Skip to content

v2026.10.6

Choose a tag to compare

@github-actions github-actions released this 04 Oct 03:13
· 390 commits to main since this release

@code-yeongyu/senpi

Breaking Changes

Added

  • open_session accepts retryFallback ({ modelFallback, fallbackChains }) and hosts advertise the retry_fallback_profile capability: the chain is that session's own, applied as an in-memory override that is never written to a settings file and never seen by another session on the host, so a task child running on a shared host can fall back to its own models mid-turn (code-yeongyu/oh-my-openagent#9512).
  • auto permission preset: approves, without asking, only actions it can prove stay inside the project, judged on the exact file each tool will open: reads, listings and writes of project files, apply_patch on project files, a content search of one or more project files, and a small set of read-only shell commands with plain in-project arguments. Everything else asks, including dotfiles such as .env, .git/, keys, anything outside the project, directory-wide searches, shell writes, cd, pipes, git show, test runners, builds and installs. Your own deny and ask rules always win, from settings, the CLI or RPC; your allow rules never widen it. Hosts advertise permission_preset_auto (#2614).

Changed

  • Startup no longer fills the first screen: a long loaded-resource list shows its first names and a +N more hint with the key that expands it, and several startup model warnings collapse into one expandable notice when startup details are hidden; the full list and every warning stay one keypress away (#2651).
  • The Claude Fable 5.1 prompt preset now asks for a one-line progress update after each tool wave that changes what the agent knows (an instruction naming the moment and the shape, in place of a recommendation that produced no more updates than presets asking for none), and three rules the preset stated twice are stated once: the Style section no longer repeats Scope's proceed-without-asking rule, the Verification section keeps only the claim audit, and the fourth Hard Limit drops the tail Scope already carries. Every other preset and the default prompt render unchanged (#2681).

Fixed

  • Linux x64 and the other newly shipped targets get the native PTY backend for terminal sessions instead of the pipe fallback: releases now ship the native PTY prebuild for every supported target, and a release missing one fails. Thanks to @Altairpaca (#1193, #1224).
  • auto permission preset: a git revision argument that names an existing path, a dangling symlink included, is checked as a path, so auto asks for it; in print mode and the unbound SDK, a request auto or your rules still ask about is always refused with a reason (#2688).
  • A rate limit (429) or a server error (5xx) from the provider now shows as one retry banner with a countdown in the status line, as a dropped connection already did, instead of printing the provider's raw JSON on every retry; authentication, quota and billing failures still show in full (#2652).
  • The apply_patch streaming preview is tail-windowed with a sticky per-file change count, so a long patch no longer fills the screen, and it no longer re-renders the whole box on every streamed chunk (#2656, #2670).
  • The edit tool card header now shows the aggregate change count next to the path (for example edit src/greet.ts (+2/-1)), so an edit's size is visible at a glance (#2653, #2668).
  • Diff lines in tool cards are readable again in both built-in themes: added and removed lines keep distinct backgrounds and read at 7:1 contrast or better, where the saturated card backgrounds had dropped them to about 4.5:1 (#2655).
  • /files and /diff open a selected file on Windows again: drive-letter paths are passed to VS Code as a plain file argument instead of through --goto, which rejected them while exiting 0. A code launcher that exits 0 but prints to stderr is now reported as a warning instead of being swallowed (#2646, #2676 by @MoerAI).
  • A model whose free or plan limit is reached ("Reached free model rate limit ... switch to a different model", as Devin reports it) is now a model-scoped usage limit: the turn moves to the next model in the fallback chain at once, and the refused model stays cooled down for the stated reset window ("reset in 9 minutes") instead of being retried or restored early (#2660).
  • Quiet, detached worker sessions on the shared in-process RPC host now release their runtimes on the next occupancy sweep once their history is persisted, while active jobs, wake sources, queued deliveries, and requests remain protected. Observational session commands such as get_state and memory_report no longer prolong idle retention for detached sessions; attached clients polling get_state keep their session alive as before, and parked sessions reopen by path with their durable identity and history (#2643 by @effortprogrammer).
  • A first run with no provider configured no longer reports "Context remains above the compaction threshold" when a message is sent: a turn an extension triggers now checks the model and credentials first, as a typed prompt already did, and fails with the /login guidance; a model with an undeclared context window (0) is treated as unknown instead of always over the compaction threshold. A background turn refused that way is not reported as an extension error: the session emits provider_required (once, until a turn is admitted again) with the same guidance, for an extension's triggered turn and its sendUserMessage alike, and the TUI shows it unless the startup "No models available" warning has just said it (#2677).

Removed

@code-yeongyu/senpi-ai

Breaking Changes

Added

Changed

Fixed

  • Cursor's resource_exhausted signatures (isCursorZeroTokenResourceExhausted, isCursorPayloadResourceExhausted, isCursorQuotaResourceExhausted) now match only the cursor and cursor-cli-oauth providers, so another provider's resource_exhausted rate or usage limit is no longer read as a Cursor payload overflow or re-mint; a rate-limited body that says its limit resets in N minutes now yields that wait as the retry hint (#2660).

Removed

@code-yeongyu/senpi-agent-core

Breaking Changes

Added

Changed

Fixed

Removed

@code-yeongyu/senpi-codemode

Breaking Changes

Added

  • An opt-in memory.idleParkMinutes setting (off by default) closes a kernel that had no cell running or queued for that many minutes to give its memory back; the next cell starts a fresh kernel and its result says every earlier global is lost (#2452).
  • Ruby eval results name their largest globals, and Ruby and Julia kernels now get the same large-memory notice as JavaScript and Python when the interpreter footprint crosses memory.noticeMb (#2452).
  • Julia eval results name their largest globals in that notice (#2452).

Changed

  • Kernel tool descriptors may name any eval language (js, py, rb, jl), not only js; today only JavaScript kernels define tools, so nothing a session sees changes (#2452).

Fixed

  • A Ruby or Julia kernel whose start hangs no longer leaves its cells waiting forever: startup fails, naming the stage it stalled in, once the runner has printed nothing, changed no stage and its process group has used no CPU for 30 s, so a slow but busy start (a cold Julia compiling its prelude) is never cut off (#2452).

  • A codemode.json that names a key this version does not know no longer throws away every other setting: the unknown key gets one warning and the rest still apply (known nested objects stay strict). Optional keys for upcoming features (environments, isolation, sandbox, prompt.advertiseHelpers, kernelTools, languages.pyInterpreter) parse with today's behaviour as their defaults (#2452).

  • A Python cell's host calls (tool.*, completion) no longer go through a configured HTTP proxy: the loopback bridge request ignores proxy settings from the environment and, on Windows, the registry, so a proxy can't refuse a 127.0.0.1 call that never needed it (#2619).

  • A JavaScript memory report no longer runs user code: array elements are read through their own descriptors (an index accessor is skipped and the estimate marked approximate), and typed arrays, buffers, Blob, Map and Set are sized through the built-in getters, so a subclass that overrides byteLength or size is never called (#2452).

Removed

@code-yeongyu/senpi-tui

Breaking Changes

Added

Changed

Fixed

Removed