- Added native `FileLock` bindings supporting cross-process advisory locking on Linux, Unix, and Windows.
- Replaced directory-based file locking and custom stale-lock reclamation with OS-backed native locks.
- Updated TypeScript declarations, native bindings, and package documentation for the new API.
- Added comprehensive unit tests and fixtures validating single-owner constraints and process death handoff.
- Restored released sections displaced by union changelog merges; [Unreleased]
now carries the entries for #7377, #7469 (with the OMP_PCRE2_JIT override),
#7475, #7215, #7287, and the shared pi-utils file-lock module.
- Moved the coding-agent lock-directory primitive to @oh-my-pi/pi-utils/file-lock
and migrated settings, MCP config-writer, and security store imports.
- Replaced the stats aggregator's parallel ~200-line token/breaker lock protocol
with the shared primitive: dead owners reclaimed immediately, live-but-wedged
owners after STATS_SYNC_LOCK_STALE_MS, unstamped acquisitions after the new
acquireStaleMs grace (10s).
- Shared primitive now treats EPERM kill probes as live owners.
- Rewrote the stats lock-reclamation regressions against the shared protocol
and moved the file-lock contract test into pi-utils.
- waitForLogEntry raced winston's async flush and JSON.parsed a
partially written line, failing the error-serialization tests on
loaded CI runners; unparseable lines now wait for the next poll.
The postmortem module bound the native hard-exit once at module init
(process.reallyExit.bind(process)). The shipped bundle defers this
module's evaluation until first access, which can land inside a
withHostGuard window where process.reallyExit is the ExtensionExitError-
throwing stub; .bind() then froze that stub permanently, so every later
host-owned exit (SIGHUP 129, SIGINT 130, fatal 1) threw and re-entered
the unhandled-rejection fatal path in a loop (exit 129 storm).
Resolve the native exit on every call instead of binding at init, and
have withHostGuard stamp its throwing replacement with the native
primitive it shadows so a signal arriving mid-guard still exits (#6488)
without the guard poisoning later exits (#7393).
Fixes#7393
On Windows process.env/Bun.env lookups are case-insensitive, so the
"env var name, else literal" resolvers turned a literal /login key like
`public` (OpenCode Zen's free key) into the built-in PUBLIC=C:\Users\Public,
sending `Authorization: Bearer C:\Users\Public` and 401ing every request.
Added `$envExact` in pi-utils, which trusts an env lookup only when an
exact-case key is enumerated (the only case-preserving signal on Windows;
the getter and hasOwnProperty/getOwnPropertyDescriptor traps are all
case-insensitive there). Wired it into all three resolvers:
resolve-config-value.ts, model-registry.ts, and auth-storage.ts.
Fixes#7361
- Implement the OMP Browser Relay extension with WebSocket communication and CDP RPC execution.
- Add browser relay server, daemon management, and bridge multiplexing in the coding agent.
- Introduce CLI commands and settings schema options for configuring and installing the relay.
- Add utility functions and test suites supporting environment parsing and relay lifecycle handling.
- Raised probe-spawning logger tests to 30s timeouts; bun's 5s default
SIGTERMed probe children (exit 143) on shared-core CI runners, matching
the precedent documented in logger-contract.test.ts.
- Allowed clippy::unused_async_trait_impl on KillCommand::execute with an
unknown_lints guard for the pinned CI nightly that predates the lint.
Scoped test-runtime detection to explicit runner markers and Bun test entrypoints, so application NODE_ENV/BUN_ENV values no longer make ProcessTerminal headless.
Added subprocess regression coverage and propagated the private marker to test children.
Fixes#7261
These four paths bypassed DirResolver's XDG-aware rootSubdir/agentSubdir
hooks, resolving directly against getConfigRootDir()/getAgentDir() and
ignoring XDG state/data layout. Add XDG-aware path helpers in dirs.ts
and route all four through them:
- secret-placeholder.key → $XDG_STATE_HOME/omp/ (state, agent flattened)
- marketplaces.json → $XDG_DATA_HOME/omp/ (data)
- run/daemons/<hash>/ → $XDG_STATE_HOME/omp/run/ (state)
- run/provider-inflight/ → $XDG_STATE_HOME/omp/run/ (state)
omp config init-xdg migrates secret-placeholder.key and marketplaces.json
from their legacy locations; run/ is ephemeral and rebuilds on restart.
Settings.init opens agent.db/stats.db before setInteractiveHost ran, so
interactive hosts received the 1000ms headless busy timeout on those
databases (issue #2421 class). Declare the flag before settings load and
add [Unreleased] changelog entries per repo conventions.
Headless hosts (print/RPC/ACP/eval/SDK) run the agent loop on the same
thread as bun:sqlite, so a lock-contention busy-wait of the interactive
5s timeout freezes the protocol loop for seconds at a time with no
liveness signal. Use a 1s busy_timeout for session-critical databases
(agent.db, history.db, stats.db) when the host is not interactive, and
let the existing asynchronous open/retry paths recover from contention.
- Reformatted the logger burst test per biome (the type-check job gates on
check:tools, which failed on the previous hotfix's formatting).
- Raised the native/unit bucket's chunk watchdog to 1200 s: the mupdf PDF
extraction chunk runs ~7 min per attempt on burstable runners under a
full fan-out and the 600 s default SIGKILLed both tries in release run
30519992654; the watchdog targets wedged children, not slow chunks.
- The hosted disk-cache prune swept ~/.cache/omp-bazel-repo file-by-file;
extracted repository contents keep upstream-archive mtimes (months old),
so a restored archive lost most of rules_rust while bazel still trusted
the entry's recorded_inputs — both darwin release legs failed with
'BUILD file not found' in release run 30519253683. Prune only the
action disk cache, whose files carry bazel-written mtimes.
- Gave the logger burst-order contract an explicit 30 s budget: two probe
children measure ~4.4 s unloaded and bun's 5 s default test timeout
SIGTERMed them (exit 143) on shared-core runners.
Skipped stdout draining after ProcessTerminal observes a native Windows terminal disconnect, while preserving normal postmortem cleanup and drain behavior for every other shutdown path.
Fixes#6917
(cherry picked from commit b45fc00ab4b5075ccb9650584947dde061beea20)