- Implemented agent type classification and persistence in the database, including a backfill for legacy records.
- Added `AgentType` categorization and aggregated token usage metrics to the backend services.
- Created an `AgentTokenShare` visualization component to display usage distribution on the overview dashboard.
- Integrated agent-based tracking into existing data pipelines, view models, and testing suites.
API-key provider login now upserts the pasted key instead of replacing active sibling credentials for the same provider. Added regression coverage for repeated API-key logins preserving multiple keys.\n\nFixes #3265
- Added `Shell.liveBackgroundJobCount` to query active background processes.
- Retained per-call `:async:` shells if background jobs are still running upon turn completion.
- Reaped shells automatically once their last background process exits to prevent lingering processes.
- Added a `share.store` configuration option (`blob` | `gist`) that allows users to choose between the default share server or a GitHub gist for storing exported session data.
- Changed the default upload target from secret GitHub gists to the share server to avoid GitHub API rate limits for shared sessions.
- Enabled fallback to the share server when a gist upload fails or the GitHub CLI is unavailable.
The completions provider stores session state under the request-time resolved base URL, which can differ from the catalog baseUrl for Moonshot, Alibaba Coding Plan, Azure deployments, and similar provider overrides. The model-switch cleanup now evicts the previous provider prefix whenever the switch leaves that completions backend, so those resolved-url keys cannot survive the switch.
`AgentSession.#closeProviderSessionsForModelSwitch` only handled
`openai-codex-responses` and `openai-responses:<provider>` keys. The
`openai-completions:<provider>:<baseUrl>:<modelId>` entries — which cache
strict-tools disable scopes and reasoning-effort fallbacks tied to the
upstream backend — survived /model switches between different providers or
base URLs, so the next request to that backend (e.g. on /model toggle
back) replayed stale decisions made against an entirely different
transport.
Switching to a model whose `(provider, baseUrl)` differs from the current
openai-completions model now evicts every cached entry sharing the old
prefix. Same-backend model toggles keep their cached state, matching the
existing codex/responses semantics.
Fixes#3260
Bun.spawn -> CreateProcess only appends `.exe` to extensionless names; `.cmd`/`.bat` are never tried. Bare MCP commands like `npx` (which exists only as `npx.cmd` on Windows) crashed the subprocess ~140ms after spawn with ENOENT/EINVAL whenever our own PATH walk couldn't pin the file down (empty `Bun.env.PATH` under a restricted parent process, UNC mounts that reject `fs.access`, locked-down shells).
`resolveStdioSpawnCommand` now routes any unresolved bare command through `cmd.exe /d /s /c` so Windows's PATHEXT search runs Windows-native. Direct-spawn fast path is preserved for resolved `.exe`/`.com` files; the existing `.cmd`/`.bat` wrap is unchanged. The reporter's stated cause ("process.env not merged") was incorrect — the merge has been in place at `transports/stdio.ts:316-319` since well before 16.1.14 — but the symptom they hit is real.
Fixes#3250
Require bracketed image-path paste detection to see an explicit local path separator or file URI before routing .png-like text to image attachment handling.\n\nFixes #3253
PerplexityProvider.isAvailable() accepted authStorage.hasAuth("openrouter")
as a valid credential, so any user with an OpenRouter key configured (for
LLM access) had every webSearch: auto request silently routed through
OpenRouter's perplexity/sonar-pro endpoint. Since Perplexity sits first in
SEARCH_PROVIDER_ORDER, downstream providers like Gemini were never reached
and users saw unexpected charges on their OpenRouter billing.
Auto-chain admission now requires a direct Perplexity credential
(PERPLEXITY_COOKIES, Perplexity OAuth, or PERPLEXITY_API_KEY).
isExplicitlyAvailable still returns true, so users who want the
OpenRouter-backed perplexity/sonar-pro path can opt in by setting
webSearch: perplexity explicitly — the existing OpenRouter fallback in
getApiConfigs handles that case unchanged.
Fixes#3251
Configured provider discovery now treats models.yml/models.json edits as a cache staleness boundary, forcing online-if-uncached refreshes instead of reusing fresh rows written before the config change.
Added regression coverage for Ollama metadata overrides with a pre-existing models.db row.
Fixes#3242
Walked custom/hook `details` recursively through the obfuscator so nested renderer fields (e.g. async-result `jobs[].label`) cannot leak configured secrets into the advisor prompt.
Fixes#3237
Rewrote file-mention path and content through the configured obfuscator before the advisor delta is formatted, matching the primary provider's hide-secrets behavior.
Fixes#3237
`pi_natives` failed to load in Bun worker threads on macOS x64 when the
host built only the `modern` (AVX2) variant. The runtime detector's
`child_process.spawnSync("sysctl", ...)` returned null from the worker
even though the build-time detector (`scripts/host-detect.ts`) succeeded
in the parent shell, so `loadNative()` resolved `variant=baseline` and
searched a file list that excluded the `pi_natives.darwin-x64-modern.node`
the build had actually produced.
Two compounding root causes in `packages/natives/native/loader-state.js`:
- `runCommand` only used `child_process.spawnSync`, which is the path
observed to fail under Bun's worker shim on darwin. The build-time
detector uses `Bun.spawnSync` and works fine.
- The darwin branch looked up `sysctl` via PATH. Login shells supply
`/usr/sbin` so the build picks it up, but worker/embedded spawn
contexts can ship without it.
Fix:
- `runCommand` now prefers `Bun.spawnSync` (matches the build-time
detector) and falls back to `child_process.spawnSync` for non-Bun
embeds.
- The darwin branch tries `/usr/sbin/sysctl` before bare `sysctl`.
- New private env key `__PI_NATIVE_VARIANT_CACHE`: once any context
resolves the variant (the main thread does first), it is written
there. Bun workers and child subprocesses inherit `process.env` at
spawn, so they read the cache and skip detection — sidestepping the
worker-context spawn flakiness end-to-end.
- New exported pure helper `selectCpuVariant({ arch, override, env,
detectAvx2 })` codifies the override > cache > detect order and
returns the cache write hints so the helper itself stays
side-effect-free.
Regression test `packages/natives/test/issue-3238-repro.test.ts` pins
every branch of the resolution order, including the file-list shape
that surfaced the bug.
Fixes#3238
Restricted the status-only rotation fallback in isUsageLimitOutcome to absent or opaque 429 bodies; informative bodies now defer to parseRateLimitReason and only QUOTA_EXHAUSTED rotates, so transient retry hints (Please retry in 5s) and capacity overload (Service overloaded 529) no longer burn sibling credentials.
Added regression coverage for opaque bodies, informative transient bodies, and the new isOpaqueStatusBody helper across rate-limit-utils, stream-auth-retry, and auth-storage-force-refresh-rotate.
Refs #3231
Routed the 429 fallback through isUsageLimitOutcome so messages classified as RATE_LIMIT_EXCEEDED by parseRateLimitReason (Too many requests, per-minute caps) stay in the provider's own backoff layer instead of marking the active credential blocked.
Added regression coverage for transient 429s not entering rotateSessionCredential / refreshGatewayApiKeyAfterAuthError, and surfacing through streamSimple without spending an auth retry.
Refs #3231
- Update `sakanaModelManagerOptions` to provide `dropCachedModelIdsOnStaticMismatch` configuration using identified static model IDs.
- Add a test case to verify that stale cached model metadata is correctly cleared when bundled model specs are updated.
- Updated system and tool prompts to explicitly forbid using shell utilities like grep, rg, awk, and find for tasks better suited to specialized tools.
- Clarified that bash should be reserved for terminal operations and computational pipelines that produce facts not available through existing specialized tool outputs.
- Updated status line to display token usage with an unknown context marker (" 5K/? ") when the model context window is unavailable.
- Updated `fugu` model specifications in `models.json` and catalog constants with corrected pricing, increased context windows, and disabled stream idle timeouts.
- Corrected OpenAI usage accounting by excluding redundant orchestration input tokens in `openai-shared` logic.
- Updated usage population to include orchestration input and output tokens.
- Adjusted total billable usage calculation to incorporate these orchestration-specific token counts.
- Added a regression test to verify accurate attribution for Fugu Ultra models.
Recognized bare HTTP 429 and insufficient_quota payloads as credential-rotatable quota failures in the auth retry path.
Added regression coverage for Codex OAuth sibling rotation before content emission and temporary credential blocking.
Fixes#3231
- Extracted common kernel and executor logic into `BaseKernel` and `executor-base` to eliminate duplicated implementations for Julia, Python, and Ruby.
- Migrated shared operational workflows--including session namespacing, environment filtering, and result mapping--to centralized backend helpers.
- Consolidated runtime discovery and resolution logic into a unified `runtime-env` utility module.
- Simplified language-specific modules by delegating subprocess lifecycle, IPC, and configuration management to the newly established base classes.
- Centralized Parallel API utilities and parsing logic into a single module.
- Exported constants and helper functions from `parallel.ts` to replace duplicated definitions in the search provider.
- Updated the search provider to leverage the unified `parseParallelSearchPayload` function with metadata parsing toggled off.
- Moved tokenization, CJK detection, and query logic from `helpers.ts` to `util/regex.ts`.
- Consolidated duplicated CJK character check logic into a single utility function.
- Exported restructured utilities to maintain existing functionality for the beam module.
- Pass `streamIdleTimeoutMs` from model compatibility settings to the streaming logic.
- Update catalog definitions for Sakana models to include a 300,000ms idle timeout.
- Add a test case to verify that the streaming client honors the model-defined idle timeout.
- Implemented `proxy.ts` utilities for HTTP/HTTPS proxying and `NO_PROXY` bypass rules.
- Added `PI_PROXY` and `PI_PROXY_<PROVIDER>` environment variable support for outbound model service requests.
- Integrated `wrapFetchForProxy` into stream dispatch logic to intercept and proxy `fetch` calls.
- Enabled proxy support for `cursor` provider via custom socket tunneling in `http2` client connections.
- Updated AWS credentials resolution to accept and propagate custom `fetch` implementations.
- Implemented Sakana AI and Fugu provider integration including authentication, API base URL resolution, and dynamic model discovery.
- Configured static model definitions and reasoning metadata for the Fugu model series within the catalog.
- Added environment variable support for API configuration and base URL overrides via `SAKANA_*` and `FUGU_*` variables.
- Verified service integration and provider registry registration through comprehensive test suites in both AI and catalog packages.
- Assert the eval tool hides disabled backends from the model-facing wire
schema (language enum + field descriptions), summary, and description by
default (rb/jl off), and advertises them once enabled — including the
enabled-subset case.
- Update the env-flag fallback test for the new rb/jl opt-in defaults and
extend the env guard to PI_RB/PI_JL so the suite is shell-independent.
- Note the opt-in default and dynamic advertising in the changelog.
- Changed default evaluation backend configuration to only enable Python and JavaScript by default.
- Implemented dynamic tool parameter generation to hide Ruby and Julia from the model's schema when they are disabled in settings.
- Updated tool summary and field descriptions to reflect the currently enabled runtime backends.
- Implemented persistent execution backends for Ruby and Julia using dedicated kernel processes and NDJSON-based IPC.
- Integrated language-specific prelude environments, runtime path resolution, and security-focused environment variable filtering.
- Exposed configuration options, tool schema updates, and lifecycle management for seamless agent interaction with both languages.
- Added comprehensive integration tests and updated prompt documentation to support the new evaluation capabilities.
- Centralized draft state and image management by migrating fields from context to the CustomEditor component.
- Standardized transcript row construction by introducing shared helpers for background jobs, IRC traffic, and file mentions.
- Refactored redundant UI logic and helper functions into reusable utility modules to streamline message submission and component rendering.
- Standardized event handler types by consolidating lifecycle definitions into a shared module while maintaining public API stability.
- Removed the `readHashLines` setting to consolidate hashline display logic.
- Simplified `resolveFileDisplayMode` to derive hashline visibility solely from the active edit mode.
- Added automatic cleanup of the `readHashLines` key from existing configuration files.
- Implement `handleWheelAt` to restrict wheel scrolling to the settings pane.
- Update selection movement to support clamping when scrolling at boundaries.
- Add tests to verify boundary behavior and spatial constraints.
- Improved delimiter-balance logic to correctly identify and spare partially deleted structural closers.
- Prevented premature deletion of structural closers by accounting for existing code below the modification range.
- Added support for tracking inserted lines to improve boundary repair accuracy across multi-section updates.
- Refined the suffix-closer identification to skip lines restated by the new payload and account for projected closers appearing after the patch.
- Established shared `subprocess` infrastructure to standardize worker IPC, environment resolution, and error handling.
- Migrated mnemopi, speech-to-text, tiny-model, and TTS clients to utilize consolidated worker-client utilities.
- Implemented common runtime helpers for ONNX model loading, logging, and process readiness probing.
- Eliminated redundant local spawn logic and environment mapping across all inference worker clients.
- Updated system and tool prompts to present dedicated tools as preferred defaults rather than absolute prohibitions.
- Relaxed the hard-forbidding of shell equivalents for file operations, searching, and editing.
- Retained guidance on prioritizing tools for their gitignore semantics, structure, and line-anchoring capabilities.