- Added `WorkerInbox` and `installWorkerInbox(port)` to queue worker messages before bind.
- Added `consumeWorkerInbox()` to replay buffered messages and clear one active inbox.
- Added buffered inbox consumption in JS and tab worker transports before direct message handlers.
- Normalized worker selector arguments to the `__omp_worker_*` naming across workers and tests.
- Fixed OAuth credentials to keep unknown fields in schema while preserving existing shape checks.
- Fixed MCP OAuth IDs to be profile-scoped and avoid deleting credentials from non-active profiles.
- Fixed string-flag parsing so PROFILE_BOOTSTRAP_BOUNDARY tokens are not consumed as values.
- Fixed active-profile directory resolution to refresh after env updates so profile .env overrides apply.
Loaded Kokoro's side-installed transformers runtime by absolute path before requiring kokoro-js, avoiding host/workspace onnxruntime libraries in the worker process.
Kept runtime-cache bare module requests inside the registered runtime cache when the parent module is already inside that cache, and covered the resolver boundary with a regression test.
Fixes#2591
Adds regression coverage the PR's stated 'bounded retries' contract
needs but lacked: gives up after the 4-retry bound and rethrows the
original EBUSY (no infinite loop, no masking), skips non-transient
codes, and never retries off Windows. Also adds the missing final
newline biome required on the new test file.
Addresses review feedback on #2382.
- Added unified `omp setup speech` flow with JSON/check modes and model picker.
- Added local STT pipeline with sherpa workers, recorder/download flow, and streaming inference.
- Added local TTS pipeline with `omp say`, backend selection, and streaming vocalization.
- Replaced legacy speech settings with unified `speech`/`speechgen` configuration keys.
Always-on LoopWatchdog (armed in TUI.start/stop) logs ui.loop-blocked with blockedMs and the current loop phase on the rising edge of a late probe tick. New pushLoopPhase/popLoopPhase/currentLoopPhase stack in pi-utils feeds it; breadcrumbs at in-process subagent dispatch (subagent:<id>) and the SelectList fuzzy filter (ui.select-filter) attribute residual main-thread stalls.
- Reworked createAbortableStream to forward abort signals to the source stream reader.
- Added cleanup logic so abort/cancel/error paths release locks and emit AbortError consistently.
- Updated related tests to verify source-stream cancellation and handoff escape-handler behavior.
- Added isMacosMallocStackLoggingEnvName() function to identify MallocStackLogging and MallocStackLoggingNoCompact variables. Updated filterProcessEnv() and Bun.env initialization to skip these variables during environment filtering. Added test case to verify malloc stack logging toggles are dropped instead of forwarded.
- Moved `fastembed` and `onnxruntime-node` to optional peerDependencies.
- Fixed bundled installs that could not resolve `onnxruntime_binding.node`.
- Added shared `runtime-install` utilities for on-demand module resolution.
- Added tests for runtime-resolution parsing and exact peer-version checks.
The format-on-write path sent a hardcoded {tabSize:3, insertSpaces:true}
on every textDocument/formatting request from two duplicated DEFAULT_FORMAT_OPTIONS
constants. Servers that honour tabSize for re-indent (yaml-language-server, the
common YAML/Kustomize/Flux case) reserialized 2-space files at a 3-space stride
on every write — exactly the corruption reported on Kubernetes/Flux YAML repos.
Replace both constants with a single resolveFormatOptions(filePath, content)
helper that layers, in order:
- .editorconfig (indent_style, indent_size, tab_width) via the new
getEditorConfigFormatting() helper in pi-utils — strict, no fallback.
- Indent sniffed from the in-memory content the agent is about to write
(first indented line decides spaces vs tabs; GCD of space-indent widths
fixes the unit).
- Hardcoded 2-space fallback. The previous 3-space stride was an unusual
default that actively damaged every file with a 2/4-space convention.
Tests cover the editorconfig and content-sniffing paths plus a direct
regression check that 2-space YAML stays 2-space (the issue's repro).
Fixes#2329
- Added a new @oh-my-pi/snapcompact package and redirected compaction call sites to it.
- Added provider-aware snapcompact shape resolution for model-specific mixed-frame behavior.
- Added optional image detail support by extending ImageContent and passing hints through OpenAI providers.
- Added native snapcompact render options, including 5x8/8x8 font loading and palette/geometry controls.
- Fixed help rendering so `--help` no longer triggers unrelated command loaders.
- Fixed startup span logging to emit markers only with PI_DEBUG_STARTUP set.
- Fixed logger startup trace behavior for `:start`, `:done`, and `:fail` phases.
- Fixed prompt template processing with cached raw-template compilation and safer formatting.
- Optimized symbol and tag parsing in prompt templates via manual parsers.
- Fixed help rendering so `--help` no longer triggers unrelated command loaders.
- Fixed startup span logging to emit markers only with PI_DEBUG_STARTUP set.
- Fixed logger startup trace behavior for `:start`, `:done`, and `:fail` phases.
- Fixed prompt template processing with cached raw-template compilation and safer formatting.
- Optimized symbol and tag parsing in prompt templates via manual parsers.
- Packed id via one BigInt hex format instead of four 16-bit segments (~1.7x faster).
- Extracted timestamp via exact double arithmetic, dropping BigInt round-trip.
- Lazily initialized the default source.
- Added round-trip and ordering tests across packing boundaries.
- Packed id via one BigInt hex format instead of four 16-bit segments (~1.7x faster).
- Extracted timestamp via exact double arithmetic, dropping BigInt round-trip.
- Lazily initialized the default source.
- Added round-trip and ordering tests across packing boundaries.
Native user-level config discovery (MCP, skills, rules, slash commands, prompts, instructions, hooks, tools, settings, extensions, and the top-level SYSTEM.md/RULES.md/AGENTS.md) now resolves the user scope through getAgentDir() in builtin.ts, omp-extension-roots.ts, and the discovery-layer getUserPath() helper. A named profile sees only its own ~/.omp/profiles/<name>/agent config instead of the default profile's ~/.omp/agent leaking into every profile, matching the /mcp config writer and getMCPConfigPath("user").
discoverExtensionModulePaths now detects top-level symlinked directories that the native glob skips (follow_links=false) and synthesizes their index/package.json entry-point matches, so an extension shared across profiles via a symlink loads like a real directory. Symlinked extension files were already handled.
cli: check --tiny-worker on the profile-flag-stripped resolvedArgv, matching the adjacent --smoke-test check and launch routing.
- Moved the overlong-component guard to run after resolveFilePath so syntactically noisy but valid paths like long/../src/file.ts still honor editorconfig rules.
- Added a regression test that proves normalized paths with an eliminated overlong component resolve the configured tab width.
Fixes#1872
- Tightened parseCachedEditorConfig to absorb any FsError, not just
ENOENT. Editorconfig lookup is best-effort indentation hinting; an
unreadable .editorconfig (ENAMETOOLONG, ENOTDIR, EACCES, ELOOP,
EINVAL, …) means "no usable config here", not a fatal condition for
callers like the edit renderer.
- Added a path-component length gate (NAME_MAX = 255 bytes) in
getIndentation that short-circuits to the default tab width before
any syscall. Renderers can hand arbitrary strings into replaceTabs
(e.g. a malformed edit tool call whose file_path is gibberish);
attempting to open <dir>/.editorconfig for a 500-byte component
would otherwise crash the TUI with an uncaught ENAMETOOLONG.
- Added regression tests covering both safety nets.
Fixes#1872
parseCachedEditorConfig caught only ENOENT, so an oversized path segment
(e.g. a 2KiB garbage string emitted by a hallucinating model) blew up
the renderer with an uncaught ENAMETOOLONG from fs.readFileSync. The
editorconfig probe is best-effort — there is no useful difference
between 'file missing' and 'open() refused for any other reason' from
the renderer's perspective. Catch every error, cache the miss so we do
not re-probe the same bogus path on every redraw, and add a regression
test that exercises the 2KiB-segment path through getIndentation.
Fixes#1871
Move the color math added for the session-accent fix into the shared
@oh-my-pi/pi-utils color module instead of a coding-agent-local file:
- colorLuma, relativeLuminance, and hslToHex now live in
packages/utils/src/color.ts (hslToHex lifted out of session-color.ts).
- Drop the duplicate hex parser: toRgb reuses the existing hexToRgb and
paletteToRgb returns the shared RGB type, so hex parsing lives once.
- Delete packages/coding-agent/src/utils/color.ts; theme.ts and
session-color.ts import from @oh-my-pi/pi-utils.
- Move the color unit test into the utils package; repoint session-color
test imports.
No behavior change to accent luminance capping.
- Classified each session's final message as done, interrupted, aborted, error, or pending from a 32 KiB tail read.
- Rendered the status as a colored segment on the session metadata line.
- Added `peekFileTail` and `readTextSuffix` across storage backends to read file tails in one pass.
- Simplified `MemorySessionStorage` to a string array mirror with a sidecar mtime map.
The MallocStackLogging / MallocStackLoggingNoCompact deletion was relocated to the
coding-agent CLI entrypoint (where it runs before any subprocess/worker inherits the
env); importing dirs.ts no longer mutates process.env as a side effect. A spawned-child
probe test asserts the inherited macOS malloc vars survive the import. Also documented
the public profile dirs API (setProfile/getActiveProfile/getProfileRootDir,
normalizeProfileName, resolveProfileEnv) and profile-aware directory resolution.
- profile-alias: refuse to rewrite a managed block whose start marker lacks a
matching end marker instead of appending, which on the next install would
splice from the stale start through the new end and delete intervening user
shell config (data loss in dotfiles).
- dirs/cli: add resolveProfileEnv so OMP_PROFILE takes precedence and an
explicitly-empty OMP_PROFILE selects the default profile instead of falling
through to PI_PROFILE; share the rule across both env-read sites.
- dirs: reject uppercase profile names so profile identity/isolation is stable
across case-sensitive and case-insensitive filesystems.
- profile-bootstrap: treat an unclassified bare long option as a possible
extension string flag and forward its successor untouched (never as a global
--profile/--alias), while exempting known value-less launch flags via
VALUELESS_FLAGS so 'omp --print --profile work' still selects a profile.
- tests: cover all four contracts.
- Add env restoration for OMP_PROFILE and PI_PROFILE in profile directory tests
- Add regression coverage for names like "work." and "work.." being rejected
- Keep test isolation symmetric with other environment-backed profile resolution paths
- Make module-load profile resolution resilient to invalid env profiles
- Prevent profile-derived PI_CODING_AGENT_DIR from becoming the default baseline
- Refresh pre-profile agent-dir baseline correctly in tests and during resets
- Anchor install-id storage under base config root so one ID spans all profiles
- Add regression tests for profile reset behavior and install-id persistence
Added named OMP profiles that isolate agent state (auth credentials,
sessions, settings, model cache, history, memories, blobs, plus
config root subdirs) under `~/.omp/profiles/<name>/agent/`. Activated
via `--profile <name>` or `OMP_PROFILE=<name>`; `default` maps back to
the regular `~/.omp/agent/` tree.
Added `--alias <command>` to generate a shell shortcut (e.g.
`omp-work`) that forwards `omp --profile <name>`. Detects the active
shell (bash, zsh, fish, PowerShell, pwsh), writes a wrapper into the
correct rc file, and preserves subcommands like `update`, `--version`,
and `--model` because the wrapper passes through argv unchanged.
The `--profile`/`--alias` bootstrap pre-parser lives in
`packages/coding-agent/src/cli/profile-bootstrap.ts` and runs before
any module that touches `getAgentDir()` (notably `@oh-my-pi/pi-utils/env`,
which eagerly loads `.env` from the agent directory at its own import
time). The pre-parser mirrors `parseArgs` value-consumption rules and
honors `--`, so commands like `omp --system-prompt --profile foo` pass
the literal `--profile` through as the prompt body instead of silently
activating profile `foo`.
XDG resolution for named profiles is keyed on the profile-specific
XDG path (`$XDG_*_HOME/omp/profiles/<name>`), never the base app root,
so a profile's location is decided once at first activation and stays
stable even after `omp config init-xdg` materializes the base later.
The default profile keeps its existing base-app-root check.
`setProfile(undefined)` (and `setProfile("default")`) restores the
pre-profile `PI_CODING_AGENT_DIR` snapshot taken at first activation
instead of unconditionally deleting it. `setAgentDir` refreshes the
snapshot since that call is the user explicitly redefining the
baseline.
Validation rejects profile names that match `.`/`..`, fail
`/^[A-Za-z0-9][A-Za-z0-9._-]{0,63}$/`, or hit a Windows reserved
device name (`CON`, `PRN`, `AUX`, `NUL`, `COM0-9`, `LPT0-9`, including
dotted variants like `CON.txt`) — those would let `setProfile` accept
the input only for directory creation to fail later with confusing
errors on Windows.
- Clamped `formatDuration` to return `0ms` for non-positive, NaN, or infinite inputs.
- Updated usage report rendering to suppress reset countdowns when `resetsAt` is absent or no longer in the future.
- Added unit tests for `formatDuration` covering clamped values and standard duration formatting.
- Added a custom JSON replacer that unwraps `Error` instances in logger output, preserving name, message, stack, cause, and enumerable fields.
- Updated uncaught-exception and unhandled-rejection logging paths to pass only `{ err }`, relying on the logger serializer for full error details.
- Extended transient socket-close matching to detect HTTP2 stream reset/refused/calm errors and added regression tests for logger error serialization behavior.