- Removed the canonical model variant indexing, selection, and tracking logic from the model registry and resolver.
- Eliminated the `canonical` sub-command, tab view, search tokens, and equivalence configuration structures from the CLI and model selector components.
- Refined model identification, lookup, and provider fallback resolution to bind exclusively to standard, raw model IDs.
- Relocated the equivalence utility script within the catalog package to support script-only policy generation.
- Anchors the incomplete-todo reminder block inside the scrollback transcript instead of a floating live container.
- Eliminates duplicate reminder copies piling up in terminal scrollback during terminal reflows.
- Removes the dedicated `todoReminderContainer` and simplifies state synchronization on todo reload.
- Updates tests to verify sequential reminders commit as separate blocks and are left intact when tools succeed.
Captured the configured thinking selector when entering plan mode so approving a plan restores auto instead of the provisional concrete effort. Reloaded DEFAULT(auto) badges from defaultThinkingLevel and covered the plan-approval handoff plus /model display.
Fixes#3901
#handleOAuthFlow now installs an editor.onEscape hook that aborts its
AbortController, and accepts an external abortSignal so the add-wizard
can thread its own controller through (the wizard owns focus and absorbs
Esc itself). Cancellation surfaces as MCPOAuthCancelledError, which the
reauth and add catches translate into a neutral status line instead of
the generic OAuth failure banner. Disambiguated from the existing 5-min
timeout via a userCancelled flag so timeouts still read as errors.
The wizard intercepts Esc/Ctrl+C while #oauthAbort is set so its own
"Press Esc to cancel" advertisement now matches the behaviour, and
renames its error heading + tip when the failure is a user cancel. Also
fixed the misleading "(Press Ctrl+C to cancel)" message in the chat
transcript onAuth block to say "Press Esc" — Ctrl+C is bound to the
editor clear action, not interrupt.
Fixes#3888
Codex review on #3829: when an MCP server lives in a non-writable
source config such as opencode.json with enabled:false, the dashboard
re-enable had nowhere to write to — the writable mcp.json fallback
did not own the server, so setMcpServerEnabled fell through to the
denylist and the source's enabled:false kept the row disabled.
Added a parallel allowlist to the user-level mcp.json that overrides
a non-writable source's enabled:false flag without ever mutating the
foreign config:
- types + schema: new enabledServers array (mirrors disabledServers).
- config-writer: readEnabledServers + setServerForceEnabled helpers,
and setMcpServerEnabled now writes to enabledServers on enable
when no writable mcp.json owns the server, clears it whenever a
writable source becomes the source of truth, and always clears the
override on disable so a force-enabled server can be turned off.
- mcp/config (runtime loader) and state-manager (dashboard read):
honor enabledServers as an override on enabled:false, while still
letting disabledServers win.
- Added a regression test that walks the full lifecycle for an
opencode.json server: enabled:false is surfaced as disabled, the
dashboard re-enable force-enables via enabledServers without
touching opencode.json, then disable clears the override and
populates disabledServers.
Fixes#3827
Codex review on #3829: the dashboard re-enable path still missed MCP
servers loaded from supported non-primary native config files such as
.omp/.mcp.json or user .mcp.json. Those rows carry enabled:false from
their source file, so falling back to the user disabledServers denylist
could not make the row active again.
- setMcpServerEnabled now accepts the loaded row's sourcePath and checks
it before the primary project/user mcp.json paths.
- extension-dashboard passes the source path for writable MCP providers
(native and mcp-json), avoiding accidental edits to third-party tool
configs while still updating .omp/.mcp.json and standalone MCP JSON
sources.
- Added a regression test for a server loaded from .omp/.mcp.json with
enabled:false; re-enable flips that file to enabled:true and does not
write the denylist.
Fixes#3827
Codex review on #3829: when an MCP server's mcp.json entry carries
enabled:false, the dashboard toggle previously only removed the name
from the user-level disabledServers denylist. state-manager's new
`server.enabled === false` check (state-manager.ts:156) then still
marked the row disabled, leaving such servers impossible to re-enable
from /extensions.
Extracted setMcpServerEnabled() into mcp/config-writer.ts mirroring
/mcp enable | /mcp disable semantics:
- Server defined in project mcp.json -> update enabled on that entry.
- Else server defined in user mcp.json -> update enabled on that entry.
- Else (discovered third-party server) -> use the user-level disabledServers denylist.
- On re-enable, always clear any stale denylist entry.
extension-dashboard.ts routes mcp:* toggles through this helper. Added
four new regression tests covering: enabled:false re-enable, mixed
flag+denylist re-enable, disable on a config-resident server writing
enabled:false (not denylist), and discovered-server denylist round-trip.
Fixes#3827
Two read paths previously diverged on whether an MCP server was active or
disabled. /mcp list (slash-commands/helpers/mcp.ts:388) treats a server
as disabled when config.enabled === false OR the name is in the
user-level disabledServers denylist; the runtime MCP loader does the
same in mcp/config.ts:115. The /extensions dashboard only consulted
the dashboard-private settings.disabledExtensions array, so a server
disabled via /mcp disable or enabled:false kept showing as active.
Toggling MCP servers from the dashboard had the mirror problem: it only
wrote to settings.disabledExtensions, so /mcp list never noticed.
- state-manager: read user-level disabledServers from mcp.json once and
consider enabled:false / denylist membership when deriving each MCP
extension's state, matching /mcp list semantics.
- extension-dashboard: route mcp:* toggles through setServerDisabled
against the canonical mcp.json denylist, and clean any legacy
settings.disabledExtensions entry on re-enable so it doesn't keep the
server marked disabled.
- Added a regression test exercising both read signals and the
setServerDisabled round-trip the dashboard's MCP toggle now uses.
Fixes#3827
- Added `git.repo.linkedWorktreeSync` to identify and resolve git worktree metadata without spawning subprocesses.
- Updated `StatusLineComponent` to detect linked worktrees and resolve project/worktree context names.
- Modified path segment rendering to collapse nested git worktree paths and display the worktree name when it diverges from the active branch.
- Introduced `icon.worktree` symbol across themes to visually distinguish git worktree paths.
- Implemented a queueing mechanism in `ToolExecutionComponent` to prevent starvation of edit previews during high-frequency argument updates.
- Replaced eager cancellation of in-flight diff computations with a drain loop that ensures every update is processed once the current compute settles.
- Added `partialJsonOf` helper to safely narrow streamed JSON buffers from tool arguments.
- Added regression test to verify that slow diff computations are not aborted by incoming stream chunks and instead queue a subsequent re-run.
- Introduced comprehensive support for multiple concurrent, independently-configured advisors via `WATCHDOG.yml` files.
- Implemented a full-screen TUI overlay for managing advisor rosters, models, tools, and instructions.
- Added session-wide advisor initialization, telemetry aggregation, and named transcript isolation.
- Enhanced advisor security and observability with secret redaction in tool results and secure XML attribute encoding.
- Introduced guest snapshot reconciliation to maintain host state consistency during session switching.
- Improved yield tool reliability by implementing incremental schema validation and strict parameter enforcement.
- Fixed a calculation edge case in the status line to prevent negative time values during activity tracking.
- Expanded the test suite with new validation for session interruption, collab state synchronization, and process error handling.
Decoupled default-role persistence from live model switching when the selected model is below the current session context window.
Updated the model selector regression coverage so the Alt+M Default action remains selectable and advances to thinking selection.
Fixes#3708
- Added `statusLine.compactThinkingLevel` setting to render the thinking level as a leading icon.
- Replaced the verbose ` · <level>` suffix with a single glyph when compact mode is enabled.
- Updated the status line controller and component to resolve and propagate the new configuration.
Address PR review: switchSession (/resume, /move, ACP fork/load,
RPC switch_session, extension switchSession) mutates the loaded
session file in place under the same AgentSession ref, so a WeakMap
keyed only on the AgentSession ref carried the previous
conversation's meter into the resumed one — the footer kept showing
the previous total after resuming a different idle session.
Snapshot the loaded sessionFile path in the per-session meter and
detect a real-to-real transition inside #meter(): on a swap, drop
the old meter and start a fresh one. The undefined → real first-save
transition only refreshes the snapshot (same conversation, same
identity, accumulated time preserved). #closeStaleActiveWindow now
routes through #meter() so the file-change check applies there too.
Adds two regression tests covering the real-to-real swap and the
first-save no-reset.
Address PR review: SessionFocusController synthesizes agent_start on
mid-turn attach but does not pair it with a synthetic agent_end on
unfocus. With a single shared StatusLineComponent meter, returning to
the main session while a subagent was still streaming left
#activeStartedAt open, so the main status line kept ticking through
idle time after the subagent finished.
Replace the single #activeMs / #activeStartedAt fields with a WeakMap
keyed on AgentSession. markActivityStart / markActivityEnd /
getActiveMs / resetActiveTime all operate on the currently-attached
session's meter, so detaching from a subagent never bleeds its open
window into main. setSession closes a stale window (in-flight + new
session not streaming) on re-focus so a subagent that finished while
we were detached does not credit the detached gap.
Adds two regression tests covering both cases.
The time_spent segment rendered Date.now() - sessionStartTime, so an
idle session displayed hours of "time spent" while the agent did
nothing — the only inputs were wall-clock and the unmoving session
start.
Replace sessionStartTime with activeMs in SegmentContext and accumulate
inside StatusLineComponent across agent_start -> agent_end windows.
markActivityStart/markActivityEnd are idempotent (reentrant agent_start
events and superseded agent_end events never double-count); the segment
ticks live during an open window and freezes when the agent yields.
The session-boundary hook drops the now-meaningless wall-clock argument
and is renamed setSessionStartTime -> resetActiveTime; it zeroes the
accumulator and drops any in-flight window so /clear / fresh-session /
joined-collab paths start the meter at zero.
Fixes#3681
- Migrated 288 lines of scattered error classification logic from `utils/error-id.ts` into a cohesive `packages/ai/src/error/` module with 13 specialized submodules covering flags, classes, OAuth, providers, rate-limiting, and finalization.
- Replaced 100+ generic `Error` throws across 60+ provider and registry files with semantic `AIError.*` classes (e.g., `AIError.MissingApiKeyError`, `AIError.OAuthError`, `AIError.ProviderResponseError`), improving error diagnostics and retry logic.
- Consolidated error utility imports from `pi-utils` and scattered classification functions into a single `AIError` namespace, reducing coupling and simplifying error handling across all packages.
- Removed "running" status and hub hint details from the subagent badge text.
- Updated relevant status line tests to expect the simplified badge format.
Address PR #3602 review feedback from chatgpt-codex-connector:
when a stdin read carries the empty bracketed paste followed by
a trailing keystroke (a user pressing Enter right after Cmd+V),
the pre-fix paste path was fire-and-forget. The trailing byte
processed synchronously while the clipboard image read was still
pending, so submit ran against an empty pendingImages and the
image landed on the next draft instead.
CustomEditor now tracks in-flight pastes with #pasteInFlight and
buffers subsequent input into #pendingInput. #trackAsyncPaste
increments the counter, awaits the paste promise, decrements, and
drains the queue through handleInput (so requeueing still works
if a drained chunk triggers another async paste).
For an assembled paste whose remaining bytes are present in the
same call, those bytes are pushed onto #pendingInput before the
async paste starts, so they always run AFTER it settles. The
text-paste branch stays sync and drains its own queue inline.
New repro test asserts the call ordering: paste:start fires, the
queued Enter does NOT, and only after the paste promise settles
does Enter dispatch.
Address PR #3602 review feedback from chatgpt-codex-connector:
when the terminal fragments a bracketed paste across stdin chunks
(\x1b[200~ in one read, \x1b[201~ in the next — Windows Terminal
under load, certain SSH muxes, tmux extended-keys passthrough),
the previous single-chunk `isEmptyBracketedPaste` /
`extractBracketedImagePastePaths` guards never saw both markers
in the same `handleInput` call. The inherited
`BracketedPasteHandler` then buffered the run as a zero-length
text paste and Cmd+V still disappeared.
CustomEditor now owns its own BracketedPasteHandler that runs
ahead of `super.handleInput`, so split bracketed pastes resolve
to a single assembled payload before any routing decision:
- empty payload -> onPasteImage (Cmd+V macOS image-only screenshot)
- image-file paths -> onPasteImagePath (#3506 also gains split-chunk
coverage as a bonus)
- everything else -> base editor's public `pasteText` so the
`[Paste #N]` markers, autocomplete, and undo state stay intact
Removed the now-redundant single-chunk `isEmptyBracketedPaste`
helper. New repro tests cover the split-chunk empty paste, the
split-chunk image-file path, and a split-chunk text paste
forwarding exactly once to the base editor.
Address PR #3602 review feedback from chatgpt-codex-connector:
a whitespace-only bracketed paste carries real user content
(indentation, blank-line padding) and must reach the editor as
literal whitespace. The prior 'trim().length === 0' guard treated
whitespace pastes the same as empty pastes and routed them to the
clipboard-image reader, which in SSH/headless sessions silently
replaced the whitespace with a 'Clipboard is empty' diagnostic.
isEmptyBracketedPaste now matches only strict zero-length payloads
('\x1b[200~\x1b[201~'). Whitespace pastes flow through to the
normal text-paste path; empty pastes still route to onPasteImage so
Cmd+V on an image-only macOS clipboard keeps working.
The whitespace-only test case is flipped to assert the preservation
contract instead of the hijack path.
macOS terminals (iTerm2, Terminal.app, Warp, Ghostty without OSC 5522,
…) intercept Cmd+V and read NSPasteboardTypeString first. For an
image-only clipboard (Cmd+Shift+5 screenshot saved to clipboard, Chrome
image copy, …) that read returns empty, so the terminal forwards a
complete-but-empty bracketed paste — '\x1b[200~\x1b[201~' — to the app.
CustomEditor.handleInput inserted that empty payload and the keystroke
disappeared, forcing users back to Ctrl+V (which is never intercepted
and already routes through handleImagePaste).
Add isEmptyBracketedPaste and route a complete, empty-or-whitespace-only
bracketed paste through the same onPasteImage smart reader the
app.clipboard.pasteImage keybind uses, so Cmd+V attaches the clipboard
image (or falls back to the #1628 smart text paste / 'clipboard is
empty' diagnostic) instead of silent nothing. Bracketed pastes carrying
any text (including the explicit image-file path branch from #3506)
keep their existing routing.
Fixes#3601
- Renamed the `find` and `search` tools to `glob` and `grep` respectively across the codebase to improve command clarity.
- Implemented full-stack support for the renamed tools, including CLI arguments, system prompts, SDK exports, and tool registration.
- Added automated migration logic in `settings` to transform legacy `find` and `search` configuration keys to their new equivalents.
- Updated the `collab-web` renderer registry to ensure backwards compatibility with legacy tool outputs.
Dropped eager todo snapshot displacement from tool_execution_start, streaming message_update, and the rebuild assistant-iteration step. Displacement now runs only when the next todo's successful result lands, so a failed follow-up leaves the last-good todo panel on screen.
Added regression coverage for the failed follow-up case and updated the streamed-second-todo test to drive displacement from the success result.
Fixes#3516
Resolved any tracked todo snapshot before storing a fresh one in the rebuild paths so an assistant message replaying multiple todo tool calls collapses to the final snapshot.
Added a renderSessionContext regression test for two todo tool calls in one rebuilt assistant message.
Fixes#3516
Kept successful todo result blocks live until a later todo update replaces them or the turn ends.
Added regression coverage for same-turn todo snapshot replacement after intervening tool output.
Fixes#3516
Reviewer caught: `extractImagePathFromText` reused the bracketed-paste
splitter, which treats unescaped spaces as separators. macOS screenshot
filenames default to names like
`/Users/me/Desktop/Screenshot 2026-06-25 at 1.23.45 PM.png` — the
splitter shredded those into 5 segments, the second segment failed the
explicit-path check, and the helper returned undefined, so the keybind
fallback pasted the path verbatim instead of attaching the image.
Add a whole-text-as-path stage gated on a new ABSOLUTE_PATH_PREFIX_REGEX
(matches `/`, `~/`, `file://`, `\\`, or a drive letter), used
only when the splitter found nothing (otherwise multi-path text like
`/tmp/a.png /tmp/b.png` would be mis-joined). Prose containing a
path-shaped fragment ("see /tmp/x.png") fails both passes and still
pastes as text.
Tests cover (a) macOS screenshot names with spaces, (b) ~/Pictures and
Windows paths with spaces, (c) anchored prose fragments not hijacking
the fallback, and (d) end-to-end real-file integration via
handleImagePaste.
Refs #3506
When the macOS pasteboard's text representation forwards a
`file:///Users/.../img.png` URL (Ghostty/iTerm2/etc. forwarding the
`public.file-url` representation after a Finder copy), the smart
bracketed-paste / keybind fallback recognized it as a path but
`loadImageInput` then tried to read a literal `file://` path and
failed. `normalizePastedPath` now decodes `file://` URLs via
`node:url.fileURLToPath` before the explicit-path check, mirroring
Codex's `normalize_pasted_path` in
`codex-rs/tui/src/clipboard_paste.rs`. Both the bracketed-paste path
and the new `extractImagePathFromText` keybind path benefit.
Refs #3506
When the clipboard exposes only a file URL for an image (e.g. Finder
`Cmd+C` on a `.png`, certain screenshot tools), arboard's
`get_image()` returns `ContentNotAvailable`. `handleImagePaste` then
fell through to the #1628 smart-paste text fallback and pasted the path
verbatim, while the terminal-mediated paste round-tripped through
bracketed-paste's `extractBracketedImagePastePaths` and attached the
image — producing the asymmetric "for image I need control+v which is
very odd" symptom on macOS.
Refactor `custom-editor.ts` to share the bracketed-paste path-detection
logic via a new `extractImagePathFromText` export, then route the text
fallback through `handleImagePathPaste` whenever the clipboard text is
exactly one explicit image file path. Both keybind- and terminal-mediated
paste now agree.
Fixes#3506
- Removed `onPasteFilePath` handler to prevent automatic background file attachment when pasting paths.
- Updated `CustomEditor` to treat non-image paths as literal text input.
- Cleaned up unused file system utilities and paste path resolution logic.
Migrate fullscreen overlay selectors onto routeSgrMouseInput() and
routeSelectListMouse(), removing duplicated SGR parsing and SelectList
hit-test boilerplate. Behavior-preserving: wheel step sizes, footer/row
offset guards, and consumption semantics are unchanged.
Make the inline-picker wrappers (theme/thinking/queue-mode/show-images/
plugin) MouseRoutable, each subtracting their single top-border row before
delegating to SelectList.routeMouse(). Name previously magic coordinate
offsets (spacerRowsAfterTabs, contentColInset).
- Implemented SGR mouse event routing for dashboard interaction, including tab selection and pane scrolling.
- Added mouse-driven list manipulation in the extension viewer with selection highlighting, click toggling, and wheel navigation.
- Enabled fullscreen alternate-screen behavior and host terminal mouse tracking for the dashboard overlay.
- Integrated hit-testing and row selection logic into the extension list to support unified mouse and keyboard inputs.