- Added T co-signal requirement for tool_arg surface so legitimate edits carrying the marker are never hard-aborted.
- Extended detectHarmonyLeakInAssistantMessage with optional toolArgParseEnd resolver; agent loop omits it, keeping tool_arg inert.
- Updated tests to inject a boundary-at-0 helper for corpus cases and added T-gate unit tests.
- Converted existing local paths to Windows paths via `wslpath -w` before opening.
- Used `wslview` directly in WSL environments, bypassing `xdg-open`'s broken file-handler translation.
- Fell back to `xdg-open` for URLs or when `wslview` is unavailable.
- Added unit tests covering WSL file, URL, and fallback scenarios.
Replace the sunset V0 Search API with V1 (POST /api/v1/search) under the
existing `kagi` provider id instead of shipping a parallel `kagi-v1`
provider. Credentials still resolve through the shared AuthStorage broker
(Bearer token, KAGI_API_KEY, /login kagi), and recency now maps to a
UTC-deterministic filters.after date.
- Merge V1 client into src/web/kagi.ts (categorized result buckets, direct
answer, related/adjacent questions)
- Keep classifyProviderHttpError mapping for auth/quota signals
- Drop the kagi-v1 entries from the provider registry, order, type union,
and settings schema
- Consolidate tests into web-search-kagi.test.ts
- Added `review_pr` task that checks out PR head in a detached worktree, classifies rank/type/area, and posts a batched GitHub review as `event=COMMENT`.
- Added four new host tools: `fetch_pr`, `classify_pr`, `pr_review_comment`, and `submit_pr_review`; review tools self-gate on `review_mode`, push/open-PR tools refuse when `review_mode` is set.
- Added sqlite staging table `pr_review_comments` with `stage_review_comment`, `list_staged_review_comments`, and `clear_staged_review_comments` DAOs.
- Routed `pull_request.opened/reopened/ready_for_review` to `review_pr` and extended `pull_request.closed` cleanup to any tracked PR regardless of author.
- Added `terminalHasEagerEraseScrollbackRisk` to detect WezTerm, kitty, ghostty, and alacritty on POSIX, where xterm ED3 (`CSI 3 J`) can snap scrolled-up readers back to the tail during streaming.
- Kept direct user-input and checkpoint rebuilds unaffected by the deferral.
- Added regression tests covering the deferred and non-deferred paths (issue #1682).
omp resolves the update target by querying https://registry.npmjs.org/ directly, but `bun install -g pkg@<version>` would then consult bun's on-disk manifest snapshot AND honour the user's npm-mirror configuration (corporate proxy, Taobao, …). Either source can lag the upstream registry by minutes-to-hours, in which case bun rejects the version with `No version matching "X" found for specifier "@oh-my-pi/pi-coding-agent" (but package exists)` even though the registry omp just queried is serving it.
The bun install step now runs with both `--no-cache` (skip the manifest snapshot) and `--registry=https://registry.npmjs.org/` (pin the official catalog regardless of bunfig/.npmrc) so the install observes the same registry state the version check used. The registry URL is centralised in an `NPM_REGISTRY` constant shared by `getLatestRelease` and `buildBunInstallArgs`.
Fixes#1686
- Changed `AgentOutputManager` to use requested names verbatim, adding `-2`/`-3` suffixes only on repeats (e.g. `Anna`, `Anna-2`).
- Renamed main agent id from `0-Main` to `Main`; nested ids now use dot notation without numeric prefix (e.g. `Parent.Child`).
- Updated task widget to render dotted hierarchy as `Parent>Child` breadcrumb without leading index.
- Resume scan now tracks seen names instead of a counter to avoid clobbering prior outputs.
- Removed the `concurrency` argument from `parallel()` and `pipeline()` in both JS and Python runtimes.
- Added `__concurrency__` bridge to resolve the pool ceiling live from `task.maxConcurrency` (default 32; 0 = unbounded).
- Eval fan-outs now run as wide as a `task` tool batch instead of being capped at 16.
- Encouraged staging helpers, datasets, and clients once, then fanning out subagents that call them directly.
- Clarified that re-importing, re-fetching, or serializing across the task boundary is unnecessary.
- Updated the role contract to allow direct trivial edits while reserving substantial work for subagents.
- Reinforced that parallel work must be fanned out broadly and that one-off task dispatches are disallowed.
- Clarified that subagents make edits only, while the orchestrator runs verification for changed files.
- Tracked the latest in-flight preview diff recompute in ToolExecutionComponent and exposed it through a new whenPreviewSettled method.
- Updated component paths that trigger preview recomputation to retain the returned promise instead of fire-and-forget calls.
- Updated the streaming preview height test to await settled diff recomputation before assertions, eliminating requestRender race-based flakes.
- Added `Settings.reloadForCwd` to mutate the live instance in place, so `/move` and cross-project resume pick up the destination project's `.claude/settings.yml` and path-scoped `enabledModels`/`disabledProviders`.
- Wired `reloadForCwd` into `applyCwdChange` (interactive mode) and the `--resume` startup path so settings always follow the active working directory.
- Added tests covering path-scoped re-resolution, no-op on same directory, and disk-backed project layer load/drop.
- Enabled resume picker to preload sessions and toggle folder/all scope with Tab.
- Enabled resume flow to fall back to all-project sessions and switch cwd on resume.
- Added centralized applyCwdChange to refresh caches, commands, and UI after cwd updates.
- Updated session restoration to adopt restored session cwd and sessionDir when present.
- Added ROW_COUNT_PROBE_CAP to limit rows scanned when counting tables, preventing JS thread freezes on large databases.
- Used sqlite_stat1 estimates for tables exceeding the cap; exact counts only for provably small tables.
- Introduced TableRowCount type with exact/estimate/atLeast variants reflected in rendered output.
- Fixed `session_id` never being created or populated; every history row had `NULL` for session.
- Added schema migration (`ALTER TABLE history ADD COLUMN session_id`) for pre-existing databases.
- Wired interactive mode to call `setSessionResolver(...)` so prompts are stamped with the active session at submission time.
- Re-enabled session ranking in `--resume` and in-session pickers via `matchingSessionIds()`, merging fuzzy and prompt-history signals.
- Added guidance that generated skills/rules/tool inventory live in prompt block 0.
- Documented APPEND_SYSTEM.md as the supported way to customize while preserving automatic skill discovery.
- Noted that SYSTEM.md users must hard-code skill instructions if they replace block 0.
Fixes#1671
- Updated hex color validation to accept only 3-, 6-, and 8-digit forms as swatchable.
- Adjusted strict prose filtering to gate only 3-digit values without hex letters.
- Added a regression test confirming 4-digit #TAG snapshot tags do not render swatches in prose or code spans.
- Computed screenshot destination extensions from the MIME type of bytes being written.
- Updated auto-generated paths in screenshot and temp directories to use the matching extension.
tp- keys scoped to the CN cluster were rejected during login because
validateXiaomiApiKey only tried SGP and AMS. The runtime model-discovery
path (xiaomiModelManagerOptions) already included CN, so the two code
paths were out of sync.
Add token-plan-cn.xiaomimimo.com as the third fallback endpoint so
login validation tries SGP → AMS → CN, matching model discovery.
- Removed the (walk-up) annotation on project SYSTEM.md lookup.
- Documented that findConfigFile only checks <cwd>/.omp etc., not ancestors.
- Clarified that the capability-layer walk-up exists but its output is never rendered by the default template under normal CLI startup.
Fixes#1671
- Documented that CLI SYSTEM.md replaces only prompt block 0 and keeps defaultPrompt.slice(1).
- Clarified append prompt ordering with and without a custom system prompt.
- Corrected deduplication wording to distinguish CLI block replacement from internal buildSystemPrompt dedupe.
Fixes#1671
- Added docs/system-prompt-customization.md covering precedence,
replace-vs-append semantics, the verbatim insertion rule for
template syntax, deduplication, and discovery behavior across
the primary findConfigFile path and the capability layer.
- Linked the new doc from docs/config-usage.md so the existing
SYSTEM.md reference points at the full contract.
Fixes#1671
Separated the fork prompt result into accepted, declined, and unavailable states.
Interactive declines now return cleanly through runRootCommand, while non-TTY
invocations continue to fail with a diagnostic instead of silently exiting 0.
Updated regression coverage for both branches.
Fixes#1668
createSessionManager threw `Session "X" is in another project (Y).` when
the user answered "n" to the fork prompt, and runRootCommand never caught
it. The throw bubbled up as an Uncaught Exception with a stack trace.
Return undefined from the decline branch instead, and treat
`typeof parsed.resume === "string" && !sessionManager` in runRootCommand
as a user cancellation: print a dimmed "Resume cancelled" message and
return cleanly (exit 0), mirroring how the picker UI handles
"No session selected".
Fixes#1668
Used the leading/trailing maxima directly and skipped repair when their sum covers the whole payload, so multi-line boundary echoes can no longer trim explicit replacement content.
Added regression coverage for the A,B,old,C,D → A,B,C,D scenario.