- Replaced the napi-cli/cargo-zigbuild/cargo-xwin/sccache build path with
Bazel: rules_rust + crate_universe over Cargo.lock, hermetic zig cc
toolchains (linux-gnu pinned to glibc 2.17, linux-musl), host Xcode for
darwin, and a repo-local hermetic clang-cl + llvm-ml + xwin toolchain for
windows-msvc (bazel/toolchains/msvc).
- All eight shipped addons build as //:natives-<target> via the release
transition in bazel/defs.bzl (opt, thin LTO, cgu=16, stripped, canonical
.node naming); scripts/bazel-natives.ts is the single driver for local
dev and CI.
- Rust validation moved to bazel test + clippy aspects (strict workspace
policy for opted-in crates, default lints elsewhere, mirroring cargo
semantics) and the rustfmt aspect; cargo stays as the dev-iteration
surface, with brush-core/brush-builtins promoted to workspace members
and excluded from cargo dev tasks to keep their historical scope.
- CI caches through an in-cluster bazel-remote action cache (TLS + basic
auth, cluster-internal only); GitHub-hosted runners never touch the
infrastructure and use an actions/cache-backed disk cache instead.
- Deleted the hand-rolled caching machinery: ci-target-cache,
ci-native-artifact-cache, ci-build-native, native-source-hash,
find-native-artifacts, restore-linux-native, native-prewarm workflow,
ensure-* toolchain actions, and all sccache/Swatinem wiring.
- Warm native rebuilds drop from ~20 minutes to seconds; a cold client
with a warm remote cache rebuilds the linux x64 pair in ~2.5 minutes.
- Enhanced CI workflows and GitHub actions to support native artifact caching and parallel builds.
- Added composite actions and scripts for computing sources, finding artifacts, and managing caches.
- Updated infrastructure documentation and runner deployment scripts with revised resource limits.
- Filter out runner-internal frames from runtime exception tracebacks to start at user code.
- Omit full tracebacks for cell syntax errors to render only the caret display with `<cell>` filename.
- Added `_normalize_host_tool_event` to `RpcClient` to remap transport tool events to executed host tools.
- Updated worker tool-end handling to verify `is_error` is false before marking terminal actions complete.
- Added test coverage in `test_client.py` and `test_worker.py` for host tool event normalization and errored review submission behavior.
- Introduce task.enableEffort setting defaulting to false to hide per-spawn effort parameters.
- Conditionally include effort in single and batch task schemas and descriptions based on the new setting.
- The broker heals its store synchronously while serving /v1/usage, but the
remote client snapshot only converges via the background long-poll; the
assertion raced that poll and flaked on slow CI runners.
- Pull one explicit snapshot after fetchUsageReports, matching the sibling
same-deadline re-upsert test.
Returning end-of-input from chunks::read on a disconnected receiver
also masked a panicking ext_sort sorter thread (comparator or Rayon
panic in sort_by), letting sort exit 0 with truncated or empty output.
Retain the sorter JoinHandle and join it after read_write_loop, mapping
a thread panic to an error; drop the sorted-chunk receiver first so a
still-running sorter unblocks instead of deadlocking the join. Added an
external multi-chunk sort test covering the spill-to-files join path.
Fixes#6736
- anthropicModelManagerOptions accepted the registry-derived base URL verbatim; bundled rows without the /v1 suffix made discovery request https://api.anthropic.com/models (404), so a stale text-only cache row stayed authoritative over fresh models.dev vision metadata and snapcompact refused to run on claude-opus-5.
- Discovery now always targets /v1/models via toAnthropicDiscoveryBaseUrl while model rows keep the provider base URL, mirroring createSimpleAnthropicProviderOptions.
- Added issue repro test covering the bare-host base URL shape.
Fixes#6563
The vendored uu-sort reader unwrapped the chunk-channel send at
chunks.rs:248, panicking with `SendError(..)` whenever the receiver
disconnected early (a consumer thread stopping after an error or a
closed output). Diverge from upstream: on a failed send, stop reading
gracefully and report end-of-input, matching the pattern already used
by the sorter thread. Added a regression test that drives read against
a dropped receiver.
Fixes#6736
- Add blocked todo status and optional blocker attribute to todo items.
- Update RPC client and worker serialization logic to support todo blockers.
- Add test coverage for parsing session state with blocked todos.
- Runtime already honored spec compat signingEndpoint via applyCompatOverrides and generated models.json emits it; the spec interface never declared it, breaking typecheck for explicit opaque-proxy overrides (#6717 remediation path).
- Moved the resolved-view doc onto the spec field; ResolvedAnthropicCompat keeps only officialEndpoint as resolved-exclusive.
A context rebuild that recreated the failed turn's message object made the
identity-keyed active-context removal miss, so the scheduled retry
continuation rejected the terminal assistant error message locally
("Cannot continue from message role: assistant") before any provider
request. auto_retry_end never fired, retryPromise stayed pending, and the
in-flight prompt() plus the TUI retry indicator hung until a manual
follow-up.
The retry path now strips a still-failed assistant tail positionally after
the backoff (generation-guarded, never in preserveFailedTurn mode), and a
continuation that still fails locally closes the retry saga with a failed
auto_retry_end via the new scheduleAgentContinue onError hook.
Fixes#5382
The rewrite pipeline realpaths resolved dependency paths, so the expected
specifiers must be built from the canonical temp root (macOS /var vs
/private/var symlink).
A failed async submission can restore the draft while a nested ask prompt
(note/custom answer) is open, re-blocking the input guard; restoreAskDialog
mounted only the ask component, routing guarded input to an unmounted
editor. Restore now mirrors the initial presentation and remounts the
draft editor whenever the guard exists.
process.cwd() reports the physical path (/private/var/... on macOS) while
mkdtemp fixtures keep the /var symlink form; normalized both sides so the
runRootCommand cross-project resume regression passes on darwin.
The lock-race and EPERM regression tests compared injection predicates
against the uncanonicalized temp config path, but the atomic writer
resolves it via realpath; on macOS /var -> /private/var made the mocks
never fire and both tests failed. Compared against the realpath instead.
Provider ids (ZenMux mirrors) and explicit compat.signingEndpoint spec
overrides on opaque proxies now qualify alongside URL-recognized signing
routes; stale-official compat and the Vertex/Copilot header exclusions
are preserved (#6717).