Measured each animated Loader paint and recursively scheduled the next frame with a 10% duty-cycle target, capped at 200ms to retain responsiveness.
Added a regression covering a slow synchronized-output direct-write path and documented the fix.
Fixes#7290
Routed direct custom-message conversion through the collab steering transform so side requests and compaction see the same enveloped user turn as primary requests.
Extended the regression test to exercise convertToLlm without transformContext.
Converted user-attributed collab prompt frames to prioritized user messages only on the model-facing path, preserving guest details in persisted transcript frames.
Added regression coverage for the provider role, steering envelope, and retained guest attribution.
Fixes#7288
- Stored replay-sanitized Codex response items as the append baseline.
- Disabled append state for responses without replayable output and covered oversized call IDs.
Fixes#7279
- Rewrote fetchCodexDiscoveryModels to resolve every stored openai-codex
OAuth account via getOAuthAccesses and reuse openaiCodexModelManagerOptions'
tested union/fail-closed path, so a single narrow account can no longer
authoritatively wipe sibling-account models from the bundle.
- Restored openai-codex gpt-5.4, gpt-5.6-sol, and gpt-5.3-codex-spark bundle
entries (and gpt-5.5's contextPromotionTarget) dropped by the previous
single-account regen.
- Updated the live Codex image tool-result tests off the retired
gpt-5.2-codex id to gpt-5.5.
Fixes#6265
The compiled registry enumerated each `exports` wildcard with a single-level
glob and explicitly skipped any key containing a slash, so a nested subpath
like `slash-commands/helpers/active-oauth-account` never entered the bundled
registry. Node matches `*` across `/`, so that import is legitimate: it
resolves from source, then falls through to `Bun.resolveSync` inside a
compiled binary and dies under bunfs. Reproducible on the published 17.2.1
binary with a real extension (`quota-hud.ts`).
Enumeration is now recursive, with every path segment held to the same
private/hidden rules as the leaf, so a `.private/` or `_internal/` directory
is no more exported than a private file. Directory index modules stay
excluded: `./x/*` must not serve `x/y` from `y/index.ts`, which Node would
not resolve either.
The move fence intentionally defers a flushSync landing in the rename window; full synchronous durability there is incompatible with orphan-avoidance for a rename-based, Windows-safe move. Document the caveat honestly instead of implying parity with the in-place rewrite path.
Refs #7270
The move fence bumped #diskEpoch, which no-oped any disk task already queued at the prior epoch (e.g. a header-only ensureOnDisk materializing rewrite), losing explicitly materialized ACP/draft sessions. Gate the append hot path on #sessionFileRelocating instead of a fresh epoch, so prior disk work still drains.
Fixes#7270
A fenced append followed by a Ctrl+C flushSync in the post-rename, pre-repoint window rewrote the full body to the old path, recreating the orphan. Sync rewrites now defer while the session file is relocating.
Fixes#7270
Rebuilt advisor runtimes with the rediscovered context files so advisor turns stop evaluating against stale AGENTS.md instructions after /reload-plugins.
Fixes#7258
Threaded the session's disabledExtensions into context-file rediscovery so a concurrently-created session's global settings cannot toggle another session's context entries.
Fixes#7258
Rediscovered context files from the active session cwd whenever plugin prompt sources refresh, while preserving explicitly preloaded SDK context.
Covered edited and disabled context files in the current system prompt.
Fixes#7258
The TUI's CommandController special-cased backend.id === "off" for
/memory stats|diagnose, but the ACP/RPC slash-command handler in
builtin-registry.ts still fell back to the generic "not available for
the off backend" template — non-TUI users with memory.backend=off saw
the self-contradictory wording this PR was meant to remove.
Extract the shared fallback into memoryStatsUnavailableMessage()
(memory-backend/messages.ts) and use it from both CommandController
and the ACP builtin-registry handler, so the two surfaces can't drift
again.
Addresses review comment:
https://github.com/can1357/oh-my-pi/pull/7251#discussion_r3695383090
/memory stats and /memory diagnose fall back to a generic
'Memory <action> is not available for the <backend.id> backend.'
message whenever the active backend's stats/diagnose hook is
undefined. For every real backend (hindsight, mnemopi, local) this
reads fine, but the off backend isn't a backend a user picked among
several stats-capable options - it's the no-op state memory falls
back to by default - so the same template renders as 'Memory stats
is not available for the off backend.', which reads as an odd,
almost self-contradictory warning.
Special-case backend.id === "off" with wording that matches the
phrasing offBackend.status() already uses elsewhere ('Memory backend
is off.'), and add a unit test covering both the off-backend wording
and the unchanged generic fallback for a real backend (local) that
simply has no stats hook.
The regression test only asserts on a mocked showWarning call and
never renders Markdown, so it doesn't need a real theme instance;
drop the global dark-theme setup/teardown to avoid leaving the
process-wide theme singleton mutated for later suites in the same
Bun process.
anthropic-messages requests dispatched through the direct Anthropic provider
path ignored the catalog compat idle timeout. Slow relayed endpoints therefore
remained limited by the default inter-event watchdog even when the model
configured a wider or disabled timeout.
Add streamIdleTimeoutMs to AnthropicCompat, preserve it through
buildAnthropicCompat, and pass it as the fallback to getStreamIdleTimeoutMs in
streamAnthropic. A value of 0 disables only the inter-event watchdog; the
first-event watchdog is unchanged.
Resolution order matches the existing timeout helper contract:
caller option
> PI_STREAM_IDLE_TIMEOUT_MS
> PI_OPENAI_STREAM_IDLE_TIMEOUT_MS
> model compat
> 300s default
The pi-native transport retains its existing transport-level timeout policy.
Tested: anthropic stream timeout suite, env-contaminated regression cases,
models config validation, and bun check.
SqliteAuthCredentialStore re-ran PRAGMA busy_timeout = 5000 on the
shared agent.db connection, overwriting the headless 1000ms bound set by
AgentStorage — so RPC/ACP/eval hosts could still stall synchronously for
five seconds per statement after auth-store initialization. Route it
through getDbBusyTimeoutMs() so the headless bound survives.