The new global smart-paste listener reused handleImagePaste(), whose
image branches insert [Image #N] into the hidden main editor when a
login/API-key prompt is focused. Mirror the enhanced-paste behavior:
show 'Image paste is not supported in this prompt' and skip image-path
detection so only clipboard text reaches the focused prompt.
Session entries keep AgentMessage objects strongly reachable for the whole
session, so WeakMap entries for compacted-away history pinned their
components' rendered layout caches forever. Rebuild now retains only
components for messages the new transcript context actually renders.
Pre-fix resumed sessions wrote cumulative transcript rows under the
incremental ${sessionId}-<ts> source_id shape, so summing every prefixed
legacy row could overshoot the real retained prefix and permanently skip
unseen turns. Use per-row max instead: it can only under-count, which at
worst re-stores one suffix before an explicit cursor row takes over.
Adds a regression seeding a legacy bank with two incremental rows plus a
cumulative resumed row and asserting turns 7-8 still get retained.
hasAuth() consults $HOME/.env via getEnvApiKey, so a CEREBRAS_API_KEY in the
runner's home .env legitimately armed prewalk and failed the no-auth case.
Force the condition with a hasConfiguredAuth spy.
Flat aggregator ids whose prefix collides with a provider slug (e.g.
openai/gpt-oss-120b hosted on OpenRouter) bypassed the authenticated-model
preference: the explicit-provider branch searched the full catalog only.
Keep provider/id exact references authoritative, but let the flat-id
fallback prefer authenticated providers before catalog order.
A retry-chain entry without its own :level suffix now inherits the
unavailable primary's configured thinking level, matching runtime
fallback-chain semantics. Regression test asserts a level that differs
from the fallback model's default.
Cold-opening a large read-only Advisor transcript froze the TUI for tens
of seconds: AgentTranscriptViewer.render() called the full
container.render() before ScrollView clipped, laying out every synthetic
`Session update` input as full Markdown. A 6.5 MiB __advisor.jsonl
blocked the first frame ~27s in a repro.
Synthetic (agent-attributed) inputs now render as a CollapsedSyntheticMessageComponent:
one dim summary row (heading, size, line count, ctrl+o hint) that builds
the heavy UserMessageComponent Markdown only on expand. Blocks above the
viewport never pay layout on cold open; the raw observability data in
__advisor.jsonl is untouched. Real user prompts stay fully rendered.
Fixes#6308
Shared the bundled task prewalk default between runtime execution and the Agent Control Center. Added dashboard regression coverage for task.prewalk.
Fixes#6306
A for:"ready" wait woke on any terminal state, but reported timedOut:false even
when readiness was never observed — the only success signal on the wait result —
so callers could chain work against a dead process. Split the wake predicate
from the ready-observed check: the wait still wakes on a terminal exit, but
timedOut now reflects whether readiness was actually observed (readyAt, live
ready, or a running daemon with no ready spec).
Fixes#6303
The model-facing start content reported when a process exited before readiness,
but launchRenderResult rebuilt the interactive result solely from structured
details and dropped that explanation. Mirror the terminal-without-readyAt
condition in the TUI start renderer and add a renderer contract test.
Fixes#6303
readyAt/readyMatch belong to the exited generation but were only reset by
#launch, which runs after the restart backoff delay. During the "restarting"
window the sticky-marker predicate from the prior commit therefore reported a
dead service as ready, letting start and for:"ready" waits race it. Clear both
markers when #settle enters "restarting"; #launch re-sets them once the new
child is up. Adds a regression test that observes the backoff window.
Fixes#6303
hub start and for:"ready" waits polled the live daemon state, so a process
that flipped starting→ready→exited within one 50ms poll interval was only
ever observed as "exited" and the wait blocked for the full readiness
timeout — despite #markReady durably recording readyAt. A pre-ready exit
had the same failure since terminal states only woke the wait during broker
shutdown.
Wake both waits on readyAt !== undefined || terminalState(state); readyTimedOut
= !ready then falls out. The start renderer reports "Process exited before
readiness was observed." for a pre-ready exit. Adds two regression tests that
hang to their caps on the old code.
Fixes#6303
- Carried startup-selected fallback role and primary selector into AgentSession.
- Continued remaining role fallback entries after the startup fallback fails.
- Added regression coverage for chained startup failover.
Fixes#6283
Versioned request-header restoration metadata inside v10 cache rows so only markers written by the old id-only matcher can bypass an unrestorable marker through requestModelId. Current aliases whose live headers differ from their static base remain unresolved and are refetched or dropped.
Added catalog and startup-registry regressions for custom-header aliases while preserving legacy Copilot -1m cache recovery.
Fixes#6284
Copilot -1m long-context variants are synthesized with transport
headers and a requestModelId to a bundled base. The v10 cache omits
headers; the writer only matched a same-id static entry, so these
variants were flagged unrestorable and dropped on the next offline
read, vanishing from the picker with a "Could not restore model"
warning. The startup registry loader dropped them the same way.
Restore/match headers through requestModelId in the cache writer, the
model-manager restore path, and the coding-agent startup loader, and
bypass a stale unrestorable marker written by the old id-only writer.
Fixes#6284