Tracked active subagent session model changes in progress snapshots so prewalk handoffs replace the starting-model badge.
Added regression coverage for a prewalk handoff and documented the fix.
Fixes#6083
#spawnTcp reserved a port, released it, spawned the adapter, then immediately
connected. On WSL2 with networkingMode=mirrored the Windows relay keeps
accepting connections to the just-released reservation port for tens of ms, so
the first connect bound a ghost socket instead of js-debug. Gate the connect on
the adapter announcing its listening port on stdout (as vscode-js-debug does
from inside its listen callback) so we only connect once the child owns the
port; this also drains stdout, which nothing else consumes in tcp mode.
Separately, the message reader only rejected pending requests from its catch, so
a clean stream end (the ghost socket dropped after we wrote initialize) left
requests and event waiters pending until their own timeout. Route both the
reader end and adapter exit through a single #failConnection that rejects
pending requests and wakes event waiters, turning every transport failure into
an immediate "DAP connection closed" error instead of a silent 30s timeout.
Fixes#6055
The TUI /usage matrix sorted each quota window's account columns
independently by used fraction, so the positional `account N` labels
denoted different credentials on each row. An account exhausted on one
window but light on another (e.g. a Kimi Code account's 5h limit)
rendered its exhausted bar under a sibling that still had quota, making
the section `% free` and capacity numbers look wrong.
Order account columns once per provider (worst-first) and hold that
order stable across every window row.
Fixes#6067
- Classified registered extension commands before automatic title generation while preserving normal and prompt-producing slash command titles.
- Added regression coverage for one-shot local handling, unnamed-session preservation, and forwarded prompt eligibility.
Fixes#6061
The flat single-spawn task wire schema carries arktype `"+": "delete"`, so a
batch `{ context, tasks[] }` payload sent while `task.batch` is disabled has
those keys stripped and is then rejected as `task must be a string (was
missing)` in the agent loop. That preempts the tool's own actionable checks
(validateShapeParams / validateSpawnParams), so the model only ever saw the
misleading arktype error instead of "task.batch is disabled…".
Mark TaskTool with lenientArgValidation so the agent loop forwards the raw
args to execute() on any arktype failure, letting the tool's shape checks
surface the real reason. Valid calls still normalize through arktype; the
success path is unchanged. Mirrors the existing yield-tool pattern.
Fixes#6039
prewalk.enabled resolved the hand-off target (default @smol) and threw
"No API key for <provider>/<id>" inside buildSessionOptions when the
target had no configured auth, aborting startup and locking the user out
of the app. Prewalk is an optional, off-by-default optimization, so an
unresolvable or unauthorized target now warns and leaves prewalk unarmed
instead of crashing.
Fixes#6064
Persisted the retained user-turn cursor in transcript metadata and restored it when sessions resume, including legacy rows from before the cursor existed.
Made forced lifecycle retention slice from that cursor so enqueue and shutdown no longer add cumulative snapshots beside incremental windows.
Fixes#6058
- Intercepted the configured smart-paste shortcut while a paste-capable modal owns focus.
- Added regression coverage for Ctrl+V API-key entry and documented the fix.
Fixes#6057
A stream that stalls or aborts mid-tool-call ends the assistant turn with
stopReason error/aborted, then appends a synthetic tool_result per un-run
tool call to keep the provider's tool_use/tool_result pairing intact. That
placeholder trailed the failed turn, so AgentSession.retry() — which only
inspected the last message and required role assistant — short-circuited to
false and /retry printed 'Nothing to retry'.
retry() now walks back over trailing synthetic tool results (details
__synthetic true) before the assistant + stopReason check, stripping both
the placeholders and the failed turn. Only synthetic results are skipped, so
a turn whose tools actually ran stays non-retryable. Adds an exported
isSyntheticToolResultMessage guard in agent-loop.ts.
Fixes#6056
Preserved settled user and assistant component instances during compaction-only transcript rebuilds so warmed Markdown and layout caches remain valid.
Covered both manual and automatic compaction paths with focused regression tests.
Fixes#6033
- Stopped asynchronous tool-result handling from overwriting newer todo state.
- Added an AgentSession regression for six exclusive completion calls.
Fixes#6148
Merged provider compatibility configuration after dynamic discovery so explicit models.yml fields remain authoritative across refreshes.
Added a regression covering Anthropic unsigned-thinking replay through refreshProvider.
Fixes#6041
- runPrintMode dereferenced session.sessionManager before checking whether
plan.defaultOnStartup was even enabled, crashing partial-session harnesses;
the settings check now short-circuits first.
- Extended the print-mode session fakes with the settings/sessionManager
members every real session provides.
- Scoped the rpc-stdin-lock stderr assertion to non-load-notice lines: the
adversarial fixture's load failure is now legitimately surfaced (#4954)
and mentions the locked stream by design.
The barrier in driveSessionToYield was unreachable for terminal yields:
the yield tool's shouldTerminate fired requestAbort("terminate"), so
abortSignal was always aborted before the barrier's loop condition ran,
and a run with pending owner jobs completed immediately with whatever
the pre-async yield said (Codex review on #6119).
- Split "stop the free-running turn after yield" from "terminate the
run": a terminal yield with pending owner async work now parks the
run with a recoverable session abort (budget-stop precedent) via
requestYieldTurnStop; only a quiescent yield terminates.
- An async-result follow-up injected after a recorded yield un-latches
it (transcript-ordered, in the run monitor) and re-runs the reminder
ladder, so the run only completes on a yield that postdates every
delivered result — including results injected during the notice turn.
- A run that never refreshes a superseded yield fails (exit 1) with an
explicit reason; the stale payload ships only as failed-run salvage
through the existing failed-after-yield finalize path.
- Rewrote subagent-async-pending.md: the "your current yield stands"
option contradicted the enforced contract.
- Regression tests: parked yield -> injected result -> fresh yield wins;
refusal -> stale payload fails; no-async fast path unchanged.
- Reverted the CURRENT_SETUP_VERSION bump (2 -> 1) introduced with the
default-model setup step (#5982): the new scene now only runs for fresh
installs instead of re-prompting every upgraded install once.
- Installs that already advanced to setupVersion 2 stay non-stale under
the cold-launch gate, so no repeat prompt either way.
Narrow the invalid-yield guard to !abortSent so array-typed incremental
yield sections no longer suppress the infinite-submit-loop abort; add
regression coverage for incremental yield followed by repeated malformed
terminal yields.
An idle worker's finalized last turn has duration set, so
calculateTokensPerSecond returned its completed rate indefinitely and the
status-line badge kept showing stale worker throughput instead of falling
back to the main session's rate. Gate the aggregation on isStreaming and
cover both the idle-worker and mixed idle/streaming contracts.
Add an optional `apply` parameter to the `task` tool so
`isolated: true, apply: false` captures patch/branch artifacts without
applying changes to the parent checkout. Available as a flat top-level
control and per `tasks[]` item. Shares the task/eval isolation-to-executor
translation via a single `toStructuredSubagentIsolationControls` adapter.
Three-piece architecture so subagents inherit async.enabled and
bash.autoBackground.enabled instead of having both force-disabled:
- Owner-routed delivery: AsyncJobManager gains registerDeliverySink /
waitForOwnerJobs; every AgentSession registers a sink for its own agent
id, so background job results inject into the owning agent's run.
Owned deliveries with no live sink dead-letter (result retained on the
job row) instead of misrouting into the first top-level session.
- Quiescence barrier: a subagent's final yield with owner jobs still
running/undelivered is a scheduling pause, not completion. The run
driver notifies the model once (hub wait/cancel), settles owner work,
and folds results in as async-result follow-ups; teardown cancels and
awaits surviving jobs before isolation worktree capture/cleanup.
- Steering soft channel: queued steering no longer hard-aborts
non-interruptible tools; it aborts interruptible waits and raises a
cooperative ToolCallContext.steeringSignal. The mid-batch watch runs
for every batch, and auto-backgroundable bash backgrounds itself on
steer so incoming messages inject promptly with no work lost.
In /vibe mode the director is often idle while workers stream, so the
status-line tok/s badge showed a stale/zero rate even while parallel
workers were actively generating tokens. The badge now aggregates the
main session's live tok/s with every live vibe worker's tok/s, and
falls back to the main session's own cached rate when no workers are
streaming.
- Extract calculateTokensPerSecond to utils/token-rate.ts (neutral
location) so vibe/runtime.ts can depend on it without the render
layer depending on the heavy vibe/task graph.
- Add aggregateVibeWorkerTokensPerSecond to vibe/runtime.ts: sums
each live worker's rate via the shared calculator, returns null
when no workers are streaming so the main rate shines through.
- StatusLineComponent takes the aggregator via an injected
setVibeWorkerTokenRateProvider callback (wired in interactive-mode)
keeping the render layer off the vibe/task dependency graph.
- #getTokensPerSecond splits into #getMainSessionTokensPerSecond
(preserves the sticky per-assistant-message cache) plus the
worker-aggregation path, so the director-idle case no longer
short-circuits to null.
The interactive !/!! shortcut wrapped commands as `fish -l -c '…'`:
resolveUserShellConfig swaps in $SHELL but inherits the bash-oriented
["-l", "-c"] args, and ensureInteractiveShellArgs injected -i only
for zsh. A login fish fires `status is-login` blocks in user config
(agent/keychain setup, PATH mutation) on every command.
fish sources the same config.fish/conf.d files for interactive shells
as for login shells, so give fish -i and strip the inherited -l: user
aliases and functions (#1816) keep working without login-shell side
effects. zsh keeps -l -i since .zprofile is login-only.