active_agents_except (finish_scan, wait_for_message) treats budget_paused as
active, so a root cannot finish the scan over a parked child. park_for_budget
only transitions a running agent, and the wake back to running happens under
the coordinator lock.
Adds budget_policy: stop | pause to run_strix_scan / ReportUsageHooks /
AgentCoordinator, independent of interactive mode. Under pause the agents
get no budget warnings and no sub-agent reserve; each agent parks before
its next LLM call once spent >= limit or the scan is paused, sessions and
sandbox stay alive, and coordinator.resume_budget(max_budget_usd=...)
replaces the limit and wakes every parked agent without adding anything
to any session. coordinator.pause_budget() parks a running scan the same
way. In-flight calls are never cancelled, so spent may end above the
limit. Parked agents count as active for stop_agent.
Siblings differ only in the skills they were spawned with, but those came
first in <specialized_knowledge>, so their prompts diverged at 39%. Shared
skills and the catalog now come first, and the requested skills follow a
cache point, so siblings share 93%.
The extra system message takes a fourth Claude breakpoint, so the Bedrock
tool_config one goes: the first system breakpoint already covers the tools.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* perf(llm): give Claude a cache point before the per-run scope
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* refactor(llm): split the system prompt at a generic <cache_point> marker
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* perf(prompt): put per-run scope at the end of the system prompt
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* test(prompt): assert scope renders once, after the shared prefix
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Repair can change files beyond the candidate's draft edits while the
manifest still verifies. Comparing the applied draft hashes against the
final manifest now demotes the result to ready_with_gaps, so SARIF and
other auto-apply consumers never offer a fix that omits verified
changes.
A report revision whose locations can no longer form a candidate now
still supersedes any recorded preparation instead of leaving a ready
result pointing at superseded locations.
Preparation results carry the candidate that was actually verified so
SARIF emits the anchor-corrected edits rather than comparing the stored
draft's digest against a re-anchored one.
- Resolve edit/anchor/manifest paths and require workspace containment so
committed symlinks cannot redirect reads or writes outside the checkout.
- Treat unreadable or non-UTF-8 anchor targets as missing instead of
raising, and never let candidate anchoring block report persistence.
- Enforce the declared command policy: subprocess env is an allowlist plus
credentials_allowed, and commands run in a network namespace (unshare)
when network_allowed is false, or are rejected when isolation is
unavailable.
- Require a clean worktree in addition to a matching HEAD commit so
pre-existing uncommitted changes are not attributed to the fix.
- Expand untracked directories into per-file manifest entries.
- Surface failed optional checks as gaps instead of silent readiness.
- SARIF fixes emit only the verified candidate (digest must match the
recorded fix_candidate), not the stale draft locations.
A local_code target can mark its tree read_only; collect_local_sources
forwards the flag and build_bind_mounts mounts the tree read-only instead
of relying on host mode bits, skipping the per-metadata remounts since the
whole tree is already immutable. Used for pulled container image layouts.
* Enrich issue technical details with local Git blame
* Bound report history enrichment and require unambiguous repository identity
* test(history): drive attribution through the CLI scan setup and isolate git config
* Simplify Git blame attribution to existing reporting instructions
* Make local blame guidance reliable in live reporting
Extra files (knowledge trees, workspace files) reached the docker sandbox as
per-file read-only bind mounts whose parent directories docker created as
root, so the sandbox user could neither edit them nor create siblings. They
now travel as one tar archive uploaded after bring-up and unpacked as the
sandbox user, on every backend.
* Add api_type field to LlmSettings
Added 'api_type' field to LlmSettings for API path selection.
* Refactor API type handling in models.py
* Implement test for LlmSettings API type
Add test for API type override settings in LlmSettings.
* fix(tests): lint api_type test, cover the api_base override route, document STRIX_API_TYPE
* fix(models): keep LiteLLM chat-completions tool schema when STRIX_API_TYPE=responses
---------
Co-authored-by: RAJVARDHAN <95933896+vardhans07@users.noreply.github.com>
Exa /search is a neural search endpoint, not a chat model, so prepending
the Perplexity system prompt made Exa match the prompt's own vocabulary
(Kali, OWASP, apt, NIST) instead of the query. The system prompt stays
on the Perplexity path where it is a chat system message; the Exa
summary instruction is unchanged.