- Added `is_implementation_authorizer` check requiring OWNER or allowlisted maintainer to authorize implementation work.
- Blocked `gh_push_branch` and `gh_open_pr` for unclassified/enhancement/proposal issues without explicit directive authorization.
- Auto-allowed bug and documentation issues without requiring a directive.
- Propagated `authorizes_impl` flag through events, server, tasks, and worker bindings.
- Added `review_pr` task that checks out PR head in a detached worktree, classifies rank/type/area, and posts a batched GitHub review as `event=COMMENT`.
- Added four new host tools: `fetch_pr`, `classify_pr`, `pr_review_comment`, and `submit_pr_review`; review tools self-gate on `review_mode`, push/open-PR tools refuse when `review_mode` is set.
- Added sqlite staging table `pr_review_comments` with `stage_review_comment`, `list_staged_review_comments`, and `clear_staged_review_comments` DAOs.
- Routed `pull_request.opened/reopened/ready_for_review` to `review_pr` and extended `pull_request.closed` cleanup to any tracked PR regardless of author.
- Upgraded workspace catalog dependencies to newer versions in both package manifests.
- Regenerated bun.lock to align transitive versions, including Vite and ecosystem tooling updates.
- Updated ACP startup tests and transport handling to fail fast on unsupported server transport types.
Fire Pass support:
- New provider with login command 'omp /login firepass'
- Hand-seeded kimi-k2.6-turbo model with Fire Pass router wire id
- pi-ai CLI --help lists firepass
AI provider fixes surfaced during the Fire Pass review:
- service_tier whitelist restored for openai/openai-codex only (was leaking to
Fireworks, Firepass, OpenRouter, Azure OpenAI Responses)
- Anthropic tool schema normalizer collapses {} -> true for additionalProperties
- anthropic.prepareParams fires onPayload after drop helpers so callers see the
real wire body
- isServiceTier type guard narrowed to ResolvedServiceTier
- transformMessages stops dropping orphan tool_result when all pending tool
calls have already resolved
- zodToWireSchema preserves null for non-scalar nullable() inner schemas
- isEmptyObject / isJsonObjectEmpty use Object.keys().length === 0 instead of
prototype-walking for...in
- Telemetry records resolved service_tier (priority) instead of scoped
placeholder (openai-only/claude-only)
- Robomp dirty-state reminder no longer asserts a formatter-failure premise
- Normalized reviewer-bot matching by stripping a trailing `[bot]` suffix when resolving configured bot logins.
- Fetched PR thread history for followup comments without directives and carried it through task execution.
- Updated followup prompt rendering to include prior conversation context for handle_comment tasks.
- Moved issue classification updates to run only after branch rename succeeds, preventing partial labeling or DB writes when rename fails.
- Adjusted workspace ownership normalization to chown workspaces to the active slot or, when slotless, to the current euid/egid, then apply shared permissions.
- Added tests for classify_issue rename-failure rollback and chown_workspace normalization in non-slot mode.
parse_issue_ref now accepts owner/repo#NN or a github issue url (with or without scheme, www., trailing slash, query, fragment). The dashboard trigger, CLI, and replay endpoint pick this up automatically; UI hints updated to match.
- Added `DirtyState` and `inspect_dirty_state` in `git_ops` to report uncommitted, unpushed, and summary state.
- Updated `_drive_turn` to recheck completion each cycle and emit dirty-state reminders or exit when clean.
- Wired `dirty_state_reminder` into persona rendering with `uncommitted`, `unpushed`, and `summary` context.
- Added `dirty_state_reminder.md` guidance for fixing/restoring changes and pushing only after `bun run fix` completes.
- Added worker tests for dirty, clean, and persistent-dirty flows and prompt-count assertions.
- Replaced `oh-my-pi/artifacts:dev` image references with `oh-my-pi/pi:dev`.
- Updated `PI_ARTIFACTS_IMAGE` → `PI_BASE` in compose and script descriptions.
- Replaced `/work/pi/Dockerfile` artifact stage with `/Dockerfile` pi-runtime stages.
- Added `pi:image` and `pi:run` commands to development command reference.
- Replaced the slim artifacts-only image with a full pi-base image (python + bun + rustup + natives + omp_rpc + omp shim).
- Moved robomp Dockerfile to repo root as Dockerfile.robomp, extending pi-base instead of copying from a scratch artifacts image.
- Renamed PI_ARTIFACTS_IMAGE to PI_BASE and updated all npm scripts and compose config accordingly.
- Split .dockerignore into per-Dockerfile shadows (Dockerfile.dockerignore, Dockerfile.robomp.dockerignore).
- Added `python/robomp` as a workspace package alongside its nested `web` sub-package.
- Added `ignoreDependencies` in `.fallowrc.jsonc` for deps used via bin or in nested workspaces.
- Removed unused `clearTriggerStatus` export and unexported `tick` and `ByModelToggle`.
- Added `omp auth-gateway serve/token/status` — a forward-proxy injecting broker credentials for OpenAI Chat, Anthropic Messages, and OpenAI Responses wire formats.
- Added `GET /v1/usage` to auth-broker and auth-gateway; usage cache switched to 5-min per-credential TTL with jitter and last-good fallback on failure.
- Added `AuthStorage.setConfigApiKey/removeConfigApiKey/clearConfigApiKeys` so `models.yml` `apiKey` beats OAuth tokens without overriding `--api-key`.
- Added `omp auth-broker migrate --from-local` for idempotent upload of local SQLite/env credentials to the broker.
- Subtree-merged github.com/can1357/roboomp with full history
- Wired python/robomp/web as a Bun workspace; migrated SolidJS deps to root catalog
- Removed nested bun.lock/bunfig.toml/biome.json; root configs now own them
- Replaced scripts/with-pi-root.sh; default PI_ROOT to ../.. (the monorepo)
- Added root recipes: test:py, lint:py, fix:py (Python opt-in, not folded into bun test)
- Updated .gitignore/.dockerignore for robomp runtime state (data/, cache/, web dist, static bundle)
- Updated README/AGENTS/.env.example to drop ROBOMP_PI_* auto-clone knobs