v2026.10.6
@code-yeongyu/senpi
Breaking Changes
Added
open_sessionacceptsretryFallback({ modelFallback, fallbackChains }) and hosts advertise theretry_fallback_profilecapability: the chain is that session's own, applied as an in-memory override that is never written to a settings file and never seen by another session on the host, so a task child running on a shared host can fall back to its own models mid-turn (code-yeongyu/oh-my-openagent#9512).autopermission preset: approves, without asking, only actions it can prove stay inside the project, judged on the exact file each tool will open: reads, listings and writes of project files,apply_patchon project files, a content search of one or more project files, and a small set of read-only shell commands with plain in-project arguments. Everything else asks, including dotfiles such as.env,.git/, keys, anything outside the project, directory-wide searches, shell writes,cd, pipes,git show, test runners, builds and installs. Your owndenyandaskrules always win, from settings, the CLI or RPC; yourallowrules never widen it. Hosts advertisepermission_preset_auto(#2614).
Changed
- Startup no longer fills the first screen: a long loaded-resource list shows its first names and a
+N morehint with the key that expands it, and several startup model warnings collapse into one expandable notice when startup details are hidden; the full list and every warning stay one keypress away (#2651). - The Claude Fable 5.1 prompt preset now asks for a one-line progress update after each tool wave that changes what the agent knows (an instruction naming the moment and the shape, in place of a recommendation that produced no more updates than presets asking for none), and three rules the preset stated twice are stated once: the Style section no longer repeats Scope's proceed-without-asking rule, the Verification section keeps only the claim audit, and the fourth Hard Limit drops the tail Scope already carries. Every other preset and the default prompt render unchanged (#2681).
Fixed
- Linux x64 and the other newly shipped targets get the native PTY backend for terminal sessions instead of the pipe fallback: releases now ship the native PTY prebuild for every supported target, and a release missing one fails. Thanks to @Altairpaca (#1193, #1224).
autopermission preset: a git revision argument that names an existing path, a dangling symlink included, is checked as a path, soautoasks for it; in print mode and the unbound SDK, a requestautoor your rules still ask about is always refused with a reason (#2688).- A rate limit (429) or a server error (5xx) from the provider now shows as one retry banner with a countdown in the status line, as a dropped connection already did, instead of printing the provider's raw JSON on every retry; authentication, quota and billing failures still show in full (#2652).
- The apply_patch streaming preview is tail-windowed with a sticky per-file change count, so a long patch no longer fills the screen, and it no longer re-renders the whole box on every streamed chunk (#2656, #2670).
- The edit tool card header now shows the aggregate change count next to the path (for example
edit src/greet.ts (+2/-1)), so an edit's size is visible at a glance (#2653, #2668). - Diff lines in tool cards are readable again in both built-in themes: added and removed lines keep distinct backgrounds and read at 7:1 contrast or better, where the saturated card backgrounds had dropped them to about 4.5:1 (#2655).
/filesand/diffopen a selected file on Windows again: drive-letter paths are passed to VS Code as a plain file argument instead of through--goto, which rejected them while exiting 0. Acodelauncher that exits 0 but prints to stderr is now reported as a warning instead of being swallowed (#2646, #2676 by @MoerAI).- A model whose free or plan limit is reached ("Reached free model rate limit ... switch to a different model", as Devin reports it) is now a model-scoped usage limit: the turn moves to the next model in the fallback chain at once, and the refused model stays cooled down for the stated reset window ("reset in 9 minutes") instead of being retried or restored early (#2660).
- Quiet, detached worker sessions on the shared in-process RPC host now release their runtimes on the next occupancy sweep once their history is persisted, while active jobs, wake sources, queued deliveries, and requests remain protected. Observational session commands such as
get_stateandmemory_reportno longer prolong idle retention for detached sessions; attached clients pollingget_statekeep their session alive as before, and parked sessions reopen by path with their durable identity and history (#2643 by @effortprogrammer). - A first run with no provider configured no longer reports "Context remains above the compaction threshold" when a message is sent: a turn an extension triggers now checks the model and credentials first, as a typed prompt already did, and fails with the
/loginguidance; a model with an undeclared context window (0) is treated as unknown instead of always over the compaction threshold. A background turn refused that way is not reported as an extension error: the session emitsprovider_required(once, until a turn is admitted again) with the same guidance, for an extension's triggered turn and itssendUserMessagealike, and the TUI shows it unless the startup "No models available" warning has just said it (#2677).
Removed
@code-yeongyu/senpi-ai
Breaking Changes
Added
Changed
Fixed
- Cursor's
resource_exhaustedsignatures (isCursorZeroTokenResourceExhausted,isCursorPayloadResourceExhausted,isCursorQuotaResourceExhausted) now match only thecursorandcursor-cli-oauthproviders, so another provider'sresource_exhaustedrate or usage limit is no longer read as a Cursor payload overflow or re-mint; a rate-limited body that says its limit resets in N minutes now yields that wait as the retry hint (#2660).
Removed
@code-yeongyu/senpi-agent-core
Breaking Changes
Added
Changed
Fixed
Removed
@code-yeongyu/senpi-codemode
Breaking Changes
Added
- An opt-in
memory.idleParkMinutessetting (off by default) closes a kernel that had no cell running or queued for that many minutes to give its memory back; the next cell starts a fresh kernel and its result says every earlier global is lost (#2452). - Ruby eval results name their largest globals, and Ruby and Julia kernels now get the same large-memory notice as JavaScript and Python when the interpreter footprint crosses
memory.noticeMb(#2452). - Julia eval results name their largest globals in that notice (#2452).
Changed
- Kernel tool descriptors may name any eval language (
js,py,rb,jl), not onlyjs; today only JavaScript kernels define tools, so nothing a session sees changes (#2452).
Fixed
-
A Ruby or Julia kernel whose start hangs no longer leaves its cells waiting forever: startup fails, naming the stage it stalled in, once the runner has printed nothing, changed no stage and its process group has used no CPU for 30 s, so a slow but busy start (a cold Julia compiling its prelude) is never cut off (#2452).
-
A
codemode.jsonthat names a key this version does not know no longer throws away every other setting: the unknown key gets one warning and the rest still apply (known nested objects stay strict). Optional keys for upcoming features (environments,isolation,sandbox,prompt.advertiseHelpers,kernelTools,languages.pyInterpreter) parse with today's behaviour as their defaults (#2452). -
A Python cell's host calls (
tool.*,completion) no longer go through a configured HTTP proxy: the loopback bridge request ignores proxy settings from the environment and, on Windows, the registry, so a proxy can't refuse a127.0.0.1call that never needed it (#2619). -
A JavaScript memory report no longer runs user code: array elements are read through their own descriptors (an index accessor is skipped and the estimate marked approximate), and typed arrays, buffers, Blob, Map and Set are sized through the built-in getters, so a subclass that overrides
byteLengthorsizeis never called (#2452).