## sudoprivacy/sudocode — v0.2.20…v0.2.21-rc.1

_106 commits._

### Features
- **feat(fs_backend): a link reports as a link, on every backend** (019bbf0)
- **feat(mailbox): the chat-list index is a link on every backend** (8ec172a)
- **feat(client): ensure_link, and stat carries the target back** (b004f54)

### Fixes
- **fix(ci): resolve runtime paths inside workflow steps** (47ab1a2)
- **fix(runtime): terminate Bash process trees on cancellation and timeout** (78bb7e7)
- **deps: pin nexus-vfs v0.7.26 with replicated tail deadlock fix** (b599515)
- **fix(cli): report truncated streaming turns as failures** (609955c)
- **Merge pull request #839 from sudoprivacy/fix/bundled-wins-over-stale-capabilities-file** (043e912)
- **Merge branch 'main' into fix/bundled-wins-over-stale-capabilities-file** (1eb6bda)
- **Merge pull request #840 from sudoprivacy/codex/fix-windows-pty-path** (bf4cd43)
- **Merge pull request #836 from sudoprivacy/fix/queued-recall-stack** (dc44507)
- **fix(repl): preserve queued messages across repeated recall** (271e7b1)
- **Merge pull request #837 from sudoprivacy/fix/cache-root-honors-userprofile** (76cf2a2)
- **Merge pull request #804 from sudoprivacy/fix/preflight-and-subagent-routing** (c8f2644)
- **perf(api): stop uploading the request twice a turn, and let a sub-agent pass its routing key on** (f551f8a)
- **Merge pull request #835 from sudoprivacy/fix/pty-sync-points-are-stream-ordered** (bc2f9b8)
- **Merge pull request #833 from sudoprivacy/fix/cache-safe-completion-mirrors-session-fields** (c951dae)
- **fix(cache): mirror session-level request fields on the cache-safe path** (e21a096)
- **Merge pull request #829 from sudoprivacy/fix/thinking-render-buffering** (1e9bfd6)
- **fix(cli): buffer thinking by line so reasoning is not dim-fragmented** (dbf0607)
- **Merge pull request #828 from sudoprivacy/fix/thinking-parameter-is-part-of-the-cache-key** (3337181)
- **Merge pull request #830 from sudoprivacy/fix/inline-resize-reflow** (ff2bc1a)
- **fix(cli): use reflow-safe inline frame anchoring** (7875c1b)
- **Merge pull request #827 from sudoprivacy/fix/chrome-semantic-styles** (7f63902)
- **fix(cli): compose chrome from independently styled spans** (411d07c)
- **Merge pull request #826 from sudoprivacy/fix/thinking-block-replay-cache** (b012e80)
- **Merge pull request #822 from sudoprivacy/fix/cli-style-preservation** (39fd531)
- **fix(cli): retain independent dim and strikethrough styles** (ee1410e)
- **fix(cli): retain formatter colors and supported styles in live chrome** (ede70cb)
- **fix(cli): use a text bullet for assistant responses** (78f5210)
- **Merge pull request #825 from sudoprivacy/fix/connection-stability-and-preflight** (8d0cf3c)
- **fix(api): stop re-uploading the whole conversation to count its tokens** (5e58ed5)
- **fix(api): stream the compaction transport, and collect streams in one place** (ac6dd16)
- **fix(api): stop reusing pooled connections the peer already closed** (7dea523)
- **Merge pull request #824 from sudoprivacy/fix/claude-review-silent-skip** (1d36e7c)
- **Merge remote-tracking branch 'origin/main' into fix/claude-review-silent-skip** (6a3bf8d)
- **Merge pull request #819 from sudoprivacy/fix/http-error-hides-its-cause** (d3b864f)
- **fix(ci): a skipped code review must not look like a passing one** (c8f0623)
- **Merge main: pick up the claude-review credential fix so this PR's review actually runs** (7e87e23)
- **Merge pull request #821 from sudoprivacy/fix/claude-review-dead-credential** (4a728a7)
- **fix(ci): code review runs on the sudorouter proxy key, not a dead OAuth token** (6f209e0)
- **fix(api): surface the cause of a transport failure, not just the URL** (2164c43)
- **Merge pull request #817 from sudoprivacy/fix/model-capability-invented-windows** (73bea5f)
- **fix(runtime): stop inventing context windows for undocumented models** (6c7c994)
- **Merge pull request #816 from sudoprivacy/fix/live-smoke-proxy-auth** (7265ef3)
- **fix(ci): model-compat sweep reported success while testing zero models** (985de2b)
- **fix(engine): subagents inherit the session's auth mode on every path, not just the REPL** (acc9409)
- **fix(ci): live smoke test uses sudorouter proxy key, not a subscription OAuth token** (ccccfb5)

### Backend
- **Merge pull request #841 from sudoprivacy/codex/model-egress-through-vfs** (f946782)
- **deps: pin published nexus-vfs v0.7.25** (06ece6e)
- **cohost: provision the model mount in the authenticated daemon harness** (5b9a949)
- **model: route co-host requests through the session Nexus mount** (b76fd1a)
- **Drop two blank lines cargo fmt objected to** (c61a319)
- **Let the bundled capability table outrank the on-disk fallback file** (a98a799)
- **Merge pull request #838 from sudoprivacy/docs/hacker-readme-principles** (8478828)
- **Resolve the prompt-cache root through the shared config home** (3a38755)
- **Merge pull request #834 from sudoprivacy/refactor/todo-slot-naming** (5ab73c2)
- **Merge pull request #818 from sudoprivacy/feat/chat-list-index-is-a-link** (90a61a5)
- **Merge pull request #831 from sudoprivacy/codex/model-discovery-20261001** (aab5434)
- **api: preserve native provider discovery paths** (8801e9f)
- **Discover and refresh model capabilities for the actual session endpoint and credentials** (e831746)
- **Declare the turn's thinking parameter on cache-safe compaction** (bb19afc)
- **Replay redacted thinking too, for the same reason as a signed block** (54c3381)
- **Stop dropping a sub-agent's thinking** (80b83d2)
- **Return the signed thinking block, so a cached prefix survives a tool round-trip** (47065ff)
- **Read an unframed body on every provider, and stop masking its errors** (6c53a49)
- **Read an unframed message body instead of re-sending the conversation** (e582d53)

### Tests
- **test(runtime): wait for the model turn after Bash timeout** (679a41f)
- **test(pty): wait for the input row before treating a screen as ready** (d1fd38d)
- **test(cohost): require the delegated task to report its calculation** (2503e22)
- **test(a2a): reproduce concurrent replicated tail deadlocks** (ed7330f)
- **test(cohost): verify funded daemon workflows and native model requests** (22f8394)
- **test(model): exercise live delegation, compaction and resumed output** (fa7e958)
- **test(pty): wait for running commands before ESC cancellation** (add325a)
- **test: fetch the daemon from the release tag in Cargo.lock** (d530849)
- **test: verify co-host model requests and refusal through Nexus** (d2b80db)
- **test: preserve a usable Git Bash path in Windows PTYs** (ff1ac6e)
- **test(repl): preserve physical rows in ConPTY screen assertions** (4dd35e3)
- **test(repl): reuse shared screen waits after rebase** (c946d44)
- **test(acp): verify routing identity through nested agent requests** (4cf4db6)
- **test(a2a): keep the output that says why the daemon never went writable** (16107bb)
- **test(pty): move the two proven-flaky waits onto the screen** (1f554ed)
- **test(pty): one screen-wait primitive, because chrome is not a stream** (723434d)
- **test(cli): load image capabilities from the fixture endpoint** (b0b2ea4)
- **test(cli): verify endpoint discovery in PTY and ACP** (d60bb15)
- **test(cli): reject duplicated chrome and lost history after resize** (c1e13cc)
- **test(cli): map wrapped style text back to physical cells** (95cd52a)
- **test(cli): resize idle chrome only after its frame settles** (bcd082b)
- **test(cli): cover consistent summary and status contrast** (1ab1098)
- **test(cli): wait for editable input after the footer** (017a1d3)

### Docs
- **docs(acp): describe foreground shell cancellation cleanup** (3f8eabe)
- **docs(e2e): describe local daemon prerequisites** (3d1774e)
- **docs: center README on simple, controllable hacker workflows** (a3d18af)
- **docs(fs_backend): the NAME is the cross-backend contract, the shape is not** (31970be)
- **docs(api): explain why thinking stays explicitly budgeted, not adaptive** (e461ffe)

### Chore
- **chore(release): prepare v0.2.21** (812b9e2)
- **build(cohost): budget measured binaries with model drivers** (4cac93b)
- **build: pin the released Nexus model transport v0.7.24** (cdfd4ba)
- **build: record model transport dependencies** (746570f)
- **refactor(api): drop duplicate preflight guard already present on main** (2d35ccf)
- **refactor(cli): name the todo-only chrome slot explicitly** (dad8f12)
- **chore(deps): pin v0.7.23 — the tag whose client actually published** (cd49843)
- **chore(deps): pin nexus-vfs v0.7.22, the release that carries the link target** (e0de1c3)
- **chore(vfs): sync the published optional link target field** (7038ab4)
- **style(cli): format combined attribute assertion** (630c148)
- **ci: review PRs with haiku, not sonnet — 3x cheaper by the gateway's own ratios** (53b664e)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/sudoprivacy/sudocode?utm_source=github-action)._