- Added `Process` class with pidfd (Linux), libproc (macOS), and handle (Windows) ownership for race-free signaling.
- Replaced `killTree`/`listDescendants` free functions with `Process.fromPid`, `fromPath`, `terminate`, and `waitForExit`.
- Added `TerminationTargets` for batching pgid+pid sets across pty and shell job teardown.
- Migrated `procmgr` and `ptree` to use the new native API, removing the `setNativeKillTree` injection pattern.
- Removed `id` fields from todo models/fixtures and switched session clones to content-based task identity.
- Replaced `/todo_write` `replace` with `init`, updated setup schemas to `list`/`phase`, and append content-only items.
- Updated `/todo` command flows to match phases and tasks by names/content (exact/prefix/substr, case-insensitive), with no ID targeting.
- Updated rendering/output labels to `# Todos`, `formatPhaseDisplayName`, and Roman-numeral phase headings across todo views.
- Aligned prompts, changelog, and todo tests/fixtures with the new init and content-based todo-write contract.
- Integrated `isUnexpectedSocketCloseMessage` into transient error detection so Bun socket-closure failures are treated as retryable.
- Added a retry fallback test that simulates a Bun socket close error and verifies the request is retried successfully with matching retry start/end events and recovered output.
- Fixed bash interceptor to check both raw and cwd-normalized commands, catching commands hidden behind leading `cd ... &&` wrappers.
- Fixed LSP client shutdown to await graceful shutdown with a 5s timeout before killing the process, and parallelized `shutdownAll` via `Promise.allSettled`.
- Fixed concurrent bash command tracking by replacing a single abort controller with a Set, preventing premature cancellation of parallel commands.
- Removed `./hooks` and `./hooks/*` export entries from the coding-agent package exports map.
- Updated pinned Rust nightly toolchain from `nightly-2026-03-27` to `nightly-2026-04-29` in `rust-toolchain.toml` and CI workflow.
- Replaced custom already-published detection in `ci-release-publish.ts` with `bun publish --tolerate-republish` flag.
Mirror anthropic.ts:disableThinkingIfToolChoiceForced for backends that 400
on combined reasoning + forced tool_choice. Kimi explicitly rejects this
combination ('tool_choice specified is incompatible with thinking enabled')
on its native API, OpenCode-Go, OpenRouter, etc. Anthropic itself enforces
the same constraint, so Claude reached through OpenAI-compat proxies
(LiteLLM, Vertex chat-completions, OpenRouter) needs the same handling.
Adds disableReasoningOnForcedToolChoice compat flag, defaulted on for any
Kimi (moonshotai/kimi*, kimi-* ids) or Anthropic (provider/baseUrl/claude*
ids) model. When tool_choice resolves to anything that forces a tool call
(required, named function), reasoning_effort and the OpenRouter-shaped
nested reasoning object are dropped for that turn. The forced tool_choice
itself stays so the agent still gets the tool call.
Replaces the previous (incorrect) approach of unconditionally dropping
tool_choice for kimi reasoning models, which broke explicit tool routing.
Fixes#827
buildSessionContext walked the entry path and unconditionally overwrote
models.default from every assistant message's reported model. Temporary
fallbacks (retry fallback, context promotion) and codex-side model
downgrades both produce assistant messages tagged with a different model
id, which clobbered the user's explicit /model pick on resume and made
the session silently revert to the older model.
Treat assistant-message inference as a legacy fallback that only fills
in models.default when no explicit `model_change` with role="default"
has been seen on the path.
Fixes#849
Add optional defaultLevel to ThinkingConfig schema/type so models.yml can
declare a preferred starting thinking level per model. On model switch
the agent session adopts model.thinking.defaultLevel when present (with
explicit caller-supplied level still winning); otherwise current behavior
is preserved. SDK initial selection prefers the model's defaultLevel
before falling back to the global defaultThinkingLevel setting.
Fixes#775
The autoContinue post-compaction prompt echoed the summary's '## Next
Steps' heading, but that section is generated only from the compacted
tail; the kept ~20k recent tokens are not fed to the summarizer. When
the user pivoted within the kept window, 'Continue if you have next
steps.' anchored the model on the now-outdated plan instead of the
latest intent.
Move the prompt to prompts/system/auto-continue.md (per AGENTS.md
no-inline-prompts rule) and rewrite it to direct the model to re-read
the kept recent messages and follow the user's most recent request,
explicitly allowing it to stop when nothing remains.
Fixes#840
- Added a shared session path resolver that maps local:// URLs through local-protocol options, skips other internal schemes, and returns an absolute filesystem path for real files.
- Updated streaming-edit pre-cache and post-edit cache invalidation to use the shared resolver, preventing internal-scheme assertions while keeping filesystem-based flow for local plan files.
- Extended streaming-edit tests to confirm local:// plan edits complete without panicking and that auto-generated checks receive resolved absolute paths.
- Added a `/context` slash command flow from registry to interactive-mode command dispatch.
- Added `handleContextCommand()` to the mode context interface and command-controller wiring.
- Added context usage breakdown utilities, cell allocation, and 20x10 usage rendering for token categories.
- Reworked compaction token estimation to use tokenizer counts, role aggregation, image token estimates, and fallback handling.
- Exported `resolveThresholdTokens()` as a public compaction helper.
- Updated `formatSessionDumpText` to skip `thinking` entries with empty or whitespace-only content.
- Prevented empty `<thinking>` sections from being emitted in session dump output.
navigateTree() was unconditionally calling buildSessionContext() twice —
once to build stateContext for agent.replaceMessages, and again after
the session_tree emit to capture any hook-driven mutations. 6 of 7
callers discard result.sessionContext, so they paid an O(N) walk for
nothing.
Gate both the emit and the post-emit rebuild behind
extensionRunner.hasHandlers("session_tree"), mirroring the
session_before_tree guard at the top of the same function. When no
handlers are registered, stateContext is returned directly (the
intermediate ops don't mutate SessionManager).
rawContext was captured before the awaited session_tree hook emit,
so extension appendEntry/setLabel mutations during hook handling were
invisible to the UI until the next full rebuild.
Rename the pre-hook build to stateContext (used only for replaceMessages)
and add a second buildSessionContext() call post-hook whose result is
returned as sessionContext for the renderer.
- Added agent identity and registry fields to session configuration and session creation, enabling relay routing metadata for agent sessions.
- Implemented non-persistent IRC relay emission to forward incoming and reply observations from non-main agents into the main session UI.
- Updated IRC UI rendering to support `irc:relay` messages with participant-aware arrow formatting and body display.
Before this change, every navigateTree → renderInitialMessages call path
performed two independent O(N) session-tree walks:
1. agent-session.ts:6586 buildDisplaySessionContext() [inside navigateTree]
2. ui-helpers.ts:402 sessionManager.buildSessionContext() [inside renderInitialMessages]
Changes:
- agent-session.ts: navigateTree() now calls sessionManager.buildSessionContext()
once, derives the display (deobfuscated) context from the raw result, and
returns the raw SessionContext in the result object.
- ui-helpers.ts: renderInitialMessages() accepts an optional prebuiltContext
parameter; reuses it when provided, falls back to buildSessionContext() otherwise.
- interactive-mode.ts: forwards prebuiltContext through the wrapper.
- modes/types.ts: updates InteractiveModeContext interface to match.
- selector-controller.ts: passes result.sessionContext from navigateTree into
renderInitialMessages(), closing the deduplication loop.
Bench (100-msg session, 200 iterations):
two walks [BEFORE]: 0.0702ms/op
one walk [AFTER]: 0.0298ms/op
Saved: 0.0404ms/navigation (57.5% reduction per navigate)
Tests: render-initial-messages-dedupe.test.ts asserts buildSessionContext is
called 0 times when a prebuilt context is passed, 1 time as fallback.
When plan-mode persists the plan file at the synthetic local://PLAN.md
URL, an Edit tool call would crash the entire session. The streaming-edit
pre-cache called resolveToCwd on the path unconditionally; that helper
asserts internal-scheme URLs cannot be resolved as filesystem paths and
threw synchronously inside the assistant-message-event interceptor. The
throw escaped as an Unhandled Rejection, killing the session.
Add an isInternalUrlPath() early-return guard at the top of:
- #getStreamingEditToolCall — returns undefined so the caller skips
pre-cache and the auto-generated guard for internal URLs entirely.
- #invalidateFileCacheForPath — early-returns; nothing to invalidate
for paths that were never cached.
Internal-scheme URLs don't have a stable filesystem path; the actual
Edit tool dispatches through its protocol handler (the same path Write
uses via resolvePlanPath), so the edit still applies — only the on-disk
pre-cache (Morph fast-apply optimization) is skipped.
Add a regression test in streaming-edit-abort.test.ts that drives a
streaming Edit toolcall with path: 'local://PLAN.md'. Without this fix
the test reproduces the original panic stack:
assertNotInternalUrl → resolveToCwd → #getStreamingEditToolCall
→ #preCacheStreamingEditFile → assistant message interceptor.
- Added an `irc_message` session event carrying custom IRC messages and emitted it when IRC records are created.
- Registered an IRC message handler in EventController that skips duplicate messages by role, custom type, and timestamp.
- The handler now appends IRC messages to chat, resets read grouping, and triggers a UI render.
- Updated `read` selector parsing for file and URL reads to accept optional leading `L` and `+` count-style ranges.
- Adjusted truncation notices and schema/help text to emit and suggest `sel` offsets without the `L` prefix, including continuation and suggestion messages.
- Updated hashline/output parsing and related tests to recognize the new `sel` formatting in truncation notices.
- Updated `formatMatchLine` to emit `*` for matched lines, a leading space for context, and a `|` anchor/content separator.
- Revised grep/hashline mismatch messages and prompts to describe the new marker and separator format.
- Aligned affected atom and hashline tests with the updated match-line prefixes and separators.
- dropSession: close persist writer before deletion to prevent EPERM
on Windows where an open file handle blocks unlink
- #runNewSessionFlow: guard UI reset on newSession return value;
session_before_switch hook cancellation now prevents chat state
being cleared and success banner being shown
- Added `AgentRegistry` singleton with session registration/unregistration and IRC routing metadata for peer lookups.
- Added IRC messaging prompts and tooling with `irc.enabled` setting, `list/send` tool paths, and peer roster rendering.
- Changed `/btw` to session-side `runEphemeralTurn`, added background IRC exchange flushing, and fixed empty-input checks.
- Added unit tests for IRC tool and BtwController ephemeral behavior, including disabled, busy, not-found, and abort cases.
/drop works like /new but permanently deletes the current session file
and artifacts instead of flushing (saving) it. Useful when the session
should not be kept.
- add drop?: boolean to NewSessionOptions
- branch in AgentSession.newSession(): skip flush, delete via
FileSessionStorage.deleteSessionWithArtifacts when drop=true;
deletion failure is non-fatal (logged, new session still starts)
- wire handleDropCommand() through InteractiveModeContext interface,
InteractiveMode delegation, and CommandController implementation
- guard: shows error if session has not been saved yet (no file to drop)
- register /drop in builtin-registry adjacent to /new
- Added `note` support to todo-write with `op: "note"` and required `text` input.
- Added optional `notes: string[]` to todo models and preserved notes in cloning and session task mapping.
- Implemented `op: "note"` append flow and markdown `>` block serialization/parsing for todo import/export.
- Updated HUD todo rendering to append superscript `+N` note markers and show in-progress note bodies.
- Documented note operation, required text field, and note rendering rules in todo-write docs and changelog.
- Session metadata now stores on-disk size bytes, populated from file stats when collecting sessions.
- The session selector metadata line now renders file size using formatBytes instead of message counts.
- Session test fixtures were updated with the new size property so they match the revised SessionInfo shape.
- Added tracking of the last successful non-error yield tool call when a yield execution ends.
- Cleared the tracked yield ID and skipped post-turn maintenance when appropriate, including when the last assistant message was a successful yield.
- Standardized unchanged-result error messages in atom and replace edit modes.
- Canonicalized file and CLI defaults from `read` to `open` across tool registration and prompts.
- Added `resolveToolAlias()` and applied alias-normalized tool selection so legacy `read` maps to `open`.
- Updated runtime, UI, and export layers to treat `open` as first-class while preserving `read` compatibility.
- Renamed read prompt docs to `open.md`/`open-chunk.md` and refreshed system guidance to recommend `open`.
- Updated tool-related tests and expectations from `read` to `open` (including test fixtures and aliases).
- Parallelized `collectSessionsFromFiles` via strided workers sized by file count and CPU parallelism, reducing large-list latency.
- Read only a fixed 1024-byte prefix per session file in `collectSessionFromFile`, avoiding full-file scans.
- Added partial-prefix fallbacks to extract session title and first user message when JSONL parsing is incomplete.
- Updated SessionManager.listAll to retrieve session files with Bun.Glob.scan instead of scanSync.
- Awaited the async glob scan results via Array.fromAsync before collecting session metadata.
- Added minimizer API fields (`MinimizerResult.text`, `settingsHash`) and shell options for minimized output behavior.
- Changed bash execution to print minimized text output and append artifact footers only after minimized output is saved.
- Added UTF-8-safe shell streaming with `on_chunk` callback routing and `replace()` output sink updates.
- Added core filter enhancements for git, cargo, go, and listing/python outputs to produce compact summaries.
- Added RTK command filters and fixtures to strip noise, truncate output, and normalize success fallbacks.
- Added command-marker metadata and lifecycle in process execution, including completion markers and exit-code writes.
- Refactored minimization to support `MarkedCommands` mode, token-based detection, and marker-aware stripping.
- Added `onMinimizedSave` and `saveBashOriginalArtifact` to persist full bash-original output artifacts.
- Expanded public exports and marker hooks so external command launch metadata can be controlled by consumers.
Addresses two P1 chatgpt-codex-connector findings on PR #623:
1. Block follow-up auto-continue during retry backoff
isStreaming only checks agent.state.isStreaming || #promptInFlightCount
and does NOT include #retryPromise. When a notification-driven follow-up
arrives during the deliberate sleep window in #handleRetryableError,
the idle gate fires and schedules agent.continue() immediately,
bypassing the configured retry delay and racing the retry timer.
Fix: include isRetrying in the gate.
2. Guard auto-continue against non-assistant resume state
agent.continue() only dequeues follow-ups from an assistant-ended
state; when the last message is user/toolResult (e.g. after an early
abort), continue() resumes prior context and runs an extra model
call on the stale prompt before draining the queue.
Fix: require messages.at(-1).role === 'assistant' before scheduling.
Extracted #canAutoContinueForFollowUp() so both the pre-schedule and
shouldContinue re-check use identical conditions.
Previously session.followUp() enqueued the message into agent.followUp()
but never scheduled a continue when the agent was idle. The message sat
in the queue until the next user turn triggered a prompt.
Mirrors the pattern already used by TTSR deferred injection: pair
agent.followUp() with #scheduleAgentContinue(). The shouldContinue guard
prevents spurious continues if multiple follow-ups arrive in a burst and
the queue drains before a scheduled task runs.
Only affects the idle path - during streaming the running loop's
getFollowUpMessages callback drains the queue at end of turn naturally.
- Standardized missing-file read errors and now return `File not found: <path>` for absent edit targets.
- Centralized AI provider, usage, and OAuth helpers into shared modules to remove duplicated logic.
- Migrated OAuth/API-key login flows to shared factory helpers and removed inline prompt/token-exchange code.
- Reused shared tools and formatter utilities for discovery, stream tails, LSP batching, and source formatting.
- Consolidated repeated test helpers and fixtures into shared modules, replacing inline helper duplicates.
Extract duplicate normalizeLocalScheme regex pattern into a shared function in path-utils.ts. Updated interactive-mode.ts, approved-plan.ts, agent-session.ts, bash-skill-urls.ts, and plan-mode-guard.ts to use the shared utility. Also fixed error message formatting (removed extra backslashes).
On Linux, Node's path.normalize() collapses the double slash in
local://PLAN.md to local:/PLAN.md, creating a directory called local:
in the project root instead of routing through the local:// protocol handler.
Defense-in-depth fixes across 5 layers:
1. resolveToCwd() now throws if a path starts with any internal URL
scheme prefix (local:, agent:, skill:, etc.), preventing all 59
call sites from treating URIs as relative filesystem paths.
2. resolvePlanPath() now matches on local: prefix (not just local://)
and normalizes local:/ to local:// before resolution, catching
all slash variants.
3. Bash URL expansion regex and early-exit checks now also match
local:/ (single slash), and normalize before resolution.
4. Edit preview/diff functions now gracefully skip internal URL paths
instead of crashing via the resolveToCwd guard.
5. All startsWith('local://') checks updated to startsWith('local:')
with normalization in agent-session, interactive-mode, and
approved-plan modules.
Also adds local: to .gitignore to prevent accidental commits of the
leaked directory.
When persist writes race with test-level tempDir cleanup (e.g. in agent-session-auto-compaction-queue.test.ts), fs.rename can fail with ENOENT during the atomic swap inside #writeEntriesAtomically. The error is already routed through #persistChain so #persistError surfaces it to future persist calls, but the awaited rejection returned by #queuePersistTask was bubbling out of the fire-and-forget callers (#rewriteFile path and the incremental writer path) and Bun's test runner reported it as an 'Unhandled error between tests' even though the test itself passed. Attach a silent .catch on both void paths so the rejection is considered handled at the callsite while the persistChain retains the error state.
- Replaced Snowflake session IDs with UUIDv7 for created, forked, branched, and resumed sessions.
- Derived cache session IDs from OpenAI request options and passed them into Responses client creation.
- Used derived session IDs for OpenAI `session_id`/`x-client-request-id` headers and `prompt_cache_key`; omitted headers when retention was none.
- Added tests for UUIDv7 session creation/branching and OpenAI cache-affinity default, override, and disabled-header modes.
- Documented UUIDv7 session handling and OpenAI cache-routing fixes in package Unreleased changelogs.
The #emitSessionEvent refactoring changed the order: #emit was called before
#emitExtensionEvent, but for non-message_update events this introduced
microtask timing issues that broke auto-compaction and handoff tests.
Fix: keep the original order (extension first, then emit) for non-message_update
events. Only message_update events use fire-and-forget extension queueing with
emit-first ordering.