- Replaced the custom MuPDF-WASM PDF extraction and rendering pipeline with the new `pdfToMarkdown` native function from `@oh-my-pi/pi-natives`.
- Removed legacy MuPDF extraction modules, WASM embedding scripts, and PDF image extraction tools.
- Added OCR warnings and browser/text redirection for unsupported PDF image reads.
- Updated native package definitions, documentation, and test suites for the new PDF inspection capability.
Passed the cmd.exe /s /c command line through Bun verbatim so configured editors and temporary paths retain their quotes.
Added command-line regression coverage and documented the fix.
Fixes#8544
- Replaced child_process spawn with Bun.spawn in packages/coding-agent/src/utils/external-editor.ts.
- Removed the browser tab evaluation test suite from packages/coding-agent/test/tools/browser-tab-evaluate.test.ts.
- Bun's inotify-backed fs.watch permanently stops delivering events after
observing git's atomic HEAD.lock -> HEAD rename in the watched directory
(oven-sh/bun#24875), so the directory-watch fix for issue #8412 still froze
the status-line branch on Linux after the first switch; CI caught it as a
30s timeout in status-line-vcs-refresh.test.ts.
- Added git.head.watch: fs.watchFile stat-poll of the HEAD path (reftable dir
for reftable repos) with a disposer; path-based polling survives inode swaps
on every platform.
- Status line and footer now consume the helper; the footer previously bound
fs.watch to the HEAD file inode and died after one switch on all platforms.
- Dropped the FSWatcher error-listener plumbing (StatWatcher has no error
mode) and reworked the watcher lifecycle tests to the stat-poll contract;
verified the atomic-rename regression test passes on Linux bun 1.3.14 in
Docker where it previously timed out.
- Replaced time-based sleeps and polling loops with event-driven promise resolvers and fake timers across agent and tool tests.
- Migrated test suites to share in-memory auth storage and fixtures using lifecycle hooks.
- Updated catalog model definitions, metadata, and configurations.
- Add comprehensive Nix flake definitions, derivations, modules, and CI workflows.
- Update tests and executables to resolve binaries from PATH rather than absolute paths.
- Ensure byte reproducibility and zeroed timestamps in embedded dashboard archives.
- Add handling for Nix-managed installations in CLI update checks.
- Set generation temperature to zero for online title generation to prevent garbled names.
- Update system prompt to instruct exact copying of technical terms and names.
- Reject generated titles containing no word characters to prevent punctuation-only sessions.
- Added `splitAddressableFileLines` to strip terminal newlines from line addressability without removing genuine blank lines.
- Updated coding-agent read tool context parsing to use addressable file lines.
- Added archive and member size assertion limits along with path byte-length checks for PAX and GNU metadata targets.
- Added support for global PAX attributes, old-GNU name records, and signed GNU base-256 numeric header fields.
- Updated archive reading in WriteTool to accept a filesystem path instead of buffered bytes.
- Added test coverage for signed GNU base-256 values, PAX extensions, overlong path rejections, and oversized archives.
- Bound PAX sparse record memory overhead by caching sparse markers and specific keys.
- Update system prompt phrasing and tests for tool inventory and date displays.
- Added Google provider thinking configuration parameters and force-reasoning-off controls.
- Implemented MCP SSE stream resumption using Last-Event-ID and `SSEResumeError`.
- Added support for TAR old-GNU sparse extension blocks, path length checks, and archive entry overrides.
- Restricted external thinking support to specific models and added semver fallback parsing.
- Capped directory-alias rewrites per lookup (ELOOP-style, 40) so a directory
symlink targeting its own subtree (a -> a/b) throws a catchable ToolError
instead of looping forever growing the path.
- Deferred pending tar link resolution while any directory on the target path
is itself an unresolved link, and rewrote targets through established
directory aliases before the exact-path lookup, so file symlinks routed
through directory aliases materialize instead of dangling.
- Regression tests reproduce both shapes: pre-fix the aliased symlink read
failed with 'cannot be materialized' and the self-cycle read hung.
Symlink targets that normalize to the archive root (current -> ., dir/up -> ..) now resolve as directory aliases to the root instead of being treated as dangling links. The lookup normalizer distinguishes an empty root target from an escaping target, and ArchiveReader treats a resolved-empty path as the root directory.
Fixes#4774
GNU 1.0 sparse PAX entries now list under GNU.sparse.name with GNU.sparse.realsize as the displayed size, so root listings no longer expose the internal GNUSparseFile path and reads of the real name reject as sparse instead of reporting the member missing. The on-disk header size still drives offset advance and truncation.
Fixes#4774
Kept directory symlinks as one alias node and rewrote requested paths through aliases in ArchiveReader instead of cloning every target descendant during indexing.
Full archive materialization now fails explicitly on directory aliases rather than expanding them without a bound.
Fixes#4774
Resolved safe file and directory symlinks against indexed members, while retaining dangling links as listed nodes that fail explicitly when read or materialized.
Required fully buffered tar inputs to reach an end-of-archive zero block so truncated downloads cannot expose partial listings.
Fixes#4774
Resolved hard-link targets after indexing so forward links and chains reuse the referenced member's storage and size. Missing, directory, or cyclic targets now surface catchable archive errors instead of silently dropping paths.
Fixes#4774
A gzip stream whose decompressed payload never presents a complete tar header or terminating zero block (a plain .txt.gz, or a tar truncated before the first header) now raises a catchable ToolError instead of returning an empty index rendered as '(empty archive directory)'. fetch falls back to binary rendering.
Fixes#4774
A member header declaring more bytes than remain in the buffer now throws a ToolError during indexing instead of being listed as a valid entry that only fails on read.
Fixes#4774
- Parsed tar and tar.gz members in-process with bounded gzip inflation.
- Added UTF-8 ustar-prefix coverage for the minimal libarchive crash shape.
Fixes#4774
- Define a centralized `USER_AGENT` constant in `@oh-my-pi/pi-utils` formatted as `omp/<version>`.
- Replace hardcoded and platform-specific user agent strings across AI providers, catalog scrapers, tools, and search providers with the unified `USER_AGENT`.
- Add unit tests for update-cli binary release distribution gating.
- Removed the Loader backpressure cap so slow ConPTY paints retain the documented proportional duty cycle.
- Made WSL terminal-title working state static to avoid a second periodic OSC write loop.
Fixes#8012
- 28 symbols across discovery, mcp header policy, agent-hub projection and
rendering, the agent registry, shell tokenizing and changelog comparison
were exported but referenced only inside their own module; they are now
module-private, shrinking the deep-import surface.
- Kept AGENT_PLUGIN_MANIFEST_SCHEMA, AGENT_PLUGIN_MCP_SCHEMA,
parseAgentPluginManifest, clearAgentPluginRootCache and mergeMCPHeaders
exported: each is a seam for tests that defend real parsing or header
precedence behavior.
- Nothing reachable from an explicit exports entry or public barrel changed.
- Implemented in-house, zero-dependency utility modules in `pi-utils` covering DOM manipulation, markdown parsing, templating, browser automation helpers, and terminal buffers.
- Migrated packages across the repository to consume the new internal utilities and `omptype` schema validators instead of external dependencies.
- Removed multiple external runtime and development dependencies including Zod, Marked, LRU cache, Turndown, and Puppeteer browser packages.
- The PR #7205 merge left cli.ts statically importing startComputerWorker,
dragging the computer worker graph (and pi_natives via the pi-utils
barrel) into normal CLI startup; --version died under --no-addons and
dotenv loaded before profile bootstrap. worker-entry is now a
self-starting side-effect module dispatched via dynamic import like
every other worker selector, and utils/clipboard.ts imports the mime
constant from its submodule instead of the barrel.
- Repointed the clipboard test spy at @oh-my-pi/pi-natives/clipboard —
spying the barrel never intercepted the subpath the code imports, so
the real native bridge ran (X11 timeouts on headless CI).
- Refreshed the pinned HTML export template digest and the scout gate
phrase the system-prompt rewrite changed.
Extracted the coding-agent scope of PR #7077 (@santhreal): single-pass
placeholder matcher so positional values containing literal $@ or
$ARGUMENTS are never re-expanded. The unrelated utils formatting changes
in that PR were not taken.
- Replaced monolithic desktop native bindings and action batching with a modular cross-platform backend structure supporting Wayland, X11, macOS, and Win32.
- Updated the computer tool schema and supervisor to execute persistent JavaScript script runs with timeout clamping and asynchronous tool calling.
- Integrated accessibility (AX) tree snapshotting, node querying, and bounds-based hit testing across platform desktop layers.
- Added native clipboard bindings and updated coding-agent prompts, renderers, and tests to validate script-based computer workflows.
- Added window discovery, targeting, and frame validation for macOS, Windows, and Linux platforms.
- Updated computer tool and protocol definitions to support listing and targeting specific application windows.
- Refactored native computer tool exposure to function-only representation across models.
- Updated documentation and test suites to reflect window-scoped computer control capabilities.