- Added resolveWindowsShell to locate Git Bash, scoop installs, and path binaries with a fallback to cmd.exe.
- Updated bash-executor to prevent wrapping user commands in cmd.exe when using fallback shell paths.
- Updated installation script to report optional shell status rather than failing when bash is absent.
OutputSink.dump() was the only path that closed the spill Bun.FileSink.
The bash and Python executors re-throw on failure and their finally
blocks never closed the sink, so any large-output command that errored
leaked the artifact descriptor until an unrelated read (e.g. a SKILL.md
load) hit EMFILE.
Added an idempotent OutputSink.dispose() that closes the sink exactly
once (awaiting any in-flight sink creation, guarding post-finalize
resurrection) and wired it into every executor's finally block.
Fixes#6463
Removed the direnv-allow preflight so an .envrc the user never allowed is
skipped silently (debug log) and never executed; only already-allowed files
export. Updated the setting description, changelog, and rewrote the tests to
allow explicitly per content change.
The interactive !/!! shortcut wrapped commands as `fish -l -c '…'`:
resolveUserShellConfig swaps in $SHELL but inherits the bash-oriented
["-l", "-c"] args, and ensureInteractiveShellArgs injected -i only
for zsh. A login fish fires `status is-login` blocks in user config
(agent/keychain setup, PATH mutation) on every command.
fish sources the same config.fish/conf.d files for interactive shells
as for login shells, so give fish -i and strip the inherited -l: user
aliases and functions (#1816) keep working without login-shell side
effects. zsh keeps -l -i since .zprofile is login-only.
- Delayed reader cancellation so pipeline consumers can flush after producers are terminated.
- Kept the JavaScript watchdog behind bounded native timeout cleanup.
- Added native and executor regressions for timeout-time output draining.
Fixes#5316
Bash command timeouts now render with a warning (yellow) border instead
of an error (red) border, reflecting that the timeout ran its course
rather than the command failing.
The timeout is no longer thrown as a ToolError — instead #buildCompletedResult
returns a non-throwing error result (isError=true, keeping the model-facing
contract) with details.timedOut=true. The renderer reads this flag to pick
state="warning" (yellow) instead of state="error" (red).
The timedOut flag is propagated from bash-executor.ts, which now sets
timedOut=true on timeout return paths and leaves it unset on user-abort
paths. This distinguishes timeouts from user Esc-cancels — previously both
returned cancelled=true with no way to tell them apart in bash.ts.
Route overlapping executions through owned Shell instances so timeout and interrupt paths can explicitly abort native child-process cleanup.
Fixes#5389
- Ran commit host completion before commit-agent session disposal so mnemopi/autolearn teardown cannot preempt a valid proposal.
- Converted missing commit-agent host outputs and split-plan gaps into thrown errors so omp commit cannot resolve into exit 0 without creating a commit.
- Preserved caller GPG_TTY state instead of forcing a bogus signing TTY in git and non-interactive subprocess environments.
Fixes#4794
Prevented explicit bash timeouts from also aborting the AbortSignal passed to pi-natives while streamed output is still draining. Native timeout_ms now owns cancellation, and the JavaScript timer only reports the fallback timeout result.
Added regression coverage for streamed output before an explicit timeout.
Fixes#5021
The executeBash direnv preflight clamps its load budget to a positive
caller command timeout, but the PTY / ACP-terminal backend preflight in
bash.ts passed the raw bash.direnvLoadTimeoutMs (30s default) with no
clamp — so a short-timeout command routed through those backends could
hang up to 30s on a cold `.envrc` before its own timeout is even
installed. Centralize the clamp inside applyDirenvPreflight (new
callerTimeoutMs option) so every backend inherits one contract:
`timeout: 0`/undefined keeps the full budget, a positive deadline clamps.
Co-Authored-By: seal <noreply@sealedsecurity.com>
Extract applyDirenvPreflight() so the ACP client terminal and PTY backends
get the same direnv/devenv overlay as executeBash (previously only the
one-shot path did). The helper is a pure (command, env) transform — merge
direnv's set under the caller's overlay, prepend a regex-gated unset -v for
removed vars — so interactive backends keep their own env shape (live TERM)
while executeBash still layers its non-interactive defaults on top. The three
dispatch branches are mutually exclusive, so no command is preflighted twice.
Also drop the content-hash export cache in loadDirenvEnv: always run
direnv export json and let direnv's own watch/mtime invalidation decide
freshness, so a changed watched file re-exports even when .envrc is unchanged.
Co-Authored-By: seal <noreply@sealedsecurity.com>
Drain stdout and stderr concurrently so a cold .envrc/devenv load can't fill the stderr pipe and block until the timeout cap. Thread the caller's abort signal and per-call timeout into the direnv preflight (AbortSignal.any + min timeout) so an aborted or short-timeout bash call returns promptly. Return the full direnv export diff and honor variable *removals*: the per-command env overlay can only add/override, so prepend a shell-level 'unset -v' for direnv's unset list, gated by a POSIX-identifier regex and skipped when the caller re-supplied the var. Tests: skip the real-direnv cases when direnv is absent, and isolate HOME/XDG so 'direnv allow' never writes into the developer's global store; add unset coverage.
The bash tool's persistent shell didn't carry a repo's direnv/devenv
environment, so devenv-provided tools (moon, project-pinned biome/bun,
toolchains) were off PATH and .envrc-set vars (e.g. GIT_DIR for a jj
secondary workspace) were missing. Resolve the nearest .envrc from the
run cwd, load its env via direnv export json, and merge it under the
caller's per-call env. Gated by bash.direnv (default auto, auto-allows).
Treat timeout 0 as an explicit no-deadline contract across the bash tool, executor, async job, and PTY paths.
Signed-off-by: Christian Stewart <christian@aperture.us>
Propagated the native shell working directory in ShellRunResult so AgentSession can refresh cwd without running a hidden pwd command in the persistent shell.
Added regression coverage for cd plus a failing command followed by echo $?, proving cwd sync no longer overwrites the user's last shell status.
Fixes#3958
Updated interactive bash execution to query the persistent shell PWD after commands and move the session cwd when it changes, keeping the status line and session-scoped settings aligned with shell navigation.
Added regression coverage for syncing persistent shell directory changes back to the owning session.
Fixes#3958
- Added `Shell.liveBackgroundJobCount` to query active background processes.
- Retained per-call `:async:` shells if background jobs are still running upon turn completion.
- Reaped shells automatically once their last background process exits to prevent lingering processes.
Skipped UTF-8 defaults for an entire Windows locale or Python encoding group when inherited or per-command env already defines one variable in that group.
Fixes#2701
Added Windows-only UTF-8 defaults for non-interactive bash child process environments when the inherited env does not already define encoding or locale values.
Added regression coverage for missing, inherited, per-command, and non-Windows env behavior.
Fixes#2701
- Extended `AgentTool.concurrency` to accept per-call resolver functions and resolved concurrency mode from each tool call, falling back to exclusive on resolver errors.
- Updated BashTool to schedule non-PTY calls as shared and PTY calls as exclusive so non-interactive bash calls can run in parallel within one message.
- Tracked in-use persistent shell sessions in the bash executor and routed overlapping calls on the same session key to isolated one-shot shells while preserving owner session availability.
artifact spill now includes the head-retained bytes (full capture was missing first ~20KB); chunk throttle coalesces instead of dropping; cd-prefix extraction defers shell-expanded paths; interceptor rule is quote-aware and catches clobber and variable targets; completed async jobs release their Shell; at job cap commands degrade to foreground; PTY mode drops the non-interactive env and notes silent downgrades; timeout/abort annotations always appended; removed dead idle-timeout-watchdog.
- Moved EvalBackendsAllowance and related functions to a dedicated eval-backends.ts module.
- Replaced ad-hoc brokenShellSessions tracking with a quarantineShellSession helper that also awaits the abort cleanup promise.
- Applied quarantine on timeout and cancellation paths, not just errors.
- Replaced Bun.sleep with scheduler.wait for Node-compatible cancellable sleeps.
- Added module-level timestamp gate to skip yields within 50ms of the last one.
- Threaded AbortSignal through ExponentialYield.sleep to cancel losing timers in race.
- Added tests covering gate behaviour and stray-timer cancellation.
- yieldIfDue() uses compensated sleep (sleepAtLeast): retries Bun.sleep()
until the requested wall-clock duration has elapsed. This is necessary
because napi callbacks (uv_async_send) can wake the event loop
prematurely, causing Bun.sleep(N) to return after only ~1-2ms.
- ExponentialYield for bash-executor: starts at 20ms, doubles to 10s.
Closes#1384
Quarantined persistent session keys only while the native cancellation promise remains unsettled, so healthy cleanup restores persistent mode and stalled cleanup cannot accumulate live shell instances.
Added coverage for both stalled and settled native cleanup paths.
Fixes#1347
Stopped marking persistent bash sessions as permanently broken when the JavaScript abort or timeout race wins.
Stopped the Rust descendant kill-wave helper once no cancellation targets remain so later commands are not swept into old cancels.
Fixes#1347
Raced bash execution against the JavaScript abort signal and timeout so the tool returns even when native shell cleanup does not settle.
Added regression coverage for native cleanup stalls on ESC abort and timeout.
Fixes#1347
- Adjusted OutputSink to disable head retention after replace(), resetting counters so later pushes append to the tail and do not trigger stale middle-elision in dump().
- Refined artifact link emission to insert a newline separator only when the minimized output lacked one.
- Added a regression test for replace-plus-push ordering that verifies no elision marker and aligned byte counts.
- Removed export leakage by demoting many helper and const symbols to module-local scope.
- Renamed underscore-prefixed internals and cache fields, then updated related references and `satisfies never` checks.
- Deleted obsolete logic branches and helpers, including harmony-stream interruption flow and unused benchmark runtime helpers.
- Updated Biome config and manifests by broadening lint coverage and removing an unused `@napi-rs/cli` dev dependency.
- Adjusted tests and utilities to use renamed test helpers and remove redundant private test-only helpers/locals.
- Added `tools.artifactHeadBytes` and `tools.outputMaxColumns` settings with defaults in `SETTINGS_SCHEMA`.
- Expanded `OutputSink` with `headBytes`/`maxColumns` and middle truncate logic with elision markers and tracking.
- Updated output-meta to resolve sink settings, emit truncation metrics, and use `truncateMiddle` for spills.
- Integrated head and column limits into JS/Python/Bash/SSH/read output flows, with `:raw` skipping read truncation.
- Documented new output middle-elision and column-cap behavior in `CHANGELOG.md`.
- Added truncation tests for `OutputSink`, `truncateMiddle`, and read-tool line handling.
- Changed `todo_write` to an ordered `op`-array model with `replace`, `start`, `done`, `rm`, `drop`, `append`.
- Removed legacy multi-field todo payloads and updated tests/fixtures to use ordered `{op, task?, phase?, items?}[]` args.
- Reworked todo operation execution to apply entries sequentially and validate missing or unknown task/phase IDs.
- Updated todo rendering to use `todo.content` only and changed bash artifact labels from `full result` to `raw output`.
- Guarded minimized output handling so the minimized text was only applied when it changed from the original output.
- Replaced the artifact footer text with a shorter `[full result: artifact://...]` marker when a minimized save artifact was created.