- Persist signed message blocks (`text`, `thinking`, `toolCall`) and encrypted reasoning payloads verbatim during session serialization instead of clearing or truncating them.
- Preserve signature keys instead of replacing them with empty strings when they exceed persistence size limits.
- Exempt official first-party OpenAI and Anthropic API endpoints from the leaked-thinking stream healing wrapper to prevent misfires on legitimate visible text fences.
- Bumped the collaborative protocol version (`COLLAB_PROTO`) from 2 to 3.
- Required protocol-3 to coordinate `ui-request`, `ui-request-end`, and `ui-response` frames.
- Rejected older protocol-2 guests at handshake to prevent host-asked requests from hanging.
- Updated verification tests and CI installation check scripts to expect protocol version 3.
The host used to ship the entire transcript inside a single welcome
frame, so a multi-MB session spent the guest's 30s first-welcome
timeout on the relay transfer itself: ~1.3 MB took ~3s, ~4.2 MB took
~12s, and ~13.6 MB never arrived before the guest gave up with
'timed out waiting for the host's welcome'.
Bump COLLAB_PROTO to 2 and split the welcome:
- welcome carries metadata only (header, state, agents, entryCount,
readOnly) and lands in well under one second.
- a train of snapshot-chunk frames (SNAPSHOT_CHUNK_BYTES = 512 KB,
oversize entries ship alone) carries the transcript. Last chunk
flips final: true; an empty snapshot still emits one final chunk.
- the host queues welcome + chunks synchronously inside #handleHello,
preserving the host comment's ordering invariant (later broadcast
frames cannot interleave between them).
- the TUI guest accumulates chunks under a SNAPSHOT_PROGRESS_TIMEOUT_MS
that resets per chunk; only after final does it write the replica
jsonl, switchSession, and render. The first-welcome timeout still
guards arrival of the small welcome.
- the collab-web GuestClient streams entries into the snapshot as
chunks arrive and flips phase to 'live' on final.
Includes a contract test (in-process relay) asserting the welcome is
metadata-only, the chunk train fans the 1.5 MB synthetic transcript
across multiple frames with only the last marked final, and the
flattened entries match the source snapshot.
Fixes#3144
- Added --recover CLI option to rebuild changelog fixes from tagged history.
- Pruned Unreleased bullets that match historical released items across all tags.
- Normalized output by sorting release sections by version and compacting bullet spacing.
- Replaced unknown model contextWindow/maxTokens sentinels with nullable values across types and catalog data.
- Mapped request token calculations to treat null maxTokens as unlimited output caps.
- Updated remote compaction and context checks to ignore unknown limits by using Infinity/0 fallbacks.
- Adjusted CLI/model registry flows to skip cap enforcement for null limits and render unknown values as '-'.
- Changed `DEFAULT_RELAY_URL` in `@oh-my-pi/pi-wire` from `wss://relay.omp.sh` to `wss://my.omp.sh` and updated the constants, collab-link, and join-command tests asserting the old origin.
- Added `DEFAULT_SHARE_URL` (`https://my.omp.sh/s`) to pi-wire with its changelog entry; it shares a changed run with the relay constant and is consumed by the upcoming /share work.
- Updated collab-web canonical/OG/twitter URLs in `index.html`, `robots.txt`, `sitemap.xml`, README, and the `local-relay.ts` doc comment to the new domain.
- Refreshed the `/collab` entry in the coding-agent changelog to reference the new relay origin.
- Added write-token generation and validation to distinguish writable and read-only guests.
- Added deep-link support using `https://<relay>/#<link>` with 32/48-byte collab secrets.
- Added full-link and key-only semantics where full links grant writes and key-only links are view-only.
- Added /collab view/status/stop command updates with read-only participant status and join hints.