- Bounded rewind report recovery to messages created after the active checkpoint.
- Added resumed-context regression coverage for late stale rewind results.
Fixes#7739
The ExtensionAPI getAllTools() wired to session.getAllToolNames(),
returning bare tool-name strings. Upstream @earendil-works/pi-coding-agent
promises ToolInfo[] with sourceInfo, so extensions loaded through the
legacy-pi shim (e.g. gentle-pi) crashed on t.sourceInfo.source at every
session start.
Added SourceInfo/ToolInfo types plus SessionTools.getAllToolInfos(), which
returns { name, description, parameters, sourceInfo } and classifies each
tool as builtin/mcp/sdk/extension. Rewired every getAllTools action site
(interactive, acp, print/rpc, subagent executor) and the example extension.
Fixes#7732
The legacy-pi load-time rewriter only recognized static require()/import
specifiers, so an extension resolving a bundled dependency through the
createRequire(base)(spec) factory form (e.g. gentle-pi loading
@heyhuynhgiabuu/pi-pretty) left the bare specifier untouched. In a
compiled binary that argument then fell through to native node_modules
resolution, which is unavailable under --compile, failing extension
validation and session load.
collectExtensionSpecifierReferences now detects createRequire(...)(spec)
factory invocations and records the invoked bare specifier as a require
reference, so the existing pipeline pins it to an absolute path. Relative
specifiers are left alone since they resolve against the createRequire
base, which is not rewritten.
Fixes#7728
- Implemented in-house, zero-dependency utility modules in `pi-utils` covering DOM manipulation, markdown parsing, templating, browser automation helpers, and terminal buffers.
- Migrated packages across the repository to consume the new internal utilities and `omptype` schema validators instead of external dependencies.
- Removed multiple external runtime and development dependencies including Zod, Marked, LRU cache, Turndown, and Puppeteer browser packages.
Repeated /mcp reauth commands could remain blocked by a prior
unfinished login because each command receives a fresh controller.
Coordinate flows through session-shared state so a replacement cancels
and cleans up the old flow before proceeding.
Extension loading iterated paths with await in a for...of loop, so each
module import (file I/O + module evaluation, the dominant cold-start
cost) blocked the next. Split loadExtension into a concurrent import
phase (Promise.all) and a sequential factory-binding phase that runs in
the original path order, keeping registration semantics (last-wins
collisions, shared runtime flag defaults) deterministic and per-extension
error isolation intact.
Fixes#7615
A single-model subagent has no fallbacks of its own, so it inherits one
and is pinned to a `subagent:<id>` role. That pin is inserted first in
`retry.fallbackChains` so no other role can capture its routing — which
also means it shadows every configured role chain at runtime.
Inheritance was hardcoded to `chains.default`, so a subagent spawned
through a role alias (the bundled scout's `model: "@smol"`) retried on
the default role's chain instead of its own. With `smol` chained to
composer/grok/luna and `default` chained to gpt-5.6-sol, every scout
fell back onto sol.
Resolve the inherited chain from the role identity still present in the
raw pattern (`@smol` -> `smol`), falling back to `default` when that
role configures no chain. An explicitly empty role chain still means
"no fallbacks", mirroring `expandDefaultRetryFallbackChains`. Explicit
model selectors keep inheriting `default`: they carry no role identity,
and a role assigned the same model must not capture the child's routing.
After the fullscreen Plan Review closed on approve-and-execute, the
conversation view stayed blank while the plan ran. The propose write's
tool_execution_end handler runs inside EventController's serialized
dispatch chain and awaited handlePlanApproval, which awaits session.prompt
for the entire execution turn, so every later agent_start/message_start/
tool/message_update event queued behind it until the run finished.
Detach the approval dispatch so the dispatch link settles immediately and
the execution turn's events render live. Follow-up to #5688, which only
moved the overlay close before the still-blocking dispatch.
Fixes#7684
Closed worker and cmux run signals before yielding for floating-rejection drainage. Stale promise continuations can no longer begin page navigation after evaluated code returns.
Classified only marked browser failures and evaluated-run stack frames as run-owned rejections. Unrelated tab-worker failures now remain on the worker guard's fatal path.
Used a run-scoped Promise subclass instead of mutating native combinator methods. Evaluated code can now freeze its Promise constructor without breaking cleanup or later browser runs.
Observed Promise.all and Promise.race results derived from browser calls during each evaluated run. User catch continuations that rethrow browser failures now fail the owning run without changing native await behavior.
Logged late user continuation failures in cmux runs and delayed worker rejection folding until request-interception cleanup completed. This closes both windows where missing awaits could be silently dropped.
Logged user continuation rejections that settle after their browser run has ended. This preserves the completed result while making missing awaits visible instead of silently dropping them.
Tracked whether user continuation callbacks create each descendant rejection. Browser errors that user code rethrows now fail the owning run instead of being contained as propagated helper failures.
Scoped browser-error markers to each run and contained only propagated browser failures. Routed floated user continuations into failed runs and added worker coverage for native await plus every continuation method.
Registered live session resume commands with postmortem handling so a
fatal rejection or exception identifies every recoverable agent before
cleanup. Escaped terminal control characters in recovery output.
Observed every browser facade continuation so fire-and-forget helper
timeouts cannot wedge or kill a tab worker. Preserved native Promise
identity for callers and test matchers.
The 17.2.9 revert (172ce9b) restored the legacy path-based session
directory names but removed all migration, including the reverse path.
Sessions written under the short-lived hashed scheme (17.2.5-17.2.8,
`<scope>-<readable>-<sha256>`) were left orphaned, so `omp -r`
current-folder scope reported no sessions.
computeDefaultSessionDir now reconstructs the hashed dir name for the
cwd and performs a one-way best-effort migration into the legacy name,
alongside the existing legacy-absolute migration.
Fixes#7677
Shift-Tab entered the off state correctly, but both status-line render paths suppressed its label. Render off explicitly so users can distinguish disabled reasoning from a missing option.
Fixes#7668
Codex Responses-Lite moves web_search into additional_tools, which the hosted backend ignores. Keep the classic top-level tools contract for all dedicated Codex web searches and cover GPT-5.6 request shape.
Fixes#7666
Under the `nerd` symbol preset, `status.enabled` and `status.shadowed` are
Nerd Font private-use icons (U+F111 / U+F10C). Those glyphs are drawn two
cells wide, but `visibleWidth` counts them as one: `tui/utils.ts` pins
`ambiguousIsNarrow: true`, and the PUA block is East_Asian_Width=Ambiguous.
With no separator the icon overhangs into the next cell and swallows the
label's first character, so the role chips in the model browser and model
hub render as `efault` / `ision` / `lan` / `ask` / `dvisor` instead of
`default` / `vision` / `plan` / `task` / `advisor`.
The adjacent `status.success` check on the very same line already carries a
leading space and renders correctly, which isolates the missing separator
as the cause rather than the glyph itself.
Role-chip assertions in test/model-hub.test.ts are updated for the new
spacing, and the change is recorded under CHANGELOG `[Unreleased]`.
Constraint: lint
Confidence: high
Scope-risk: low
Scanned the Windows host USERPROFILE .agents directory when running under WSL so globally installed Agent Skills are available alongside Linux-home skills.
Fixes#3779
(cherry picked from commit c3468dae4f9b91646bf50f2cf4ded9075572290e)
Reset-window rotation requires account-specific wording; concurrency caps require an actual cap signal; credential removal gated on AuthFailed without UsageLimit so a valid-but-blocked 403 credential is retained.
(cherry picked from commit 2f72752c2586352a4f7e9e814af1cdb0cf192af4)
Account-reset hint evaluated before short retry hints; account-scoped caps rotate on status 403 or undefined (Devin statusless trailer); statusless concurrency caps marked transient; transient same-model retries use the concurrency backoff.
Refuted: quota-worded concurrency caps were already excluded from rotation before the usage-limit text match.
(cherry picked from commit f2b9a18d715ddbcb6ae703670f2212da36bb2826)