- Add `renderPdfPageScreenshot` to render PDF pages via headless Chromium.
- Update `ReadTool` to intercept legacy PDF image paths and return page screenshots.
- Ensure daemon clients are closed on read command exit.
Detected npm and Bun ownership from the bin link immediate target within each precise global node_modules root. Foreign aliases now update their resolved standalone binary without replacing the alias.
Fixes#8468
Resolved npm and bun bin-entry symlinks before selecting the update method, and preserved foreign aliases by replacing their standalone target.
Fixes#8468
- Replaced time-based sleeps and polling loops with event-driven promise resolvers and fake timers across agent and tool tests.
- Migrated test suites to share in-memory auth storage and fixtures using lifecycle hooks.
- Updated catalog model definitions, metadata, and configurations.
Two overlapping `omp update` runs now share the target only for the
swap + stale-artifact sweep, guarded by withFileLock. This closes the
rollback race the unique-temp fix left open: a concurrent run's sweep
could delete a live run's .bak before its failed verification rolled it
back. The download stays outside the lock (unique temp path, safe to
overlap). Adds a regression covering a failed verification overlapping a
successful update.
Two overlapping `omp update` runs shared the fixed `<binary>.new` temp
path. downloadVerifiedBinary unlinks the target before writing, so the
second run's unlink deleted the first run's still-downloading temp file;
the first kept writing to its open fd (size and digest still passed),
then chmod hit the missing path and aborted with ENOENT.
Give the temp path the same unique per-attempt suffix the backup path
already uses (pid, timestamp, and a new process-local counter that also
covers same-millisecond, same-process collisions). Generalize the stale
backup sweep to also reclaim orphaned `.new` temp files, age-gated by the
download window so a concurrent run's in-progress temp is never deleted.
Fixes#8434
Moved strict --tools validation to the completed session registry so extension modules, custom tool directories, and plugin manifest tools are all eligible while unknown names still fail startup.
Deferred --tools validation until extension discovery, then validated against built-in and registered tool names while preserving strict rejection of unknown names.
Fixes#8421
- Added Anthropic prompt-cache refresh scheduling and state management to keep prompts warm across idle sessions.
- Updated pricing models and database stats tracking to calculate and store cost-weighted cache savings.
- Integrated cache savings metrics and efficiency displays into the stats CLI, dashboard routes, and UI components.
- Added support for package renaming, manifest pointer tracking, and installation migration during CLI updates.
- Add comprehensive Nix flake definitions, derivations, modules, and CI workflows.
- Update tests and executables to resolve binaries from PATH rather than absolute paths.
- Ensure byte reproducibility and zeroed timestamps in embedded dashboard archives.
- Add handling for Nix-managed installations in CLI update checks.
- Added Google provider thinking configuration parameters and force-reasoning-off controls.
- Implemented MCP SSE stream resumption using Last-Event-ID and `SSEResumeError`.
- Added support for TAR old-GNU sparse extension blocks, path length checks, and archive entry overrides.
- Restricted external thinking support to specific models and added semver fallback parsing.
- Added the `--external-thinking` CLI flag alongside model capability checks to gate external thinking tool availability.
- Updated Anthropic and Google transports to honor `forceReasoningOff` for native thinking-off controls.
- Renamed the `thoughts` property and parameter to `notes` across think fixtures, tools, and tests.
- Updated system prompt instructions and test suites to verify transport-specific thinking and tool activation.
- Added discovery subagent and custom checker specifications for alternative toolings across multiple languages.
- Implemented interactive TUI flows for target picking and free-form request discovery.
- Added output parsers for popular static analysis and linting tools.
- Increased default maximum subagents cap and documented the new capabilities.
- Implemented the `omp compress` command with batch processing, file resolution, and concurrency support.
- Added the semantic compression protocol, session factory, and rewrite-approve evaluation loop.
- Included prompt templates, tool descriptions, and comprehensive test coverage for compression targets.
- Generalized the progress reporter module for shared use across CLI commands.
- Added a curated think gallery fixture; the generic fallback carries no
thoughts field, so the streaming state rendered zero lines.
- Seeded the shared test registry with a runtime openai key: the prompt
preflight validates through the registry, not the per-request getApiKey
override, so keyless CI runners threw before reaching the mock server.
- Expected reasoning effort "none" — the only disable level the Responses
wire accepts; "off" is not a wire value.
- Extracted version verification logic into a reusable function accepting an explicit binary path.
- Updated shim takeover to verify the newly placed executable path directly instead of re-resolving via PATH.
- Added `resolveReleaseDist` and `shouldForceBinaryUpdate` to parse package manifests and gate major updates to binary releases.
- Implemented `updateViaShimTakeover` in `update-cli.ts` to seamlessly replace Windows script launchers with standalone binaries.
- Added comprehensive unit tests covering release distribution parsing, binary force updates, and script-shim takeover behavior.
Detected Bun-compiled entry points before preserving source invocations. Added a regression for the virtual bunfs argv shape and documented the fix.
Fixes#8233
The earlier dry-run change moved scope into an options object, silently
ignoring the legacy uninstallPlugin(id, "user") runtime shape still reachable
from compiled or plain-JS callers. Restore scope as the positional second
argument and carry dryRun in a trailing options bag, preserving the existing
call shape while keeping the non-mutating dry-run path.
Fixes#8178
Route marketplace dry-runs through MarketplaceManager's normal pre-mutation
validation so ambiguous or mismatched scopes fail exactly as real uninstalls
do. Move the manager's scope argument into an options object and add a dry-run
option that returns only after all removal planning has succeeded.
Fixes#8178
handleUninstall dropped the parsed dryRun flag and unconditionally called
mktMgr.uninstallPlugin / manager.uninstall, so `omp plugin uninstall
<plugin> --dry-run` removed the plugin on both the marketplace and npm
routes. Propagate dryRun into handleUninstall and short-circuit before
both removal calls, reporting the resolved removal (with its source)
instead of mutating state.
Fixes#8178
Shares a saved session by id prefix or .jsonl path without launching the
agent - same encrypted upload, store selection, and share.redactSecrets
handling as the /share slash command.
- Routed session tool provenance through live and rebuilt transcript render paths.
- Kept same-named extension tools on the generic renderer while preserving native tool rendering.
- Added regression coverage for an external recall result collision.
Fixes#7770
- Implemented in-house, zero-dependency utility modules in `pi-utils` covering DOM manipulation, markdown parsing, templating, browser automation helpers, and terminal buffers.
- Migrated packages across the repository to consume the new internal utilities and `omptype` schema validators instead of external dependencies.
- Removed multiple external runtime and development dependencies including Zod, Marked, LRU cache, Turndown, and Puppeteer browser packages.
Review findings on #7586:
- validate an explicit release version before comparing; the shared
comparator never throws, so 999.bad previously reached every manifest
- ci-release-notes imports the comparator by relative path: the
release_github job runs without bun install
- route Bun cache pruning through compareVersions and delete
compareSemverLikeVersions
- regression test for the release-version guard
Threaded the loopback hostname returned by startServer through the omp stats CLI and /stats slash command so the browser and logged URL target the actual listener instead of localhost.
Fixes#7633
- Serialized group and ungroup operations to prevent duplicate tab group creation races.
- Queued and serially drained tab grouping requests in the relay bridge to prevent overlapping RPCs.
- Mirrored tab group titles to session storage and healed duplicate groups during background service worker recovery.
- Renamed run-cancellation utility to run-scope and updated corresponding module and test references.
The OpenAI service tier could only be chosen through the `tier.openai`
setting, or for a resumed session through whatever tier that session
recorded. Wanting flex or priority for a single run meant editing
settings and putting them back afterwards, while `bench` already took a
`--service-tier` flag that the session CLI did not offer.
Add `--service-tier` to the root command. The flag wins over the
configured setting and over a resumed session's recorded tier, leaves
the Anthropic and Google entries untouched, and records the resulting
map so a later resume keeps it. `none` removes the OpenAI entry, which
omits `service_tier` from the request.
Signed-off-by: Christian Stewart <christian@aperture.us>
- Implement the OMP Browser Relay extension with WebSocket communication and CDP RPC execution.
- Add browser relay server, daemon management, and bridge multiplexing in the coding agent.
- Introduce CLI commands and settings schema options for configuring and installing the relay.
- Add utility functions and test suites supporting environment parsing and relay lifecycle handling.