Scanned the Windows host USERPROFILE .agents directory when running under WSL so globally installed Agent Skills are available alongside Linux-home skills.
Fixes#3779
(cherry picked from commit c3468dae4f9b91646bf50f2cf4ded9075572290e)
403 concurrency caps bypass credential rotation in stream and auth-retry paths; snake-case concurrency codes classify; a session-level test covers the Copilot credential-removal gate.
(cherry picked from commit aca348e797ed987750a14ecf625952b6b971f7a5)
Canonicalized file URI keys at the diagnostics map boundary so server and client spellings match across percent encoding and Windows casing.
Added regression coverage for equivalent percent-encoded URIs and the marksman Windows drive-letter form.
Fixes#7662
The previous #runSerialized waited on the shared #dispatchTail, then ran
unconditionally: when two or more events queued behind an in-flight run,
each resumed from the same settled await and started its own run in
parallel, defeating the ordering guarantee for a burst landing in one
coalescing window (message_end + agent_end behind a suspended flush).
Each waiter now chains its own link onto the current tail
(tail.then(run, run)), so queued runs start strictly one after another;
the idle path still runs synchronously, preserving the flush timing the
coalescing tests assert on. The in-flight flag clears only when the
settling link is still the tail, so a later chained link's settle does
not clear it early.
Regression test: two message_end events queued behind a suspended window
flush stay serialized (init call count steps 1 -> 2 -> 3 as each gate
opens); fails on the previous implementation.
The Claude/Cursor/Gemini/Windsurf importers appended user entries before
project entries, so a project `enabled: false` could not claim its dedupe key
ahead of a same-named user server and the disable was silently ignored. Load
project entries first, matching the native/Codex loaders, so a project disable
suppresses a same-named user server.
Updated docs/mcp-config.md to reflect the project-first precedence and added
compound regression coverage.
Fixes#7652
Set HOME and os.homedir() to a dedicated temporary directory for each translated-provider fixture, then restore both after every test. This prevents real user MCP configs from shadowing the project fixture through capability deduplication.
The Claude Code, Cursor, Gemini CLI, Windsurf, and VS Code importers built
their canonical MCPServer object without mapping serverConfig.enabled, so a
server declared with "enabled": false stayed undefined and the central
suppressServer filter never fired. Only disabledServers masked the gap.
Map the field in each importer, mirroring opencode.ts and codex.ts, and add
a table-driven regression test across all five importers.
Fixes#7652
AgentSession.#emit fires listeners fire-and-forget, and the coalesced
message_update flush fires from its own 33ms timer — neither path awaited
the other. A rapid stream tail (message_update -> message_end ->
agent_end) could therefore run the end handlers while the flush was
suspended mid-await, agent_end removing streamingComponent before
#handleMessageEnd finalizes and records the final message (issue #7443
follow-up).
- #runSerialized chains listener dispatch and the timer flush through one
promise chain; an in-flight run holds later events until it completes.
Idle dispatch stays synchronous (no added microtask), preserving the
timing the coalescing tests assert on.
- Regression test: a message_end landing while the window flush is
suspended on init is queued behind it (initCalls 1 while suspended,
then 2), where the pristine code ran both concurrently (2 while
suspended). Fails without the fix.
Per-event stdout writes in --mode json (and text) were fire-and-forget
and relied on an empty-write flush barrier before dispose/exit. The
barrier awaited its own callback, not the preceding large write, so a
big final agent_end could be truncated when the process exited before
the pipe drained -- while still exiting 0.
Serialize every print-mode stdout write on its own completion callback
(honoring backpressure) and block shutdown on the tail so the terminal
record is delivered in full.
Fixes#7635
Added the no-op setter to lightweight print-mode session mocks so text-mode runs without a submitted prompt no longer throw at the final commit call.
Fixes#7625
Made text replay safety depend on whether the active output sink has committed streamed text.
Kept tool calls, images, and server tools replay-unsafe while covering text and JSON print policies plus a transient socket-close recovery.
Fixes#7625
Completes the maintainer's removal of per-call model selection from
subagent spawns (9f8aa87dbf removed it from the task tool and the
model-facing agent() docs/prompt, but the eval agent() runtime and all
four preludes still accepted and forwarded a per-call model).
Subagents now always resolve through the selected agent's frontmatter
model and settings, so an explicit model: "default" can no longer
silently route children onto the parent session model.
- agent-bridge: drops "model?" from agentArgsSchema and the request
forward; adds "+": "delete" so a legacy model argument is stripped
(same contract as the task wire schemas).
- JS/Python/Ruby/Julia preludes: remove the model parameter from
agent(); completion()'s tier selector is unchanged.
- docs (tools/eval.md, python-repl.md) updated to the removed surface.
Refs #6438