- Updated the OpenAI Codex provider to unroll native computer calls and tool outputs into standard function calls.
- Added support for the `PI_CODEX_RESPONSES_LITE` environment variable override via the request transformer.
- Updated documentation and tests to cover lite response resolution and native computer response unrolling.
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
XTest input with keysym mapping) compiled into the core addon on every
published target; Linux arm64 and musl are now supported and headless
hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
build dependencies, and the now-unreferenced vendored libspa crate;
reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
XTest layouts reject negative origins and coordinates beyond 0..=32767,
batch coordinates stay bound to the frame last returned to JS with
intermediate screenshots deferred, coordinate input requires a
previously returned frame, and failed chord releases still release
every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
no input is emitted after expiry and wait-heavy batches are rejected
upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
a regular function tool with a typed GA action schema across OpenAI,
Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
/vibe (a full director/worker orchestration mode) had no user-facing
documentation, and /fresh appeared only as a matrix row in the
session-operations doc whose title already promised a "fresh" section.
Neither was mentioned in the README.
- Add docs/vibe-mode.md: enable/disable, fast/good worker tiers, the five
vibe_* control tools, and the director workflow.
- Add a "## Fresh" section to the session-operations doc describing the
provider-stream/session-state reset and its contrast with /new and /drop.
- Add a "Session controls" subsection to the README linking both docs.
Fixes#6440
- Replaced single-provider preferences with ordered priority lists for web search and image generation.
- Added a `MultiSelectSubmenu` component supporting toggle and reordering interactions in settings.
- Implemented migration logic to convert legacy single-provider preferences into ordered priority lists.
- Updated setup wizard scenes, image generation fallback logic, and search provider chains to use priority lists.
Two fixes on top of the paged transport:
- Near-limit v2 framing no longer materializes the full base64 transport:
chunk lines are generated lazily from a single serialization, the 64 MiB
reassembly ceiling is enforced via Buffer.byteLength before any
full-payload allocation, and RPC stdout writes drain with backpressure
one physical line at a time. Peak RSS for a 63 MiB response drops
~686 MB -> ~521 MB; a rejected 80 MiB response drops ~507 MB -> ~259 MB
(parity with the v1 path).
- get_messages_page errors now carry a machine-readable code
(session_busy | stale_cursor). Both bundled clients' high-level
getMessages() drains discard partial pages and fall back to the legacy
snapshot on either code — previously a cursor invalidated by a
background mutation (e.g. an appended bash message) threw instead of
falling back. Direct page calls remain strict.
The advisor-watchdog.md slash-command table described /advisor,
/advisor on, and /advisor off as toggling the persisted advisor.enabled
setting. Commit 3c5e32f21b made the toggle session-local: setAdvisorEnabled
mutates only the in-memory #advisorEnabled field and writes nothing to
config.yml. Corrected the three rows to describe the session-scoped
override.
Fixes#6128
One ChatGPT email can hold several workspaces (a personal Plus/Pro plan
plus Team/Enterprise seats), each with its own workspace-scoped OAuth
token and independent limit pools. Codex credentials were deduped by
bare email, so logging into the second workspace silently replaced the
first, and usage reports from the two pools merged into one row.
- capture the workspace (chatgpt_account_id) as orgId at login, with
the plan type as its display label; token refreshes never rewrite it
- key openai-codex credential identity as email + org via the existing
org-scoped machinery; legacy email-keyed rows are claimed in place by
the first workspace-scoped login, and workspace-less credentials
never clobber workspace-scoped rows
- exclude the org-mirroring account base from same-org row claims so
two members of one workspace (shared chatgpt_account_id) keep
separate rows
- partition usage-report dedupe by workspace and require every shared
identity dimension to agree when reconciling codex usage blocks
Fixes the openai-codex half of #2966 (anthropic half shipped in #5170);
also covers the #633 scenario.
Added TCP server transport for vscode-js-debug and recursively handled startDebugging requests, breakpoint synchronization, active child routing, and tree cleanup.
Fixes#5984
The normal-yield conclusion claimed a blocked steer is always preserved as a card. During the advisor.immuneTurns cooldown, resolveAdvisorDeliveryChannel returns aside and the note rides the YieldQueue to the next step boundary, not a card. Qualified the conclusion to separate the card cases from the aside downgrade.
Clarified that plan mode preserves every would-be advisor steer, including live-streaming notes, because only user-driven turns converge on ask/resolve.
Documented that ACP bridges deferring agent-initiated turns preserve idle advice unless the bridge allows those turns, while advice can still steer an already-streaming turn.
Updated the severity table and changelog to make all delivery statements conditional on these session and client constraints.
The severity table listed `concern` as unconditionally interrupting and the
prose claimed a normal yield can always steer/resume the agent. Neither holds
once the primary ends with a terminal text answer and no queued work: per #4840
`resolveAdvisorDeliveryChannel` preserves a late `concern` as a passive card
rather than waking the agent to restate completion, while a `blocker` still
steers a triggered turn (#5628).
Documented the streaming-vs-idle split and the terminal-answer carve-out so the
observed idle delivery reads as intended behavior.
Fixes#5913
Loaded a platform-delimited (: on Unix, ; on Windows) path-list of settings overlays from PI_CONFIG_FILES before explicit --config overlays, so wrapper-based setups can inject settings without argv surgery.
Dropped the earlier global --config extraction as too risky; --config remains a launch/acp/models flag as before.
Fixes#5685
Logged one actionable warning per LiteLLM management base when rich metadata discovery fails, while keeping missing 404 routes silent.
Documented metadata-route permissions and covered forbidden versus absent endpoints.
Fixes#5801
- v17.0.1 (#5476) rewrote the normal buffer in place per SIGWINCH, so
the terminal's own width reflow pushed wrapped fragments into native
scrollback mid-drag and resize smoothness collapsed.
- Throwaway drag frames paint on the alternate screen again; the settle
full paint fuses the buffer exit ahead of its destructive repaint.
- Kept the #5319 fixes: deferred overlay alt-exit fusing, confirmed-only
DECRPM 2026 handling, and Warp's in-place resize path.
Added an opt-in viewport-pinned live-region policy and propagated it through transcript composition for in-flight vibe_wait TV walls.
Pinned mutable wall frames now repaint virtually until finalization, while append-only live regions retain their existing frozen-snapshot behavior.
Fixes#5777
Extension-scheduled setInterval/setTimeout/detached callbacks ran outside
the handler-dispatch try/catch, so a throw surfaced as a process-level
uncaughtException and the global postmortem handler tore down the whole
session instead of isolating the misbehaving extension.
- Added ManagedTimers backing sanctioned ctx.setInterval/setTimeout/clearTimer:
callbacks run with handler-dispatch isolation (throw/rejection logged and
routed through onError), handles are unref'd, and all are cleared on
session_shutdown.
- Wired the helpers into ExtensionRunner.createContext and the runner-less
command-context fallback; onSession now inherits the runner context.
- Documented in-process no-isolation behavior and the managed timers in
docs/extensions.md and docs/skills/authoring-extensions.md.
Fixes#5664