The first interactive submit fired session.generateTitle() before
startPendingSubmission() painted the optimistic user row, and
tinyTitleClient.generate() spawned the local tiny-title subprocess
synchronously in #ensureWorker() before its first await. With a local
providers.tinyModel configured, subprocess-spawn latency therefore landed
ahead of the first frame, stalling the first prompt.
Paint the pending row before starting titling, and prewarm an idle,
unref'd worker at TUI startup via a no-op ping (no model load) so the
first submit reuses a live subprocess.
Fixes#6462
OutputSink.dump() was the only path that closed the spill Bun.FileSink.
The bash and Python executors re-throw on failure and their finally
blocks never closed the sink, so any large-output command that errored
leaked the artifact descriptor until an unrelated read (e.g. a SKILL.md
load) hit EMFILE.
Added an idempotent OutputSink.dispose() that closes the sink exactly
once (awaiting any in-flight sink creation, guarding post-finalize
resurrection) and wired it into every executor's finally block.
Fixes#6463
- collectMcpServerNames takes an includeDisabled flag (default true); the
/mcp completer now passes false for test/reconnect/reauth/unauth, whose
handlers (#resolveServerForAuth, reconnectServer) can never resolve a
disabled-only discovered name (dropped from mcpManager, absent from
mcpServers). enable/disable keep offering it since #handleSetEnabled
handles that case for both directions.
- Moved the /mcp autocomplete CHANGELOG entry from the now-released
## [17.1.0] section (where an earlier upstream merge relocated it) back
under ## [Unreleased].
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
XTest input with keysym mapping) compiled into the core addon on every
published target; Linux arm64 and musl are now supported and headless
hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
build dependencies, and the now-unreferenced vendored libspa crate;
reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
XTest layouts reject negative origins and coordinates beyond 0..=32767,
batch coordinates stay bound to the frame last returned to JS with
intermediate screenshots deferred, coordinate input requires a
previously returned frame, and failed chord releases still release
every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
no input is emitted after expiry and wait-heavy batches are rejected
upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
a regular function tool with a typed GA action schema across OpenAI,
Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
/mcp remove <name> only ever succeeds against a config-file mcpServers
entry (project scope by default, user scope via --scope user) —
runtime-discovered-only servers have no config entry and always fail
with "not found in <scope> config". Restrict remove completions to
config-file names, and tag a user-only name with --scope user so the
inserted command is directly executable.
- collectMcpServerNames now unions userConfig.disabledServers so a
third-party-discovered server that was /mcp disable'd (and thus dropped
from mcpManager.getAllServerNames()) still tab-completes as an /mcp
enable target.
- collectMcpServerNames accepts an optional preloaded { userConfig,
projectConfig }; #handleList() passes what it already read instead of
re-reading both config files a second time.
- /mcp's argument completer catches collectMcpServerNames failures (e.g.
malformed config JSON) and returns null instead of letting the
rejection escape un-awaited callers.
Adds an exported collectMcpServerNames() helper (used by both /mcp list
and the new completer) and a runtime-bound getArgumentCompletions for
/mcp that resolves server names after enable/disable/test/remove/
reconnect/reauth/unauth, filtered by the typed prefix. Subcommands with
a different argument shape (add, smithery-search, ...) keep returning
null, and subcommand-name completion is unaffected.
Closes#5654.
Settings.get returns raw merged config without element validation, so a
scalar or non-string tools.xdevInlineDevices entry reached Bun.Glob and
threw while building the system prompt. Normalized the allowlist to
string patterns and compiled globs once per render.
Applied the session-scoped tool reset after /branch and /btw create their
branched logical sessions, closing the same stale-state leak as /new,
handoff, and cross-session switches.
Added a branch transition to the staged-preview regression matrix.
Applied the session-scoped tool reset after handoff creates its replacement session.
Added regression coverage for stale staged preview directives across handoff.
Fixes#4093
Cleared queued tool-choice directives and ACP always decisions after successful logical session transitions.
Added new-session and cross-session regression coverage for staged resolves and both ACP always decisions.
Fixes#4093
- Added `src/live/` subsystem with WebRTC transport, protocol parser, session controller, and headless Chromium audio injection.
- Added `LiveVisualizer` component with phase states, transcript display, and animated waveform rendering.
- Added `/live` slash command and `LiveCommandController` to toggle live voice sessions.
- Suppressed local TTS via `vocalizer.suspend()` during live mode to prevent audio conflicts.
- Added live-instructions and agent-final-message prompts for agent messaging context.
- Added `protocol.test.ts` covering event parsing, chunking, and context message construction.
- Pinned displaceable snapshots like hub waiting polls and todo lists to the viewport during active execution.
- Prevented unpinned spinner ticks from repeatedly committing mutating rows to native scrollback and force-sealing blocks.