- Simplified `bash` guidance to tighten allowed command patterns, pipeline limits, and launch-based process handling.
- Reworked `browser` instructions into grouped helper sections while preserving selector restrictions and key action semantics.
- Harmonized `eval`, `irc`, `read`, and `todo` prompt wording around state reuse, messaging, selector formats, and task operations.
- Added schema and type updates for task-agent fields and model resolver settings.
- Extended discovery helper logic to carry resolved task-agent metadata through execution setup.
- Updated task/agent registration and execution paths to use the new capability/field data.
- Expanded test coverage for agent-field parsing, model resolution, and executor prewalk behavior.
- Removed `selector`/`sel` arguments from read and grep tool schemas and related execution arg handling.
- Reworked read and grep path processing to parse line selectors from `path` suffixes instead of separate fields, including inline range propagation.
- Updated delegation and execution call paths (including JS/Python preludes and executor tests) to pass selectors embedded in `path`.
- Updated read/grep prompt docs and changelog for the breaking inline-selector API, and removed obsolete selector-specific tests and expectations.
- plugin-install-validation mocks now answer the bun pm cache probe that refreshBunGitCache issues before bun update on git re-installs.
- working-accent tests render the loader before asserting accent computation counts: colorizers run lazily at render time since the loader layout cache landed.
Some models intermittently prefix an otherwise-valid path with a leading
`:` (e.g. `:/abs/path`, `:../rel`). read/edit/grep hard-failed because
resolveToCwd left the colon intact and resolution missed the real file.
The #4618 literal-preferring probe cannot recover it: the literal
`:/abs/path` does not exist on disk, so the peel proceeds to an empty
path.
Strip the mangled prefix in expandPath — the shared resolution funnel for
read (resolveReadPath), grep (resolveToolSearchScope), and edit
(resolvePlanPath) — mirroring the existing @-prefix normalization. The
lookahead only fires before `/`, `~/`, `./`, or `../`, so selector-shaped
tokens like `:raw` are untouched.
Fixes#5508
- Minted the guided-goal Codex side session id once per interview in handleGuidedGoalCommand and threaded it through every turn via GuidedGoalTurnOptions.sideSessionId, so a multi-question interview shares a single websocket-only Codex socket instead of opening a fresh one each turn (which could trip websocket_connection_limit_reached and fall back to the rejected SSE path).
- Exported newGuidedGoalSessionId; runGuidedGoalTurn mints its own id only when no side session id is supplied (one-shot callers, tests).
- Added regression coverage asserting the supplied side session id is reused across turns.
Fixes#5304
Cursor exec bridges derived failure state only from thrown exceptions, so structured AgentToolResult.isError failures were emitted as successes. Propagate the returned flag through standard and streaming shell execution, with regression coverage for both paths.
wantsSnapcompact is true for both the default strategy and an explicit
/compact snapcompact mode override. The prior fix downgraded both to LLM
compaction, which silently shipped the transcript to a provider for users
who deliberately requested the local-only no-LLM archive path. Only the
default-configured strategy now falls back; explicit snapcompact keeps
failing locally. Added a regression test for the explicit path.
Fixes#5064
Route overlapping executions through owned Shell instances so timeout and interrupt paths can explicitly abort native child-process cleanup.
Fixes#5389
- Wrapped every Kitty graphics APC for tmux passthrough, preserved quiet mode across chunks, and enabled placeholder placement when Kitty is explicitly forced.
- Routed Agent Hub transcript images through the shared image budget and terminal image setting.
Fixes#5381
A stalled or dropped provider stream that surfaces as stopReason:"error"
carrying the bare "Request was aborted" sentinel fell through both retry
gates: #isRetryableReasonlessAbort required stopReason:"aborted", and
#isRetryableError's classifier returns no retriable kinds for the generic
sentinel. The turn died immediately despite retry.enabled.
- Relaxed #isRetryableReasonlessAbort to accept an empty generic-abort
sentinel turn under stopReason "aborted" or "error", tagging it Abort so
#handleRetryableError retries it without model fallback.
- Kept the deliberate-abort guards intact: user interrupts and silent aborts
carry their own markers (not the generic sentinel), and #abortInProgress /
#isDisposed / #streamingEditAbortTriggered still settle without retry.
- Rewrote the stale fallback test that froze the buggy no-retry behavior to
assert retry-and-recover for the error-stop sentinel.
Fixes#5375
Fetched current heads and tags into Bun's matching cached bare clone before running bun update.
Added an isolated HTTP git regression covering a moved branch with a stale cache.
Fixes#5401
navigateTree() treated every custom_message entry as a re-editable user
turn, setting the leaf to the injection's parent and dumping the expanded
skill body into the editor. A /skill:<name> invocation is persisted as a
skill-prompt custom_message, so selecting it in /tree dropped the skill off
the active branch. Skip the parent-leaf/editor-prefill path for
skill-prompt entries so the leaf lands on the injection node itself.
Fixes#5374