## Why
Concurrent test spawns can inherit a writable descriptor for the MCP server
wrapper, causing `ETXTBSY` when launching it on Linux.
## What changed
Write the wrapper through a separate `/bin/sh` process on Linux so its writable
descriptor stays out of the test process. Check the writer's exit status and
include stderr on failure. Retain direct file writes on other Unix platforms.
GitOrigin-RevId: f99952ec000ba7317243e87fd664dc0e31bb7b24
Stop logging response headers on successful WebSocket connections and payload
previews for tool calls. Keep the connection URL, tool name, and thread ID in
their respective log entries.
GitOrigin-RevId: 1d410b6aef8f12153da9bfc60c515b8e797a9de0
Replace the stale `start_fresh_session_with_summary_hint` call with
`start_fresh_session` in the test for restoring blank drafts and built-in
permissions.
GitOrigin-RevId: a1f1f75dc173a732af712511cf8f6a16f2e3c0fa
Set `CFBundleName` to `ChatGPT` and add `CFBundleDisplayName` with the same
value in the generated `Info.plist`.
GitOrigin-RevId: e40a0b10895227148d6fdc199b1c4166b5c59372
## Why
Untouched threads have no rollout for `thread/resume` yet. Switching away from a blank startup or fresh session needs to preserve its live subscription, draft, and settings so it can be reopened.
## What changed
- Retain blank startup and fresh sessions for non-ephemeral connections to an external app server, and save their input state before navigating away.
- Restore the current thread name and apply background settings updates after restoring drafts, so saved model choices do not overwrite newer server settings.
## Testing
Extend the task-switching regression test to cover blank startup and fresh sessions, preserved drafts and model choices, updated thread names, and restoration without `thread/resume` or `thread/unsubscribe`. Verify that background model, permission, and approval-policy updates are used for the first submitted turn.
GitOrigin-RevId: 958b0cb48a5a873d8d8f5858ac334fecbfad60c7
## What changed
Remove the previous session's token usage and resume hint from the history
shown when starting a fresh session or resuming another thread. Remove the
unused summary helpers and their tests, and rename the fresh-session helper
to `start_fresh_session`.
GitOrigin-RevId: d808bdf355831d1c7b937b6a101ffbb33a805234
## Why
Empty list items can lose their markers, and a bare marker received during streaming can still acquire content in a later chunk.
## What changed
- Render pending markers when an empty item ends or a nested list starts on a new line, including inside blockquotes.
- Keep trailing bare list markers mutable during streaming so later content and terminal resizing preserve the item correctly.
## Testing
Add snapshot coverage for empty ordered, nested, and blockquoted list items, plus regression tests for streamed continuations, finalization, and resizing with a held marker.
GitOrigin-RevId: d9116bddc49670ad66d71dbddc66b2ab347cb6b7
## What changed
Remove automatic next-message generation after successful turns, suggestion rendering in the composer, and the associated Tab acceptance and Escape dismissal handling. Remove the `tui.prompt_suggestions` configuration option and its schema entry, along with suggestion-specific tests and snapshots.
GitOrigin-RevId: 63bf6f2ca85da6ece502c86e2a805d000bf34210
## What changed
Add `Features::persistent_mode_enabled` and use it for persistent instructions and current-time reminder defaults. Enablement still requires `ReasoningEffort::Persistent`.
Change `PersistentModeState::new` to accept an explicit enablement boolean, separating instruction rendering from reasoning-effort selection.
## Testing
Update persistent-context tests to use boolean enablement while preserving coverage for instruction replacement, removal, deduplication, and retained history without a snapshot.
GitOrigin-RevId: f412b90d783438d1526956a56c11b9e66385ee0e
## What changed
- Delete the `plugin-creator` skill, its assets, reference docs, helper scripts, and associated Python tests.
- Update the app-server skills context budget warning test to expect six omitted skills instead of seven.
GitOrigin-RevId: 005b1ab7f2f7c2933e6c297d01541746cc489f68
## Why
A provisioned executor can still be resuming after readiness is reported. Initial connection attempts can exhaust the ordinary registry retry limits before the executor comes online.
## What changed
Retry `environment_offline` registry responses during initial Noise rendezvous connections for provisioned environments until a fixed five-minute deadline, starting after provisioning succeeds. Keep the existing retry limits for other registry errors and stop on permanent failures.
## Testing
Add tests covering the five-minute deadline, ordinary limits for other errors and stalled requests, and termination on a later permanent error. Verify that readiness and info requests remain pending through an extended offline period and succeed using the same environment handle once the executor comes online.
GitOrigin-RevId: e22211499d9ec2f3590e75224eb39e2e4bf3538d
## Why
Long descriptions could exhaust the 4 KiB tool summary budget and hide later namespace names, limiting their visibility for tool discovery.
## What changed
- Reserve space for all namespace names before sharing the remaining budget across descriptions, including added and removed groups.
- Truncate descriptions at UTF-8 boundaries with `...`, including at the existing 250-character cap. Omit whole namespaces only when names alone exceed the budget, reserving omission notices only in that case.
- Render namespace names and descriptions without XML escaping.
## Testing
Add unit and snapshot coverage for description allocation, Unicode boundaries, namespace omissions, and empty-state notices. Add a scenario verifying that a crowded catalog retains every namespace name, allows discovery of a late namespace with its full description, and keeps the summary unchanged on follow-up.
GitOrigin-RevId: 9743cda5aa14190db22c788c9e91e1785a32682b
## Why
Private IP destinations always bypassed inherited upstream proxies, preventing their use for private networks reachable through an upstream VPN proxy.
## What changed
- Add `codex exec-server --proxy-private-ips-via-upstream`, also configurable with `CODEX_EXEC_SERVER_PROXY_PRIVATE_IPS_VIA_UPSTREAM=true`. The setting defaults to disabled.
- Allow permitted RFC 1918, carrier-grade NAT, and IPv6 unique-local destinations to use an applicable upstream proxy. Loopback and link-local destinations retain direct routing, and destination access policy still applies.
- Keep connections direct when no valid upstream proxy applies or `allow_upstream_proxy=false`. Errors after selecting an upstream proxy do not trigger a direct retry.
- Rename `ExecServerRuntimePaths` to `ExecServerRuntimeOptions` and carry the routing setting from executor startup into the managed network proxy.
## Testing
Add routing coverage for private address ranges, special-use addresses, and public targets with the option enabled and disabled. Verify that HTTP and CONNECT requests still enforce destination allowlists and denylists, and update the CLI help snapshot.
GitOrigin-RevId: b7c9cc7da0e0f545694a6521b74c9b36b7b92769
## Why
System libcurl needs access to `com.apple.TrustEvaluationAgent` for TLS, but Seatbelt network profiles did not allow lookup of this service.
## What changed
Allow `mach-lookup` for this service when unrestricted networking is enabled or a restricted profile permits proxy ports or local binding. Keep access denied for network-disabled, Unix-socket-only, and managed profiles without usable endpoints.
## Testing
Add macOS regression tests that apply Seatbelt policies and check trust-service access and loopback connections without external network dependencies. Cover managed-network overrides and verify that unrelated service lookups and connections to unapproved ports remain denied.
GitOrigin-RevId: 8b190d6181fe1321186837557caa379275abfaee
## What changed
- Use the compact title, version, and directory layout for all session headers, including resume, fork, and clear-screen flows. Remove the boxed model row and retain the optional greeting and YOLO permissions indicator.
- Share title styling with the status card and honor the active render mode and wrapping policy when inserting a fresh header after clearing the screen.
## Testing
Update header and startup snapshots for the borderless layout, narrow widths, and halfwidth directory characters. Add assertions that clearing history preserves the raw header in raw output mode.
GitOrigin-RevId: 0b91c1ce6646f9d9d1954b1442936abe93bdcd3c
## Why
Hiding an already-visible working tip during mouse selection shifts the transcript layout and disrupts selection.
## What changed
Keep displayed working tips visible while interacting with the transcript or scrolling away from the latest output. Initial tip display and completion tips still require an idle viewport following the latest output.
Check usage notices directly when suppressing tips so a tip cannot appear merely because interaction temporarily hides the composer warning.
## Testing
Add a mouse-selection regression test and snapshot covering deferred initial display, stable transcript rows through mouse down, drag, and release, correct selected text, and continued tip suppression when a usage warning is hidden during interaction.
GitOrigin-RevId: 3cee527f3a7daaccecbeedbdf083c61075dfa32f
## Why
Inline `$0$` was left unrendered, and expressions containing `\bigwedge`, `\bigl`, or `\bigr` fell back to raw LaTeX.
## What changed
- Allow `$0$` through the inline math detection heuristic.
- Render `\bigwedge` as `⋀`, with limits stacked above and below in display math.
- Handle `\bigl` and `\bigr` like `\left` and `\right`.
## Testing
Add a regression snapshot covering inline zero, inline big wedge, and a multiline display expression with stacked limits and delimiters.
GitOrigin-RevId: 89f596ea5f38070274505cfa7ea757595d7ae137
## Why
Copied table selections became code blocks containing the rendered grid, losing table structure. Stripping trailing whitespace from completed responses also removed Markdown hard breaks and spaces in code.
## What changed
- Reconstruct Markdown tables from selected cells across grid and record layouts, preserving alignment, inline formatting, and list or blockquote nesting.
- Copy a single selected cell as inline content and leave unselected cells empty without adding their text. Escape literal pipes in table code spans and link destinations.
- Preserve trailing whitespace on lines unchanged by assistant directive removal.
- Keep blank rows in copied text without painting newline selection highlights on empty rows.
## Testing
Add regression coverage for wrapped and rewrapped tables, partial selections, empty cells, literal pipes, and separate table and code blocks. Update snapshots for nested tables and selection highlights, and verify completed-response copying preserves hard breaks and code whitespace.
GitOrigin-RevId: 661e4c8331f2737bedff286548f9343bac44e0cb
## Why
Clicking the welcome blossom replays its animation, but completion abruptly switches from full color to the dim idle frame.
## What changed
Fade the blossom back to idle opacity over 400 ms after the replay finishes spinning. Keep scheduling redraws until the fade completes, then clear the replay state.
## Testing
Extend the replay test with color snapshots at the start, midpoint, and end of the fade, and assertions that redraws stop and the original idle frame is restored.
GitOrigin-RevId: ec3fafb6766533d9c221913e8a3be03b8a8036f7
## Why
When browser sign-in does not open automatically, users need to copy the login URL. Onboarding should also allow terminal selection of login URLs and device codes in fullscreen mode.
## What changed
- Add a `c` shortcut to copy the browser sign-in URL, with status messages for pending, successful, unconfirmed, busy, and failed clipboard requests.
- Apply asynchronous clipboard results only to the matching login attempt.
- Disable mouse capture during onboarding so the terminal can select text, and restore the previous input policy afterward.
## Testing
Update the narrow-screen login snapshot to show the copy shortcut and extend mouse-policy coverage to verify onboarding leaves mouse capture disabled.
GitOrigin-RevId: 01676b737efb192d900da306cd2c6b32f791ceb9
Identify the failing setup step when starting, completing, or verifying managed runtime package registration, granting metadata permissions, or persisting the completed registration. Preserve the underlying errors with `anyhow::Context`.
GitOrigin-RevId: 85f712faf2519e95704d7e8cea15d2deeed0d51e
## What changed
- Show a compact session header with a randomly selected greeting, preserving the greeting and blossom state from startup into the live session.
- Center a settled blossom in unused fullscreen space and replay its animation on click. Hide it while typing or when space is insufficient, and respect `tui.animations` and `tui.effects.welcome`.
- Hide startup tips in the fullscreen transcript while retaining them in terminal scrollback, and prevent hidden entries from shifting the first visible header.
- Keep the composer visible and responsive during daemon startup, routing startup diagnostics through tracing while direct lifecycle commands retain stderr output.
## Testing
Add regression tests and update snapshots for blossom placement and click replay, welcome opt-outs, greeting stability, startup transitions, tip visibility, and transcript spacing.
GitOrigin-RevId: ec7b082fbe25ced1180cad3348f5c76e48c0e92b
## Why
Steering an active WebSocket response previously dropped the connection and
resent the full history. Draining the response preserves the connection and
allows the follow-up request to continue with `previous_response_id`.
## What changed
- Drain WebSocket responses when steering. For models using
`use_responses_lite`, first send `response.interrupt` with
`mode: "discard_partial_items"` once the response ID is available.
- Treat `response.incomplete` with reason `interrupted` as completion with
`end_turn: false`, preserving token usage and allowing the turn to continue.
Other incomplete reasons remain errors.
## Testing
Update the steering integration test to cover completed and discarded reasoning
items, asserting connection reuse, incremental follow-up input, and token usage
from the interrupted response.
GitOrigin-RevId: bc714b713e797cf1a67e3b26ffbf7664cb92eb33
## Why
Local daemons use a remote request handle even though their login callback is local, so the TUI skipped opening the browser. Login completion could also arrive while the browser was opening, before the TUI had recorded the active login.
## What changed
- Use `AppServerTarget` to open the login URL for embedded servers and local daemons, while continuing to skip automatic browser opening for remote workspaces.
- Set the pending login state and schedule a frame before opening the browser so completion notifications can match the active login.
## Testing
Add regression tests for browser opening across embedded, local daemon, and remote targets, and for login completion during browser opening.
GitOrigin-RevId: 3feceb877e6131bfd0671c3556314c6c7fd4a677
## Why
Windows launchers such as `cargo run` can prevent background processes from outliving them, causing automatic daemon startup to fail and blocking the CLI from opening.
## What changed
- Classify detached launch restrictions by retrying an access-denied launch probe without the job breakaway flag. Keep both probes suspended and terminate and reap successful probes.
- Use the embedded server with a visible warning when automatic startup encounters this restriction. Preserve errors for other launch failures, including inaccessible executables and elevated startup.
- Keep explicit daemon lifecycle operations failing on the restriction, with guidance to build and run `codex.exe` directly.
## Testing
Add Windows coverage for restriction classification and executable access failures, plus a CLI integration test and warning snapshot for embedded fallback under a restrictive job. The integration test also checks that elevated startup still fails and no daemon PID file is created.
GitOrigin-RevId: fc7c46e0f5f07ca0aba12b535a0e372021bdf46a
## What changed
- Reject unsupported flowchart shapes and Markdown strings so the terminal renderer preserves the source with an unsupported-feature notice instead of misrendering it. Keep ordinary quoted labels containing shape-like punctuation valid.
- Preserve class relationship targets beginning with `o`, such as `A --orange`, instead of consuming the first letter as an aggregation marker.
- Accumulate state aliases and descriptions in source order: use the first as the title and subsequent entries as body rows, preserving state identity and limiting body rows to 16.
## Testing
Add parser regressions for these cases and description limits, update class and state snapshots, and extend TUI snapshots to verify source preservation for unsupported flowchart syntax.
GitOrigin-RevId: c44d954312c77229a3752a0d9ada14e34a43a376
## Why
Piped child processes launched from a detached Windows process should not allocate a console window.
## What changed
Set `CREATE_NO_WINDOW` by default for `codex-rs/utils/pty` child commands. Preserve it alongside `CREATE_SUSPENDED` when preparing a child for Job Object containment, since Tokio's `creation_flags` replaces existing flags.
## Testing
Add a Windows regression test that runs from a detached process and verifies that children have no console window and retain working piped stdin and stdout, both with and without Job Object containment.
GitOrigin-RevId: 990386032d74fa783a66bb20faff769539ea41c1
## What changed
Make `tui.copy_on_select = "auto"` copy on mouse release unless a direct terminal is known to forward its native copy shortcut: Ghostty with a parsed version at least `1.2.0`, Kitty on macOS, Windows Terminal, or VS Code on Windows.
Unknown terminals and Ghostty with older, missing, or unrecognized versions now default to copying. Keep copying enabled under tmux/Zellij and preserve explicit `always` and `never` overrides. Update the configuration documentation and schema to describe these defaults.
## Testing
Expand the existing configuration test matrix to cover more terminals, Ghostty versions (including `1.2.0-dev`), platform-specific defaults, and multiplexer behavior alongside configuration and launch overrides.
GitOrigin-RevId: 410abfa580156454b0f88e0bf4ed977fb8c81b1e
## Why
Changes in executor availability can alter cloud skill catalog rendering under a shared budget and repeat an unchanged executor catalog when it reconnects.
## What changed
- Cap cloud skills at three quarters of the metadata budget initially, leaving the remaining budget and unused cloud allowance for filesystem skills. Reduce the cloud cap only when doing so allows all skill entries to fit; description truncation alone does not trigger rebalancing.
- Persist the allocation across disconnects, compaction, and thread resume. Recompute it when the cloud inventory or total budget changes.
- Emit a short availability update when an unchanged selected-environment catalog returns and its full text remains in history. Reinject the full catalog when that text is missing.
## Testing
Add coverage for allocation stability, catalog and budget changes, omission handling, and full catalog reinjection after compaction and resume. Extend the selected capability stack test to verify reconnection avoids repeating the catalog.
GitOrigin-RevId: 839fe98024e00c4082a46e6a40675e15fd2c16c6
## What changed
- Show a random tip beneath the working status after 30 seconds, using the existing tooltip catalog and current key bindings.
- Show completion tips only after successful turns with a final answer, starting with the third turn and spacing displayed tips by at least three turn starts. Limit completion tips to two per app session, and skip them when a working tip was already shown for that turn.
- Respect `tui.show_tooltips`, hide tips during composer or transcript interactions, and omit tips when space is insufficient. Count exposure only when a tip is rendered.
- Anchor completion tips after queued history updates, keep them outside transcript selection and search, and dismiss them on history replay or transcript clearing.
## Testing
Add lifecycle tests for timing, completion cadence, duplicate notifications, failed and interrupted turns, and hidden tips. Add rendering snapshots and assertions for completion ordering, resizing, limited terminal space, and exclusion from transcript selection and search.
GitOrigin-RevId: 9e956f5b0377e3be71f9574639c3c6ef11ad1168
## What changed
Print `To reconnect, run:` followed by the indented resume command on its own line in disconnect exit summaries. Update CLI expectations and TUI snapshots for the new layout, and adjust the remote reconnect test to parse the command from its new line.
GitOrigin-RevId: 46f05084482063cf4f196b3b49471f331bc91384
## Why
Destination-only filtering stripped raw tool result metadata and MCP attribution when the built-in OpenAI provider used a custom endpoint.
## What changed
Add a runtime-only `include_internal_metadata` grant to `ModelProviderInfo` and enable it for the built-in OpenAI provider. Apply the provider grant or the existing first-party HTTPS destination check to both HTTP and WebSocket Responses requests.
Keep the grant out of serialized configuration and schemas, and default it to false for providers received through remote configuration. Providers without the grant retain the existing destination filtering.
## Testing
Update HTTP and WebSocket tests to expect metadata at overridden OpenAI endpoints. Cover provider grants, destination filtering, MCP attribution on requests, and the grant's exclusion from TOML serialization and configuration.
GitOrigin-RevId: 53aad6fb4d52cdfa9c79c6d92fe87383e1d0d1ef
## Why
The five-attempt limit could stop reconnection before the existing 120-second budget expired, preventing recovery from longer temporary failures.
## What changed
Continue retrying with an eight-second delay after the initial backoff until reconnection succeeds or the shared deadline expires.
## Testing
Update the exhaustion test to require the full 120-second budget. Extend the integration test to recover after five failed `thread/resume` attempts and verify draft preservation and notification delivery.
GitOrigin-RevId: 321d4ad100dbec1254bfe8aafd67ff63fb9a6e93
## Why
Detached Windows daemons can inherit the launcher's output pipes, leaving callers waiting for EOF after the launcher exits.
## What changed
Clear inheritance flags on the launcher's standard handles before spawning managed Windows processes. Leave the flags cleared to protect concurrent launches while preserving the child's configured stdio, and tolerate missing or already-closed handles.
## Testing
- Add a Windows regression test verifying that captured launcher output closes while the detached child remains alive and writes to its configured log.
- Give optional MCP startup grace tests more time to complete on slow runners while keeping the pending server's startup timeout longer than the turn timeout.
GitOrigin-RevId: 053e0417793db3c961e738476a05c7467978f339
## What changed
Expose Windows process creation flags on the shared command wrapper and use
`CREATE_NO_WINDOW` when launching local stdio MCP servers, including fallback
launches without Job Object containment. Preserve `CREATE_SUSPENDED` when
assigning the server to a Job Object before execution.
## Testing
Add a Windows regression test covering direct launches and launches through
`cmd.exe`. Verify that the server has no console, initializes successfully,
returns tools, and exits after shutdown.
GitOrigin-RevId: 84475e82999d91a431e09327d4f5639b59c01427
## What changed
Move `response.failed` classification and rate-limit retry-delay parsing into `responses_error.rs`, preserving existing error mappings, fallback messages, and malformed-payload behavior. Replace the inline classification logic in the SSE event handler with `parse_failed_response`.
## Testing
Add regression coverage for missing or malformed failed-response payloads, including invalid values in unused error fields. Move the existing retry-delay parsing tests alongside the extracted parser.
GitOrigin-RevId: 6faa09b3fb312f1990509eef7088c8a086724615
## Why
Compaction using the previous model can inherit the current turn's access program, producing a model/program pair that the server rejects.
## What changed
- Persist `cyber_access_program` in previous-turn settings and restore it during rollout reconstruction.
- Use the previous turn's access program when compacting with its model, preserving an absent program instead of inheriting the current selection.
- Pass the selected access program into local compaction prompts.
## Testing
Add regression coverage for local and remote compaction after model switches, including resume, fork, rollback, and compaction checkpoints. Verify fallback and subsequent sampling use the current model/program pair, and API-key sessions do not inherit access-program authorization.
GitOrigin-RevId: eaa7162e8711446dc9eb1bfff194e711abd54d7e
## Why
When a nested code-mode call's recorded arguments were truncated and attached to an output before its result arrived, the recorder could no longer attach the result metadata to that call.
## What changed
Retain validated call bindings so late result metadata updates the original output across retries and subsequent waits. Keep truncated arguments and incomplete call inventories intact, and apply existing metadata budgets.
Invalidate late metadata bindings when duplicate IDs, reused cells, conflicting outputs, or changed call inventories make attribution ambiguous. Clear stale pending calls when a cell ID is reused, and avoid counting duplicate pending IDs against capacity more than once.
## Testing
Add recorder regression tests for late metadata across retries, compaction, waits, and cell closure, plus ambiguous bindings and budget limits. Add a code-mode integration test that delays a tool result until its truncated call has been recorded and verifies metadata remains attached to the original output across later waits.
GitOrigin-RevId: 7398beaaa1a513147deebdea7aa841513a79d06b
## Why
Sibling tests can spawn children while an executable fixture is open for
writing, allowing inherited writable descriptors to cause `ETXTBSY` when
launching the fixture.
## What changed
Add a shared `copy_executable` helper for the daemon, doctor path safety, and
exec-server tests. On Linux, run `/bin/cp` in a separate process and wait for
it to exit before launching the fixture, then restore the source permissions
to account for restrictive umasks. Keep `std::fs::copy` on other platforms.
GitOrigin-RevId: 88f36826bbc6ab4e16e28ff02d5e7d6bd8dbf793
## Why
Opening a separate-window editor from the fullscreen TUI leaves the alternate screen, hiding the draft and the instruction to save and close the editor.
## What changed
Preserve and repaint the last Codex frame when handing the terminal to an external editor, while releasing keyboard and mouse input modes. Track whether the alternate screen's keyboard mode is active so cleanup does not pop it twice if the editor switches screens. Restore TUI modes and the alternate screen when the editor returns.
## Testing
Add terminal integration coverage for separate-window editors, terminal editors that switch or reuse screens, and inline mode. Verify the visible draft and handoff hint, disabled mouse reporting, edited draft recovery, and continued typing. Add a unit test for balanced keyboard stacks whether or not the editor leaves the alternate screen.
GitOrigin-RevId: c2ff1046a933f5f9e3168663e2c326999845c578
## Why
Yield signals and queued runtime events can detach an observer during termination, before the remaining output has been drained.
## What changed
Track the active yield signal separately from the observer so termination can disable yielding while keeping the observer attached. Ignore `Started`, `Pending`, and `YieldRequested` events during termination, allowing queued output to reach the observer in `CellEvent::Terminated`.
## Testing
Extend the termination regression test with an immediate yield timeout, a canceled yield signal, and queued start, yield, output, and completion events. Assert that both the termination caller and the initial observer receive the queued output in the terminated event.
GitOrigin-RevId: 1c08bdec06838123aaa102268da2f50b63ddea3f
## Why
Closing the warnings viewer dismisses warnings whose pages were displayed. Allow users to keep a warning available for later review while moving through the remaining warnings.
## What changed
- Press `k` to keep the current warning and advance, closing the viewer after the last warning.
- Preserve kept warnings when applying queued dismissal updates, so a later keep decision takes precedence for the same warning details.
- Reserve `k` in the viewer, update footer hints, and suppress key repeats so holding it does not skip warnings or modify the restored draft.
## Testing
Add coverage for keeping warnings, leaving unvisited warnings undismissed, conflicting key bindings, repeated key events, draft preservation, and queued dismissal updates. Update warning footer snapshots.
GitOrigin-RevId: da267b9142ddda78086418192970db2aec370d3a
## Why
Closing the warnings viewer left reviewed diagnostics in the warning badge and subsequent visits, with no way to dismiss them.
## What changed
- Dismiss only warning pages actually rendered when closing with `Esc`, `F2`, or `Ctrl+C`, and update the footer hint to “dismiss & close”. Unviewed warnings remain available.
- Hide dismissed diagnostics from the badge and viewer while their details are unchanged. Updated details make a warning visible again.
- Reset dismissals when clearing the transcript and ignore queued dismissals from an earlier transcript.
- Cache warning counts until transcript cell identities or dismissal decisions change.
## Testing
Add regression coverage for partial dismissal, navigation that skips rendering a page, changed warning details, and transcript resets with queued dismissals. Update snapshots for the close hint and remaining warning count.
GitOrigin-RevId: 3ce88c62a7f0ff9de34062165051e22168d3db25
Move JSON-to-HTTP header conversion from `responses_websocket` into the
crate-wide `responses_headers` module and update the WebSocket code to use it.
Preserve conversion of string, number, and boolean values, while continuing to
ignore invalid header names and unsupported or invalid values.
GitOrigin-RevId: f179de214cf763549b5b8a898dc4bcda3ce07ebd
## Why
Archived threads without previews were filtered out of thread listings, even though they had valid session metadata.
## What changed
- Include archived threads with empty previews in both SQLite and rollout-file listings.
- Add archive-specific indexes for creation, update, and recency ordering so these listings can use indexed pagination.
## Testing
Add regression coverage for paginated archive listings with and without SQLite, archive query plans that avoid temporary sorting, and metadata reads that preserve source and file timestamps for empty archived threads.
GitOrigin-RevId: e29d0257b2e029bea5fdf94eed6dab1006d2a8f2
## Why
An execution environment's enabled proxy configuration was reduced to traffic restrictions, leaving restricted commands offline without a controller proxy or an approved network grant.
## What changed
Carry `NetworkProxyConfig.enabled` into `EnvironmentNetworkPolicy.requires_proxy` and honor it when activating managed networking. This lets environment owners require filtered proxy access while direct network access remains restricted. Policies without an explicit proxy requirement retain the existing activation behavior.
## Testing
Extend remote command coverage to check allowed and denied proxy requests without a controller proxy, and verify that direct network access remains blocked.
GitOrigin-RevId: 7cc0063a0d1118de56b1bd30036338cf14360f6a
Daemon tests repeatedly hash large CLI binaries, even in `fastbuild` mode.
Set `blake3`'s build-script `OPT_LEVEL` to `3` and Rust compiler flag to
`-Copt-level=3` so both the native backends and Rust implementation are optimized.
GitOrigin-RevId: ebf9b96255e68ba775443077ebf3fd897282795d
## Why
Checking notification data size after SSE parsing leaves oversized fields and unterminated frames free to accumulate in the parser. Malformed UTF-8 can also be retained indefinitely by the decoder.
## What changed
Enforce `MAX_BODY` on incoming frame bytes before SSE parsing and reject malformed UTF-8 incrementally. Reset the byte count at blank lines, supporting LF, CR, and CRLF across chunks, so the limit applies per frame rather than per connection. Stop reading the source stream after an error.
## Testing
Extend the remote board contract test to cover oversized readiness fields, unterminated fields, and multiline data frames. Verify that a long sequence of heartbeat frames with all three line endings still permits notification delivery.
GitOrigin-RevId: c3a95ead88f53e7acfb28c5ba23141bc11d25532
## Why
Sourced snapshots parse options and aliases as a group before restored options take effect. Aliases serialized with `RC_QUOTES` enabled can therefore be misinterpreted by the replay shell.
## What changed
Serialize zsh aliases for sourced snapshots with `NO_RC_QUOTES` in a subshell, preserving the captured shell options and avoiding a dependency on the optional `zsh/parameter` module.
## Testing
Extend regression coverage to execute restored aliases with `RC_QUOTES` enabled and disabled across source and eval replay. Expand macOS zsh concurrent replay tests to cover quoted aliases, preserved options, and blocked descriptor paths with and without a TTY.
GitOrigin-RevId: 48086f380c21318bece9226dfe6486c179c2a440