Adds @isaacs/ttlcache to avoid repeated gh CLI calls for the same
working directory. Concurrent lookups for the same cwd share a single
in-flight promise. Cache expires after 30s by default.
The file-based daemon-launch.log was added as temporary instrumentation
for debugging Windows startup. Desktop now logs lifecycle events through
electron-log; CLI and server supervisor drop the launch logging entirely.
Loop runs can now specify separate provider/model for worker and verifier
agents (--provider, --model, --verify-provider, --verify-model). The
--archive flag preserves agent conversation history after each iteration
instead of destroying them.
The desktop app uses the paseo:// custom protocol scheme, but the
origin was only passed via PASEO_CORS_ORIGINS when the desktop started
the daemon itself. If the daemon was started by the CLI, the origin
was missing and the Electron renderer's WebSocket connection was
rejected.
Also removes file:// and null from allowed origins — any page loaded
via file:// could connect to the daemon, which is a security gap.
* Add metrics collection and terminal performance tests
* feat: add loop, schedule, and chat commands with slash-namespaced RPC
Introduce three new server-side features with CLI command groups:
- `paseo loop` — iterative agent execution with verify-check/verify-prompt
- `paseo schedule` — recurring tasks on interval or cron cadence
- `paseo chat` — chat rooms for agent-to-agent coordination
All features use new slash-namespaced RPC methods (e.g. `loop/run`,
`schedule/create`, `chat/post`) instead of flat message types, backed
by file-based persistence and wired through the existing WebSocket
session dispatch.
* test: stabilize loop schedule chat rollout
- sherpa-runtime-env: use case-insensitive key lookup when modifying PATH
on plain env objects. On Windows, `{...process.env}` stores PATH as
`Path` but `applySherpaLoaderEnv` used hardcoded `"PATH"`, creating a
duplicate key that could shadow the real system PATH in child processes.
- runtime-toolchain: use `wmic` on Windows instead of Unix-only `ps -o`
to resolve the node executable path from a PID.
- claude-agent: pass `findExecutable("claude")` as
`pathToClaudeCodeExecutable` so the SDK uses the user's installed
binary when available. Update spawn hook to only replace bare
"node"/"bun" with process.execPath, preserving native binary paths.
- desktop/paseo.cmd: use ELECTRON_RUN_AS_NODE with node-entrypoint-runner
for the Windows CLI wrapper.
* Add metrics collection and terminal performance tests
* fix: handle Windows drive-letter paths across the codebase
Windows paths like C:\Users\foo\project were broken in multiple places:
- agent-storage slugified D:\MyProject as D:-MyProject (illegal colon)
- terminal-manager rejected all non-/ paths as relative
- bootstrap parser misparsed drive colons as TCP host:port
- daemon/client connection helpers misclassified Windows paths
- CLI cwd filtering used hardcoded / separators
- checkout-git worktree detection used hardcoded / in path checks
- worktree archive used split("/").pop() instead of path.basename()
All path helpers now normalize separators and handle Windows
drive letters with case-insensitive comparison where needed.
Codex delete operations were displayed as edits with green (added) lines
because the translation pipeline didn't distinguish deletes from edits.
Now detects kind="delete" and *** Delete File directives, producing proper
unified diffs with removed lines and +++ /dev/null headers.
Delete unused system-prompt.ts, agent-prompt.md, and the entire
terminal-mcp/ directory (tmux-based MCP server) — nothing imports
any of these. The codebase uses src/terminal/ (node-pty) instead.
When interrupting a Claude agent mid-tool-call and sending a replacement
message, the SDK's abort error result was being attributed to the new
foreground turn, causing [System Error] banners and displaced replies.
Root cause: pendingInterruptAbort was cleared by visible activity from
the new turn before the stale result arrived (timing race), and the
stale result then poisoned the replacement turn.
Fix:
- Suppress stale non-success results at the top of routeSdkMessageFromPump
before any turn attribution, using both flag-based (pendingInterruptAbort)
and content-based (isAbortError) detection
- Stop clearing pendingInterruptAbort on visible activity — only consume
it when a result message arrives
- Prevent idle flash during replacement by checking pendingReplacement
in agent-manager turn_completed/turn_canceled handlers
- Fix vitest env loading to use import.meta.url instead of process.cwd()
- Load .env.test eagerly in agent-configs.ts for collection-time availability
Includes regression tests covering the exact f160a2a3 daemon log ordering.
When a foreground message interrupts an autonomous turn, the notification
content has already been dispatched to subscribers. Canceling says "this
turn didn't happen" — but it did. Complete it instead, preserving the
lifecycle semantics and preventing notification loss.
- Change interrupt() to call completeAutonomousTurn instead of
cancelAutonomousTurn, with flushPendingToolCalls before completion
- Remove dead cancelAutonomousTurn method (no remaining callers)
- Fix autonomous wake tests B and C to handle notification/foreground
timing race: when task_notification arrives during a foreground turn,
there is no separate autonomous running edge afterwards
Remove `pendingInterruptAbort = false` from startTurn() and
`queryRestartNeeded = true` from requestCancel(). Both violated the
existing coordination contracts:
- pendingInterruptAbort must only be cleared by the stream pump at its
safe consumption points, not eagerly by the turn lifecycle
- queryRestartNeeded is for transport-level restarts (config changes,
rewind), not for normal interrupt/cancel flows — setting it on every
cancel killed the Claude process and destroyed background tasks
The actual fix for the send-during-tool-call bug was the manager-side
pendingForegroundRun settlement wait added in the previous commit.
- Fix race in agent-manager where pendingRun wasn't fully cleaned up
before the next streamAgent call, causing "already has an active run"
- Fix Claude agent query restart: null out query/input before awaiting
old iterator return so the old pump skips failActiveTurns
- Reset pendingInterruptAbort on new foreground turn
- Add system error assertion to send-during-tool-call e2e test
- Rename mode color tiers: drop "default", rename "readonly" to
"planning", update color assignments across providers and UI
Strip parent Claude Code session env vars (CLAUDECODE, CLAUDE_CODE_ENTRYPOINT, etc.)
from child agent environments so spawned agents don't fail with "cannot be launched
inside another Claude Code session". Centralize isProviderAvailable to check both
binary and credential availability. Add red e2e test for send-during-tool-call bug
and force-cancel stale foreground turns in cancelAgentRun.
Replace three competing event paths (foreground stream, live event pump,
JSONL history poller) with a single push-based subscribe() + startTurn()
contract. This fixes duplicate user messages and stuck running state caused
by timing-based routing between concurrent event sources.
Key changes:
- AgentSession interface: remove stream(), add subscribe() and startTurn()
- All providers (Claude, Codex, OpenCode): single subscribers Set with
notifySubscribers() for push-based event delivery and turnId stamping
- Agent manager: identity-based turn ownership via activeForegroundTurnId
replacing pendingRun async generator
- Delete: dual queues, routeSdkMessageFromPump, startLiveHistoryPolling,
snapHistoryOffsetToEnd, liveEventBacklog, Pushable
- Fix Codex provider not clearing activeForegroundTurnId on turn completion
- Add real-provider integration tests for event stream invariants
* Expose PASEO_AGENT_ID to managed agents
* refactor(server): make managed agent launch context explicit
* refactor(server): pass launch env through agent providers
* fix: use workspace-agnostic root tsconfig
* fix(server): align CI tests with current agent behavior
* fix(server): restore Claude history and sidechain CI coverage
Client-side xterm.js was generating Device Attributes responses via
onData, which fed back to the PTY as visible text. Register CSI handlers
to consume query responses on the client and respond to DA1 on the server.
TimelineAssembler.messages map retained full assistantText and
reasoningText for every message for the lifetime of the session.
Replace with a lightweight finalizedMessageIds set that prevents
duplicate emission during history replay without holding the text.