The v10 model cache never persists request headers (#5780). The registry's
startup cache readers (#loadCachedStandardProviderModels /
#loadCachedDiscoverableModels) read cache.models directly, so cached rows
replaced bundled models (github-copilot, kimi-code, nanogpt) with header-less
copies for the cache TTL after every restart. Restore bundled static headers,
drop unrestorable rows so bundled fallbacks win the merge, and mark
discoverable providers stale when header-bearing models were excluded.
refreshProvider's #reloadStaticModels could also evict models discovered by
other runtime providers; re-merge them from cache with online-if-uncached.
- Parsed live named efforts, mandatory-thinking state, and model protocol metadata.
- Sent native Kimi named efforts and adaptive Anthropic override efforts without generic token budgets.
Fixes#5893
Added an opt-in compatibility flag for non-official Anthropic OAuth endpoints while preserving authoritative OAuth and Cloudflare credentials.
Fixes#5888
Loaded a platform-delimited (: on Unix, ; on Windows) path-list of settings overlays from PI_CONFIG_FILES before explicit --config overlays, so wrapper-based setups can inject settings without argv surgery.
Dropped the earlier global --config extraction as too risky; --config remains a launch/acp/models flag as before.
Fixes#5685
Lands the intent of #5318 on the established generate_image.enabled
gate instead of introducing a parallel imagegen.enabled key; sessions
must opt in before the tool registers top-level or as an xd:// device.
Resolved sdk.ts overlap with #5651 (kept getCursorTools alongside the
extracted transformToolCallArguments) and beginDispose overlap with
#5668 (kept both title-generation and autolearn-capture aborts).
- Implemented parsing of id-prefixed wildcard keys and entries, allowing provider-specific prefixes in retry fallback configuration.
- Added logic to re-prefix failing model IDs and to match id-prefixed keys, with validation of provider existence.
- Updated settings schema description and changelog, and added tests covering the new behavior.
- Prevented compaction from reopening a settled terminal answer unless queued work or an active goal remains.
- Ran auto-learn capture in an abortable detached agent with constrained tools and isolated provider state.
- Replaced primary-turn capture coverage with private-capture regression tests.
Fixes#5715
A Qwen-family model served through llama.cpp ships a jinja chat template that
defaults `enable_thinking: true`, but `discoverLlamaCppModels` stamped every
local model with `reasoning: false` and an empty compat, so `--thinking off`
never reached the wire and the model kept emitting a reasoning block.
Route Qwen-family ids (plus the Qwen3.6-derived PrismLM Ternary Bonsai GGUFs,
matched with a scoped pattern rather than broadening the global
`isQwenModelId`) through a shared `applyLlamaCppQwenThinking` upgrade. It gives
them `reasoning: true` with the `qwen-template-false` disable dialect and
`qwenPreserveThinking`, since omp emits `preserve_thinking` inside
`chat_template_kwargs` for Qwen, and switches them to the chat-completions API
because the implicit llama.cpp provider defaults to `openai-responses`, whose
disable path has no Qwen encoding. The runtime base URL gains a `/v1` suffix so
the completions request does not POST to the native root, which serves
`/models` and `/props` but not `/chat/completions`; a model kept on a custom
transport (e.g. `pi-native`, whose client appends `/v1/pi/stream`) retains its
base URL so the suffix is not doubled. Non-Qwen local models keep the
configured api, base URL, and minimal compat.
The upgrade is idempotent and re-applied as the outermost transform after
discovery merges, provider/transport overrides, and cache fallbacks, so a
configured native-root `baseUrl` (which wins in `mergeDiscoveredModel`) or a
fallback to a pre-fix cached row cannot leave the routed model on the old
`openai-responses` / `reasoning: false` spec. Because routed models carry a
`/v1` base URL, the runtime metadata refresh probes the native `/models`
endpoint (stripping `/v1`, matching the existing `/props` probe) so a model's
`meta`, `status.args`, and `architecture.input_modalities` fields are not lost.
Adds discovery tests pinning the resolved reasoning/api/base URL/compat for
Qwen and non-Qwen local ids, that a configured native-root provider keeps the
`/v1` runtime URL, that a pi-native-transport model keeps its gateway URL, and
that the runtime metadata refresh for a routed model stays on native `/models`.
Signed-off-by: Christian Stewart <christian@aperture.us>
The v17 rename (46ad908) of dev.autoqa.consent -> dev.autoqaConsent and
todo.reminders.max -> todo.remindersMax added no case to
Settings.#migrateRawSettings, so pre-rename nested or quoted-dotted config
left the leaf beneath the parent path. The parent then resolved to an
object, making dev.autoqa truthy (isAutoQaEnabled saw Auto QA enabled) and
discarding the reminder limit.
Lift both legacy leaves onto the new keys during raw settings load via a
shared migrateNestedLeafRename helper: an explicit new key wins, a
separately configured parent boolean is preserved, an irrecoverable
object-valued parent is dropped so the schema default applies, and only the
new representation persists on save.
Fixes#5632
- Routed native xAI Responses search through configured provider base URLs and headers.
- Kept endpoint credentials coupled and rejected official OAuth tokens for custom endpoints.
- Added proxy routing and credential-leak regression coverage.
Fixes#5599
- Updated schema and runtime paths to use `dev.autoqaConsent` and `todo.remindersMax`, including auto-QA consent reads/persistence and todo reminder limit checks.
- Adjusted settings expectations so obsolete BM25-discovery keys were dropped on load and `tools.xdev` now kept its default unless explicitly set.
- Added/updated tests for the setting key migration and refreshed issue-consent flows, plus a new `refreshMCPTools` test for steered `xdev-mount-notice` updates without prompt rebuilds.
Instead of including the xd:// device inventory in the system-prompt signature, mount/unmount events now inject a steered `xdev-mount-notice` message so the system prompt (and its provider cache prefix) stays byte-stable across MCP connects and disconnects. Full device docs are picked up opportunistically on the next unrelated rebuild.
Also caps external (dynamic-mount) device descriptions to 200 chars in `docsAll` to prevent server-controlled prose from consuming prompt budget; built-ins keep their full curated docs, and `read xd://` always returns the untruncated text.
Legacy `discoveryMode: "off"` → `tools.xdev: false` migration is removed; the setting keeps its own default without inference from the deprecated key.
- Added the `xd://` virtual device protocol (`internal-urls/xd-protocol.ts`, `tools/xdev.ts`): tools declaring `loadMode: "discoverable"` are unmounted from the request tools array and driven via `read xd://` (list/docs+schema) and `write xd://<tool>` (execute), gated by the `tools.xdev` setting (default on) and inlined into the system prompt.
- Merged the `irc`, `job`, and `launch` tools into a single `hub` tool (`tools/hub/`, `async/job-manager.ts`): messaging keeps `send`/`inbox`/`list`, job control maps to `wait`/`cancel`/`jobs`, process supervision keeps `start`/`logs`/`stop`/`restart`/`describe` with `ps`, and the unified `wait` races background jobs against peer messages; SDK `IrcTool`/`JobTool`/`LaunchTool` are replaced by `HubTool`.
- Removed the hidden `resolve` tool in favor of the `xd://resolve`/`xd://reject`/`xd://propose` resolution devices, auto-including `write` whenever a deferrable tool or plan mode is present.
- Removed the BM25 tool-discovery system: the `search_tool_bm25` tool, the `tool-discovery` module, the `tools.discoveryMode`/`mcp.discoveryMode`/`mcp.discoveryDefaultServers`/`tools.essentialOverride` settings, per-tool MCP selection, and the `mcp_tool_selection` message type.
- Unified tool presentation on `ToolLoadMode` (`essential`|`discoverable`), replacing the custom-tool `xdev?: boolean` opt-out; custom, extension, MCP, RPC host, image-generation, and TTS tools now default to `discoverable`, and added a `satisfies` predicate to `SoftToolRequirement`.
- Removed the standalone `ssh` command tool and `ssh/ssh-executor` (the `ssh://` read/write/search protocol stays), and made `--tools` address hidden built-ins.
- Updated collab-web to render `xd://` dispatches and `hub` op families, dropped the `search_tool_bm25`/`ssh`/`report-finding` renderers, refreshed tool docs and prompts, and migrated the affected tests and changelogs.
- Added the `enforceSeenLines` option to hashline `PatcherOptions` (defaults `true`); the seen-line guard in `Patcher` now runs only when enabled.
- Added the `edit.enforceSeenLines` coding-agent setting (default off) and wired it through `edit/hashline/execute.ts` into the `Patcher`.
- Stopped `file-snapshot-store` excluding column-clipped (>512-char) lines from a snapshot's seen set, so single-line edits on long lines apply without a full-width re-read.
- Updated `seen-line-guard` tests and the hashline/coding-agent changelogs.
- Restored the compact two-row `Editor` layout by default and gated the dedicated IME-safe bottom border behind `setImeSafeCursorLayout()`.
- Added `tui.imeSafeCursor` as an opt-in appearance setting and applied it to initial and replacement editors.
- Added regression coverage for compact default rendering while retaining terminal-local IME preedit protection.
- Updated the TUI changelog for the opt-in compatibility layout.
- Added schema and type updates for task-agent fields and model resolver settings.
- Extended discovery helper logic to carry resolved task-agent metadata through execution setup.
- Updated task/agent registration and execution paths to use the new capability/field data.
- Expanded test coverage for agent-field parsing, model resolution, and executor prewalk behavior.
Built-in discovery skipped the OAuth refresh whenever a fresh authoritative cache existed, so an openai-codex user with an expired access token never got the model manager constructed and stale bundled models (e.g. gpt-5.4-nano) stayed selectable for the full cache TTL. Force the refresh for authoritative providers and forward the registry fetch through the Codex manager so discovery honors the configured transport.
Fixes#5364
generate_image was registered as a custom tool and force-activated via the alwaysInclude list in createAgentSession, so it survived --no-tools (empty toolNames) and any explicit whitelist that omitted it. There was also no generate_image.enabled setting, so /settings had no toggle.
Add a generate_image.enabled setting and only register the tool when enabled and either no whitelist is given or it names generate_image.
Fixes#5305
parseModelPatternWithContext ran matchModel on the whole pattern
(including a trailing :level thinking suffix) and only stripped the
suffix if that first pass missed. matchModel's provider-scoped fuzzy
match normalizes colons away and does subsequence matching, so
kimi-for-coding:high matched the longer sibling kimi-for-coding-highspeed
before the suffix was recognized as a thinking level, silently switching
model and billing tier.
Match the full pattern exactly first (new exactOnly mode skips the
fuzzy/substring fallbacks), then strip a valid :level suffix and recurse
before any fuzzy match; fuzzy-match the whole pattern only as a last
resort. Literal ids ending in :max still win via the exact pass.
Fixes#5151
Preferred the active session provider after any explicit image preference and retained the configured auto order for remaining candidates.
Continued to the next credentialed image provider after HTTP failures.
Fixes#5218
The pre-flight auth check in resolveModelOverrideWithAuthFallback called
getApiKey without a session id. For providers with session-sticky OAuth
credentials, this returned undefined even though the credential was
usable once the subagent session started, causing the auth fallback to
silently replace the configured model with the parent's (#5325).
The subagent's id is now forwarded as the session id so session-sticky
credentials resolve during the pre-flight check. Genuinely broken auth
(stale OAuth, revoked tokens) still falls back as before.
Also propagate model resolution warnings through resolveModelOverride
and log them in the executor so users see why a pattern didn't match.
- Added `tui.scrollbackRebuild` configuration with interactive startup/controller wiring to apply `setScrollbackRebuild`.
- Exposed prewalk session state in `SegmentContext` and rendered a dedicated prewalk segment/icon in the status line.
- Added divergence-aware TUI full-paint logic that enables scrollback erase-and-replay rebuilds for non-multiplexer divergence cases.
- Updated rendering and streaming tests to verify rebuild behavior (`3J`) and eliminate stale marker expectations under drift scenarios.