- Reworked Linux clipboard writes to use a shared `OnceLock<Mutex<Option<Clipboard>>>` so a `Clipboard` instance persists for the process and keeps X11 ownership alive.
- Updated `copy_to_clipboard` to route Linux calls through the persistent helper while macOS and Windows keep transient on-thread writes.
- Added changelog entries for the native X11 clipboard fix and the AI default Anthropic model note.
Fixes#2075
- Added first-party-first provider priority defaults for model ranking.
- Consolidated model resolution to use getModelMatchPreferences from session settings.
- Prioritized providerPriorityRank ahead of usage rank when picking preferred models.
- Added second-pass fallback to default-model or API-key-valid matching order.
- Tracked each role assignment with an `autoSelected` flag to distinguish inferred defaults from configured models.
- Resolved unconfigured known roles from `pi/{role}` candidates in `#loadRoleModels` and marked them as auto-selected defaults.
- Added a selector test verifying unconfigured models render `[SMOL auto]` and `[SLOW auto]` badges.
- Replaced the TUI row truncation path with per-character and ANSI-sequence iteration that tracks visible cells before clipping output.
- Added ANSI helpers to parse sequence boundaries and preserve OSC66 visible payloads while enforcing max source length during truncation.
- Added natives regression coverage for Ghostty super+alt backspace key matching and parsing.
- Added `getCredentialOrigin` and `getEnvApiKeyName` to classify auth source.
- Surfaced provenance tags in the `/login` and `/logout` provider picker.
- Made the picker search filter match credential origin and env var name.
- Added coverage for credential-origin precedence and env naming.
- Adjusted deduplicateToolCallIds in transform-messages.ts to enforce max tool-call ID length.
- Updated convertMessages in openai-completions.ts to pass provider-specific ID limits and suffix settings.
- Added regression coverage for duplicate tool IDs on OpenAI and Mistral truncation paths.
- Handled local resumes with missing source CWD by prompting to move and reopening sessions.
- Shared missing-CWD relocation logic between local and global resumes for consistency.
- Added regression test for local explicit-session-dir resumes and session-header cwd updates.
- Tracked kitty-dot payload listings to emit BEL-terminated OSC5522 responses.
- Updated non-kitty-dot writes to include mime in metadata and drop ST terminator.
- Adjusted enhanced-paste tests to assert BEL terminator and metadata formatting.
- Switched long-row truncation to visible-cell width, preserving suffixes after zero-width prefixes.
- Added issue-2045 regression test in issue-2045-repro.test.ts for combining-prefix truncation.
- Updated startup handling so `applyStartupCwd` now re-syncs `parsed.cwd` to the resolved absolute project directory after `setProjectDir` runs.
- Adjusted the CLI cwd tests to verify a relative `--cwd` argument is normalized to an absolute path and does not double-resolve against the new process cwd.
Defer read-output line-number stripping from #handleRaw to #flushPending and
gate it on uniformity: a bare "N:text" row is only a pasted-snapshot artifact
when *every* bare body row in the hunk carries the prefix. A mixed set (e.g.
"3:keep" next to "plain") is treated as genuine content and left intact,
avoiding silent corruption of bodies that legitimately start with "digits:".
Removes at most one prefix per row; "+"-prefixed literal rows stay untouched.
Reverts the now-orphaned stripLeadingHashlinePrefixes export back to private.
- Added an interrupt state in EventController to switch the working label to `Interrupting...` and suspend intent-driven updates until the turn resets.
- Called `notifyInterrupting()` from streaming-interrupt paths in InputController and exposed it on InteractiveModeContext so Esc acknowledgement shows immediately while tools tear down.
- Added tests to verify loader acknowledgement, freeze of late intent updates during interruption, and label updates resuming on the next agent start.
- Changed the `github-copilot` service provider to resolve credentials only from `COPILOT_GITHUB_TOKEN`.
- Updated CLI extra help text to document `COPILOT_GITHUB_TOKEN` as the GitHub Copilot environment variable.
- Reworded environment variable docs to reflect the revised Copilot/GitHub token usage and order.
When a session's working directory is moved or renamed (e.g. `git worktree
move`), the session file stays under the old cwd-encoded bucket while the new
directory is empty. Resuming was lossy:
- `--continue` rejected the terminal breadcrumb purely on cwd mismatch and then
found nothing in the new bucket, silently starting a fresh empty session.
- cross-project `--resume <id>` only offered to *fork* (duplicate) the session
into the new directory, forcing manual id selection and leaving a stale copy.
Detect relocation via the strong, low-false-positive signal "recorded cwd no
longer exists on disk" and re-root in place with the existing `moveTo()`:
- `continueRecent` re-roots the terminal's last session into the current
directory when its recorded cwd is gone and the new location has no sessions
of its own (otherwise behavior is unchanged). `readTerminalBreadcrumb` is
refactored into `readTerminalBreadcrumbEntry` returning the raw cwd +
session file so callers can interpret a cwd mismatch.
- cross-project `--resume <id>` offers "Move (re-root)" instead of fork when the
source directory is gone; a still-existing different project still forks.
Tests: continue-relocation (re-root on move, no-hijack on plain cd, prefer
local recent) and cross-project move-vs-fork routing.
Add unit and E2E coverage for the impersonated_service_account ADC path:
RS256 JWT-signed service_account sources, IAM URL reconstruction, delegate
forwarding, and end-to-end routing so the impersonated token (not the
source token) authorizes the Vertex request. Reflow google-auth.ts to match.
`finalizeSubprocessOutput` always spliced collected `report_finding`
entries onto a top-level `findings` array regardless of the active output
schema. A caller-supplied schema with `additionalProperties: false` and
no `findings` property would accept the raw payload in-tool (via the
`yield` validator, which only sees the pre-injection data) but then fail
post-mortem validation — emitting `schema_violation: findings: must not
be present` and propagating as a fatal `RuntimeError` through
`agent-bridge.ts` and the eval Python/JS preludes, collapsing the entire
workflow cell along with any prior successful subagent work.
`normalizeCompleteData` now takes the resolved validator and only
performs the injection when the augmented candidate validates. When the
schema rejects it, the raw payload is returned instead — which the in-
tool yield validator already accepted, so the lockstep guarantee
documented at the top of `output-schema-validator.ts` is honored.
Findings remain visible via the agent progress stream and JSONL
artifact, so no information is dropped when injection is suppressed.
Both finalize call paths (yield-success and no-yield fallback) now share
the single validator build instead of constructing it twice, and the
yield-path schema_violation branch is now reached only via the
explicit malformed-schema check, never via spurious findings rejection.
Fixes#2070
Ghostty on macOS reports Option+Backspace as kitty modifier 11
(wire) = 10 (mask) = super(8) | alt(2). The native key matcher only
recognised shift/ctrl/alt, so:
- format_kitty_key in crates/pi-natives/src/keys.rs rejected any
sequence whose effective modifier had bits beyond shift/ctrl/alt
set; parseKey returned undefined for \x1b[127;11u.
- parse_key_id recognised only those three modifiers, so even an
explicit 'super+alt+backspace' degraded to 'alt+backspace' and
could not match an actual super+alt encoded press.
- The editor's matchesKey(data, 'alt+backspace') branch was never
reached and Option+Backspace either no-op'd or fell through to
single-character delete.
Added a MOD_SUPER constant, taught parse_key_id, format_with_mods,
and format_kitty_key about the super bit, added super+alt+backspace
(and super+alt+delete / super+alt+d) to tui.editor.deleteWord*
defaults, and broadened the editor's direct matchesKey calls to
accept the super+alt variants. Existing alt+backspace / alt+d /
alt+delete paths are untouched, so the legacy ESC+DEL workaround
keeps working too.
Added Rust unit tests for the super modifier (positive and
negative for hyper/meta sequences we still drop) and TS
regressions in keys.test.ts and editor.test.ts that exercise
\x1b[127;11u end-to-end.
Fixes#2064