted only the ask component, routing guarded input to an unmounted
editor. Restore now mirrors the initial presentation and remounts the
draft editor whenever the guard exists.
- Replaced parsed --cwd with the resumed project after explicit-id and picker project switches.
- Asserted session construction receives the destination cwd when resume starts with a launch-project --cwd.
Fixes#6752
- Warm the resumed project plugin roots before session creation instead of relying on the unawaited re-warm inside clearPluginRootsAndCaches.
- Assert the destination cwd is preloaded during the switch.
Fixes#6752
- Re-resolve settings-derived model scope once a resume switches projects.
- Extract resolveScopedModels shared across startup, explicit resume, and picker.
- Assert destination enabledModels drive the resumed scope.
Fixes#6752
- Removed the implicit fork branch from explicit session-id resume resolution.
- Re-scoped process cwd, settings, plugin roots, and capabilities before session creation.
- Preserved the missing-directory move flow and covered both paths with regression tests.
Fixes#6752