Move the per-request date/cwd line out of the system prompt into a
first-turn system-reminder so open-weight providers keep their tool-schema
prefix cache; the reminder refreshes itself at midnight. Closes#7404.
Generated with Codebuff 🤖
Co-Authored-By: Codebuff <noreply@codebuff.com>
Detected npm and Bun ownership from the bin link immediate target within each precise global node_modules root. Foreign aliases now update their resolved standalone binary without replacing the alias.
Fixes#8468
formatReadHashlineHeader collapsed every relative in-workspace path to its
basename, so reading a nested file (e.g. src/settings.json) emitted
[settings.json#tag]. When a same-basename file existed at the session cwd,
a verbatim follow-up edit resolved against the cwd file; Patcher.prepare only
runs snapshot-tag path recovery when the authored path is missing, so the
valid edit was deterministically rejected with "hash is not from this
session". Keep the workspace-relative path, which names the file uniquely and
stays directly resolvable against cwd. Out-of-workspace absolute paths remain
shortened; root-level files are unchanged.
Fixes#8482
Resolved npm and bun bin-entry symlinks before selecting the update method, and preserved foreign aliases by replacing their standalone target.
Fixes#8468
Kept the Bun event loop live across subagent yield drains and delayed parent result flushes. Added a timer-lifecycle regression for the idle flush.
Fixes#8462
- The b279db1790 rewrite wrapped runner.emit() in vi.useFakeTimers() and
hand-advanced the clock, but the runner registers its cap setTimeout after
more microtask turns than the test advances (emit defers the timeout
machinery to the first matching handler and hops through Bun.sleep(0)),
so the cap timer never fires, emit never settles, and fake timers also
neutralize bun's per-test timeout — the singleton/global-state CI bucket
hung silently until the 600s watchdog SIGKILL (exit 137).
- Restored the pre-refactor real-time version: it has no sleeps or polling
loops, runs the hung handlers against a 100ms cap, and asserts bounded
wall-clock plus the per-extension timeout warnings.
- Verified the full 79-file singleton bucket passes (867 tests) and the
restored file passes on Linux bun 1.3.14 in Docker.
- Restored the original 17.3.1 status-line changelog bullet (released
sections stay immutable).
- Bun's inotify-backed fs.watch permanently stops delivering events after
observing git's atomic HEAD.lock -> HEAD rename in the watched directory
(oven-sh/bun#24875), so the directory-watch fix for issue #8412 still froze
the status-line branch on Linux after the first switch; CI caught it as a
30s timeout in status-line-vcs-refresh.test.ts.
- Added git.head.watch: fs.watchFile stat-poll of the HEAD path (reftable dir
for reftable repos) with a disposer; path-based polling survives inode swaps
on every platform.
- Status line and footer now consume the helper; the footer previously bound
fs.watch to the HEAD file inode and died after one switch on all platforms.
- Dropped the FSWatcher error-listener plumbing (StatWatcher has no error
mode) and reworked the watcher lifecycle tests to the stat-poll contract;
verified the atomic-rename regression test passes on Linux bun 1.3.14 in
Docker where it previously timed out.
The executable version probe added in ecb22957 ("validate Linux browser
executables") replaced the file-only check in resolveSystemChromium with
isChromiumExecutable, which spawns the candidate `--version` for every
platform. On Windows chrome.exe is a GUI-subsystem binary: `--version`
does not print to a detached stdout and can hand off to a running
instance, opening/activating the user's normal browser window, after
which the probe rejects the candidate and falls back to cached Chrome
for Testing.
Gate the spawn probe on process.platform === "linux" (its intended
platform, where non-Chromium PATH wrappers are the real risk) and trust
the executable-file check on Windows and macOS.
Fixes#8445
Two overlapping `omp update` runs shared the fixed `<binary>.new` temp
path. downloadVerifiedBinary unlinks the target before writing, so the
second run's unlink deleted the first run's still-downloading temp file;
the first kept writing to its open fd (size and digest still passed),
then chmod hit the missing path and aborted with ENOENT.
Give the temp path the same unique per-attempt suffix the backup path
already uses (pid, timestamp, and a new process-local counter that also
covers same-millisecond, same-process collisions). Generalize the stale
backup sweep to also reclaim orphaned `.new` temp files, age-gated by the
download window so a concurrent run's in-progress temp is never deleted.
Fixes#8434
Legacy Pi extensions build raw tool-parameter documents against real
TypeBox, whose Type.* builders return plain JSON-Schema objects. omptype's
builders return callable schema values instead, so a legacy document that
embeds them (Type.Unsafe({ anyOf: [Type.Array(...), Other] })) or spreads
them (Type.Unsafe({ ...Schema, description })) carries functions. The shim
then structured-cloned that document during plugin install validation and
threw "The object can not be cloned.", rejecting extensions that load fine
when linked (e.g. pi-subagents, all published versions).
Type.Unsafe now lowers embedded builders to their wire JSON and rebuilds
spread documents from the copied run self-reference before cloning or
serializing, matching the plain-object schemas real TypeBox produces.
Fixes#8420
Deferred --tools validation until extension discovery, then validated against built-in and registered tool names while preserving strict rejection of unknown names.
Fixes#8421
Expose the Pi-compatible tui, rpc, json, or print host mode to every extension context and cover mode transitions in the runner regression suite.
Fixes#8419
The status-line branch watcher bound fs.watch to the .git/HEAD file.
git updates HEAD via a lock file plus an atomic rename (HEAD.lock ->
HEAD), which unlinks the watched inode, so the watch fired for the
first branch switch and then died on the stale inode. The displayed
branch froze on the previous branch while later switches went unseen.
Watch the git directory instead of the HEAD file (and, for reftable
repos, the reftable dir as before) and filter directory events for the
HEAD entry. The directory inode is stable across renames, so the watch
survives every switch.
Fixes#8412
- Deduplicated the re-imported changelog bullets from the PR #8403 merge,
keeping the condensed register with only the new #8402 entry.
- getUserHomeCandidates memoizes the WSL home candidate keyed by
platform + WSL markers + USERPROFILE, so a wedged interop pipe costs
one bounded probe per process instead of one 500ms stall per
discovery loader, while env changes (tests, SDK embeddings) still
recompute.
- Displace overwritten destination into a temporary sibling directory during workspace renames.
- Restore the displaced file and clean up the temp directory if the main rename operation fails.
resolveWindowsUserProfile() ran Bun.spawnSync(cmd.exe echo %USERPROFILE%)
with no timeout during startup discovery. When the WSL->Windows interop
pipe is wedged, cmd.exe never returns and the synchronous spawn blocks
the JS thread forever, so the TUI never paints and no log is written.
Route both best-effort probes (cmd.exe and wslpath) through a shared
runHostProbe() helper that spawns under a 500ms hard timeout with SIGKILL
and reports a killed/non-zero exit as "host home unavailable", so
discovery falls back to the Linux $HOME/~/.omp candidates instead of
hanging.
Fixes#8402
- Replace the obsolete agent dashboard control center with a new fullscreen agents hub component.
- Integrate AI-assisted agent creation architect flow using model sessions.
- Provide interactive property strips and model browser integration for agent configuration.
- Update tests and documentation to support the redesigned agents hub.
The willRenameFiles loop caught every non-abort, non-method-not-found
error into serverNotes and fell through to fs.rename, so a genuine
failure from a server that supports the request moved the path without
its semantic edits, leaving references dangling. Split client acquisition
from the request, track hard failures, and abort before any mutation when
a supporting server errors. Servers replying method-not-found are still
skipped without blocking.
Fixes#8380
The direct diagnostics loop caught non-abort server errors without recording them, so a file whose every applicable server failed produced an empty aggregate rendered as OK with success: true — a false-negative hiding a total diagnostics failure.
Track per-file and global success/failure counts: zero successful server responses now yields success: false with an explicit failure line, while partial success still surfaces diagnostics and names the servers that failed.
Fixes#8377
rename_file wrote server-provided reference edits before creating the
destination parent and moving the source, with no rollback. A failed
mkdir/rename (e.g. EXDEV across mounts, EACCES) left the reference files
rewritten while the source stayed put, violating the atomic "moves file
AND rewrites all imports/references" contract.
Extract applyEditsThenRename in lsp/edits.ts: snapshot each edited file,
apply edits, then mkdir+rename; on failure restore every snapshot before
rethrowing. Rewire the rename_file handler to build the summary and hand
the edits to the helper.
Fixes#8379
Propagated CreateFile, RenameFile, and DeleteFile options through workspace edit planning and enforced their overwrite, ignore, and recursive semantics during execution.
Fixes#8373
Assigned concurrent mux links separate language-server processes while retaining idle processes for later reuse.
Added regression coverage for session-specific open-document content and updated mux lifecycle expectations.
Fixes#8371