`/goal <objective>`, `/plan <prompt>` and `/vibe <prompt>` promote the
composer draft into the first turn, but built their submission from the
draft *text* only:
this.onInputCallback(this.startPendingSubmission({ text: objective }));
The editor-submit path in `InputController` passes
`editor.pendingImages`/`pendingImageLinks` alongside the text; these four
call sites did not. A draft holding pasted screenshots therefore reached
the model with its positional `[Image #N, WxH]` markers intact and every
image payload missing, so the agent saw markers pointing at nothing and
`read "Image #1"` resolved against an empty list.
The payload was not only dropped, it also outlived the draft: the mode
commands cleared the composer with `editor.setText("")`, which leaves
`pendingImages` attached. The orphans then rode along with whatever the
user typed next, one index off, which is how a later message can attach a
screenshot the user never re-pasted.
Measured on 259 image-bearing user messages across 10 local session logs
(v17.2.x): 36 of 37 messages submitted as a goal objective lost every
image, against 190 of 198 preserved on the ordinary submit path.
Fix:
- `#takeDraftImages()` detaches the composer's pending images and links,
and all four mode-command submissions spread it into
`startPendingSubmission` (`cancelPendingSubmission` already restores
them when a submission is cancelled).
- `/goal`, `/guided-goal`, `/plan` and `/vibe` clear the draft with
`editor.clearDraft()` instead of `editor.setText("")`, so images can
never outlive the text they were pasted into (the streaming branch of
`/goal` never submits, so its draft must die whole).
Tests: two regression cases in `goal-mode-integration.test.ts` assert the
objective submission carries the image and empties the composer; both
fail on the previous behaviour with `images: undefined`. The `/plan`,
`/goal` and `/guided-goal` slash stubs now model `clearDraft`.
- Replaced monolithic desktop native bindings and action batching with a modular cross-platform backend structure supporting Wayland, X11, macOS, and Win32.
- Updated the computer tool schema and supervisor to execute persistent JavaScript script runs with timeout clamping and asynchronous tool calling.
- Integrated accessibility (AX) tree snapshotting, node querying, and bounds-based hit testing across platform desktop layers.
- Added native clipboard bindings and updated coding-agent prompts, renderers, and tests to validate script-based computer workflows.
- Added window discovery, targeting, and frame validation for macOS, Windows, and Linux platforms.
- Updated computer tool and protocol definitions to support listing and targeting specific application windows.
- Refactored native computer tool exposure to function-only representation across models.
- Updated documentation and test suites to reflect window-scoped computer control capabilities.
- Implemented session stores and metadata converters to import Claude and Codex sessions into OMP.
- Added `--from-claude` and `--from-codex` CLI flags and `/resume` command arguments for foreign session resolution.
- Updated session selector components and controllers to support listing and picking external agent sessions.
- Added comprehensive unit tests and documentation covering foreign session import functionality.
- Reworked the `/guided-goal` command to send a hidden interview brief instead of a modal popup flow.
- Removed the deprecated `guided-setup.ts` module and system prompt template.
- Updated goal tool availability and activation logic to support goal creation during the interview.
- Replaced existing tests and added new verification for the updated guided-goal workflow.
- Add `pinSessionOAuthAccount` storage method and active account flag to the auth storage API.
- Introduce session account selector component, controller logic, and interactive mode delegation.
- Implement the `/session pin` builtin slash command with text listing and account pinning capabilities.
- Add unit tests covering session account selection, component navigation, and command handling.
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
XTest input with keysym mapping) compiled into the core addon on every
published target; Linux arm64 and musl are now supported and headless
hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
build dependencies, and the now-unreferenced vendored libspa crate;
reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
XTest layouts reject negative origins and coordinates beyond 0..=32767,
batch coordinates stay bound to the frame last returned to JS with
intermediate screenshots deferred, coordinate input requires a
previously returned frame, and failed chord releases still release
every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
no input is emitted after expiry and wait-heavy batches are rejected
upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
a regular function tool with a typed GA action schema across OpenAI,
Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
- Update `acp-builtins.test.ts` to support interactive session movement and path session file testing.
- Clarify `/move` command routing in `/move` slash command tests.
- Rename internal `search` references to `grep` to align with product definitions.
- Refactor TUI render tests to use `Promise.withResolvers` for cleaner flow control.
Address three P1 code review comments on PR #3352:
1. Colon-separator bypass: parseSlashCommand() treats ':' as an argument
separator, but shouldSkipHistory only split on whitespace. So
/login:?code=abc&state=xyz bypassed the filter. Now uses the same
earliest-whitespace-or-colon splitting as parseSlashCommand.
2. /join <link> secret: the collab join link carries a 32-byte room key
and optional write token. Add /join to the denylist — skip any /join
with arguments.
3. Added regression tests for colon-separator forms and /join denylist.
parseCallbackInput() accepts three forms: redirect URLs, query strings
(?code=...), and raw auth codes — all carry OAuth secrets. The previous
filter only skipped URL-like inputs, leaking query strings and raw codes.
Skip ALL /login commands with any argument. The minor convenience loss
(can't recall /login <provider>) is far less important than the risk of
persisting OAuth authorization codes.
Previously only 4 commands (/plan, /goal, /mcp, /ssh) stored their text
in history via per-handler addToHistory calls. All other built-in slash
commands were silently skipped because executeBuiltinSlashCommand returned
true before the input controller's addToHistory was reached.
- Centralize history recording in the input controller after successful
slash command dispatch, for both Enter and Ctrl+Enter submit paths.
- Remove all 10 per-command addToHistory calls from slash command handlers
to prevent duplicates.
- Add shouldSkipHistory() security filter to exclude commands that may
carry secrets: /login <url> (OAuth callback with code=/state= params)
and /mcp add --token <token> (bearer token).
- Add regression tests for the security filter (8 cases).
- Update 7 existing test files to remove handler-level addToHistory
assertions (now the input controller's responsibility).
- Replaced the `/debug dump-next-request` command with an updated `/dump` command that exports LLM request context to JSON sidecar files.
- Removed persistent debug path state and manual path configuration in favor of automated generation.
- Updated session logic to handle serializing LLM request context to temporary directories.
- Refactored testing suites to remove path-based debug tests and verify dynamic request file generation.
- Added a `mode` property to `CompactOptions` to allow fine-grained control over compaction strategies.
- Implemented `soft`, `remote`, and `snapcompact` submode overrides for the `/compact` command.
- Integrated `parseCompactArgs` to enable robust subcommand routing and validation, including focus instruction rejection for specific modes.
- Established a `CompactMode` registry to manage compaction strategies and verify remote availability.
- Removed qrcode and qrcode-view subcommands from the collab command.
- Updated showCollabLink to always trigger QR code display.
- Refactored internal verb logic to simplify session sharing flow.
- Added collab.webUrl and rendered browser links as web UI wrappers whose fragments carry relay links.
- Added one-shot /collab qrcode and /collab qrcode-view commands with terminal QR rendering.
- Updated coding-agent and collab-web parsers to prefer parseable wrapper fragments while preserving legacy links.
- Added regression tests and changelog entries for split-host collab links and QR commands.
- Add buildDirectoryArgumentCompletions() to suggest directories relative to project dir
- Support relative paths, ./, ../, ~/ and absolute paths
- Allow spaces in destination paths (e.g. My Project/src/)
- Use expandTilde() so ~foo prefixes resolve correctly and completions are resolvable
- Emit display values that preserve the user's prefix style
- Expand ~ in /move handler so accepted completions move to the intended directory
- Wire /move command to the new completion provider
- Add unit tests covering empty prefix, filtering, subdirs, relative/parent/home/absolute paths, and space-containing directories
- Mock os.homedir() in home-relative test for deterministic results
- Update CHANGELOG
- Only add /btw, /tan, /omfg to history when their argument is non-empty, so blank invocations rejected by the controller are not persisted.
- Add regression coverage for addToHistory behavior on /btw, /tan, /omfg, /memory, /rename, and /move.
- Routed the /model TUI slash command back to the full model setup picker.
- Kept /switch on the temporary session model selector and updated slash-command coverage.
Fixes#2933
Recorded args-bearing /plan and /goal commands in TUI history regardless of whether the mode was already active, so the typed slash command can be recalled after first entry.
Fixes#2887
- Routed the TUI /model command through the temporary session model selector used by /switch and Alt+P.
- Added slash-command coverage for /model opening the session selector.
Fixes#2846
- Added explicit request-debug path helpers in `packages/ai/src/utils/request-debug.ts` for one-shot dumps.
- Added `/debug dump-next-request`, `/debug dump-request`, and `/debug next-request` subcommands to arm next-request dumps.
- Changed `debug` handling in `packages/coding-agent/src/slash-commands/builtin-registry.ts` to execute args instead of always opening selector.
- Fixed explicit request-debug mode to resolve `~`/relative paths and create parent directories before logging.
- Fixed one-shot request-debug mode to consume its target after one call and overwrite existing response logs.
- Centralized catalog and registry handling on `ModelSpec` and `buildModel`, resolving compatibility at model build time.
- Removed runtime compatibility detectors and switched provider request flows to direct `model.compat` reads.
- Added compat fields (`supportsReasoningParams`, `alwaysSendMaxTokens`, `strictResponsesPairing`, `whenThinking`).
- Persisted explicit compatibility overrides through `compatConfig` in discovery and cache merge paths.
- Added `/tan` slash command registration and interactive handling.
- Added TanCommandController validation and async task scheduling for `/tan` dispatch.
- Added session cloning that suppresses breadcrumbs, copies artifacts, and handles abort cleanup.
- Added `promptCacheKey` support in Agent and inherited `providerPromptCacheKey` in session creation.
- Removed the built-in `background` (`bg`) slash command and its `handleBackgroundCommand` path from the interactive flow.
- Deleted background event subscription and shutdown handling by removing `handleBackgroundEvent` from the event, input, and interactive controllers.
- Simplified `InteractiveModeContext` by dropping background-only fields and helpers such as `isBackgrounded`, background UI context creation, and background event callbacks.
- Added `AgentSession.freshSession()` to rotate provider-facing IDs and prune provider stream state.
- Added `/fresh` command handling in the builtin registry and mode command flow.
- Kept persisted session metadata intact during `/fresh` and cleared transient IDs on session switches.
- Invalidated `appendOnlyContext` and provider caches when refreshing provider state.
- Dropped `summarizeShakeRegions`, the shake-summary prompt, and related types.
- Removed `shake-summary` compaction strategy and `providers.shakeSummaryModel` setting.
- Migrated existing `shake-summary` configs to plain `shake` on load.
- Simplified `/shake` to `elide` and `images` modes only.
- Added `/omfg <complaint>` command integration from slash registry to mode context and input handling.
- Added OMFG panel and controller for live draft streaming, up to three retries, and confirmed save flow.
- Added strict OMFG rule extraction and validation with JSON parsing, alias checks, and history-based repair.
- Fixed auto-thinking restore to preserve resolved effort instead of reverting to pending auto sessions.
- Added setup wizard with provider login, glyph mode, and theme scenes shown once per setup version.
- Wired `omp setup` (no args) to trigger the wizard in a TTY; `--check`/`--json` still show help.
- Extracted `gradientEscape` and exported `PI_LOGO`/`ShineConfig` from welcome for shared use in splash/outro.
- Fixed race condition in `setSymbolPreset`/`setColorBlindMode` by tracking load request IDs.