## What changed - Let higher-priority providers in `features.network_proxy.credentials` displace lower-priority providers with overlapping `env` sources, including in profiles. Preserve inherited settings when providers swap sources, and compare environment names case-insensitively on Windows. - Preserve provider definitions across ordered batch remaps and persist displaced-provider removals without overwriting unrelated sibling updates. - Validate remapped providers using the credential broker's compilation rules before persisting writes, while allowing incomplete drafts and explicit deletions. - Omit displaced providers from config origins and report writes overridden by another provider's source ownership. - Build trusted credential-broker configuration before merging managed layers for project discovery, preserving remapped providers' environment protections. ## Testing Add unit and config RPC regression tests for source precedence, source swaps, ordered edits, concurrent sibling updates, atomic rejection of invalid remaps, persistence, and override reporting. Add a macOS managed-config regression test for remapped provider bindings during project discovery. GitOrigin-RevId: b7d402727acf4e5b0f25946db1cf18811f5e2679
User verification cancellation (experimental)
Local UI clients can cancel a native user-verification RPC by sending
userVerification/cancel with {requestId} and the experimentalApi opt-in.
The result is an empty acknowledgment ({}). This API does not enable desktop
verification capability advertisement.
requestId is the original status, enroll, delete, or verify RPC's string or
integer ID on the same connection, not the server elicitation ID. Use fresh IDs
for each operation and a distinct ID for the cancel RPC. Unknown, finished,
unrelated, and other-connection requests are no-ops.
The acknowledgment confirms the cancellation signal without waiting for the OS
prompt to close. The original RPC completes independently, with
cancelled/interrupted when cancellation prevents completion. Cancellation
cannot roll back completed effects. It remains effective while a proof waits for
outbound queue capacity, but cannot retract a response already enqueued.
Canceling or resolving an elicitation does not itself stop a separate
userVerification/verify RPC. Clients must cancel that RPC separately and discard
late proofs after the approval is canceled or resolved. Only one native worker
runs per app-server; if an OS call remains active after cancellation or timeout,
subsequent local operations return failed/providerError until that worker exits.
Thread removal
thread/archive and thread/delete reject attempts to remove a live internal
worker with JSON-RPC error -32600. The worker's owner controls its shutdown.
For example, a Guardian reviewer remains available to its parent conversation
after a client tries to archive or delete it.
After the owner releases the worker, its saved conversation can be archived or deleted normally. Ordinary client-controlled threads keep their existing behavior.
Amazon Bedrock authentication
If model_providers.amazon-bedrock.aws.credential_export is configured, Bedrock setup and
Bedrock login return an error without changing configuration or saved credentials. Remove the
exporter configuration before selecting another credential source. aws.credential_export and
aws.profile cannot be configured together.