- Replaced monolithic desktop native bindings and action batching with a modular cross-platform backend structure supporting Wayland, X11, macOS, and Win32.
- Updated the computer tool schema and supervisor to execute persistent JavaScript script runs with timeout clamping and asynchronous tool calling.
- Integrated accessibility (AX) tree snapshotting, node querying, and bounds-based hit testing across platform desktop layers.
- Added native clipboard bindings and updated coding-agent prompts, renderers, and tests to validate script-based computer workflows.
- Added an LSP multiplexer server, protocol definitions, and daemon lifecycle management to route traffic across sessions.
- Introduced `lsp.shared` settings configuration and SDK session creation support for shared language servers.
- Migrated shared daemon ensure helpers into a central launch module with updated import references.
- Added comprehensive unit tests and fake LSP server fixtures covering muxing, sharing, caching, and restarts.
- Serialized group and ungroup operations to prevent duplicate tab group creation races.
- Queued and serially drained tab grouping requests in the relay bridge to prevent overlapping RPCs.
- Mirrored tab group titles to session storage and healed duplicate groups during background service worker recovery.
- Renamed run-cancellation utility to run-scope and updated corresponding module and test references.
- Added window discovery, targeting, and frame validation for macOS, Windows, and Linux platforms.
- Updated computer tool and protocol definitions to support listing and targeting specific application windows.
- Refactored native computer tool exposure to function-only representation across models.
- Updated documentation and test suites to reflect window-scoped computer control capabilities.
- Added `isStreamEnvelopeErrorText` to packages/ai/src/error/flags.ts to recognize stream envelope truncation errors.
- Updated `streamAnthropicOnce` in packages/ai/src/providers/anthropic.ts to throw an envelope error when streams die mid-generation without a terminal frame.
- Updated `recoverTransientErrorToolTurn` in packages/agent/src/agent-loop.ts to recognize Anthropic stream envelope truncation errors for tool call salvage.
- Implement the OMP Browser Relay extension with WebSocket communication and CDP RPC execution.
- Add browser relay server, daemon management, and bridge multiplexing in the coding agent.
- Introduce CLI commands and settings schema options for configuring and installing the relay.
- Add utility functions and test suites supporting environment parsing and relay lifecycle handling.
Bazel's patch parser applies pure-insertion -U0 hunks one line early,
which dropped the lib.rs layout asserts inside 'mod ffi' on linux builds
(E0433). Regenerated the text hunks with -U1 context and moved the C
probe block after the miniaudio include so no hunk touches the crate's
newline-less final line, which the parser also rejects. Verified the
patched lib.rs type-checks for all four linux binding sets and the
darwin natives + maudio_layout_test pass under bazel.
The 17.2.4 bump moved maudio-sys 0.1.4 -> 0.1.5, which upstreamed the
per-target pregenerated bindings this patch used to add; the old build.rs
hunks no longer applied (CONTENT_DOES_NOT_MATCH_TARGET) and broke every
bazel natives fetch. The rebased patch keeps only what upstream lacks:
- x86_64-unknown-linux-musl pregenerated bindings
- C static asserts + omp_maudio_* ABI probes for maudio_layout_test
- lib.rs compile-time layout asserts pairing with the C side
Hunks are -U0 so bazel's patch parser never sees the no-trailing-newline
marker in miniaudio_version_check.c. Also refreshed MODULE.bazel.lock
for the 17.2.4 Cargo manifest hashes.
The CI harness exports PI_TEST_RUNTIME=1, which the wrapper subprocess
inherited; isBunTestRuntime() then suppressed unref in the worker client
and deterministically kept the wrapper alive until the test timed out.
Override PI_TEST_RUNTIME=0 in the wrapper env and restore the 10s bound.
- Updated sdk-tool-activation expectations for 386385f18b: sessions
without a granted write tool keep extension/SDK tools top-level and
allocate no xd:// state instead of auto-granting write.
- Raised the unref'd-worker parent-exit repro to a 30s timeout; the 10s
ceiling SIGTERMed the wrapper (exit 143) on shared-core CI runners.
386385f18b made xd:// mounting require both granted transport halves and
stopped auto-granting write; a read-only session now surfaces deferred
MCP tools top-level. The test still encoded the old auto-grant contract.
- Raised probe-spawning logger tests to 30s timeouts; bun's 5s default
SIGTERMed probe children (exit 143) on shared-core CI runners, matching
the precedent documented in logger-contract.test.ts.
- Allowed clippy::unused_async_trait_impl on KillCommand::execute with an
unknown_lints guard for the pinned CI nightly that predates the lint.
pi-shell calls sys::signal::kill_process on the windows target; the
pub(crate) glob re-export made it invisible outside brush-core, unlike
the unix module where kill_process is pub. Mirrors unix visibility.
- Made infallible ProcInfo accessors const and annotated Option-returning
accessors with allow(unnecessary_wraps) since Option is the shared
cross-platform contract.
- Boxed ParseProcResult::Options to shrink the enum.
- Restructured kill signal resolution to bind signal once instead of
let-then-reassign sequences.
- Simplified liveness re-check with Option::is_none_or.
- Implemented new shell builtins including `top`, `pgrep`, `pkill`, `pidwait`, and `kill`.
- Added a cross-platform process snapshot module supporting Linux, macOS, and Windows.
- Extended job and process handling utilities with process iteration and handle termination methods.
- Replaced test mutex locks with thread-local counters to prevent test races in the minimizer engine.
- #readPersistedCredentialBlockReconcileAfter no longer rethrows
non-corruption errors; transient failures (e.g. SQLITE_BUSY) log at
debug and fall back to the in-memory probe window, mirroring
#readPersistedCredentialBlock.
- Constructor's best-effort cleanExpiredCredentialBlocks now routes
errors through #handlePersistedBlockStoreError so init-time corruption
latches immediately instead of deferring to the first block read.
- reload() latches and surfaces repair guidance when listAuthCredentials
throws on a corrupt store, then still rethrows: continuing with zero
credentials would silently log the user out of every provider.
- The #7298 test asserted PRAGMA-vs-DDL ordering by spying on
Database.prototype.run SQL strings — implementation plumbing.
- Now a child process creates the db and holds BEGIN EXCLUSIVE for 750ms
(past open()'s ~700ms retry budget, under the 1000ms headless
busy_timeout), signaling readiness via a filesystem sentinel; open()
only survives if the busy handler is installed before the leases DDL.
- Verified the test fails with the ordering fix reverted.
- Claude ids now alias to google-vertex suffixed entries (claude-opus-4-6@default etc.) so Antigravity follows Google's price if it diverges from Anthropic's list price; plain-id anthropic lookup remains as dangling-alias fallback.
- Regenerated models.json via gen:models.
- Added `applyAntigravityPricingFallback` to back-fill unpriced `google-antigravity` models using first-party list prices from `google` and `anthropic`.
- Mapped Antigravity model IDs to preview-id aliases (e.g., `gemini-3.1-pro` to `gemini-3.1-pro-preview`) for correct pricing resolution.
- Added test coverage in `packages/catalog/test/generated-policies.test.ts` verifying fallback pricing and preservation of billable costs.
Fail broker-facing block mutations on the first corrupt SQLite write and every later latched call instead of returning a false durability acknowledgement. Internal request-path persistence remains an in-memory no-op, preserving local availability.
Verify RemoteAuthCredentialStore keeps its optimistic rate-limit block and does not refresh an empty snapshot when the broker rejects persistence.
- Parsed OpenRouter reasoning effort ladders and defaults during discovery.
- Preserved explicit thinking metadata from models.yml patches.
- Regenerated the catalog and covered both regression paths.
Fixes#7307
Route credential-block reconcile-after reads through the same corruption latch used by persisted block reads and writes. A latched store now returns an immediate zero probe time without touching SQLite; a first corruption from reconcile-after latches and reports once, while transient errors still propagate.
Add a Codex regression covering a corrupt block write followed by healthy usage reconciliation.
- Make over-context models selectable in the model picker by graying them instead of disabling them.
- Trigger automatic session compaction with the current model prior to switching when an over-context model is chosen.
Route the broker-facing list, upsert, and delete methods through the same per-process corruption latch as credential selection. Preserve transient error propagation while returning safe empty/no-op fallbacks for SQLITE_CORRUPT and SQLITE_NOTADB.
Add table-driven coverage proving each public block operation independently reports once and short-circuits every later store call.
Installed a five-second SQLite busy timeout before the read-only usage query and covered lock contention with a subprocess-backed regression test.
Fixes#7300
normalizeGeneratedTitle only guarded emptiness and the none sentinel, so
when the tiny title model ignored the titling task and answered the first
user message, its full one-line reply became the session title verbatim.
Bound accepted titles to 80 chars / 12 words and return null past that,
deferring titling to the next user turn. Both the online and local-worker
paths funnel through this normalizer, so both are covered.
Fixes#7303
AuthStorage caught unrecoverable SQLite errors (SQLITE_CORRUPT family /
SQLITE_NOTADB) from the persisted credential-block read and write paths
at debug level with no latch. A corrupt agent.db therefore re-queried the
broken store on every credential evaluation while persisted rate-limit
blocks silently stopped applying, failing open in the direction that
hammers rate-limited accounts.
Detect the corruption family via isSqliteCorruptionError, report it once
at error level with the store location and repair guidance, and
short-circuit every later persisted-block read/write for the process
lifetime. Availability is preserved through the in-memory backoff map;
only cross-process persistence is lost.
Fixes#7296
SqliteAuthCredentialStore.open() ran #ensureAuthCredentialRefreshLeasesTable
(CREATE TABLE/INDEX for auth_credential_refresh_leases) with Bun's default
busy_timeout=0, before the constructor's #initializeSchema installed the
handler. Under a concurrent write lock (WAL recovery on parallel omp
startups) the lock-taking DDL failed immediately; the error was not
BUSY-classified, so open()'s bounded retry loop was bypassed.
Install the busy handler on the connection right after it opens, before any
lock-taking statement, via a shared #installBusyTimeout helper reused by
#initializeSchema. Honors the issue-#2421 invariant on every entry path.
Fixes#7298
- Prevent xdev state allocation and tool mounting in sessions lacking a write tool.
- Expose discoverable tools top-level instead of auto-granting write transports.
- Change the default MCP JSON-RPC request ID format from snowflake strings to sequential integers.
- Update server configuration schema, connection equivalence checks, and tests to reflect the new integer default.