Expanded `!` bash and `eval` execution output kept rendering the
`… N more lines (ctrl+o to expand)` footer after Ctrl+O revealed every
line, because `hiddenLineCount` was computed from the collapsed preview
window regardless of the `#expanded` (or sixel-passthrough) state.
Zero the hidden count whenever the full output is shown so
`buildStatusFooter()` stops advertising hidden lines and ctrl+o.
Fixes#5842
Brings the per-advisor toggle, status-line glyphs, quota display, and the
failing-advisor stall/abort fix (f4c8143) onto main's rewritten advisor
runtime. Conflict reconciliation kept main's architecture (fingerprint
prefix reconciliation, host-level onTurnError recovery + fallback chains,
terminal-failure classification) and ported the branch semantics onto it:
- #failing latch: waitForCatchup resolves immediately while an advisor is
mid-failure; parked waiters wake the moment a turn fails, before any
async hook or retry sleep.
- Turn-end render containment: a formatter bug restores the cursor/prefix/
dedup snapshot and never propagates into the primary's turn-end callback
(per-advisor try/catch boundary in AgentSession).
- Quota pause: when host recovery declines a usage-limit failure, the
runtime latches quotaExhausted, requeues the batch, and notifies —
cleared only by an explicit reset.
- Hard halt after a permanent rejection or three backlog-drop cycles.
- #recoverAdvisorTurn also marks usage limits for structural errors thrown
before any assistant turn is recorded.
- Reverted PR #5751 (issue #5749): continuation rows wrapped the editor
top border onto extra lines, which is unacceptable for the input frame.
- EditorTopBorder is back to a single content/width pair; narrow widths
drop right segments, shrink the path, then drop left segments.
Rendered each keyed extension status on an independently truncated line while preserving deterministic key ordering.
Added narrow-width regression coverage for multiple extension status keys.
Fixes#5617
- Updated schema and runtime paths to use `dev.autoqaConsent` and `todo.remindersMax`, including auto-QA consent reads/persistence and todo reminder limit checks.
- Adjusted settings expectations so obsolete BM25-discovery keys were dropped on load and `tools.xdev` now kept its default unless explicitly set.
- Added/updated tests for the setting key migration and refreshed issue-consent flows, plus a new `refreshMCPTools` test for steered `xdev-mount-notice` updates without prompt rebuilds.
- Added the `xd://` virtual device protocol (`internal-urls/xd-protocol.ts`, `tools/xdev.ts`): tools declaring `loadMode: "discoverable"` are unmounted from the request tools array and driven via `read xd://` (list/docs+schema) and `write xd://<tool>` (execute), gated by the `tools.xdev` setting (default on) and inlined into the system prompt.
- Merged the `irc`, `job`, and `launch` tools into a single `hub` tool (`tools/hub/`, `async/job-manager.ts`): messaging keeps `send`/`inbox`/`list`, job control maps to `wait`/`cancel`/`jobs`, process supervision keeps `start`/`logs`/`stop`/`restart`/`describe` with `ps`, and the unified `wait` races background jobs against peer messages; SDK `IrcTool`/`JobTool`/`LaunchTool` are replaced by `HubTool`.
- Removed the hidden `resolve` tool in favor of the `xd://resolve`/`xd://reject`/`xd://propose` resolution devices, auto-including `write` whenever a deferrable tool or plan mode is present.
- Removed the BM25 tool-discovery system: the `search_tool_bm25` tool, the `tool-discovery` module, the `tools.discoveryMode`/`mcp.discoveryMode`/`mcp.discoveryDefaultServers`/`tools.essentialOverride` settings, per-tool MCP selection, and the `mcp_tool_selection` message type.
- Unified tool presentation on `ToolLoadMode` (`essential`|`discoverable`), replacing the custom-tool `xdev?: boolean` opt-out; custom, extension, MCP, RPC host, image-generation, and TTS tools now default to `discoverable`, and added a `satisfies` predicate to `SoftToolRequirement`.
- Removed the standalone `ssh` command tool and `ssh/ssh-executor` (the `ssh://` read/write/search protocol stays), and made `--tools` address hidden built-ins.
- Updated collab-web to render `xd://` dispatches and `hub` op families, dropped the `search_tool_bm25`/`ssh`/`report-finding` renderers, refreshed tool docs and prompts, and migrated the affected tests and changelogs.
- Added schema and type updates for task-agent fields and model resolver settings.
- Extended discovery helper logic to carry resolved task-agent metadata through execution setup.
- Updated task/agent registration and execution paths to use the new capability/field data.
- Expanded test coverage for agent-field parsing, model resolution, and executor prewalk behavior.
- Removed `selector`/`sel` arguments from read and grep tool schemas and related execution arg handling.
- Reworked read and grep path processing to parse line selectors from `path` suffixes instead of separate fields, including inline range propagation.
- Updated delegation and execution call paths (including JS/Python preludes and executor tests) to pass selectors embedded in `path`.
- Updated read/grep prompt docs and changelog for the breaking inline-selector API, and removed obsolete selector-specific tests and expectations.
- Wrapped every Kitty graphics APC for tmux passthrough, preserved quiet mode across chunks, and enabled placeholder placement when Kitty is explicitly forced.
- Routed Agent Hub transcript images through the shared image budget and terminal image setting.
Fixes#5381
Extensions importing legacy pi UI components (e.g. DynamicBorder from
@earendil-works/pi-coding-agent) receive a second src module graph in
npm-package installs. Host startup assigns the module-level `theme` only
inside the bundled dist copy, so the src-graph copy stays undefined and
DynamicBorder.render dereferenced `theme.boxRound` unconditionally,
throwing "undefined is not an object" and taking down the whole TUI.
Route the default color through the existing `fgOrPlain` guard and fall
back to the default rounded glyph when `theme` is undefined, matching the
`typeof theme === "undefined"` degradation already used by fgOrPlain and
getSettingsListTheme.
Fixes#5366
The empty-editor left-left gesture opens the Agent Hub whenever persisted
or parked subagents exist (intended since f3e372e7b), but the hub's own
close detector starts fresh at 0 with no handoff from the editor's
double-tap detector. The two taps that opened the hub were consumed by the
editor, so a single subsequent left did nothing and the user had to press
left-left again to escape while input and hotkeys stayed disabled.
Thread an armCloseTap option from the gesture through showAgentHub to the
new AgentHubOverlayComponent.armCloseTap(), which seeds the table's
#lastLeftTap so one more left (within the tap window) dismisses the hub.
Fixes#4780
Paste-code OAuth providers (Codex, Anthropic, Gemini CLI, GitLab Duo,
Antigravity, Devin) need the user to paste the fallback redirect URL
when the loopback callback cannot complete (headless/remote/Windows).
The login dialog took focus and cleared the editor but only rendered the
auth URL plus a tip pointing at `/login <redirect URL>` — a command only
reachable through the now-hidden, unfocused editor. The dialog never
mounted an Input, so a pasted URL was silently dropped and login stalled.
Route onManualCodeInput through the focused dialog's showManualInput so
the paste lands in a visible, submittable field. Make showManualInput
idempotent so the OAuth callback retry loop reuses the mounted input
instead of stacking duplicate prompts.
Fixes#5339
The prompt-style HookEditorComponent (used by the ask tool's "Other"
custom-input flow) rendered its title, option list, and hint via
Text(padX=1) while the borderless editor beneath renders its `> ` gutter
at column 0, leaving the input row one column left of everything else.
Pad the prompt-style chrome at column 0 to match the gutter; hook-style
(bordered) chrome keeps its 1-column indent that lines up with the
bordered editor body.
Fixes#5313
Threaded the authorization server's advertised registration endpoint through OAuth discovery, add, reauth, and the client flow instead of deriving metadata from the authorization endpoint.
Added pathful-issuer discovery and end-to-end DCR regression coverage.
Fixes#5267
Plugin/custom tool renderers can return a component whose render() throws
(e.g. a plugin styling its header off an object without a bold method,
producing TypeError: th.bold is not a function). ToolExecutionComponent only
caught the renderCall/renderResult factory, not the child component's later
render() pass, so the exception escaped and crashed the transcript.
Wrap every renderer-returned call/result component in SafeToolRendererComponent,
which catches render() errors and falls back to the tool label (call) or raw
result text (result), logging once per component.
Fixes#4978