- Raised probe-spawning logger tests to 30s timeouts; bun's 5s default
SIGTERMed probe children (exit 143) on shared-core CI runners, matching
the precedent documented in logger-contract.test.ts.
- Allowed clippy::unused_async_trait_impl on KillCommand::execute with an
unknown_lints guard for the pinned CI nightly that predates the lint.
Scoped test-runtime detection to explicit runner markers and Bun test entrypoints, so application NODE_ENV/BUN_ENV values no longer make ProcessTerminal headless.
Added subprocess regression coverage and propagated the private marker to test children.
Fixes#7261
These four paths bypassed DirResolver's XDG-aware rootSubdir/agentSubdir
hooks, resolving directly against getConfigRootDir()/getAgentDir() and
ignoring XDG state/data layout. Add XDG-aware path helpers in dirs.ts
and route all four through them:
- secret-placeholder.key → $XDG_STATE_HOME/omp/ (state, agent flattened)
- marketplaces.json → $XDG_DATA_HOME/omp/ (data)
- run/daemons/<hash>/ → $XDG_STATE_HOME/omp/run/ (state)
- run/provider-inflight/ → $XDG_STATE_HOME/omp/run/ (state)
omp config init-xdg migrates secret-placeholder.key and marketplaces.json
from their legacy locations; run/ is ephemeral and rebuilds on restart.
Settings.init opens agent.db/stats.db before setInteractiveHost ran, so
interactive hosts received the 1000ms headless busy timeout on those
databases (issue #2421 class). Declare the flag before settings load and
add [Unreleased] changelog entries per repo conventions.
Headless hosts (print/RPC/ACP/eval/SDK) run the agent loop on the same
thread as bun:sqlite, so a lock-contention busy-wait of the interactive
5s timeout freezes the protocol loop for seconds at a time with no
liveness signal. Use a 1s busy_timeout for session-critical databases
(agent.db, history.db, stats.db) when the host is not interactive, and
let the existing asynchronous open/retry paths recover from contention.
- Reformatted the logger burst test per biome (the type-check job gates on
check:tools, which failed on the previous hotfix's formatting).
- Raised the native/unit bucket's chunk watchdog to 1200 s: the mupdf PDF
extraction chunk runs ~7 min per attempt on burstable runners under a
full fan-out and the 600 s default SIGKILLed both tries in release run
30519992654; the watchdog targets wedged children, not slow chunks.
- The hosted disk-cache prune swept ~/.cache/omp-bazel-repo file-by-file;
extracted repository contents keep upstream-archive mtimes (months old),
so a restored archive lost most of rules_rust while bazel still trusted
the entry's recorded_inputs — both darwin release legs failed with
'BUILD file not found' in release run 30519253683. Prune only the
action disk cache, whose files carry bazel-written mtimes.
- Gave the logger burst-order contract an explicit 30 s budget: two probe
children measure ~4.4 s unloaded and bun's 5 s default test timeout
SIGTERMed them (exit 143) on shared-core runners.
Skipped stdout draining after ProcessTerminal observes a native Windows terminal disconnect, while preserving normal postmortem cleanup and drain behavior for every other shutdown path.
Fixes#6917
(cherry picked from commit b45fc00ab4b5075ccb9650584947dde061beea20)
Compiled Bun binaries autoload project dotenv files, so snapshotting Bun.env inside one captured the secrets as launcher-owned and forwarded them to every shell. Drop that branch and record launcher values, restoring an empty launcher value that Bun overwrote with a dotenv secret.
- filterChildShellEnv now also filters Bun-autoloaded .env.{NODE_ENV||development}
entries, closing the .env.production/.env.development leak into child shells.
- parseEnvLine skips backslash-escaped quotes when locating the closing
delimiter, restoring baseline/Bun-literal handling of values like JSON="{\"a\":1}"
that the new parser truncated.
- Adds a parseEnvFile regression test for escaped quotes.
- The 2s deadline returned the -999 kill sentinel when a cold bun spawn
transpiling the pi-utils module graph exceeded it on loaded parallel CI
runners; green runs still resolve on child exit, so the bound only
guards genuine hangs.
Handled export prefixes and quote-aware inline comments when parsing dotenv files, and filtered child shells by launcher provenance so injected values are dropped regardless of value formatting.
Covered export and inline-comment forms in unit and shell-filter tests.
Fixes#6813
Tracked project values loaded by OMP separately from names present in the original launch environment, preserving parent values even when dotenv repeats the same bytes.
Covered Bun-autoloaded and no-env-file launch modes.
Fixes#6813
Bun's `process.title` setter is a JS-level no-op: it stores the value
internally but never calls `prctl(PR_SET_NAME)`, so `omp` appeared as
`bun` in ps/pgrep/killall/top and `pkill bun` became a footgun killing
every Bun process. Add `setProcessName` in pi-utils that also drives
prctl via bun:ffi on Linux, and use it at CLI startup and in the daemon
broker.
Fixes#6815
Matched both raw OMP-loaded values and Bun-expanded project values when removing launch dotenv entries from child shell environments.
Covered Bun autoload and no-env-file execution modes.
Fixes#6813
Filtered launch-directory .env and .env.local values from the base shell environment while preserving explicit per-command overrides.
Expanded the shell environment regression test across both dotenv files.
Fixes#6813
- Recorded the scoop/no-bash startup fix (No bash shell found) in pi-utils
and pi-coding-agent 17.1.4 sections, which were finalized before the fix
commit landed on the release.
- Added resolveWindowsShell to locate Git Bash, scoop installs, and path binaries with a fallback to cmd.exe.
- Updated bash-executor to prevent wrapping user commands in cmd.exe when using fallback shell paths.
- Updated installation script to report optional shell status rather than failing when bash is absent.