Default ChildProcess unconditionally pushed every raw stderr chunk into
`#stderrChunks`, so long-lived noisy subprocesses (LSP/DAP/RPC) grew OMP
memory linearly despite the 32 KiB visible tail cap.
- Allocate `#stderrChunks` only when full capture is requested at spawn.
- Decouple retention from stream exposure via `spawnInternal`, so
`exec({ stderr: "full" })` retains without an unused live tee.
- Reject retroactive `wait({ stderr: "full" })` on a default child with a
clear error instead of returning truncated data.
Fixes#5759
Kept live process logs isolated while globally retaining only the five newest files from completed processes.
Removed one-use audit files after their owning process exits and covered short-lived invocation cleanup.
Fixes#5716
Made fatal reporting bypass revoked stderr streams and armed a referenced forced-exit watchdog around bounded cleanup.
Separated rotating log and audit namespaces by PID and disabled compression pipelines so concurrent TUI processes cannot race shared rotation state.
Fixes#5716
Argument/flag validation failures in the minimal CLI framework threw a
plain Error that bubbled to the process-level catch in cli.ts, which
dumps a Bun.inspect code frame — a minified dist/cli.js excerpt in
compiled binaries. A missing model on `omp bench` looked like a crash.
- Add CliUsageError; throw it from Command.parse for missing/invalid
args and flags.
- Catch CliUsageError in run(): print `error: <msg>` plus the command
usage line to stderr, exit 1, no stack.
- Render required variadic positionals as MODELS... in usage, not the
misleading optional [MODELS]; extract commandUsageLine helper.
Fixes#5369
Rules whose condition led with a PCRE-style inline flag group (e.g.
`(?i)`) never registered: `new RegExp("(?i)...")` throws in Bun/JS, so
the condition failed to compile and `TtsrManager.addRule` dropped the
rule as having zero usable conditions.
- Add `compileRuleCondition` in capability/rule.ts translating a leading
`(?i)`/`(?m)`/`(?s)` group into native RegExp flags; wire it into the
TtsrManager and both ttsr-cli compile sites.
- Strip surrounding quotes from scope tokens so a malformed
`scope: "text","thinking"` recovers to canonical `text`/`thinking`.
- Reparse each value in parseFrontmatter's YAML fallback so one bad line
can't leave sibling values wrapped in literal quotes.
Fixes#4796
Registered ACP session disposal with postmortem and replaced the hard EOF exit with the awaited graceful shutdown path.
Classified stdio-write EPIPE separately from worker IPC EPIPE so ACP peer loss exits successfully after cleanup.
Fixes#4788
- Added bounded A* routing extents plus an expansion backstop so unreachable attachment points return null instead of searching the unbounded quadrant.
- Covered the reported declaration-order graph and an enclosed destination attachment point.
- Documented the Mermaid ASCII routing fix in the utils changelog.
Fixes#5293
On a fresh profile ~/.omp/logs may not exist yet (the logger creates it
lazily), so opening getLogPath() with "a" threw and the guard fell back to
/dev/null — discarding macOS diagnostics and native crash reports instead
of preserving them in the omp log. mkdir the redirect target's parent
(recursive) before opening; the /dev/null fallback stays as the safety net.
On macOS, libmalloc writes runtime diagnostics (e.g. "MallocStackLogging:
can't turn off malloc stack logging because it was not enabled") directly
to fd 2 of the running TUI process at arbitrary times, painting into the
viewport. The existing env-strip only protects child processes.
Add a fd-level stderr guard in pi-utils (suppressTerminalStderr /
restoreTerminalStderr) that dup2-redirects fd 2 to the omp log file while
the TUI owns the terminal, and restores it at every ownership handoff
(external editor, Ctrl+Z suspend, shutdown, crash restore). Postmortem
fatal handlers restore fd 2 before printing so crash reports stay visible.
Mirrors openai/codex#24459.
- Added comprehensive test suite for `postmortem` utility error handling, covering cleanup symbol marking, cause chain depth validation, and process exception suppression.
- Added tests for `browser-run-cancellation` ensuring proper `unhandledRejection` suppression and correct `ToolAbortError` propagation during teardown.
- Implemented `collectUnhandledRejections` helper to verify silence of process-level rejections during async race conditions in browser runs.
- Added integration-style probe tests for `postmortem` to verify that marked cleanup errors allow process survival while unmarked ones remain fatal.
- Mark demoted thinking blocks with a symbol to decouple paragraph separators from the raw text content.
- Update `openai-completions` to conditionally insert a newline only when a demoted thinking block is followed by other content.
- Ensure terminal demoted thinking blocks are trimmed to prevent trailing whitespace that causes rejection by the Anthropic API.
- Implemented classifyJsonPrefix to categorize buffers as complete, valid prefix, or invalid based on RFC 8259 strictness.
- Added utility to support disambiguation of identifierless streaming tool-call deltas during model response processing.
- Validated classifier logic with comprehensive suite covering nested structures, escape sequences, and strict formatting rules.
- Added support for parsing unquoted bareword strings in object and array value positions.
- Implemented safety checks to prevent bareword recovery from masking structure, consuming non-finite atoms, or swallowing valid JSON delimiters.
- Included logic to preserve URL-style and Windows-style paths containing colons while rejecting invalid or ambiguous syntax.
- Extracted the `tls-fetch` implementation and tests from `@oh-my-pi/pi-ai` to `@oh-my-pi/pi-utils`.
- Exported the `wrapFetchForExtraCa` and `withExtraCaFetch` utilities publicly from `@oh-my-pi/pi-utils`.
- Introduced `ExtraCaError` to replace the AI-specific `ValidationError` for missing `NODE_EXTRA_CA_CERTS` paths.
- Updated imports in `packages/ai/src/stream.ts` to consume the relocated utility.
- Added preprocessing to quote ambiguous plain scalars containing a colon-space sequence when standard YAML parsing fails.
- Preserves the parsed types of unaffected fields and prevents fallback warnings for common unquoted description strings.
- Added tests to verify successful recovery of unquoted values and continued fallback warning coverage for unrecoverable syntax.
- Restored the fetchWithRetry early return for Retry-After and quota hints larger than maxDelayMs.
- Added coverage so oversized provider retry hints do not sleep and retry internally.
- Introduced `isProbablyBinary` utility to sniff file headers for NUL bytes or invalid UTF-8 sequences.
- Updated `ReadTool` to use the binary sniffer, preventing mojibake corruption in output when reading non-text files.
- Refined `file-mentions` auto-reads to skip binary files and mark them as `binary` in the message transcript.
- Added comprehensive unit tests for binary detection logic, covering NUL bytes, truncated multibyte characters, and path-based file sniffing.
Rejoined split Windows extension module paths before launch parsing finishes and stripped extended-length Win32 prefixes before Bun import and worker spawn APIs see them.
Fixes#3804
Bun's `Response(stream).bytes()` returns the raw `ArrayBuffer` once the
body arrives in more than one chunk, which happens for subprocess stdout
past ~128 KB. The public contract of `ptree.ChildProcess.bytes()` is
`Promise<Uint8Array>`, and callers — most visibly the `ssh://` read
path's `decodeUtf8Text` — rely on `Uint8Array` methods such as `.indexOf`
and `.subarray`. On larger remote text files this surfaced as:
TypeError: bytes.indexOf is not a function
Normalize the result at the boundary: when `Response.bytes()` hands back
an `ArrayBuffer`, wrap it in a zero-copy `Uint8Array` view before
returning. Adds a regression test that drives a 256 KB stdout payload
through `ptree.spawn(...).bytes()` and asserts the contract.
Fixes#3712
The #3348 change is a single retry-window constant (25->50ms); the test asserted
it via mock.module("node:fs") + process.platform/Bun.sleepSync mutation, which
AGENTS.md bans (leaks across the full suite). The retry-on-EBUSY loop already has
coverage; a config constant does not warrant a global-mutating test.
- Centralized JSON parsing and stream processing logic by moving utilities from `packages/ai` to the shared `@oh-my-pi/pi-utils` package.
- Standardized import paths for JSON parsing and streaming across the agent, ai, and coding-agent packages.
- Refactored SSE stream handling to use consolidated `parseStreamingJson` logic and introduced robust error recovery for malformed container-shaped tail events.
- Cleaned up legacy bundled registry references and updated related module exports and tests to reflect the new utility structure.
- Set logger to silent mode when no transports are active to avoid "no transports" errors during log emission.
- Added a regression test to verify that disabling all transports suppresses warnings and that log output resumes after re-enabling transports.
- Corrected TTY property restoration to properly delete injected properties instead of redefining them as truthy values.
- Updated environment restoration to modify process.env keys individually to prevent breaking environment object reference bindings.
- Prevented pollution of TTY-gated code and environment variable state across test suites.
- Pin colorMode to none in golden test suites to prevent nondeterministic ANSI escape sequences.
- Normalize render calls across test files to ensure stable output comparison.
- Prevent test flakes caused by environment-specific TTY auto-detection in the renderer.
Snapshot and restore PI_CODING_AGENT_DIR, OMP_PROFILE, PI_PROFILE, and
XDG_CACHE_HOME instead of relying on setAgentDir(originalAgentDir), which
cannot restore previously-unset or profile-derived env state. Reset the
profile snapshot and rebuild dirs from env in cleanup to prevent
suite-order pollution.
Also reject empty cached content in parseCacheEntry() to harden the
cache contract against corrupted/empty entries.