## sudoprivacy/sudocode — v0.2.19…v0.2.20

_176+ commits._

### Features
- **feat(host): a CLI session reaches the whole filesystem, not just its launch dir** (9cd1b18)
- **feat(cli): break cache breaks down by cause in `scode cache stats`** (d5df87c)
- **feat(nexus): collapse A2A connect config to endpoint + credential (7 -> 2)** (0ff43b8)
- **feat(api): record which upstream served each request, not just the totals** (cce1a1d)
- **feat(cohost): a prose answer reaches the one who asked — once** (98b6a82)
- **feat(mailbox): an auto-reply kind, and a count of what an agent sent** (d7ee863)
- **feat(cohost): forward driver-ai, so a co-host can carry llm_mount** (602ce2d)
- **feat(repl): wire ↑-dequeue into the iocraft input slot** (85cec29)
- **feat(tools): enforce a shared task template via required tool params** (15a29cd)
- **feat(runtime): run sub-agent spawns in parallel, and give the batch a ceiling** (d85158b)
- **feat(cli): add `scode cache stats`, and say where the records stop** (b4b3943)
- **feat(api): hold cached prefixes for 1h on subscriptions, matching Claude Code** (1c6932e)
- **feat: sub-agents are throwaway (CC Task model); mint a stable agent name** (b2fe407)
- **feat(cohost): nexusd-cohost — the cluster daemon that hosts sudocode agents, built here** (7ec209b)
- **feat(tools): send refuses a known-dead pid (D1), one guard not a forked path** (820d193)
- **feat(host): both hosts declare where host-side execution runs, and the list of differences is a test** (871a6e2)
- **feat(runtime): a backend roots sub-agents, as it already roots sessions** (76435f9)
- **feat(cohost): a co-hosted agent's session lives where its filesystem says** (775c685)

### Fixes
- **fix(acp): restore interrupted tool results before resumed turns (#814)** (ce0314f)
- **Merge pull request #813 from sudoprivacy/fix/render-extended-thinking** (f2259ea)
- **Merge pull request #810 from sudoprivacy/fix/a2a-live-stamp-claims** (7682ebd)
- **Merge remote-tracking branch 'origin/main' into fix/a2a-live-stamp-claims** (fabd360)
- **Merge pull request #809 from sudoprivacy/fix/prompt-cache-ledger-records-every-request** (9de2602)
- **perf(tools): reveal every deferred tool on the first ToolSearch** (ad4b096)
- **Merge remote-tracking branch 'origin/main' into fix/prompt-cache-ledger-records-every-request** (929c8fa)
- **fix(api): report a prefix that was discarded before it was ever read** (956ec06)
- **fix(api): record stream usage at the logical end of the message** (c20130c)
- **Merge pull request #806 from sudoprivacy/fix/cron-tools-test-env-race** (d20e469)
- **fix(examples): migrate a2a_poke/a2a_read to the credential contract** (a88c049)
- **Merge pull request #800 from sudoprivacy/fix/a2a-authon-readiness** (51626d7)
- **Merge branch 'main' into fix/a2a-authon-readiness** (32aa150)
- **fix(e2e): the auth-on restart waited on a line the first boot had written** (1ef1074)
- **Merge pull request #796 from sudoprivacy/fix/agent-list-residual** (3f04f60)
- **fix(nexus-backend): create_dir_all actually creates the directories** (eff7062)
- **fix(mailbox): a presence probe that fails is an error, not a non-agent** (1169705)
- **Merge pull request #792 from sudoprivacy/fix/agent-list-shape-and-errors** (560b341)
- **fix(agent_list): surface read failures + skip non-agent entries (#786)** (c6d7171)
- **fix(cohost): the lockfile has to cover driver-ai, and CI has to prove it** (243f1c8)
- **Merge pull request #790 from sudoprivacy/fix/agent-spawn-template-optional** (fdbf147)
- **Merge remote-tracking branch 'origin/main' into fix/agent-spawn-template-optional** (21927ed)
- **Merge remote-tracking branch 'origin/main' into fix/agent-spawn-template-optional** (a1d06b7)
- **fix(tools): make the task template optional on agent_spawn** (8c6226d)
- **Fix live PTY failures caused by mailbox routing and status wrapping (#789)** (00b3940)
- **Merge pull request #782 from sudoprivacy/fix/cohost-version-identity** (27a7b68)
- **fix(cohost): --version says which binary this is, and what is inside it** (7fe97a6)
- **Merge pull request #781 from sudoprivacy/fix/cohost-presence-visible-to-agent-list** (621f42b)
- **fix(a2a): one prompt section for both hosts, so they cannot say different things** (c88b9c5)
- **fix(repl): ↑-dequeue skips a2a/peer, pops the newest human queued item** (86e0050)
- **fix(tools): stop two sub-agents sharing an id when the clock stands still** (d74b3d2)
- **Merge pull request #776 from sudoprivacy/fix/agent-name-verbatim-prefix** (08e7ea9)
- **fix(mailbox): normalize Windows verbatim path prefix in local_agent_name** (2119787)
- **fix(api): tell an appended turn apart from a rewritten prefix** (eeb0153)
- **Merge pull request #779 from sudoprivacy/fix/cohost-refuses-without-config** (fe98913)
- **fix(cohost): refuse to spawn an agent this host cannot run** (9458d5a)
- **Merge pull request #778 from sudoprivacy/fix/metadata-device-id** (2076422)
- **fix(api): send device_id in metadata.user_id so pooling upstreams accept it** (2514219)
- **Merge pull request #774 from sudoprivacy/fix/cohost-release-macos-intel** (4587a8c)
- **Merge pull request #772 from sudoprivacy/fix/one-nexus-vfs-pin-check** (0851e61)
- **Merge pull request #773 from sudoprivacy/fix/cohost-delivery-cursor-assert** (98a1953)
- **Merge pull request #768 from sudoprivacy/fix/plan-test-isolation** (cf53d0d)
- **fix(cohost): keep the daemon tree behind a feature, so nobody else compiles it** (cdc7623)
- **fix(e2e): read the pinned commit however the pin is spelled, and let the guard speak** (6ad9c47)
- **Merge pull request #767 from sudoprivacy/fix/pending-slot-empty-no-blank-line** (33e275c)
- **fix(repl): don't reserve a blank line for an empty pending overlay** (e0d8950)
- **Merge pull request #763 from sudoprivacy/fix/plan-store-on-session-fs** (314e557)
- **fix(runtime): the plan file is the session's, on the session's filesystem** (b808a77)
- **Merge pull request #762 from sudoprivacy/fix/cohost-cron-fail-loud** (ffe8b7d)
- **fix(cohost): a co-hosted agent is not offered crons this daemon will never fire** (1252d9e)
- **fix(tools): the sub-agent store is read and written on the filesystem that roots it** (a86778e)
- **fix(runtime): the filesystem that answers for a concern is the one that rooted it** (0b5db8e)
- **fix(memory): a co-hosted agent's memory is READ through its own filesystem** (72506bf)
- **fix(runtime): todos, drafts and turn rollback follow the session's filesystem** (b1e12cd)
- **fix(memory): a co-hosted agent's memory is its own, in the VFS** (f3bffd7)
- **fix(tools): a sub-agent inherits its parent's filesystem** (873c73e)
- **Merge pull request #751 from sudoprivacy/fix/config-option-lists** (b411159)
- **fix(config): offering and accepting are two jobs, so two lists** (bf141dc)
- **fix(config): the menu and the parser are different questions** (386b999)
- **fix(config): one list of permission-mode spellings, not three** (386eeab)
- **Merge pull request #761 from sudoprivacy/fix/agent-list-backend-discovery** (7573033)
- **fix(tools): agent_list discovers peers through the mailbox, not local disk** (d47bf91)

### Backend
- **cli: render extended thinking instead of discarding it** (58caf4c)
- **Merge pull request #812 from sudoprivacy/chore/remove-nexus-a2a-peer** (b1906f5)
- **Merge pull request #811 from sudoprivacy/feat/one-tool-reveal-per-session** (d27f2d4)
- **Merge branch 'main' into feat/one-tool-reveal-per-session** (9aae24a)
- **Merge remote-tracking branch 'origin/main' into feat/one-tool-reveal-per-session** (bc701f2)
- **Merge pull request #808 from sudoprivacy/feat/cli-wide-root-mount** (a482dfd)
- **Merge pull request #805 from sudoprivacy/chore/e2e-auth-on-migration** (2c1c2db)
- **Merge pull request #807 from sudoprivacy/chore/remove-dead-file-snapshot** (64eb781)
- **Merge pull request #799 from sudoprivacy/feat/nexus-credential-env** (450ee0a)
- **Merge pull request #803 from sudoprivacy/ci/guard-the-third-live-assertion** (b6f7053)
- **Merge pull request #802 from sudoprivacy/chore/pin-nexus-vfs-v0-7-20** (cd00601)
- **Merge pull request #801 from sudoprivacy/obs/session-account-join** (dad7da5)
- **Merge branch 'main' into obs/session-account-join** (a2f3ba8)
- **Merge branch 'main' into obs/session-account-join** (584cb3a)
- **Merge pull request #798 from sudoprivacy/feat/a-prose-answer-reaches-the-sender** (370bbec)
- **Merge pull request #797 from sudoprivacy/ci/a-dead-credential-says-so** (a9aea80)
- **Merge pull request #780 from sudoprivacy/feat/anthropic-cache-ttl-1h** (a514f1a)
- **Merge branch 'main' into feat/anthropic-cache-ttl-1h** (1fa3e43)
- **Merge pull request #793 from sudoprivacy/ci/cohost-provenance-comments-positive** (21b5454)
- **Merge branch 'main' into feat/anthropic-cache-ttl-1h** (bc222e5)
- **Merge branch 'main' into feat/anthropic-cache-ttl-1h** (d109193)
- **Merge pull request #791 from sudoprivacy/feat/cohost-forwards-driver-ai** (bf0b642)
- **Merge pull request #788 from sudoprivacy/ci/cohost-release-gates** (58effa4)
- **Merge pull request #784 from sudoprivacy/feat/up-dequeue-skip-a2a** (22d1cdd)
- **Merge pull request #783 from sudoprivacy/feat/task-template-params** (0282f42)
- **Merge remote-tracking branch 'origin/main' into feat/task-template-params** (b59ebc9)
- **Merge pull request #777 from sudoprivacy/chore/bump-nexus-vfs-v0.7.16** (258045f)
- **Merge pull request #775 from sudoprivacy/feat/subagent-throwaway-identity** (1253eca)
- **Merge pull request #771 from sudoprivacy/chore/release-nexusd-cohost** (571ce7b)
- **Merge pull request #769 from sudoprivacy/feat/nexusd-cohost** (5a7c8f0)
- **Merge pull request #766 from sudoprivacy/chore/bump-nexus-vfs-2467f358** (8c5354d)
- **Merge pull request #765 from sudoprivacy/feat/send-dead-target-guard** (9229c3e)
- **Merge pull request #764 from sudoprivacy/feat/host-parity-shell-root** (9de4dec)
- **Merge pull request #760 from sudoprivacy/feat/subagent-store-on-backend** (7b0e4dc)
- **Merge pull request #759 from sudoprivacy/feat/cohost-session-persistence** (fe4347e)

### Tests
- **test(e2e): the A2A harness docs claimed a posture no daemon serves** (43efb36)
- **test(e2e): migrate the nexus-A2A harness from auth-off to auth-on cert-only** (4a3c6f6)
- **test(tools): guard the deferred-tools listing test against the cron env race** (e0f1c97)
- **test(a2a): discovery asserted from BOTH nodes** (a8299e2)
- **test(e2e): PTY guard ↑-dequeue returns human, skips queued a2a** (5dcaf72)
- **test(plan): supply required template fields in mock; assert structured plan file** (1f812dc)
- **test(mailbox): make verbatim-prefix test cross-platform** (08b646c)
- **test(cohost): assert the storm's signature, not a turn count tuned to one machine** (fe8d59b)
- **test(runtime): isolate the co-hosted-agent plan test from ambient SUDOCODE_PLAN_FILE** (e725ea0)
- **test(runtime): one generous budget for the spawn-task waits that expect an event** (5e40646)
- **test(engine-host): both hosts' sub-agent roots, asserted side by side** (fa7a564)
- **test(engine-host): the co-host's turn is recorded in the VFS** (427502d)

### Chore
- **chore(release): prepare v0.2.20 (#815)** (57d108d)
- **refactor(a2a): drop the static NEXUS_A2A_PEER hint for dynamic discovery** (5308e57)
- **refactor(runtime): remove the dead file_snapshot module and its flaky test** (063f792)
- **ci: guard the live assertion a dead credential actually reaches** (0cbb6a8)
- **chore(deps): nexus-vfs v0.7.20** (e3cd42b)
- **ci: a check that failed on a dead credential says so** (d54f572)
- **chore(deps): nexus-vfs v0.7.19 — the kernel half of #786** (f999b21)
- **refactor(mailbox): delete the enumeration nothing routes through** (450378c)
- **ci(cohost): say what the artifact carries, not what it used to** (f5b6905)
- **ci(cohost): drop the sidecar PAIRING.txt, the binary says it now** (0f27d2c)
- **ci(cohost): nexusd-cohost gets its own size budget** (3545f6a)
- **ci(cohost): assert the stamp actually reached the binary** (2117b8a)
- **chore(gitignore): ignore .sudocode-inbox/ runtime mailbox dir** (9ccdb4c)
- **refactor(config): give cache_ttl_1h one home in sudocode.json** (65369fc)
- **chore(deps): pin nexus-vfs v0.7.16** (73746f8)
- **ci(release): build nexusd-cohost for Intel macOS too** (974a0b0)
- **ci: check the one-nexus-vfs-pin invariant instead of asserting it in prose** (8d16edb)
- **ci: match the workflow directory, so a new workflow arrives already gated** (125d3a7)
- **ci(release): publish nexusd-cohost on its own tag namespace** (36a68cb)
- **refactor(cohost): derive the service set from the cluster daemon instead of re-listing it** (3506f5e)
- **chore(deps): one nexus-vfs pin for the workspace, expressed as the tag it must be** (735f6ce)
- **chore(deps): pin nexus-vfs at the rev the daemon runs (2467f358)** (caf0cf6)
- **refactor(runtime): one storage-root contract instead of one method per concern** (6a795ac)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/sudoprivacy/sudocode?utm_source=github-action)._