- Introduce OverlayPanel and PanelDivider classes to standardize rounded-box inline overlays and section rules.
- Migrate various UI dialog, selector, and panel components to inherit from OverlayPanel instead of Container.
- Remove manual DynamicBorder elements and custom title/header components across migrated components.
- Update test helpers and assertions to match the new overlay panel structure and rendering methods.
- Added shared process data collection and table formatting helpers to support rendering.
- Added an interactive alt-screen TUI monitor for bare `omp ps` executions on TTYs.
- Added a `--plain` flag to force static process listing output.
- Added a new ps command to list, inspect, view logs, and control daemon processes.
- Implemented CLI handlers and help metadata supporting daemon process operations.
- Added helpers for managing daemon scope metadata, paths, and live broker PIDs.
- Added Tool.coerceArguments (default true); false skips every LLM-quirk
repair pass (object->string stringification, unrecognized-key deletion,
JSON-string parsing) so validation runs verbatim.
- YieldTool opts out: its args are the deliverable, and the repair layer
silently stringified object payloads into string-typed schema fields
while bypassing yield's own validate-and-retry loop.
- Losslessly salvaged weak-caller envelopes observed in session traces:
type:"result" without the result wrapper finalizes as last-turn,
top-level data/error are wrapped, and JSON-string result/data parse
before consuming a schema retry.
- Introduce CleanseBoardModel and clean up status board rendering logic.
- Decouple CLI and interactive modes with CleanseRunUi interface and core runner.
- Add CleansePanelComponent and controller to manage interactive cleanse overlay.
- Register builtin `/cleanse` slash command and integrate into interactive mode.
- Added compaction.asyncEnabled (Async Compaction, default on): when
context enters the pre-threshold band [threshold - lead, threshold)
with lead = clamp(threshold * 0.125, 8192, 32000), maintenance
speculatively summarizes in the background off a branch snapshot
(first configured LLM-backed method: remote, handoff, or soft) using
a side session id isolated from the live turn. Crossing the threshold
splices the armed result in instantly instead of blocking on a
summarization round-trip. Armed results are invalidated by branch
changes, reset boundaries, model switches that strand provider-native
replay payloads, and context growth past keepRecentTokens (which
re-speculates); extensions registering session_before_compact keep
exact blocking semantics (speculation disabled).
- Reworked handoff to commit in place: /handoff and the auto handoff
method now write the generated document as a regular compaction entry
on the current session (summary = document + <files> tag, cut from
prepareCompaction) instead of starting a new session. SessionHandoff
shrank to a document generator; session_before_switch/session_switch
no longer fire with reason "handoff"; mid-turn maintenance no longer
suppresses the handoff preference; overflow recovery can apply an
armed handoff result.
- Extracted the shared auto-compaction commit tail
(#commitAutoCompactionResult / #commitCompactionEntry) used by the
blocking production path, the armed speculative apply, manual
compaction, and manual handoff.
- Status line pulses the auto-compact icon while a speculation runs and
holds it in accent once a result is armed.
- Exported remotePreserveReusable from pi-agent-core/compaction for
apply-time validation of speculative remote results.
- Implement a live status board utility for transient multi-line CLI status displays with TTY fallback support.
- Add progress callback support and forward subagent progress events to runner hooks.
- Update cleanse execution flow to track checker runs, agent progress, and status rendering.
- Add comprehensive unit tests for live board repainting and cleanse progress assertions.
- Implemented an animated collapse effect for the interactive mode todo header bar when tasks settle.
- Added timer management and render loop updates for the todo bar collapse transition.
- Replaced legacy `compaction.strategy` and `remoteEnabled` settings with `compaction.methodOrder` across session maintenance, schema, and tests.
- Added automatic fallback mechanism to try subsequent compaction methods upon failure or unsupported model capabilities.
- Added mouse drag-and-drop reordering support and click handlers to multi-select settings submenus.
- Updated documentation and test suites to reflect ordered compaction strategy preferences and fallback chains.
- Added long-context pricing tiers and billing policies for subscription Codex models in the catalog.
- Introduced the `extendedContext` configuration setting to control premium long-context windows.
- Implemented runtime policy refresh and model re-binding when context settings change.
- Added comprehensive unit tests for pricing tiers, context capping, and policy toggling behavior.
Addresses a broad audit of built-in shell utilities against their real counterparts: timeout gains signal delivery, -s/-k/--preserve-status/--foreground/-v, and GNU exit codes; diff defaults to normal format and gains -w/-b/-B/-i/-c/-x/-L/-s/--strip-trailing-cr and proper -r gating; find fixes -newerXY timestamp comparison direction, anchors -regex to whole paths, and gains BSD -perm +mode, -type lists, -size T/P suffixes, -E/-x/-s flags; date gains BSD -r epoch, -v adjustments, -j -f strptime, and non-greedy -I; tail/head accept obsolete -N/+N at any position with any file count; rg resolves case flags by last occurrence and gains --path-separator and clean -0 output; stat prints integer epochs for %X/%Y/%Z and gains BSD -s/-x/-t; cksum is registered as a builtin; truncate implements -o/--io-blocks and b/= size suffixes; sleep/timeout accept infinity; yes/errno/kill accept hyphen-prefixed operands; nohup -- cmd no longer runs --; which gains BSD -s.
- Replaced the stage-position counter in the todo HUD header with a summed progress bar counting closed and total tasks across all stages.
- Added a trailing overflow summary row to announce hidden stages past the collapsed cap.
- Introduced theme symbol support for filled and empty progress bar glyphs across unicode, nerd, and ascii presets.
- Replaced the `ctok` implementation with the `utok` universal tokenizer supporting multiple model families and UTF text encodings.
- Added tokenizer support and embedding data for Qwen3, DeepSeek V3, Kimi K2, and GLM-5 model variants.
- Added fixture generation scripts, vocabulary packers, and golden test suites for validating tokenization parity.
- Updated dependency requirements and Bazel workspace definitions for new crates and tools.
- Add `setPromptDropped` hook and `DroppedPrompt` type to return prompts that were cancelled during turn setup before dispatch.
- Restore dropped prompt text and image attachments to the interactive mode editor and remove the optimistic transcript row.
- Implemented the `ctok` Rust native tokenization engine with offline support for Claude V3, V47, V5, and V5Sonnet families.
- Replaced global token estimation with model-scoped `Tokenizer` instances and provider-anchored transcript accounting across packages.
- Added vocabulary generation scripts, test fixtures, and comprehensive unit tests for tokenizer routing and matching modes.
- Replace newline characters with visual indicators in subagent HUD descriptions and task previews.
- Add unit tests verifying multiline description and task rendering.
- Added `qwenTemplateReasoningEffort` model compatibility option to disable Qwen chat template kwargs for strict local servers.
- Implemented fallback handling to strip rejected `chat_template_kwargs.reasoning_effort` and hoist values to top-level fields.
- Added comprehensive test coverage for Qwen reasoning effort fallback and keyword rejections.
- Add support for risk notes and warning markers on setting items in the TUI settings list component.
- Update the external thinking setting schema and help command to include a warning about provider abuse enforcement.
The ask-card note renderer (#8786) grew tool-views.generated.js by 126 bytes; CI regenerates the asset so the byte-pinned template contract (bytes/chars/sha256) moved. Values verified identical between CI and a fresh local gen:tool-views.
`resolveCliArgv` hoisted a subcommand hidden behind leading global launch
flags to the front and forwarded those flags to the subcommand's own
parser (#2970). Launch-shaped commands (`launch`/`acp`) share the launch
flag surface, but strict-parsing subcommands like `update` declare only
their own flags, so a leading `--cwd` reached `node:util.parseArgs` and
threw `Unknown option '--cwd'`. This bit users whose shell alias/wrapper
runs `omp --cwd <dir> update`.
Leading launch-global flags are now stripped when the hoisted subcommand
is not launch-shaped, and still forwarded for `launch`/`acp`. Shared the
launch-command set with the profile bootstrap to keep one source of truth.
Fixes#8891
parseFileDiffs split the captured `git diff --cached --binary` on
"
diff --git ", consuming the newline that terminates each file block, and
patch.join ended with `.replace(/\n+$/, "")`. Both dropped the blank line
that terminates a `GIT binary patch` block, so rebuilding a split-commit
patch produced a corrupt binary patch rejected by `git apply --binary`.
Split on a line-start lookahead so blocks keep their terminators verbatim,
and concatenate join parts without stripping trailing newlines. Both
trailing and mid-diff binary blocks now round-trip byte-exact.
Fixes#8899
`/mcp reauth <name>` probed the server with `{ oauth: false }` and treated a
successful unauthenticated `initialize` as proof that OAuth was unnecessary,
hard-erroring with "Server connection succeeded without OAuth; reauthorization
is not required." Per the MCP spec a server may allow unauthenticated
`initialize` while requiring a bearer token for `tools/call`, so this left no
way to acquire a credential for such servers.
When the handshake succeeds without an in-band tool challenge, fall back to
`discoverOAuthEndpoints(config.url)` and proceed with the flow if the server
advertises OAuth metadata; only refuse when no OAuth endpoint is discoverable.
Fixes#8922
Unanchored regex mapped BCP-47 script subtags to bogus regions
(lang:zh-hans -> location=HA) and prefix-matched 3+ letter codes
(lang:eng -> language=en). Require a subtag boundary, matching the
Perplexity provider's parsing.
The Roles panel renderer looped from the first row with a hard height cap and no scroll offset, so roles and model-keyed fallback chains past the visible height were never drawn and unreachable by keyboard, with no truncation indicator. Unlike the sibling provider list (model-browser windows via #windowStart/#ensureSelectedVisible), the Roles panel had no equivalent.
Window #renderRolesView around #roleIndex via #ensureRoleVisible, offset mouse hit-testing by the scroll start bounded to the visible count, and draw an up/down '+N more' hint when the list is clipped.
Fixes#8817
ExtensionRunner.emitAfterProviderResponse accepted the response model but
discarded it, calling createContext() with no model. Response-scoped hooks
therefore saw the primary session model in ctx.model and ctx.models.current()
even when the response came from a cross-provider side request, so an extension
that revokes a credential on an HTTP 402 could target the wrong provider.
Call createContext(model) to match emitBeforeProviderRequest, plus a regression
test asserting both fields expose the response model.
Fixes#8955
The shared query pipeline parses a lang:/language: directive into StructuredQuery.lang, which sibling providers (DuckDuckGo, Perplexity, SearXNG) map onto their native locale params. The TinyFish provider dropped parsed.lang entirely, so every request fell back to the API's US/English default and non-US locales were silently lost.
Map parsed.lang onto TinyFish location (ISO 3166-1 alpha-2) and language (ISO 639-1): lang:it-it yields location=IT&language=it, lang:it yields language=it only. Behaviour is unchanged when no locale directive is present.
Fixes#8913
Remote OAuth MCP servers dropped out of /mcp under `omp auth-broker
serve` once their access token expired: neither the client nor the
broker could complete the refresh.
- Client: the MCP manager threw on the broker-redacted refresh sentinel
(REMOTE_REFRESH_SENTINEL) instead of asking the broker to refresh. It
now routes redacted MCP refreshes through
AuthStorage.forceRefreshCredentialById, which calls back to the broker
(the real refresh token never leaves the broker host).
- Broker: the serve process had no mcp_oauth:* refresh path, so
POST /v1/credential/:id/refresh answered "Unknown OAuth provider". Its
AuthStorage is now built with a refreshOAuthCredential override that
refreshes MCP credentials with a generic refresh_token grant from the
credential's embedded token endpoint and client id. The background
refresher keeps MCP tokens live through the same path.
Extract shared refreshManagedMcpOAuthCredential and
mcpOAuthServerUrlFromCredentialId helpers so both paths use identical
refresh material selection and RFC 8707 fallback-resource logic.
Fixes#8933
InputController.#invokeSkillCommand cleared the draft and awaited the full
promptCustomMessage dispatch with no transcript render. AgentSession.#promptWithMessage
runs awaited preflight (memory recall, before_agent_start hooks, auto-thinking
classification, pre-prompt compaction) before the message reaches the agent, so a slow
step such as a Hindsight auto-recall timeout left the composer cleared with no pending
row, unlike a normal prompt's optimistic row from startPendingSubmission.
Idle skill submissions now paint an optimistic skill row before the awaited dispatch;
the canonical message_start reconciles it in place via EventController instead of
appending a duplicate. Streaming submissions still queue and show their chip.
Fixes#8895
getContextBreakdown used message position (anchorIndex >= pending.cutoffCount) as a proxy for usage freshness. After a mid-run compaction rebased the in-flight snapshot, an in-flight provider response whose request predated the compaction landed past the rebase cutoff carrying pre-compaction usage, so it out-ranked the rebased estimate and reported the pre-compaction token count (~2.6x the real one). That phantom overflow tripped the "freed too little context to make progress" guard and drove the frame-rescue path on a byte-identical tokensBefore.
Assistant context snapshots now carry a monotonic compaction epoch, bumped in rebaseAfterCompaction and stamped at message-record time. A post-cutoff anchor whose epoch predates the pending snapshot's epoch is no longer trusted over the rebased estimate.
Fixes#8887
Split-commit captured the staged diff with `git diff --cached --binary`,
whose stdout is hard-capped at GIT_COMMAND_OUTPUT_LIMIT_BYTES (8 MiB) by
readCappedText. A single large binary (base85-encoded inline) crossed the
cap; the capture was truncated silently, so files sorting after the binary
were absent from the parsed diff and stage.hunks threw a misleading
`No diff found for <path>` naming an innocent file.
Surface truncation as GitCommandResult.truncated, add a requireComplete
diff option that throws the new GitOutputTruncatedError instead of
returning a silently truncated diff, and have runSplitCommit request a
complete diff and abort with a clear message pointing at the real cause.
Fixes#8897
TUI.render merged live-region seams with a topmost-seam-wins rule that
adopted only that seam's pin policy for the whole frame. While the primary
turn streams, the transcript reports the topmost, unpinned seam, so the
frame-wide pin flag becomes false and a pinned AnchoredLiveContainer below
it (the /btw panel, the working HUD) loses its pinning: once its content
grows past the viewport, the emit path commits the scrolled-off rows as
frozen snapshots on every growth frame, piling duplicates into native
scrollback.
Track a pinnedBoundary (start row of the topmost pinned region)
independently of which seam wins the topmost merge, and cap every commit
ceiling at it. Equivalent to the prior behavior for a fully-pinned frame
and for a frame with no pinned region; only the mixed case changes.
Fixes#8793
bash.patterns only feeds the bash tool's approval decision. The eval
tool declares the exec tier and can spawn a shell via subprocess, so a
deny rule there does nothing for the same command run through eval;
under yolo the exec call resolves to allow. Note the scope and point at
tools.approval.eval as the lever that closes the path in
bash-tool-runtime.md, approval-mode.md, and settings.md.
Fixes#8838
Both subagent revivers rebuilt the session but never wired the extension
runtime, leaving it pre-init where every action method throws
ExtensionRuntimeNotInitializedError. An extension with a tool_call handler
touching a runtime action then tripped the fail-closed gate in emitToolCall
and blocked every tool, including the hidden yield, so the revived agent
could neither finish nor exit and looped until killed.
Both the warm lifecycle reviver (executor.ts) and the cold persisted
reviver (persisted-revive.ts) now call the shared initializeExtensions
helper on the rebuilt session, restoring runtime actions, onError, and the
session_start event.
Fixes#8824