- Fix typo "stauts" → "status" in stream.test.ts comment
- Update frontmatter.ts link to packages/utils/src/ (moved from coding-agent)
- Update notebook.ts link to src/edit/ (moved from src/tools/)
- Mark removed bash-normalize.ts in docs and update description
- Add CHANGELOG.md for swarm-extension and utils packages
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
- Classified usage-limit gateway responses as `429 rate_limit_error` in auth handling paths.
- Aligned auth-gateway and pi-native key retrieval with derived `sessionId` for `getApiKey` lookups.
- Handled usage-limit auth failures by rotating credentials with retry hints and returning undefined when none available.
- Replaced stream auth checks with retryable-upstream logic for 401 and usage-limit errors before content.
- Expanded `extractRetryHint` parsing for `~`, `sec`, `ms`, and minute/hour units.
- Added coverage for classifyGatewayError, retry-hint parsing variants, and stream-auth retry edge cases.
- Imported isPromise from node:util/types in four modules.
- Replaced four instanceof Promise checks with isPromise calls for more reliable promise detection.
- Clamped `formatDuration` to return `0ms` for non-positive, NaN, or infinite inputs.
- Updated usage report rendering to suppress reset countdowns when `resetsAt` is absent or no longer in the future.
- Added unit tests for `formatDuration` covering clamped values and standard duration formatting.
- Added a custom JSON replacer that unwraps `Error` instances in logger output, preserving name, message, stack, cause, and enumerable fields.
- Updated uncaught-exception and unhandled-rejection logging paths to pass only `{ err }`, relying on the logger serializer for full error details.
- Extended transient socket-close matching to detect HTTP2 stream reset/refused/calm errors and added regression tests for logger error serialization behavior.
- Restructured the auth-broker `openSnapshotStream` tests to be top-level cases under the describe suite.
- Added a stream parser test asserting pure ": keepalive" lines are not included in subsequent SSE event raw output.
- AuthBrokerClient now checked the response Content-Type and rejected non-SSE responses before parsing.
- It required the first parsed SSE event to be a snapshot and treated ended or truncated streams as errors.
- Added coverage for non-SSE and missing-initial-snapshot streams, and reset raw SSE state for empty events.
The Bun.env scrub and filterProcessEnv used isValidEnvName (strict shell
identifier shape), which deleted standard Windows variables like
ProgramFiles(x86) and CommonProgramFiles(x86). procmgr.ts imports this
module before resolving the shell and reads Bun.env['ProgramFiles(x86)']
to find Git Bash under 32-bit Program Files, so installations that only
had Git there were no longer discovered and failed with 'No bash shell
found'.
The unsafe cases for native execve are '=' or NUL in names and NUL in
values, not parentheses. Introduce isSafeEnvName covering exactly those
cases and use it for the in-place Bun.env scrub and the spawn-env
filter. Keep isValidEnvName (strict) for dotenv parsing, where strict
shell-identifier shape is the right contract.
- Buffered `start` events until after the first replay-unsafe event and replayed them on auth failure.
- Retried stream requests with refreshed credentials when `onAuthError` returned a new key for gateway and pi-native.
- Added 401 error-status parsing for assistant errors and updated stream-auth tests for start+401 retry behavior.
- Added `AuthRetryFailure` helpers and status extraction types to propagate auth-retry metadata through stream attempts.
- Added a new `setTransports` logger API to swap console and file winston transports at runtime.
- Refactored logger transport creation to lazily build rotating file logs via a shared directory helper.
- Updated auth-broker serve startup/shutdown to use structured logger output and switch to console-only logs for its headless runtime.
- Added `AuthBrokerClient`, `RemoteAuthCredentialStore`, `AuthBrokerRefresher`, and `startAuthBroker` server in `packages/ai/src/auth-broker`.
- Renamed `AuthCredentialStore` class to `SqliteAuthCredentialStore`; extracted `AuthCredentialStore` as a persistence interface.
- Added `exportSnapshot`, `forceRefreshCredentialById`, `disableCredentialById`, and `upsertCredential` to `AuthStorage` for broker wire protocol.
- Added `omp auth-broker` CLI subcommand (serve, token, login, logout, import, status) and `discoverAuthStorage` broker-mode path keyed on `OMP_AUTH_BROKER_URL`.
- Added declaration-only compiler options to multiple package publish tsconfig files.
- Standardized publish include/exclude settings to emit types from src into dist/types.
- Added manifest rewrite helpers to remap type paths from ./src to ./dist/types/*.d.ts.
- Updated publish flow to append dist/types/extra files and skip publish build/rewrite for native packages.
- Unified line-ending normalization to `replace(/\r\n?/g, "\\n")` in editor, scraper, benchmark, and utils modules.
- Added terminal-aware line sanitization in code-cell rendering to collapse inline carriage returns and avoid overwrite corruption.
- Tightened editor and paste sanitizers to trim control characters consistently after CR normalization.
- Updated plan-mode and hindsight session state lookups to use Array.findLast for selecting the latest assistant or user message.
- Updated postmortem callback iteration to use Array.toReversed before mapping cleanup callbacks.