When the active js-debug child exits or terminates while other tree
sessions remain alive, #activeSessionId pointed at the dead child and
every subsequent tool action failed. Reassign to a live tree session
(preferring stopped, then non-root) on exited/terminated/proc-exit.
Regression test proves threads route to the surviving session.
rev-parse --git-common-dir resolves symlinks while ensureIsolation derives
sourceCommonDir lexically from the session cwd (resolveRepository walks
path.resolve'd components). On any symlinked repo path (macOS /tmp,
symlinked project dirs) the lexical comparison missed, detachGitDir
returned "independent", and the parent-mutation leak silently survived.
Realpath both sides before comparing; regression test drives the gate
through a symlink alias.
- Match the rcopy worktree-add registration via realpath: git canonicalizes
the admin gitdir back-reference (macOS /var -> /private/var), so the
lexical comparison missed it and left a stale registration in the source
repo's worktree list.
- Carry core.fileMode so an explicit filemode=false source does not read as
mode-changed files in the detached isolation.
- Carry core.splitIndex and the sharedindex.* files referenced by a split
source index; restoring the raw index without them broke every git read.
- Carry the source shallow boundary file so history traversal over the
borrowed object DB stops at the boundary instead of failing.
- Regression test covering all three carries.
A fresh `git init` in detachGitDir dropped core.sparseCheckout and the
sparse-checkout patterns, and rebuilding the index via write-tree/
read-tree discarded skip-worktree bits. Files intentionally absent from
a sparse working tree then read as deletions, which delta capture could
apply back to the parent.
detachGitDir now restores the index verbatim (preserving skip-worktree,
assume-unchanged, and exact stage entries) and carries
core.sparseCheckout, core.sparseCheckoutCone, and info/sparse-checkout
into the detached .git before restoring the index. Falls back to
read-tree HEAD only when the source had no index.
Fixes#6003
A linked git worktree with an unborn HEAD (a fresh/orphan branch with no
commits) still shares the parent's common dir, so an isolated task's
first branch and commit would write into the parent repo. The previous
early return on a missing HEAD SHA left that shared metadata intact.
detachGitDir now severs unborn worktrees too: `git init -b <branch>`
preserves the checked-out branch name, ref freezing is gated on a born
HEAD, and the rcopy worktree registration is still removed.
Fixes#6003
- Moved `#todoReminderAwaitingProgress` clearing into tool result handler for synchronous state update.
- Moved `#lastAssistantMessage` tracking to message_end to prevent stale reads when events land in same tick.
Passed the per-request model through SDK payload callbacks and ExtensionRunner context creation.
Added regression coverage for Codex-primary and Anthropic-request contexts.
Fixes#6006
Copy isolation backends (reflink/apfs/btrfs/zfs/block-clone/rcopy)
materialise the worktree by duplicating its `.git` verbatim. When the
parent is a linked git worktree its `.git` is a pointer file, so the
isolation shared the parent's HEAD/index/ref namespace: a task's
`git checkout`/`commit` moved the parent's branch, and the rcopy
`git worktree add` path stacked task branches in the shared namespace.
`ensureIsolation` now runs `git.detachGitDir` after `isoStart`, turning
each isolation into a standalone repo with a frozen HEAD/refs/index
snapshot that borrows the source object database via
`objects/info/alternates`. Isolated git ops stay private, every task
branch is parented on the requested base, and patch/branch capture
(`git fetch <merged>`) still resolves objects.
Fixes#6003
- Removed the once wrapper from Puppeteer's request emitter on first fire so it cannot leak into later runs.
- Added regression coverage asserting a fired once handler leaves zero residual request listeners.
Fixes#6004
- Removed run-scoped Puppeteer request handlers and disabled interception on every browser.run exit path.
- Recycled workers when bounded interception cleanup cannot restore the tab, with raw CDP recovery for held requests.
- Added live Chromium coverage for held requests, normal traffic restoration, and thrown setup calls.
Fixes#6004
- Clarified that snapshot refs work in any selector slot with equivalence example.
- Expanded navigation gotcha to include re-renders and virtualized lists.
- Added bare `eN`/`@eN` regex to `parseAriaRefSelector` so agents can copy refs straight from snapshot output.
- Applied ref resolution to `press`, `screenshot`, `drag`, `select`, and `uploadFile` action handlers.
- Fixed `#select` to assign the full option set first then read back, avoiding double-counting when unselecting mid-loop.
- Added `#subscriberEmitGate: Promise<void>` FIFO ticket to order concurrent `#emitSessionEvent` calls and prevent event reordering.
- Modified `#emitSessionEvent` to serialize subscriber fan-out: waits for previous gate before emitting, ensuring `message_start` arrives before `message_end` regardless of extension handler asymmetry.
- Added `#prunedTerminalRefusal` field to retain classifier-refusal turns for post-settle readers.
- Added `#prunedTerminalRefusal` field to store the pruned refusal for post-settle consumers.
- Modified `getLastAssistantMessage()` to return the pruned refusal before active-context lookup.
- Reset `#prunedTerminalRefusal` on `agent_start` so a fresh run supersedes the settled refusal.
- Updated test mock helpers to include `getLastAssistantMessage` for consistency.
- Removed `#compactedChildStart` state, `compactable` segment field, and `#compactCommittedPrefix()` method, stopping the local-frame pruning of committed finalized rows.
- Post-finalize mutations now surface on every render via version tracking, instead of requiring a destructive replay to rehydrate the compacted block.
- Changed `print-mode.ts` to use `session.getLastAssistantMessage()` instead of array tail read, fixing access to terminal assistant messages after compaction removal.
- Validated the openai-codex credential origin against the registry storage that supplies the bearer, closing the OAuth-leak path when authStorage and modelRegistry diverge.
- Added a regression test covering the mismatched storage case.
Fixes#6001
- Routed Codex web search through configured Responses base URLs, API keys, and headers while preserving the official OAuth backend.
- Refused OAuth leakage to custom endpoints and stopped explicitly selected providers from silently falling back.
- Added transport, safety, and fail-closed regression coverage.
Fixes#6001
- Reported the spawned PTY child PID through the native start callback.
- Replaced broker PID-file polling with the authoritative spawn event.
- Covered finite PTY startup without the legacy handoff in integration tests.
Fixes#5996
Resolved tool interruptibility from each call's raw arguments so mixed-operation tools can keep side-effecting calls non-interruptible.
Restricted the unified hub to interrupt passive waits and followed logs while preserving start, send, and lifecycle operation results.
Fixes#5995
- Kept tall-preview pages inside the selected option row.\n- Compared cached overflow output against the initial width-adjusted render.\n\nNote: pre-existing repository formatting failures in bun check are not addressed by this PR.
Added TCP server transport for vscode-js-debug and recursively handled startDebugging requests, breakpoint synchronization, active child routing, and tree cleanup.
Fixes#5984
Ask dialogs accepted the configured cancel binding but always advertised Escape. Derive the compact footer label from the active binding so the displayed key remains actionable.
Rich ask options previously exposed preview content only for the highlighted row. Render every preview beneath its option and keep long content reachable without reviving the split-pane layout.
omp's canonical getPackageDir() returns undefined inside a bun --compile
binary (import.meta.dir is /$bunfs/root, no owning package.json — issue
#1423). Re-exporting it directly broke pi's string-valued contract:
legacy extensions doing path.join(getPackageDir(), ...) crashed at
runtime in the shipped binary, the primary distribution.
Wrap the canonical helper so the shim always returns a string, falling
back to the executable's directory in compiled mode (where the binary is
the install root). PI_PACKAGE_DIR and dev/source/npm-dist walk-up still
win. Test covers the compiled-mode fallback via isCompiledBinary spy.
Fixes#5968
The legacy pi compatibility shim only forwarded getAgentDir (via
`export * from "../index"`). getProjectDir and getPackageDir were absent,
so any pi extension importing either from @earendil-works/pi-coding-agent
failed Bun's static export check during extension validation and the
install was rolled back.
Re-export getProjectDir from @oh-my-pi/pi-utils and getPackageDir from
omp's canonical config helper (returns the coding-agent package root,
matching pi semantics).
Fixes#5968