`#recordAdvisorInterruptDelivered()` ran before the plan-mode and ACP-defer
preserve branches, so a blocker that was merely preserved (never interrupting
or starting a turn) still armed the post-interrupt immune window. With the
default `advisor.immuneTurns = 3`, the next three turns' concerns/blockers
were then downgraded to skip-idle-flush asides and could again be deferred.
Move the cooldown arm below every preserve branch so it fires only on the
actual steer/trigger path.
Fixes#5628
An idle ACP session sets `deferAgentInitiatedTurns`, so a steered terminal
blocker routed through `sendCustomMessage({ triggerTurn: true })` was buried
in `#pendingNextTurnMessages` instead of starting a turn — invisible and
deferred to the next user prompt, the exact regression #5628 avoids.
`#routeAdvice` now preserves the blocker as a visible card when a turn cannot
auto-trigger (idle + ACP defer without an explicit allow), folding the
existing plan-mode preserve branch into the same guard.
Fixes#5628
A late interrupting advisor note delivered after the primary ended with a
terminal text answer (no queued work) was routed to `preserve` for every
severity, so a `blocker` flagging a mistake in the final output became a
passive card that the model ignored until the next user turn.
Scope the terminal-answer preserve rule to non-blocker severities: a
`blocker` now steers a triggered turn so the primary acknowledges and
continues before the turn is considered done, while a late `concern` still
preserves as a visible card (keeps the #4840 no-duplicate-completion path).
Fixes#5628
expandPath's leading-colon strip only fired before POSIX prefixes
(`/`, `~/`, `./`, `../`), so Windows-mangled inputs like `:C:\repo\file`
or `:.\src` slipped through and path.resolve treated them as relative
children of cwd. The omp grep subcommand is the Windows grep path, so it
hit the common Windows form of the same bug.
Broaden the lookahead to admit `\` separators, `.\`/`..\` relatives, and
drive-letter absolutes (`[A-Za-z]:`). Add expandPath regression tests
for the Windows forms and the bare-token non-strip cases.
Fixes#5624
The `omp grep` subcommand resolved its path argument with a bare
`path.resolve` in `runGrepCommand`, bypassing `expandPath`. The
leading-colon strip from #5529 never fired, so `:/abs/path` was
mangled into `<cwd>/:/abs/path` and failed to resolve.
Route the path arg through `expandPath` so it inherits the leading-`:`
strip plus `@`-prefix, tilde, and unicode-space normalizations, matching
`read`/`edit`/in-agent `grep`.
Fixes#5624
Rendered each keyed extension status on an independently truncated line while preserving deterministic key ordering.
Added narrow-width regression coverage for multiple extension status keys.
Fixes#5617
- Routed native xAI Responses search through configured provider base URLs and headers.
- Kept endpoint credentials coupled and rejected official OAuth tokens for custom endpoints.
- Added proxy routing and credential-leak regression coverage.
Fixes#5599
- Updated schema and runtime paths to use `dev.autoqaConsent` and `todo.remindersMax`, including auto-QA consent reads/persistence and todo reminder limit checks.
- Adjusted settings expectations so obsolete BM25-discovery keys were dropped on load and `tools.xdev` now kept its default unless explicitly set.
- Added/updated tests for the setting key migration and refreshed issue-consent flows, plus a new `refreshMCPTools` test for steered `xdev-mount-notice` updates without prompt rebuilds.
Instead of including the xd:// device inventory in the system-prompt signature, mount/unmount events now inject a steered `xdev-mount-notice` message so the system prompt (and its provider cache prefix) stays byte-stable across MCP connects and disconnects. Full device docs are picked up opportunistically on the next unrelated rebuild.
Also caps external (dynamic-mount) device descriptions to 200 chars in `docsAll` to prevent server-controlled prose from consuming prompt budget; built-ins keep their full curated docs, and `read xd://` always returns the untruncated text.
Legacy `discoveryMode: "off"` → `tools.xdev: false` migration is removed; the setting keeps its own default without inference from the deprecated key.
- Added the `xd://` virtual device protocol (`internal-urls/xd-protocol.ts`, `tools/xdev.ts`): tools declaring `loadMode: "discoverable"` are unmounted from the request tools array and driven via `read xd://` (list/docs+schema) and `write xd://<tool>` (execute), gated by the `tools.xdev` setting (default on) and inlined into the system prompt.
- Merged the `irc`, `job`, and `launch` tools into a single `hub` tool (`tools/hub/`, `async/job-manager.ts`): messaging keeps `send`/`inbox`/`list`, job control maps to `wait`/`cancel`/`jobs`, process supervision keeps `start`/`logs`/`stop`/`restart`/`describe` with `ps`, and the unified `wait` races background jobs against peer messages; SDK `IrcTool`/`JobTool`/`LaunchTool` are replaced by `HubTool`.
- Removed the hidden `resolve` tool in favor of the `xd://resolve`/`xd://reject`/`xd://propose` resolution devices, auto-including `write` whenever a deferrable tool or plan mode is present.
- Removed the BM25 tool-discovery system: the `search_tool_bm25` tool, the `tool-discovery` module, the `tools.discoveryMode`/`mcp.discoveryMode`/`mcp.discoveryDefaultServers`/`tools.essentialOverride` settings, per-tool MCP selection, and the `mcp_tool_selection` message type.
- Unified tool presentation on `ToolLoadMode` (`essential`|`discoverable`), replacing the custom-tool `xdev?: boolean` opt-out; custom, extension, MCP, RPC host, image-generation, and TTS tools now default to `discoverable`, and added a `satisfies` predicate to `SoftToolRequirement`.
- Removed the standalone `ssh` command tool and `ssh/ssh-executor` (the `ssh://` read/write/search protocol stays), and made `--tools` address hidden built-ins.
- Updated collab-web to render `xd://` dispatches and `hub` op families, dropped the `search_tool_bm25`/`ssh`/`report-finding` renderers, refreshed tool docs and prompts, and migrated the affected tests and changelogs.
- Renamed the system prompt's project-context section wrapper from `<context>` to `<repo-rules>` in `project-prompt.md`, so it no longer collides with the `task` tool's `context` parameter under in-band XML tool dialects.
- Updated `snapcompact-inline`'s context-section strip pattern to match `<repo-rules>`.
- Updated the `snapcompact-inline` test fixture to the new wrapper.
- Changelog entry for this rename rides with the fused device-migration commit (adjacent changelog lines).
- Added the `enforceSeenLines` option to hashline `PatcherOptions` (defaults `true`); the seen-line guard in `Patcher` now runs only when enabled.
- Added the `edit.enforceSeenLines` coding-agent setting (default off) and wired it through `edit/hashline/execute.ts` into the `Patcher`.
- Stopped `file-snapshot-store` excluding column-clipped (>512-char) lines from a snapshot's seen set, so single-line edits on long lines apply without a full-width re-read.
- Updated `seen-line-guard` tests and the hashline/coding-agent changelogs.
The re-entry system prompt led with "Read the existing plan" and its
"different task -> overwrite it" step contradicted the planExists guidance
("leave that plan in place and start a fresh file"). Weak models fixated on
reconciling the incomplete old plan and dropped the new request entirely.
- Rewrote the Re-entry procedure in plan-mode-active.md to treat the new
request as the primary input and the old plan as reference only, and to
fold corrections for unfinished old work INTO the new plan rather than
substituting them for the new request.
- Aligned the "different task" branch with the planExists section (fresh
file, no overwrite), removing the contradiction.
- Added reentry-prompt.test.ts asserting the anchoring contract and the
absence of the contradiction.
Fixes#5576
- Added `interruptMode: never` to all updated Go, Rust, and TypeScript built-in discovery rule files.
- Changed `ts-no-inline-cast-access.md` from `interruptMode: tool-only` to `interruptMode: never`.