- Fixed bash interceptor to check both raw and cwd-normalized commands, catching commands hidden behind leading `cd ... &&` wrappers.
- Fixed LSP client shutdown to await graceful shutdown with a 5s timeout before killing the process, and parallelized `shutdownAll` via `Promise.allSettled`.
- Fixed concurrent bash command tracking by replacing a single abort controller with a Set, preventing premature cancellation of parallel commands.
- Removed `./hooks` and `./hooks/*` export entries from the coding-agent package exports map.
- Updated pinned Rust nightly toolchain from `nightly-2026-03-27` to `nightly-2026-04-29` in `rust-toolchain.toml` and CI workflow.
- Replaced custom already-published detection in `ci-release-publish.ts` with `bun publish --tolerate-republish` flag.
- Renamed legacy `just` tool/config wiring to `run_command` and `runCommand.enabled`, replacing the old `just` prompt.
- Added `RunCommandTool` plus prompt and renderer registration so clients use the new `run_command` API.
- Implemented `op`-based runner/task resolution with new runner metadata for Just, Package, Cargo, Make, and Task with error handling.
- Refactored Bash shell rendering helpers and added run-command tests for detection and execution routing behavior.
- Renamed the built-in `grep` content-search tool to `search` across settings, schemas, and SDK exports.
- Switched execution wiring so `Task`, `Plan`, cursor, and shell mapping now invoke `search` instead of `grep`.
- Updated prompts, plan-mode docs, and example tool lists to replace `grep`/`ls` references with `search` guidance.
- Aligned `Grep*`/`grep` event, renderer, and hook types to `Search*`/`search` across runtime and tests.
- Documented and fixed `search` result rendering budget behavior and added internal-URL/path-list transcript notes.
- Added a unified `job` prompt and removed `poll` and `cancel-job` prompts, documenting merged async actions.
- Renamed `PollTool` to `JobTool` and replaced `poll`/`cancel_job` tool exports with a unified `job` tool.
- Expanded `JobTool` schema to accept `poll` and `cancel` IDs, adding cancel-first execution for cancel-only requests.
- Consolidated poll/cancel rendering in `renderJob`, mapping `await`, `poll`, and `cancel_job` keys to the unified job renderer with action badges.
- Updated bash/task prompts and tests to use `job` for polling and cancellation flows, including JobTool auto-background checks.
- Added `examples` support to `StringEnum` schemas and propagated it to tool metadata.
- Added concise descriptions and example values across coding-agent tool schemas for clearer guidance.
- Documented the new StringEnum examples capability in `packages/ai/CHANGELOG.md`.
- Cast `real` to `HASHLINE_BIGRAMS` elements in `staleBigramFor` test setup.
- Added command-marker metadata and lifecycle in process execution, including completion markers and exit-code writes.
- Refactored minimization to support `MarkedCommands` mode, token-based detection, and marker-aware stripping.
- Added `onMinimizedSave` and `saveBashOriginalArtifact` to persist full bash-original output artifacts.
- Expanded public exports and marker hooks so external command launch metadata can be controlled by consumers.
- Added AST-based minimizer planning with brush-parser to classify commands before minimization.
- Added original text capture and byte-metric `minimized` telemetry to shell execution results.
- Added minimizer configuration controls, including trust-gated loading via `settingsHash` and limits.
- Added `onMinimizedSave` callback wiring to persist minimized outputs and annotate Bash sinks with artifact IDs.
When a bash tool call requests a timeout outside the allowed 1-3600s
range, the effective clamped value and the originally requested value
are now emitted as a notice appended to the tool output and exposed on
BashToolDetails via requestedTimeoutSeconds. The renderer shows the
clamped+requested pair inline in the timeout badge.
- Standardized missing-file read errors and now return `File not found: <path>` for absent edit targets.
- Centralized AI provider, usage, and OAuth helpers into shared modules to remove duplicated logic.
- Migrated OAuth/API-key login flows to shared factory helpers and removed inline prompt/token-exchange code.
- Reused shared tools and formatter utilities for discovery, stream tails, LSP batching, and source formatting.
- Consolidated repeated test helpers and fixtures into shared modules, replacing inline helper duplicates.
On Linux, Node's path.normalize() collapses the double slash in
local://PLAN.md to local:/PLAN.md, creating a directory called local:
in the project root instead of routing through the local:// protocol handler.
Defense-in-depth fixes across 5 layers:
1. resolveToCwd() now throws if a path starts with any internal URL
scheme prefix (local:, agent:, skill:, etc.), preventing all 59
call sites from treating URIs as relative filesystem paths.
2. resolvePlanPath() now matches on local: prefix (not just local://)
and normalizes local:/ to local:// before resolution, catching
all slash variants.
3. Bash URL expansion regex and early-exit checks now also match
local:/ (single slash), and normalize before resolution.
4. Edit preview/diff functions now gracefully skip internal URL paths
instead of crashing via the resolveToCwd guard.
5. All startsWith('local://') checks updated to startsWith('local:')
with normalization in agent-session, interactive-mode, and
approved-plan modules.
Also adds local: to .gitignore to prevent accidental commits of the
leaked directory.
- Replaced deprecated `await` tool wiring with `poll` in tool exports and built-in tool registry.
- Updated bash and task prompts plus start-result messaging to direct users to the `poll` tool.
- Added effective timeout metadata to Bash tool results and rendered output to show that effective timeout.
- Implemented bounded auto-background wait logic that backgrounds jobs when the timeout window is exhausted.
- Added bash.autoBackground.enabled and bash.autoBackground.thresholdMs settings with defaults for background job behavior.
- Added auto-backgrounding support for long foreground bash commands with managed job state and timeout threshold.
- Updated bash prompts, job-protocol messages, and tool activation checks to use async and auto-background support.
- Added background bash completion integration with AsyncJobManager and end-to-end tests for short/long auto-background scenarios.
- Added bounds clamping to prologue and epilogue byte calculations to prevent out-of-range boundary violations.
- Extended chunk boundaries for indent-based languages when epilogue exceeds calculated range with trailing newline.
- Added comprehensive test coverage for Python chunk editing operations including body/head replacement and indentation preservation.
- Extracted working directory formatting logic into reusable utility function and applied tab sanitization to bash command previews.
- Extracted prompt rendering and formatting utilities from coding-agent to centralized pi-utils package with new API surface (prompt.render, prompt.format, prompt.registerHelper).
- Migrated parseFrontmatter utility from coding-agent to pi-utils package; updated 8 files to import from @oh-my-pi/pi-utils.
- Removed 170-line prompt-format.ts module and consolidated 192 lines of Handlebars helper registrations into pi-utils prompt module.
- Updated 60+ files across coding-agent and typescript-edit-benchmark to use new prompt.render() and prompt.format() API from pi-utils.
- Simplified prompt-templates.ts by delegating core functionality to pi-utils while retaining custom helper registrations (jtdToTypeScript, jsonStringify, etc.).
- Extracted OAuth identifier logic into public functions extractOAuthCredentialIdentifiers and extractOAuthTokenIdentifiers.
- Replaced single credentialIdentity string with multi-identifier resolveCredentialIdentifiers returning string[] for flexible matching.
- Changed credential deduplication from email-based to accountId-based matching in replaceAuthCredentialsForProvider.
- Updated auth-storage tests to verify accountId-prioritized deduplication behavior across soft-disable and hard-delete scenarios.
- Added documentation comments in coding-agent modules explaining partial JSON preservation for streaming tool previews.
- Documented streaming tool preview requirements and render paths in AGENTS.md.
- Added `env` parameter to bash tool for safe environment variable passing without shell re-parsing.
- Added support for rendering partial environment variable assignments in command preview during streaming.
- Updated bash tool prompt to recommend `env` parameter for multiline, quote-heavy, and untrusted values.
- Refactored tool execution component to conditionally merge partial JSON arguments during streaming.
- Added helper functions for environment variable normalization, escaping, and formatting.
- Added auto-inclusion of ast_grep and ast_edit tools when their text-based counterparts are enabled.
- Made AST tool recommendations conditional in bash tool prompt based on session availability.
- Replaced timeout-based cancellation with AbortSignal-based cancellation in ask tool.
- Added auto-correction of escaped tab indentation in edits via PI_HASHLINE_AUTOCORRECT_ESCAPED_TABS environment variable.
- Added warning detection for suspicious Unicode escape placeholder in edit content.
- Added `tools.maxTimeout` setting to enforce global timeout ceiling across all tool calls.
- Centralized per-tool timeout constants and clamping logic into `tool-timeouts.ts` module.
- Extracted `clampTimeout()` function to standardize timeout enforcement across bash, python, browser, ssh, and fetch tools.
The non-interactive environment variables (pager, editor, and prompt
suppression) were only applied in the PTY (interactive) bash path.
The non-PTY executeBash path had no such defaults, so commands could
block on pagers or credential prompts.
- Extract NO_PAGER_ENV from bash-interactive.ts into shared
non-interactive-env.ts module (renamed to NON_INTERACTIVE_ENV)
- Apply it in executeBash (non-PTY) with user overrides taking
precedence
- Fix ordering in interactive PTY path so user env overrides
the defaults (was reversed)
- Add test verifying defaults are applied alongside user env
- Consolidated @oh-my-pi/pi-utils subpath imports into single package root import across 100+ files.
- Moved tryParseJson utility from local web scrapers module to @oh-my-pi/pi-utils package for centralized JSON parsing.
- Renamed loadSkillsFromDir to scanSkillsFromDir and refactored skill discovery to use fs.promises.readdir instead of glob-based approach.
- Replaced custom parseJSON with tryParseJson across discovery modules for consistent error handling.
- Removed emitCustomToolSessionEvent method and cleanupSshResources function, consolidating shutdown logic into dispose method.
- Updated glob pattern construction to use GlobBuilder with literal_separator(true) for improved path handling.
- Standardized XML tag naming from snake_case to kebab-case across 50+ prompt files for consistency.
- Replaced imperative language with RFC 2119 keywords (MUST/SHOULD/MAY/MUST NOT) throughout system and tool prompts for clarity.
- Removed artifactsDir parameter from Python executor and simplified environment variable handling to use PI_SESSION_FILE only.
- Renamed read_path.md to read-path.md and updated memory guidance with hierarchy rules and conflict resolution workflow.
- Added noEscape option to bash URL expansion and extracted cwd parameter from leading cd commands for improved path handling.
- Exported NO_PAGER_ENV constant from bash-interactive module for centralized environment variable management.
- Added per-command `pty` parameter to bash tool for fine-grained PTY mode control.
- Removed global `bash.virtualTerminal` setting in favor of per-command PTY parameter.
- Fixed potential deadlock in shell session cleanup by replacing blocking lock with non-blocking try_lock.
- Updated async session key generation to include jobId for improved session isolation.
- Added poll_jobs tool for blocking until background jobs complete without manual polling loops.
- Added task.maxConcurrency setting to limit concurrent subagent task execution with semaphore-based control.
- Enhanced task progress tracking to report per-task status with individual timing and token metrics.
- Improved parallel task execution to schedule multiple background jobs independently for true concurrent execution.
- Updated bash and task tool documentation to recommend poll_jobs instead of polling read jobs:// in loops.
- Added async background job execution for bash and task tools with configurable concurrency limits and automatic result delivery.
- Added cancel_job tool and /jobs slash command to manage and inspect running background jobs with status display.
- Added jobs:// internal protocol handler for querying job status and retrieving job execution details.
- Added async.enabled and async.maxJobs settings to control background job execution behavior.
- Enhanced status line to display count of running background jobs with visual indicator.
- Implemented AsyncJobManager with exponential backoff retry delivery, job lifecycle tracking, and automatic eviction.
Fixes#56.
- Moved artifact management from ToolSession to SessionManager for centralized lifecycle control and caching.
- Replaced getArtifactManager() with allocateOutputArtifact() async method in ToolSession interface for simplified artifact allocation.
- Updated bash, fetch, python, and ssh tools to call session.allocateOutputArtifact() directly with optional chaining fallback.
- Fixed Lobsters scraper to handle user fields as strings instead of nested objects in API responses.
- Extracted credential storage to shared @oh-my-pi/pi-ai package with AuthCredentialStore and AuthStorage classes.
- Consolidated UI formatting logic from ToolUIKit class into standalone utility functions across render-utils and output-meta modules.
- Moved utility functions (parseCommandArgs, substituteArgs, expandPath, normalizeUnicode) to dedicated modules for improved code reuse.
- Extracted JTD type definitions and type guards to jtd-utils module for shared use across schema conversion tools.
- Updated Claude model pricing and added cache read costs in models.json for accurate billing calculations.
- Refactored agent-storage to delegate credential management to AuthCredentialStore instead of direct SQLite operations.
- Consolidated truncation and output utilities from tools/truncate.ts and tools/output-utils.ts into session/streaming-output.ts with improved UTF-8 boundary handling.
- Renamed formatSize() to formatBytes() across codebase for consistency and clarity in byte-level formatting.
- Refactored OutputSink to use windowed byte truncation instead of full-buffer encoding, improving memory efficiency on large outputs.
- Migrated from Buffer to Uint8Array in web scrapers for better cross-platform compatibility and native browser support.
- Added getArtifactManager() lazy-initialization method to ToolSession for deferred artifact manager instantiation.
- Simplified API surface with wildcard exports from tools and session modules, reducing import complexity.
- Fixed persistent shell session state not being reset after command abort or hard timeout.
- Fixed hard timeout handling to properly interrupt long-running commands exceeding grace period.
- Introduced hard timeout mechanism with Promise.race() to enforce absolute timeout limit and prevent command hangs.
- Replaced shell command execution with explicit timeout and SIGKILL signal handling in shell-snapshot.
- Simplified bash command normalization to use only explicit head/tail parameters from tool input.
- Exported getAntigravityUserAgent() function for centralized User-Agent header construction.
- Replaced all direct `process.cwd()` calls with `getProjectDir()` utility function across 40+ files to centralize project directory resolution logic.
- Added `getProjectDir()` and `setProjectDir()` functions to `@oh-my-pi/pi-utils/dirs` module to provide abstracted project directory management.
- Made `SessionManager.list()` method asynchronous to support asynchronous session discovery operations.
- Updated default working directory resolution throughout codebase to use `getProjectDir()` instead of `process.cwd()` for improved project directory detection.
- Added PTY (pseudo-terminal) backed interactive command execution with streaming output support via PtySession class in pi-natives.
- Added PtyStartOptions and PtyRunResult types to configure and report PTY session execution status.
- Added write(), resize(), and kill() methods to PtySession for interactive control of running commands.
- Added interactive bash execution via PTY with real-time terminal rendering and input forwarding in bash-interactive tool.
- Added --no-pty CLI flag and PI_NO_PTY environment variable to disable PTY-based interactive bash execution.
- Added bash.virtualTerminal setting to control PTY-backed interactive execution behavior.
- Changed hashline display format separator from pipe to two spaces for improved readability.
- Removed `lines` and `hashes` parameters from read tool in favor of automatic file display mode resolution.
- Added `resolveFileDisplayMode` utility to centralize file display mode configuration logic.
- Integrated file display mode settings into grep and read tools for consistent output formatting.
- Consolidated tool parameter types to use schema-derived types via Typebox `Static` utility.
- Updated parseLineRef to handle both legacy pipe-separator and new two-space hashline formats.
- Added abort event listener registration in bash executor to properly handle abort signals and clean up resources in finally block.
- Improved bash tool error handling to distinguish between user-initiated aborts via AbortSignal and other cancellations, throwing ToolAbortError for aborted requests.
- Wrapped bash executor command execution in try-finally block to ensure abort event listeners are properly removed after execution completes.
- Migrated console.error() calls to structured logger.warn() and logger.error() throughout codebase.
- Updated os.tmpdir() import style in browser tool from destructured to namespace import.
- Fixed tab character display in error messages and bash tool output by applying replaceTabs() sanitization.
- Added TUI rendering sanitization documentation to AGENTS.md with guidelines for sanitizing text in tool renderers.
- Applied replaceTabs() function to error text in patch shared module to ensure proper tab-to-space conversion.
- Applied replaceTabs() function to bash tool output lines in both expanded and collapsed display modes.
- Implemented caching for tool output block rendering to avoid redundant computations on re-renders.
- Enhanced read tool grouping to prevent coalescing across narrative boundaries (text/thinking blocks between tool calls).
- Improved string preview formatting to detect multi-line strings and display line counts with ellipsis indicators.
- Refactored tool execution component to use reactive render state tracking for better state management.
- Enhanced error handling in tool renderers with logging for failures.
- Fixed truncation indicator to use ellipsis character instead of verbose suffix.
- Converted class properties to TypeScript parameter properties across 51 files to reduce boilerplate code.
- Removed explicit field declarations and manual assignments in constructors by using TypeScript's parameter property syntax with access modifiers.
- Applied consistent pattern of declaring private readonly and public readonly properties directly in constructor parameters.
- Added exclusive concurrency mode enforcement to file-modifying tools (edit, write, bash, python, ssh, todo-write) by introducing a new public `concurrency` property set to "exclusive" on each tool class.
- Updated CHANGELOG.md to document the enforcement of exclusive concurrency mode for file-modifying tools.
- Cleaned up imports in tool-execution.ts by removing unused Theme type import and reordering imports for better organization.
- Consolidated directory listing functionality from dedicated `ls` tool into the `read` tool.
- Removed the `ls` tool and all related exports, types, and configurations from the public API.
- Updated `read` tool to return formatted directory listings with modification times instead of redirecting to `ls` tool.
- Removed `bashInterceptor.simpleLs` setting and related interception logic from bash tool.
- Removed `ls.enabled` setting and related tool registration logic.
- Removed test cases for the `ls` tool and updated tool type definitions to remove `LsToolResultEvent`.