- Added a `mode` property to `CompactOptions` to allow fine-grained control over compaction strategies.
- Implemented `soft`, `remote`, and `snapcompact` submode overrides for the `/compact` command.
- Integrated `parseCompactArgs` to enable robust subcommand routing and validation, including focus instruction rejection for specific modes.
- Established a `CompactMode` registry to manage compaction strategies and verify remote availability.
- Validated every stage of a pipeline against `simple_command_is_safe` instead of only the first stage to prevent improper segmentation of compound shell constructs.
- Guarded segment re-execution by verifying that each `Display`-reconstructed command parses back to the expected pipeline shape.
- Configured segmented-chain execution to fall back to an unsegmented, whole-command path whenever a reconstructed segment diverges from the original AST.
- Resolved a syntax error during command execution by preventing `Display` from stripping terminators from compound commands like `while` and `for` loops.
- Removed qrcode and qrcode-view subcommands from the collab command.
- Updated showCollabLink to always trigger QR code display.
- Refactored internal verb logic to simplify session sharing flow.
Drop the runtime qrcode + @types/qrcode packages in favor of a zero-dependency
byte-mode QR encoder (versions 1-40, EC L/M/Q/H, auto version + mask selection)
with a half-block ANSI renderer. Cross-validated byte-for-byte against the qrcode
reference library and decoded end-to-end with jsQR. Adds encoder regression tests.
- Added collab.webUrl and rendered browser links as web UI wrappers whose fragments carry relay links.
- Added one-shot /collab qrcode and /collab qrcode-view commands with terminal QR rendering.
- Updated coding-agent and collab-web parsers to prefer parseable wrapper fragments while preserving legacy links.
- Added regression tests and changelog entries for split-host collab links and QR commands.
- Migrated the `pi` AI dialect from legacy XML-style elements to a compact, token-frugal sigil-delimited format using `§` for calls, `""` for body fences, and `¤` for thinking.
- Implemented robust parsing for the new format, including support for incremental streaming of tool arguments and automatic escalation of body fences to prevent content collisions.
- Updated documentation, settings configurations, and test suites across the `ai` and `coding-agent` packages to ensure consistency with the new dialect rules.
- Standardized moderation category terminology in `stats` to improve clarity in reporting metrics.
getOpenRouterRouteSuffix() used strict parseThinkingLevel(), which never
recognizes the max->xhigh alias, so openrouter/<id>:max was consumed as an
OpenRouter route suffix and cloned into a literal <id>:max model id with the
reasoning level dropped. This hit every exact-selector funnel
(parseModelPattern -> resolveCliModel/--model, resolveModelRoleValue/modelRoles
+ model picker, SDK default role) for the dominant aggregator provider.
Exclude max via parseThinkingSuffix(.., MAX_THINKING_SUFFIX_OPTIONS) so the
pattern falls through to the existing max-aware selector split. Literal :max
ids stay safe (none exist under openrouter; nanogpt literals win via exact
lookup before this path). Adds an openrouter/<id>:max regression test.
The dispose() disconnect added by this PR awaited mcpManager.disconnectAll()
unbounded. An owned manager holding an HTTP/SSE server whose session-
termination DELETE hangs would block dispose for the full MCP request timeout
(30s default, unbounded when OMP_MCP_TIMEOUT_MS=0), stalling /exit and
print-mode shutdown on a broken remote endpoint.
Wrap the disconnect in withTimeout(..., 3_000) — mirroring the bounded
async-job teardown two lines above and the startup bound from issue #2100.
stdio close (the subprocess reap this PR targets) completes well within the
bound; a slow transport close is left to finish detached.
Adds a regression test driving the real MCPManager.disconnectAll() with a
stalled transport close.
The quoted-path fix entry was appended under the already-released [16.0.6] section (creating a duplicate ### Fixed heading); released sections are immutable per repo convention. Move it to [Unreleased] and normalize the bullet.
Resolved Amazon Bedrock application inference profile ARNs through the provider-specific model resolver and routed Bedrock requests to the ARN region.
Fixes#3004
Threading printThoughts only into runPrintMode is too late when
hideThinkingBlock is set (settings or --hide-thinking): the session is
built with hideThinkingSummary=true, so the provider omits reasoning
summaries and --print-thoughts prints nothing. Override hideThinkingBlock
to false for single-shot print mode before session creation, gated on
print mode; an explicit --hide-thinking still wins.
After plan approval the executor delivers the plan-mode-reference exactly
once and sets `#planReferenceSent = true`. Both compaction paths — `compact()`
and `#runAutoCompaction()` — replace the conversation history that carried
that reference but never cleared the flag, so `#buildPlanReferenceMessage()`
short-circuited to null on every subsequent turn and the executor permanently
lost the plan it was working on (exactly the long-session failure reported).
Clear `#planReferenceSent` right after `replaceMessages()` in both paths so the
next turn re-reads the plan from disk and re-injects it. The reset is a no-op
for ordinary sessions: the default plan path (PLAN.md in session-local scratch)
has no file on disk, so `#buildPlanReferenceMessage()` still returns null there.
Adds a deterministic regression test (short-circuited compaction, mock stream)
that fails before this change and passes after, plus a guard proving normal
sessions get no spurious plan injection.
Fixes#1246
- Refined the advisor's scope to prioritize concrete technical risks and user advocacy while discouraging process-related critiques.
- Explicitly barred the advisor from intervening on user intent, process questions, or issues already handled by developer tooling.
- Updated `advise` tool documentation to clarify its purpose in preventing wasteful or incorrect work.
A login entry can store credentials under a different provider id via
storeCredentialsAs (e.g. openai-codex-device => openai-codex). Filtering
only on provider.id left such alias logins visible after disabling the
underlying model provider. Surface storeCredentialsAs on OAuthProviderInfo
and hide a login entry when either its own id or its storeCredentialsAs
target is in disabledProviders.
Addresses Codex review on #2906.
The vendored markit engine kept `mupdf` external, but a single-file
`bun --compile` binary has no node_modules to resolve it from, so the
standalone binary aborted at startup with `Cannot find package 'mupdf'`
— the otherwise-lazy import is resolved eagerly at boot. Bundle mupdf and
embed its WASM blob (scripts/embed-mupdf-wasm.ts, reset after the build);
npm and source installs still load mupdf from node_modules.
Import mupdf lazily inside the PDF converter so the bundled markit chunk's
init stays synchronous: mupdf's top-level await otherwise made the chunk
init async and bun's compiled bundler failed to await it through the
barrel, exposing the converters before their module-level const tables
initialized (undefined EXTENSIONS). Also keeps the ~10MB wasm off non-PDF
document conversions.
- Replaced insufficient file size checks with comprehensive validation for ZIP header and length limits.
- Added explicit rejection for archives that would exceed ZIP32 entry counts, name lengths, or total offsets.
- Added validation for central directory size to prevent overflow before generating the EOCD record.
- Implemented structured markdown role headings and tool result merging to improve conversation readability.
- Added explicit `<out>` tags for tool result wrapping and enhanced rendering for thinking blocks.
- Refactored authentication snapshot validation to use manual structural checks instead of schema dependencies.
- Fixed instability in settings overlay scrolling and addressed assistant message splitting issues.
- Removed the `fflate` dependency in favor of using `node:zlib` for ZIP operations.
- Updated documentation and internal code comments to reflect the transition to native `node:zlib` DEFLATE support.
- Replaced `fflate` dependency with `node:zlib` and manual ZIP framing in `src/utils/zip.ts`.
- Implemented lazy loading for site-specific scrapers to reduce cold-start latency.
- Unified ZIP compression and extraction logic to use native `zlib` stream decoders.
- Optimized ZIP member decoding by implementing memory-safe length-bounded inflation.
- Restrict the advisor from providing redundant insights, context, or second opinions.
- Prohibit restating information or problems already visible to the agent via its own tools.
- Prevent repetition of previously provided advice to minimize noise.
- Refactor deep imports by targeting specific sub-modules in `@oh-my-pi/pi-ai` to reduce barrel file overhead.
- Utilize jitless ArkType scopes in schema definitions to reduce startup JIT codegen costs by approximately 65%.
- Reorganize internal `auth-storage` exports to maintain clean boundaries between core and broker-specific functionality.
- Centralized archive operations into a new `utils/zip.ts` module with unified support for ZIP, tar, and tar.gz formats.
- Optimized ZIP reading using lazy, ranged central-directory access and implemented ZIP64 support for large files.
- Hardened archive extraction with directory traversal protection and configured memory limits for loading and extraction.
- Refactored tool-specific logic to utilize the new centralized utility and deleted the redundant `archive-reader.ts`.