- Added unified isolation primitives (BackendKind, ProbeResult, IsoError) and resolve fallback selection logic.
- Added Diff, FileChange, and ChangeKind with default_diff choosing git mode or filesystem walk based on repository state.
- Added APFS/btrfs/zfs/reflink/overlayfs/projfs/rcopy/block-clone backends with platform-aware start, stop, and probe.
- Mapped backend operations to canonicalized paths, recursive clone helpers, rollback cleanup, and unavailable error mapping.
- Added unified native exports isoBackend/isoProbe/isoResolve/isoStart/isoStop/isoDiff and removed projfsOverlay APIs.
- Replaced task isolation resolver flow with ensureIsolation/cleanupIsolation and migrated mode handling to auto plus legacy-mode aliases.
- Replaced Python execution with a local `python -u runner.py` subprocess and NDJSON stdin/stdout framing.
- Removed shared-gateway architecture, including coordinator lifecycle APIs, `useSharedGateway` wiring, and `jupyter` CLI/actions.
- Simplified setup checks to a plain Python 3 availability probe and removed automatic dependency-install fallbacks.
- Updated kernel cancellation and display processing to use status frames, SIGINT/SIGTERM escalation, and normalized output coercion.
- Added `python-runner` integration and display tests while deleting legacy websocket and kernel lifecycle test suites.
External plugins, extensions, and downstream wrappers (notably the upstream
`@mariozechner/pi-coding-agent` AgentSession routed through the legacy-pi-compat
shim) call `modelRegistry.hasConfiguredAuth(model)` before launching a subagent
to short-circuit when no API key is configured. Our `ModelRegistry` did not
expose that method, so the direct agent-launch path threw
`this._modelRegistry.hasConfiguredAuth is not a function` and exited with 0
tokens, 0 tool uses, ~100ms runtime — well before any model conversation began.
The `task` tool path bypassed the preflight and worked, masking the missing
API.
Add a thin `hasConfiguredAuth(model)` wrapper that returns true for keyless
providers and providers with stored auth, matching upstream semantics. Add a
focused regression test asserting the method exists and distinguishes
configured vs. unconfigured providers.
Fixes#993.
The 30 second default for 'ask.timeout' silently auto-selects the
recommended option mid-deliberation, which surprises users who are
weighing options the agent flagged as having materially different
tradeoffs. The setting was meant to be opt-in: 0 already means
'wait indefinitely' and plan mode already forces the timer off.
Flip the default to 0 so a fresh install matches the documented
'wait until the user replies' behavior, and update the AskTool
prompt so the model expects unlimited reply time by default. Users
who liked the auto-select can still set a positive timeout from
the Interaction settings tab.
Add a regression test asserting the dialog timeout is not passed
to the underlying selector when 'ask.timeout' is unset.
- Added explicit prompt markers and wrappers across system templates, including `[env]`, `[role]`, `[coop]`, `[closure]`, and `[now]`.
- Removed `renderTemplate` and `sectionSeparator` flows, deleted `task/template.ts`, and switched to per-task `renderSubagentUserPrompt` rendering.
- Updated system prompt assembly to `shortenPath`-normalize `cwd`, append rendered now metadata, and preserve trailing `[now]` blocks.
- Removed legacy template tests and added prompt-composition tests for ordered `[contract]`->`[project]`->`[now]` blocks and context-only system placement.
- Reworked shared prompt utilities by collapsing consecutive blank lines and removing obsolete `OPENING_HBS`/`LIST_ITEM` helper behavior.
- Added macOS power assertion settings for idle, system, user, and display with schema defaults.
- Added idle, system, and user options to MacOSPowerAssertionOptions in TS typings and Rust, preserving display.
- Changed agent-session power flow to use begin/end/reset in-flight helpers and avoid manual counter updates.
- Updated power assertions to combine multiple kinds per native handle and support safe repeated-stop behavior.
- Updated unreleased changelog notes to document the breaking behavior and canceled-prompt unblock correction.
Reporter screenshot showed a parent session on DeepSeek V4 Pro dispatching
a task subagent that resolved to `qwen3.6-plus-free` — an opencode-zen
model the user had no working credentials for. The dispatch hit a
provider that could not serve the model and surfaced a confusing API
rejection instead of using the parent's already-authenticated model.
Adds `resolveModelOverrideWithAuthFallback`, an auth-aware wrapper
around `resolveModelOverride` that checks the resolved subagent model's
credentials via `modelRegistry.getApiKey` + `isAuthenticated` and
falls back to the parent session's active model pattern when the
primary has no working auth. The parent's active model is plumbed
through `ExecutorOptions.parentActiveModelPattern` from `TaskTool`
into `runSubprocess`. If neither has working auth (or they resolve to
the same model), the primary resolution is preserved so the existing
error path still surfaces a meaningful failure downstream.
Fixes#985
- Model resolver: provider-prefixed `<provider>/<id>` selectors are now
strict. If the provider is known and the exact pair does not resolve,
return undefined instead of silently crossing provider boundaries
(e.g. routing `anthropic/claude-3-7-sonnet` to amazon-bedrock when
the user only has Anthropic auth). Unqualified resolution is unchanged.
- Compaction: when the current model's provider has no credentials,
manual compaction now retries across compaction model candidates and
falls back to an authenticated role; if no usable fallback exists, it
throws a clear provider-specific pre-stream error instead of bubbling
a 503 `auth_unavailable` from the provider stream.
Fixes#986Fixes#980
- Added `./hashline` package exports and redirected callers to the new hashline entrypoint.
- Moved hashline logic out of `edit/` to `src/hashline` and removed `edit/modes/hashline`/`edit/line-hash` paths.
- Added hashline parsers, anchors, types, and diff helpers with stricter input and mismatch validation.
- Implemented preflight and cache-recovery execution flows to reapply edits and handle stale anchor mismatches.
- Documented the hashline API relocation as breaking changes in `CHANGELOG.md`.
Add an explicit openai-models-list discovery type for custom providers while keeping lm-studio as a compatible alias. Custom providers can now point baseUrl at an OpenAI-compatible /v1 endpoint, provide an api key, and auto-populate models via GET {baseUrl}/models.
Discovered models merge cleanly with user-defined models from models.yml/models.json, so YAML entries still win for display name and token limits. The provider picker now explains when discovery succeeds but returns zero models, and when the configured /models endpoint responds with 404.
Fixes#970
- Added `.ipynb` detection and editable-cell conversion utilities, including merge/serialize helpers in `edit/notebook`.
- Rerouted hashline, patch, and replace edit flows, plus read/write paths, through notebook-aware helpers before persistence.
- Removed the dedicated `notebook` tool, its schema flags, renderer, and built-in registration/settings checks.
- Updated notebook read behavior, docs, and tests so `.ipynb` reads return editable `# %%` cells and edits reserialize to JSON.
Added two settings:
- tools.discoveryMode ("off" | "mcp-only" | "all", default "off")
- tools.essentialOverride (string[], default empty)
Converted BUILTIN_TOOLS from Record<string, ToolFactory> to
Record<string, BuiltinEntry> with a per-tool loadMode ("essential"
or "discoverable") and an optional summary used as the BM25 corpus
entry when discovery hides the tool.
Marked read, bash, edit as essential. Marked the remaining 24 built-in
tools as discoverable with hand-written summaries. search_tool_bm25
stays essential (always loaded when discovery is on; gated separately
by isToolAllowed).
Added DEFAULT_ESSENTIAL_TOOL_NAMES, computeEssentialBuiltinNames
(reads tools.essentialOverride with a default fallback), and
getBuiltinDiscoverableEntries (used by the search tool to build the
BM25 corpus).
mcp.discoveryMode is preserved as a back-compat alias for "mcp-only".
- Added a new `read.summarize.prose` setting to control markdown and plain-text read summaries.
- Updated the read tool to skip summarization for prose files unless that setting is enabled.
- Added coverage for default and enabled markdown read-summary behavior.
- Added a new `edit.hashlineAutoDropPureInsertDuplicates` boolean setting with default `false` for hashline edits.
- Threaded the setting through tool execution contexts so hashline previews and execution honor the configured option.
- Changed pure-insert duplicate boundary absorption to run only when enabled and added tests for default-disabled and enabled behavior.
- Updated read schema, path utilities, and dispatch to parse selectors from :raw/:L suffixes on path, removing standalone sel usage.
- Changed truncation/error notices to continue with :<nextOffset> and :1 guidance for read and sqlite pagination.
- Added summarizeCode support with tree-sitter summaries, read.summarize settings, and N-API Summary types/exports.
- Added tests and docs updates for path-embedded selectors, summary behavior, and explicit raw/offset SQL/read cases.
- Added mental-model settings and config defaults for enablement, auto-seed, refresh interval, and render budget.
- Added built-in mental-model seeds and scope-aware rendering with `<mental_models>` extraction, truncation, and tag handling.
- Added `/memory mm` aliases and handlers for list, show, refresh, history, seed, reload, and delete commands.
- Added client APIs and bootstrap/cache wiring so snippets refresh and inject into prompts on startup.
- Added tests covering seed scope behavior, rendering caps, diffs, and backend/session reload behavior.
- Added inline hashline parse and apply support for `<` prepend and `+` append operations with prefix+suffix edits.
- Added fail-fast behavior to reject inline modify ops combined with delete or replace on same line.
- Renamed HASHLINE_* and mode symbols to HL_* in prompt tooling, read/search checks, and prompt templates.
- Standardized separators to `PI_HL_SEP`/`HL_EDIT_SEP` and fixed `HL_BODY_SEP='|'`, updating parser formatting behavior.
- Updated benchmark subtype constants and python cleanup test setup to use HL_* values and AgentRegistry mock failure injection.
- Added configurable hashline separator support via `PI_HASHLINE_SEP` with `|` fallback.
- Replaced hardcoded `|` payload markers with `{{hsep}}`/`$HSEP$` in prompts, grammar, and parsing.
- Updated payload parsing to strip shared separator prefixes while preserving whitespace-only prefixes.
- Replaced `resolveLarkLidPlaceholders` with `resolveHashlineGrammarPlaceholders` and added a compatibility alias.
- Removed settings UI entries for `display.tabWidth`, `stt.language`, and similar values lacking valid `ui.options`.
- Refactored `pathToSettingDef()` in `settings-defs.ts` to derive submenu options directly from schema metadata.
- Introduced `SubmenuOption`/`AnyUiMetadata` in `settings-schema.ts` and added `options: "runtime"` support for dynamic lists.
- Added `hindsight.scoping` and `HINDSIGHT_SCOPING` with global, per-project, and per-project-tagged modes.
- Migrated legacy `raw.hindsight` handling to scoping-based behavior and removed deprecated `dynamicBankId`/`agentName` keys.
- Replaced `deriveBankId` with `computeBankScope`, returning `bankId` plus optional retain/recall tags by mode.
- Forwarded scoped tags through memory ops so recall and retain/reflect calls use `tags`, `tagsMatch`, and `recallTags`.
- Validated `scoping` values from env/settings, warning and defaulting to `per-project-tagged` when invalid.
- Updated runtime memory config loading and backend resolution so `memory.backend === "local"` now enables the local pipeline directly, while `memories.enabled` is treated only as a legacy migration input.
- Switched the `memory.backend` default to `off` and kept `memories.enabled` hidden from the Memory tab UI for migration compatibility.
- Adjusted memory runtime, resolver, and documentation/tests to match the new backend-selection semantics.
- Added `memory.backend` and `hindsight.*` settings schema with migration from `memories.enabled` legacy mode.
- Added Hindsight memory backend runtime modules for resolved config, client creation, bank ID derivation, and state lifecycle.
- Added off/local/hindsight backends and resolver wiring across SDK, commands, and compaction context.
- Added `hindsight_recall`, `hindsight_reflect`, and `hindsight_retain` tools with schema validation and backend gating.
- Added Memory tab metadata and symbols to expose backend selection in the settings UI.
- Added package export barrels and tests for bank ID, content formatting, and hindsight config env precedence.
- Added an isSettingsInitialized helper to expose whether global settings were created.
- Updated interactive mode to use the session name when settings are not yet initialized.
- Guarded the status-line accent lookup behind settings initialization to avoid premature access.
- Added a new boolean statusLine.sessionAccent setting to settings schema and propagated it through status-line preview, controller, and component setting updates.
- Updated status line rendering and interactive border coloring to disable session-based accent colors when the setting is false.
- Added a regression test verifying the status-line gap uses theme border color instead of session accent when session accents are disabled.
Fixes#918
- Added a cached provider/model index with a WeakMap for resolver calls.
- Indexed each provider and model key to either a model entry or an ambiguity sentinel.
- Updated exact and fallback OpenRouter lookups to use map-based resolution and return undefined on ambiguous matches.
- Tracked `models.json` modification time in the registry to skip redundant static model reloads when unchanged.
- Reworked model overlay merges and package-runner detection to use indexed lookups plus parallel file/JSON scans instead of sequential searches.
- Cached compiled prompt templates and reduced startup work by bypassing up-to-date changelog parsing and deferring background model refresh.
- Updated AGENTS.md discovery to use glob search honoring .gitignore, depth limits, and deduped results.
- Updated eval tool flow so Python preflight runs only when needed and exec now maps to eval when available.
- Deferred canonical model-index rebuilds during refresh/rebuildProvider and replayed pending rebuilds after resume.
- Added memoized model-equivalence resolution with trailing-marker and canonical reference caches.
- Optimized frontmatter key normalization to keep unchanged keys/arrays/objects without extra cloning.
- Updated JS executor tests to use base-path concatenation for nested fixture filesystem calls.
- Added a unified eval framework with parser grammar, backend interfaces, and JS/Python execution result types.
- Added eval tool docs and updated prompts for fenced cells, `eval.py`/`eval.js`, and fallback behavior.
- Replaced the built-in `python` tool with `eval` across registry, rendering, interactive modes, and tool settings.
- Migrated Python execution runtime from `src/ipy` to `src/eval/py`, renamed state fields, and removed legacy introspection.
- Refactored browser tooling from in-process VM helpers to worker-managed tab supervisors and protocol transport.
- Added eval parser fallback and JS tool-bridge tests, updated imports, and removed obsolete python-mode suites.
- Documented and removed `utils/oauth` from the `ai` package entrypoint, noting it as a breaking change.
- Refactored `cli`, `auth-storage`, and `utils/oauth` to load provider modules via scoped dynamic `import()` calls.
- Removed top-level provider imports and barrel exports from `utils/oauth/index.ts`, streamlining oauth module loading.
- Consolidated OAuth symbol, type, and provider imports in coding-agent and tests to `@oh-my-pi/pi-ai/utils/oauth` modules.
- Defined `DEFAULT_LOCAL_TOKEN` locally in model-registry and removed its cross-package OAuth import usage.
Exposes model.compat.disableStrictTools (already supported by the anthropic
transport since #826) via models.yml so users can configure it without code
changes.
Set disableStrictTools: true at the provider level to disable strict tool
schemas for third-party Anthropic-compatible endpoints (AWS Bedrock, Vertex
AI proxies, custom gateways) that reject the strict field.
- Add disableStrictTools to ProviderConfigSchema
- Merge { disableStrictTools: true } into provider compat override when set,
flowing through the existing compat pipeline to model.compat.disableStrictTools
- disableStrictTools alone is sufficient for an override-only provider entry
- Update docs/models.md with field reference, Bedrock example, and proxy note
- Add tests covering provider-level propagation, built-in override, and
overlay merge
Commit a190397d8 made `Model.compat` resolve to `OpenAICompat | AnthropicCompat`
under the default `TApi = any`. The widened union broke every site that treated
`compat` as openai-shaped: model-registry deep-merge, openai-completions resolved
compat, and ~20 test fixtures. This restores the assumption locally instead of
papering over it with casts.
- getBundledModel is now generic on TApi so test fixtures that spread it into
`Model<"openai-completions">` get the narrow compat back.
- mergeCompat is generic over TBase/TOverride; the schema-driven model-registry
override path keeps its OpenAICompat-shaped merge fields, anthropic overrides
pass through untouched.
- OpenAICompatSchema gains the openai-only fields it was missing
(requiresMistralToolIds, reasoningContentField, requiresReasoningContent*,
thinkingFormat, requiresThinkingAsText, disableReasoningOnForcedToolChoice).
- resolveOpenAICompat fills in disableReasoningOnForcedToolChoice so the
Required<OpenAICompat> shape stays satisfied.
- Anthropic tool-result block id assignment uses the proper unknown double-cast.
- isForcedToolChoice accepts unknown so it can read `params.tool_choice` whose
type comes from the OpenAI SDK ChatCompletionToolChoiceOption (now wider than
our local OpenAICompletionsToolChoice).
- Test fixtures and Required<OpenAICompat> literals updated for the field set.
Fixes CI red on main.
Add optional defaultLevel to ThinkingConfig schema/type so models.yml can
declare a preferred starting thinking level per model. On model switch
the agent session adopts model.thinking.defaultLevel when present (with
explicit caller-supplied level still winning); otherwise current behavior
is preserved. SDK initial selection prefers the model's defaultLevel
before falling back to the global defaultThinkingLevel setting.
Fixes#775
- Updated the tool configuration key and labels from runCommand to recipe, including its settings UI schema.
- Renamed the run_command tool implementation, prompts, and test wiring to recipe and updated tool registry and renderer registrations.
- Adjusted auto-included tool behavior and availability checks to use the recipe name and recipe.enabled setting.
- Renamed legacy `just` tool/config wiring to `run_command` and `runCommand.enabled`, replacing the old `just` prompt.
- Added `RunCommandTool` plus prompt and renderer registration so clients use the new `run_command` API.
- Implemented `op`-based runner/task resolution with new runner metadata for Just, Package, Cargo, Make, and Task with error handling.
- Refactored Bash shell rendering helpers and added run-command tests for detection and execution routing behavior.
- Added an `isOAuth` model flag and passed it through Anthropic stream calls to force OAuth-shaped request options.
- Extended model-registry config handling with an `auth: oauth` mode and default `isOAuth` resolution for `anthropic-messages` providers while allowing explicit `apiKey` auth to remain unset.
- Added tests covering OAuth defaults and opt-outs for Anthropic and non-Anthropic custom providers.
- Added a new `loop.mode` enum setting and UI option entries for prompt, compact, and reset behaviors.
- Updated interactive mode's loop auto-submit flow to execute selected compact or reset actions before re-submitting the prompt.
- Registered a new `just.enabled` setting in the tools settings schema.
- Added loop-mode command handling in interactive mode, including enable/disable toggling, repeated auto-submission scheduling, and Escape-based cancellation.
- Propagated loop mode state to the status line via a renamed `mode` segment that now renders plan or loop status, and updated presets/theme assets for the new loop icon.
- Migrated persisted status-line segment usage from `plan_mode` to `mode` in configuration defaults and normalization so legacy settings continue to load.
- Added compact Lark grammar processing and applied it to OpenAI custom-format tools before conversion.
- Reworked atom mode into `---PATH` compact commands with new grammar, parser, and rm/mv file operations.
- Updated `hline`/`href`/`hrefr` helper behavior and hashline mismatch guidance using shared anchor state.
- Standardized path formatting with `formatPathRelativeToCwd` across LSP, prompts, and edit/search/write tools.
- Added benchmark run-path handling, including `.gitignore` runs mapping, absolute reports, and safer snapshot output.
- Added tests for compact grammar payloads, atom parsing/execution, renderer streaming, and path-list outputs.