Separated the fork prompt result into accepted, declined, and unavailable states.
Interactive declines now return cleanly through runRootCommand, while non-TTY
invocations continue to fail with a diagnostic instead of silently exiting 0.
Updated regression coverage for both branches.
Fixes#1668
createSessionManager threw `Session "X" is in another project (Y).` when
the user answered "n" to the fork prompt, and runRootCommand never caught
it. The throw bubbled up as an Uncaught Exception with a stack trace.
Return undefined from the decline branch instead, and treat
`typeof parsed.resume === "string" && !sessionManager` in runRootCommand
as a user cancellation: print a dimmed "Resume cancelled" message and
return cleanly (exit 0), mirroring how the picker UI handles
"No session selected".
Fixes#1668
- Replaced `Bun.sleep(50)` with `Promise.withResolvers` resolved on first chunk to avoid races.
- Used a filesystem marker file to detect shell startup before aborting in persistent-session test.
- Prevents flaky failures where aborts arrived before shell setup completed.
- Moved EvalBackendsAllowance and related functions to a dedicated eval-backends.ts module.
- Replaced ad-hoc brokenShellSessions tracking with a quarantineShellSession helper that also awaits the abort cleanup promise.
- Applied quarantine on timeout and cancellation paths, not just errors.
When the autocomplete popup is visible, ESC unconditionally falls through
to the editor base class so it can dismiss the popup. Only an ESC with no
popup visible reaches onEscape and routes to the global interrupt handler.
Removed the shouldBypassAutocompleteOnEscape callback that paved over the
popup-dismissal path whenever the agent was busy (streaming, bash, /btw,
auto-compaction, etc.) — that is precisely the moment the user is most
likely to hit ESC while the popup is open, and dismissing-then-aborting in
one keystroke is a footgun, not a feature. Two-press semantics now match
the standard TUI/IDE pattern: first ESC closes the popup, second ESC
aborts.
Tests cover both branches in custom-editor-keybindings.test.ts and the
input-controller escape suite no longer asserts the dead callback.
Fixes#1655
- Added `DiagnosticsLedger` to track diagnostics already surfaced per file, suppressing repeats within a session.
- Wired dedup into both edit and write tools via a `transformDiagnostics` hook on the writethrough pipeline.
- Added `lsp.diagnosticsDeduplicate` setting (default: true) to control the behavior.
- Only bridge heartbeats (`agent()`/`llm()`) now re-arm the watchdog; compute, stdout, `log()`/`phase()`, and ordinary tool calls count against the budget.
- Emitted an immediate heartbeat at bridge call start to avoid early abort near budget edge.
- Removed `idle` flag and "of inactivity" suffix from timeout annotation strings.
- Updated docs, prompts, and comments to reflect the new wall-clock semantics.
- Introduced helper `createEmptyWorkspaceTree` to reduce duplication.
- Populated missing `workspaceTree` field in test contexts for `buildSystemPrompt`.
- Extended ResolveContext / WriteContext with localProtocolOptions so the
internal-URL router can thread the calling session's local-root mapping
through to handlers.
- LocalProtocolHandler.resolveOptions now prefers context.localProtocolOptions
before consulting the process-global override or the first main-kind session
in AgentRegistry, fixing multi-session ACP hosts (cmux) where reads of
local://PLAN.md were routing to a sibling session's artifacts dir even
though plan-mode writes succeeded against the calling session.
- read, find, ast_grep, ast_edit, and search now thread
this.session.localProtocolOptions into the router so local://, memory://,
agent://, and other handlers see the right caller.
- Added regression tests covering the override-vs-context priority and the
ENOENT-against-caller-root path.
Fixes#1608
Guarded find renderer path summaries so raw pre-validation string paths render instead of throwing. Added coverage for pending, fallback, empty, and detailed result render paths.\n\nFixes #1622
The catch around the subagent yield-reminder prompt previously logged
every exception at ERROR. User cancel (^C) and compaction-driven aborts
both surface as ToolAbortError through awaitAbortable, so benign control
flow generated 9 spurious 'Subagent prompt failed' errors in 2 days on
the reporter's instance.
Gate the ERROR branch on '!abortSignal.aborted && !(err instanceof
ToolAbortError)' and route the abort path to logger.debug. The outer
catch + finally still mark the run aborted, so observable behaviour is
unchanged.
Fixes#1623
Include pending prompt messages in the pre-send context estimate so auto maintenance runs before providers reject over-limit requests. Suppress auto-continue when maintenance runs inline for an active prompt.
Fixes#1618
Enable eager native scrollback rebuild mode while assistant text is actively streaming so reflowed Markdown rows do not leave stale duplicated tails in WSL/Windows Terminal scrollback.\n\nFixes #1615
The first cut at the subprocess isolation swallowed every signal exit (`exitCode === null`) on the assumption it was the intentional SIGKILL from `terminate()`. That misclassifies real worker deaths — SIGSEGV from a native crash, SIGKILL from the OOM killer, an operator `kill -9` — so any in-flight title/completion/download promise would await forever while `#worker` still pointed at a dead process.
Added an `intentionalExit` flag flipped by `wrapSubprocess.terminate()` right before its SIGKILL. `onExit` swallows only the flagged exit; every other signal exit now fires the `errors` channel with a "signal SIGFOO" message so `TinyTitleClient.#handleWorkerError` clears `#pending` and dumps the dead worker handle. Added two regression tests pinning both branches.
Reported by chatgpt-codex-connector on #1607.
Moved the tiny title/memory worker from a Bun Worker thread into a child process spawned via Bun.spawn IPC. The agent CLI gains a hidden --tiny-worker dispatch the parent invokes through process.execPath; the parent SIGKILLs the child on dispose so onnxruntime-node's NAPI finalizer never runs in any address space the agent owns. On Windows that finalizer was segfaulting Bun at shutdown after the tiny title model loaded (issue #1606). Drops the now-dead 'close'/'closed' handshake and the unused parentPort bootstrap, and removes tiny/worker.ts from --compile worker entries in both build scripts plus the regression test that pinned them.
Fixes#1606
- Added `repairDoubleEncodedJsonString` to unescape fields double-encoded by the model (e.g. literal `\n`, `\"`, `\uXXXX` in `context`/`assignment`/`description`).
- Scoped repair to natural-language fields only, leaving code-bearing tools untouched.
- Applied repair on both render and execution paths in `TaskTool`.
- Converted [SECTION]...[/SECTION] markers to "SECTION\n===" format in system prompt templates.
- Updated system conventions doc to reference the new marker style.
- Updated tests to match against the new header pattern.
Included the reviews field in comments-enabled PR view fetches so pr:// output can show formal review submissions and approvals.
Added protocol coverage that emulates gh --json field selection before asserting rendered approval output.
Fixes#1600
When Zed provisions MCP servers through `session/new.mcpServers`, the
ACP agent
correctly connects to them and registers their tools via
`refreshMCPTools`, but
the tools were never activated. `refreshMCPTools` builds the next
active tool
set from `getSelectedMCPToolNames()`, which — with discovery disabled —
returns
only MCP tools already in the active set. Since ACP sessions start with
no MCP
tools, this created a circular deadlock: tools could only become active
if they
were already active.
Added an optional `{ activateAll?: boolean }` parameter to
`refreshMCPTools`.
When true, every newly registered tool is force-activated regardless of
prior
selection. `AcpAgent#configureMcpServers` passes `activateAll: true` on
both
call sites so client-provisioned tools are immediately usable.
Leaving the dead connection in `#connections` made `getConnectionStatus` report `connected` and `waitForConnection` hand a closed transport to callers after the breaker had explicitly suspended the server. Mirror `#doReconnect`'s teardown: detach `onClose`, fire-and-forget `transport.close()`, and drop the entry from `#connections` (plus its in-flight slots in `#pendingConnections`/`#pendingToolLoads`). Tools stay registered in `#tools` so the user can recover with `/mcp reconnect`.
Test asserts `getConnectionStatus("crashy") === "disconnected"` after the burst.
Refs #1592
A stdio MCP server that completes the initialize + tools/list handshake and then exits cleanly will fire `transport.onClose` on every clean exit, and the old `MCPManager.reconnectServer` path spawned again unconditionally. A misconfigured PHP-shebang MCP (e.g. Laravel Boost in a non-Laravel project) hit this loop and forked 66 487 `php84` processes parented directly to the agent's `bun` PID until macOS force-rebooted.
Add a per-server sliding-window circuit breaker: at most 5 reconnect attempts per 30 s window. The transport `onClose` callback and the per-tool-call retry in `tool-bridge` are subject to the breaker; `/mcp reconnect` passes `{ manual: true }` to reset the window so users can recover after fixing the underlying misconfiguration. Stale `onClose` is detached when the breaker trips so a late EOF event cannot re-arm the loop.
Defended by `mcp-reconnect-storm.test.ts`: a Bun stdio fixture answers the handshake and exits, then asserts the spawn count stays at ≤ 10 (was 127 without the fix).
Fixes#1592
Send the LSP exit notification after a successful shutdown response before falling back to process termination. Add a regression test that fails when a server receives shutdown but not exit.\n\nFixes #1593
- Replaced perimeter-based border animation with a bottom-edge `borderSegmentHeadCol` bounce cycle.
- Constrained animated segment rendering so only the bottom border can be darkened while other edges stay flat accent.
- Updated tests to validate non-teleporting width-based motion and bottom-edge easing behavior.
git clone --depth 1 --single-branch only fetches the tip of the
requested branch, so any subsequent git checkout <sha> for a non-tip
commit fails with 'reference is not a tree'. The error was caught and
rethrown as 'shallow clone may not contain this commit', but the clone
arguments were never adjusted.
Drop --depth 1 (and --single-branch when no ref is requested) when the
caller supplies options.sha so the desired commit is present in the
local object store. The ref-only path remains shallow.
Fixes#1589
- Dropped `summarizeShakeRegions`, the shake-summary prompt, and related types.
- Removed `shake-summary` compaction strategy and `providers.shakeSummaryModel` setting.
- Migrated existing `shake-summary` configs to plain `shake` on load.
- Simplified `/shake` to `elide` and `images` modes only.
- Defaulted the test createAgentSession input to an empty object before spreading.
- Computed workspaceTree from the normalized options, preserving the cwd fallback behavior.