- Added a `suppressBreadcrumb` option to `SessionManager.open()` so headless opens skip writing the per-TTY `--continue` breadcrumb, and passed it from the subagent opens in `task/executor.ts` and the HTML export open in `export/html/index.ts`, which run in the parent's terminal and were clobbering the breadcrumb with their own artifact-dir session file.
- Added `resolveBreadcrumbToInteractiveRoot()` and applied it in `continueRecent()` so already-poisoned breadcrumbs pointing inside a parent's artifacts dir (`<parent>/<agentId>.jsonl`) resolve back up to the top-level interactive session.
- Added `subagent-breadcrumb.test.ts` covering both that a subagent open keeps `--continue` on the parent and that a stale subagent-pointing breadcrumb is recovered.
- Added `isUserQueuedMessage()` to `agent-session.ts`, treating only plain user turns and visible `attribution: "user"` custom messages (e.g. `/skill`) as restorable, so advisor concern/blocker notes, hidden goal/plan/budget steers, and IRC/extension asides no longer leak into the editor on Esc/Alt+Up.
- Reworked `clearQueue()` to return only user-authored messages while re-queuing advisor cards via `replaceQueues()` (so the user-interrupt abort path still re-records them as advice) and dropping other agent-authored steers to prevent a silent auto-resume on leftover internal context.
- Filtered `getQueuedMessages()` chips and rewrote `popLastQueuedMessage()` to skip agent-authored cards and pull the last user-authored entry, while `queuedMessageCount` still counts all displayable queued work.
- Extended `input-controller-skill-queue.test.ts` with a `queueAdvisorSteer` helper and cases asserting advisor/IRC cards count as pending work but stay out of chips, restore, and `popLastQueuedMessage`, and survive `clearQueue()`.
- Changed `InputController`'s no-input-waiter submit path to call `session.prompt(text, { streamingBehavior: "steer", images })` instead of `session.steer(text, images)`, so a submission made while the loop is idle between turns starts a real prompt rather than queueing behind a non-resumable transcript; the steer streaming behavior still preserves queueing if a background turn races in.
- Updated the failure-recovery comment to reference prompt dispatch rejection.
- Rewrote `input-controller-orphan-submit.test.ts` to assert the `prompt` dispatch path and added a real-session case proving an orphaned idle submit starts via `agent.prompt` (not `continue`) and leaves no queued messages.
- Added the `### Fixed` CHANGELOG block under `[Unreleased]`; its three entries are adjacent lines forming one indivisible run, so this commit also carries the changelog text for the queued-restore and breadcrumb fixes that follow.
- Updated #isRetryableReasonlessAbort to reject reasonless aborts when the streaming-edit guard flag is set.
- This prevented routing those aborts through retry logic and avoided prompt hangs or unintended guard bypasses during edit-stream recovery.
Install a subagent's ordered model candidates as child-session retry fallback chains so a retryable provider failure advances to the next candidate instead of killing the worker (issue #2750).
Isolate the plugin-discovery test from the real ~/.omp on all platforms via an os.homedir mock, cleared XDG vars, and a pre-write guard (issue #2721). Supersedes #2724 (Windows-only).
Auto-retry empty/reasonless provider aborts without model fallback (issue #2685). Includes review fix b7a3d01439: skip the retry while the session is disposing to avoid a shutdown hang.
Re-inject eager task/todo reminders after compaction (reminder-only, no forced tool_choice; issue #2681). Supersedes #2686. Known follow-up: shake-strategy compaction may duplicate a surviving prelude.
Unwrap literal <thinking> envelopes in the render-layer raw dumps (issue #2700). Includes review test 222562ecb2 (render-layer regression coverage). Orthogonal to #2698 (provider-source layer).
Default Windows bash child processes to a UTF-8 locale; win32-gated so POSIX behavior is byte-identical, and existing user LANG/LC_* values are preserved.
Load .github/instructions/*.instructions.md as rules. Includes review fix c509a5d59c: split comma-separated applyTo via parseCSV and treat **/* as an always-apply glob.
Union plugins/package.json dependencies with the lockfile so linked local plugins appear in list() and are not treated as orphans by doctor() (issue #2742). Supersedes #2743 (which left doctor() deleting linked entries).
Route MuPDF WASM print/printErr warnings to logger.debug instead of console.error/the TUI (issue #2766). NOTE: duplicates #2768 for the same issue; merged as the more complete fix (ships an end-to-end regression test) - close#2768.
A dispose-driven bare abort() yields the same empty/reason-less aborted turn as a transient provider abort, but with #isDisposed set and #abortInProgress unset. #isRetryableReasonlessAbort matched it and routed it through #handleRetryableError, which created #retryPromise and scheduled a continuation the disposed guard then skipped without resolving the promise — hanging the in-flight prompt() in #waitForPostPromptRecovery during shutdown.
Guard the predicate on !#isDisposed so lifecycle aborts settle the turn, and add a regression test. Addresses review feedback on #2689.
Empty provider-side aborted turns now enter the existing auto-retry path without switching retry model fallback, while aborted turns with partial content still settle normally.\n\nFixes #2685
The routing bypass in matchModel() returned early for any provider whose
post-slash id contained a valid @slug, so fuzzy provider-qualified patterns
over non-aggregator ids that legitimately end in @ (e.g. google-vertex/opus@default
-> claude-opus-4-8@default) resolved to nothing. Gate the bypass on
providerModels.some(supportsUpstreamRouting) so only OpenRouter / Vercel Gateway
short-circuit to the routing fallback. Addresses Codex review feedback on #2710.
GitHub documents applyTo as a single comma-separated string (e.g.
"**/*.ts,**/*.tsx") and treats both ** and **/* as all-files. The rule
loader kept the whole CSV value as one glob and missed **/* for
always-apply. Split applyTo via parseCSV and include **/* as all-files.
Addresses review feedback on #2734.
The first-message eager-task / eager-todo preludes are the oldest messages in a
session, so auto-compaction summarizes them away and the agent silently loses the
delegate-via-tasks / phased-todo guidance mid-work. Re-assert those reminders on
the auto-continuation turn that follows a compaction.
- Widen #createEagerTaskPrelude / #createEagerTodoPrelude to accept
`string | undefined`; `undefined` (post-compaction) skips only the
first-message and prompt-suffix gates, keeping the mode / agent-kind /
plan-mode / surviving-todo / active-tool gates intact.
- Reminder-only post-compaction: the todo nudge never attaches a forced `todo`
tool_choice on the resumed turn (forcing a tool after a mid-turn compaction
would override the agent's in-flight action).
- Add #buildPostCompactionEagerNudges() and prepend its output on the single
#scheduleAutoContinuePrompt continuation hook. All three call sites are
willRetry-safe, so overflow/incomplete retry recoveries never carry the nudge.
Op: extend
Installed the MuPDF WASM print hooks before markit-ai can import mupdf, preserving recoverable PDF warnings in the file logger instead of terminal stderr.\n\nAdded a regression test with a tagged PDF Screen annotation that previously reached console.error while conversion still succeeded.\n\nFixes #2766
Matched retry fallback roles against the plain model selector as well as the routed in-flight selector, preserving configured chains for compat-routed OpenRouter and Vercel models.
Added regression coverage for a compat-routed OpenRouter primary using a plain role selector.
Stopped retry fallback selector parsing from treating every @ suffix as upstream routing, preserving exact model ids like google-vertex Claude @default variants.
Resolved fallback candidates from raw selectors during preflight so routed selectors still work without corrupting exact at-suffixed ids.
Resolved retry fallback primaries from the raw selector during cooldown restore so OpenRouter and Vercel upstream pins survive fallback recovery.
Added regression coverage for routed OpenRouter primaries reverting after cooldown expiry.
Kept OpenRouter and Vercel upstream routing suffixes in subagent retry fallback selectors so same-base routed candidates stay distinct.
Resolved retry fallback candidates from the raw selector before model switching so routed fallback models keep their requested upstream route.
Placed subagent-scoped fallback chains ahead of inherited retry chains so overlapping primary selectors prefer the explicit subagent model order.
Expanded the regression to pin fallback chain insertion order when a global chain shares the same primary selector.
Installed subagent-scoped retry fallback chains from ordered task model candidates so provider failures can advance to the next configured worker model.
Updated task result tracking to surface the fallback-applied final model and added focused regression coverage for the executor wiring.
Fixes#2750
Taught plugin doctor to treat lockfile-only plugins with node_modules entries as installed instead of orphaned.
Added coverage for plugin doctor --fix after linking a local plugin without package dependencies.
Fixes#2742
Included lockfile-only linked plugins when building plugin list output so local symlink installs are visible after successful link operations.
Added regression coverage for plugin link followed by plugin list --json.
Fixes#2742
Run session_shutdown extension handlers concurrently under the existing shutdown cap so /exit and /quit do not wait one full timeout per hanging extension.
Fixes#2736
Added GitHub Copilot instruction-file discovery to the github rule provider path, mapping applyTo frontmatter into always-apply or glob-scoped rules and avoiding duplicate always-apply prompt content when context imports the same file.\n\nFixes #2731
Register tree-sitter-elisp in the shared AST language registry so
.el files infer the emacs-lisp grammar across blockRangeAt,
summarizeCode, astGrep/astEdit, and native aliases.
This fixes edit-tool block operations on top-level Emacs Lisp forms
instead of returning unsupported-language block errors.
- Add canonical emacs-lisp aliases and .el extension inference.
- Teach summaries to fold Lisp forms without grouping arbitrary lists.
- Map .el rendering and highlighting aliases through coding-agent/native.
- Cover defun, ERT, use-package, with-eval-after-load, pcase,
summary, astMatch, astEdit, and edit-tool insertion paths.
- Document the language and update package changelogs.
plugin-extensions-discovery.test.ts redirected XDG_DATA_HOME to a temp dir to isolate the plugins directory, but XDG is gated to Linux/macOS in dirs.ts, so on Windows getPluginsDir() still resolved to the real ~/.omp/plugins. The suite then wrote fixtures into -- and fs.rmSync'd the node_modules of -- the developer's real plugins directory, wiping installed plugins (green on Linux CI, destructive on Windows local).
Isolate the whole config root cross-platform: mock os.homedir() so configRoot = <tempHome>/.omp, AND clear the XDG_* vars in beforeEach (restored in afterEach). Clearing XDG is required because on Linux/macOS the resolver prefers $XDG_DATA_HOME/omp over the home config root when that dir exists, so an XDG-migrated environment would otherwise still resolve -- and these tests would rm -r -- the real plugins dir. Test-only; no production change.
Verified on Windows: real ~/.omp/plugins/package.json sha256 is unchanged across a full run; with XDG_DATA_HOME set to a sentinel containing an omp/ dir, no plugins dir is created there. 9/9 tests pass.
Installed pi packages declare their entry as `pi.extensions: ["./extensions"]` with the real module at `extensions/<name>/index.ts`, but the plugin manifest resolver only matched a file or a directory containing a direct index.{ts,js,mjs,cjs}. A directory whose entry sits one level below resolved to null, so `omp plugin install` rejected it ("declared extension entry not found on disk") and runtime load silently skipped it.
For the extensions key, resolveManifestEntryFiles now resolves a directory like OMP's configured-directory (-e) scanner: the directory's own package.json omp/pi extensions (authoritative -- a declared-but-missing entry is reported, not replaced by a decoy index), then a direct index.{ts,js,mjs,cjs}, then a one-level scan where each child directory is itself resolved manifest-first plus direct *.{ts,js,mjs,cjs} files. The directory expansion is gated to the extensions key; tools/hooks/commands keep direct-index resolution so a directory entry like `tools: "."` is unaffected.
Adds CHANGELOG Unreleased entry and regression tests for subdir-index, nested-manifest-over-index, missing-declared-entry, and key-aware (tools vs extensions) resolution. Verified: omp plugin install @zosmaai/pi-llm-wiki registers all 14 wiki_* tools; pi-mcp-adapter loads.
Prevented provider-scoped fuzzy matching from consuming OpenRouter @upstream selectors whose slug also appears in the model id.
Added resolver coverage for openrouter/deepseek/deepseek-v4-pro@deepseek:high so the upstream routing block and thinking level are both preserved.
Fixes#2708
Skipped UTF-8 defaults for an entire Windows locale or Python encoding group when inherited or per-command env already defines one variable in that group.
Fixes#2701
Added Windows-only UTF-8 defaults for non-interactive bash child process environments when the inherited env does not already define encoding or locale values.
Added regression coverage for missing, inherited, per-command, and non-Windows env behavior.
Fixes#2701
Parsed literal thinking envelopes independently before transcript rendering so interleaved thinking blocks do not collapse into one malformed wrapper. Added advisor raw dump regression coverage for sibling literal thinking blocks.\n\nFixes #2700
Cleared Anthropic thinking signatures when literal thinking-envelope normalization changes provider bytes, preventing same-model replay from pairing stale signatures with rewritten text.
Extended the wrapped-thinking regression test to verify replay demotes the rewritten block instead of sending an invalid signed thinking block.
Fixes#2695
- SetAdvisorEnabled now used settings.override for advisor.enabled when enabling or disabling, keeping advisor toggles session-local.
- /advisor on|off handlers now called refreshStatusLine after each toggle, and the status line updates immediately in the UI.
- A regression test was added to assert setAdvisorEnabled invokes override with both values and does not call set.