- Minted the guided-goal Codex side session id once per interview in handleGuidedGoalCommand and threaded it through every turn via GuidedGoalTurnOptions.sideSessionId, so a multi-question interview shares a single websocket-only Codex socket instead of opening a fresh one each turn (which could trip websocket_connection_limit_reached and fall back to the rejected SSE path).
- Exported newGuidedGoalSessionId; runGuidedGoalTurn mints its own id only when no side session id is supplied (one-shot callers, tests).
- Added regression coverage asserting the supplied side session id is reused across turns.
Fixes#5304
Cursor exec bridges derived failure state only from thrown exceptions, so structured AgentToolResult.isError failures were emitted as successes. Propagate the returned flag through standard and streaming shell execution, with regression coverage for both paths.
Added a direct-argv PTY entry point and used it for Windows launch sessions so portable-pty no longer re-quotes cmd.exe command text.
Rejected direct .bat and .cmd applications with guidance to use cmd.exe /c.
Fixes#5416
- Added a Codex rate-limit parser for `x-codex-*` headers and registered it with the Codex usage provider.
- Updated auth-storage to require parsed usage headers before ingesting usage data, treated exhaustion as non-throttled, and renamed ranked candidate drain fields.
- Reworked key ranking math to use `headroom / remainingHours` with a 1-minute minimum, then applied measured-usage precedence with hot-window demotion behavior.
- Updated session handling and tests to support provider-aware header ingestion with deterministic, exhaustion-aware account selection.
Discovered plugin .mcp.json stdio servers launched relative command/cwd
values against the session cwd instead of the plugin's config directory,
breaking bundled ChatGPT/Codex plugins (e.g. Computer Use) with ENOENT
when spawning ./... from an unrelated cwd.
The claude-plugins and omp-plugins providers now resolve relative cwd and
path-like command (./ or ../) against the .mcp.json directory via a shared
resolvePluginStdioPaths helper; bare executables such as npx are left
untouched so PATH lookup still works.
Fixes#5330
The consumer ask endpoint (/rest/sse/perplexity_ask) intermittently closes
its socket before responding. getApiConfigs emitted the OAuth session JWT
(returned by getApiKey while OAuth is the active origin) as a direct
api.perplexity.ai api-key config, so a transient transport failure on the
ask endpoint fell through and sent the session token as a Bearer to the
direct API, whose 401 masked the real error.
- Suppress the direct api-key config when getCredentialOrigin reports the
active perplexity credential as oauth.
- Give the OAuth ask request one transport-only retry; HTTP responses
(including 401/429) are final and never retried.
- Add regression coverage for both legs.
Fixes#5315
- Passed the session provider transport (providerSessionState + preferWebsockets) and an isolated session id to the /guided-goal interview completion so websocket-only Codex models (gpt-5.6-luna/sol/terra) get a websocket session instead of an SSE fallback the Codex /responses endpoint rejects with "Model not found".
- Added regression coverage asserting the guided-goal request inherits the session transport with an isolated session id.
Fixes#5304
generate_image was registered as a custom tool and force-activated via the alwaysInclude list in createAgentSession, so it survived --no-tools (empty toolNames) and any explicit whitelist that omitted it. There was also no generate_image.enabled setting, so /settings had no toggle.
Add a generate_image.enabled setting and only register the tool when enabled and either no whitelist is given or it names generate_image.
Fixes#5305
ExtensionToolWrapper caught a thrown tool exception, emitted tool_result
with the modifiable result, then rethrew the original executionError whenever
the effective error state stayed true. This discarded any replacement content
or details a handler returned, so an extension could only surface modified
content by returning isError: false, which wrongly converted the failure into
a success.
Return the (possibly modified) result carrying isError instead of rethrowing.
The agent loop already honors AgentToolResult.isError (coerceToolResult) and
surfaces it as a tool error on the wire, so replacement failure content now
reaches the model while the call remains an error. No-modification, error->success, and success->error paths keep their existing semantics.
Fixes#5302
disposeBrowserHandle awaited Puppeteer's browser.close() for the headless
kind with no timeout. browser.close() resolves only once Chromium fully
exits, so a wedged process (a Windows failure mode) left releaseTab stuck
in the "Closing tab" phase forever.
Cap the close at 5s and force-kill the Chromium process tree on timeout so
the tool call always releases.
Fixes#5260
Threaded the authorization server's advertised registration endpoint through OAuth discovery, add, reauth, and the client flow instead of deriving metadata from the authorization endpoint.
Added pathful-issuer discovery and end-to-end DCR regression coverage.
Fixes#5267
history:// resolve/complete/index queried the in-memory AgentRegistry
exclusively, so transcripts of unregistered one-shot helpers
(keepAlive: false), released agents, or any subagent after a session
resume threw "Unknown agent" despite their .jsonl session file
persisting on disk — unlike agent://, which reads .md outputs off disk.
Added sessionFilesFromDisk() to registry-helpers: a recursive scan of
the artifacts dirs keyed by agent id, excluding advisor transcripts
(__advisor*.jsonl) and EPERM-rewrite backups (.bak). HistoryProtocolHandler
now falls back to it on a registry miss (resolve and the else branch),
merges on-disk agents into the index, and unions them into completions.
Documented history:// in the system prompt's Internal URLs section.
Fixes#5261
The allowArgs branch in PromptActionAutocompleteProvider.getSuggestions
returned CombinedAutocompleteProvider's result verbatim, so a null from
the base provider short-circuited before getInternalUrlSuggestions.
Internal URL schemes (agent://, skill://, omp://, ...) never completed
inside slash command arguments.
Fall through to internal-url completion when the base provider yields no
argument match. `#` prompt-action tokens stay literal inside slash args.
Fixes#5263
- Disabled the eval watchdog when timeout is explicitly zero.
- Classified session deadline aborts as TimeoutError while preserving their message.
- Documented and tested both timeout contracts.
Fixes#5250
The /todo rm reminder was a generic "user manually modified" message
showing an empty list, so the model read the cleared list as missing and
re-populated it on the next turn. buildSystemReminder now emits an explicit
do-not-recreate / do-not-re-add directive for removals while keeping
status mutations (done/drop) neutral.
Fixes#5258
- retry-cap rollover repro no longer pins which sibling credential the
session hash starts from; it asserts all four are rolled through
- STRING_VALUE_FLAGS table test accepts value-validating flags that
reject the consumed token with CliUsageError (--max-time)
- python dispose-detach test follows the eval abort-shield contract:
runs aborted mid-flight report cancelled even when the kernel races
to completion