- Capped directory-alias rewrites per lookup (ELOOP-style, 40) so a directory
symlink targeting its own subtree (a -> a/b) throws a catchable ToolError
instead of looping forever growing the path.
- Deferred pending tar link resolution while any directory on the target path
is itself an unresolved link, and rewrote targets through established
directory aliases before the exact-path lookup, so file symlinks routed
through directory aliases materialize instead of dangling.
- Regression tests reproduce both shapes: pre-fix the aliased symlink read
failed with 'cannot be materialized' and the self-cycle read hung.
- Refactored and condensed numerous system prompts, agent instructions, and tool documentation files across packages.
- Streamlined workflow rules, formatting constraints, and execution guidelines for improved clarity and brevity.
- Updated discovery rules, recommendation criteria, and syntax standards in prompt templates.
- Update the ty parser regex to correctly match file path and position before the severity and error code.
- Adjust discovery prompt documentation and test cases to match the revised ty output format.
- Added a markdown template defining a tool-only turn directive for Gemini models.
- Appended the forced tool directive to request contents when using Antigravity Gemini routes with forced tool mode.
- Added discovery subagent and custom checker specifications for alternative toolings across multiple languages.
- Implemented interactive TUI flows for target picking and free-form request discovery.
- Added output parsers for popular static analysis and linting tools.
- Increased default maximum subagents cap and documented the new capabilities.
- Implemented the `omp compress` command with batch processing, file resolution, and concurrency support.
- Added the semantic compression protocol, session factory, and rewrite-approve evaluation loop.
- Included prompt templates, tool descriptions, and comprehensive test coverage for compression targets.
- Generalized the progress reporter module for shared use across CLI commands.
Symlink targets that normalize to the archive root (current -> ., dir/up -> ..) now resolve as directory aliases to the root instead of being treated as dangling links. The lookup normalizer distinguishes an empty root target from an escaping target, and ArchiveReader treats a resolved-empty path as the root directory.
Fixes#4774
GNU 1.0 sparse PAX entries now list under GNU.sparse.name with GNU.sparse.realsize as the displayed size, so root listings no longer expose the internal GNUSparseFile path and reads of the real name reject as sparse instead of reporting the member missing. The on-disk header size still drives offset advance and truncation.
Fixes#4774
Kept directory symlinks as one alias node and rewrote requested paths through aliases in ArchiveReader instead of cloning every target descendant during indexing.
Full archive materialization now fails explicitly on directory aliases rather than expanding them without a bound.
Fixes#4774
Resolved safe file and directory symlinks against indexed members, while retaining dangling links as listed nodes that fail explicitly when read or materialized.
Required fully buffered tar inputs to reach an end-of-archive zero block so truncated downloads cannot expose partial listings.
Fixes#4774
Versionless Fable/Mythos aliases (bundled claude-fable-latest) never parse a numeric version, so the parser path missed them and they fell to the 1568px default. Restored the /claude.*(fable|mythos)/i rule ahead of the generic Claude rule, mapping to the shared high-res tier.
Added regressions for anthropic/claude-fable-latest and its ~ prefixed alias.
Replaced the local Opus version regex with the shared catalog Anthropic identity and semantic-version parser. This recognizes both kind-first and version-first model IDs, provider proxy prefixes, and multi-digit minor versions while preserving the 4.7 floor.
Added regressions for anthropic--claude-4.8-opus and claude-opus-4-10.
MODEL_VARIANTS gated the 1932px frame tier on /claude-?opus-?4[.-][7-9]/i,
so claude-opus-5 fell through to the generic /claude/i entry and rendered at
the 1568px default reserved for older lines that downscale. The 1932px tier
tracks the Anthropic 4,784 visual-token cap — a family-wide billing property
opus-5 shares with opus-4-8 — so the version bound was stale rather than a
per-version eval gap.
Widened the pattern to cover Opus 5 and later; 4.0-4.6 still keep the safe
1568px default. Documented why 1932 specifically (largest square not
downscaled under the 4,784-patch cap, kept below the 2000px per-image limit).
Added regression assertions for opus-5/opus-6 (high-res) and opus-4-6
(default).
Fixes#8256
Headless `omp -p` armed an interactive plan-review flow whenever
plan.defaultOnStartup was set. Its only headless exit was a watcher that
fired on a successful `xd://propose` execute-dispatch, so any turn where
the model did not emit exactly that dispatch stranded until --max-time,
printing nothing. --plan-yolo could not rescue it because print mode's
arming clashed with the prewalk coordinator's plan-yolo handoff.
Print mode no longer honors the startup default: headless has no surface
to review, approve, or exit a plan. It writes a one-line stderr note and
runs the prompt normally. --plan-yolo remains the deterministic headless
plan flow and no longer clashes.
Fixes#8272
- Added a curated think gallery fixture; the generic fallback carries no
thoughts field, so the streaming state rendered zero lines.
- Seeded the shared test registry with a runtime openai key: the prompt
preflight validates through the registry, not the per-request getApiKey
override, so keyless CI runners threw before reaching the mock server.
- Expected reasoning effort "none" — the only disable level the Responses
wire accepts; "off" is not a wire value.
- Added support for external thinking and forced reasoning disablement across AI provider options and request transformers.
- Implemented the private scratchpad think tool along with its renderer, system prompt rules, and schema configuration.
- Updated agent session management and SDK tools to support dynamic runtime activation of the think tool via the externalThinking setting.
- Added comprehensive unit tests covering reasoning fallbacks, tool activation, and rendering behavior.
Implemented 2025-11-25 Streamable HTTP polling semantics for POST SSE responses: retain event IDs and retry intervals, wait as instructed, and reconnect with GET plus Last-Event-ID until the originating JSON-RPC response arrives.
Extended the shared SSE parser to expose valid id/retry fields and control-only events so reconnecting consumers do not need to reparse raw lines.
Fixes#8264
The header is transport-owned. Strip any user-configured MCP-Protocol-Version so it cannot leak onto the initialize request before negotiation, nor override the negotiated value afterwards.
Fixes#8264
A server supporting only an older MCP revision may reject an initialize request that already carries a newer MCP-Protocol-Version header. The spec requires the header only on requests after initialize. Hold it back until the initialize response is negotiated (setProtocolVersion), then echo the negotiated value.
Fixes#8264
Treat AWS_BEDROCK_SKIP_AUTH as configured authentication for the Amazon Bedrock registry entry before probing shared AWS credential files. Keep Bedrock Mantle gated on real AWS credentials.
Fixes#8267
The Streamable HTTP transport never emitted the MCP-Protocol-Version header and the client pinned the stale 2025-03-26 revision. Spec-current servers (e.g. AWS Bedrock AgentCore Gateway with an outbound per-user OAuth target) discard the negotiated version and deny every tools/call with a generic internal error.
Bump the negotiated version to the current stable 2025-11-25 (MCP_PROTOCOL_VERSION) and echo the negotiated version in the MCP-Protocol-Version header at the transport's single #fetch choke point, so it rides GET/POST/DELETE requests uniformly.
Fixes#8264
/handoff mints a fresh session via newSession(), producing a new
artifactsDir and an empty local/ root. The handoff document routinely
references plans and scratch files under '/data/workspaces/can1357__oh-my-pi__8261/.omp-session/2026-08-11T16-39-09-489Z_019ff1b1-31b1-7000-81f5-c540f4ebf43d/local/,' so every reference
became a dangling pointer in the new session. The plan approve-and-execute
path already copies artifacts across the boundary; handoff did not.
Extracted the plan-approve copy helper into a shared copyLocalArtifacts()
in local-protocol.ts and invoke it across the handoff session switch
(best-effort, since the switch is already committed).
Fixes#8261
Resolved hard-link targets after indexing so forward links and chains reuse the referenced member's storage and size. Missing, directory, or cyclic targets now surface catchable archive errors instead of silently dropping paths.
Fixes#4774
A gzip stream whose decompressed payload never presents a complete tar header or terminating zero block (a plain .txt.gz, or a tar truncated before the first header) now raises a catchable ToolError instead of returning an empty index rendered as '(empty archive directory)'. fetch falls back to binary rendering.
Fixes#4774
A member header declaring more bytes than remain in the buffer now throws a ToolError during indexing instead of being listed as a valid entry that only fails on read.
Fixes#4774
- Parsed tar and tar.gz members in-process with bounded gzip inflation.
- Added UTF-8 ustar-prefix coverage for the minimal libarchive crash shape.
Fixes#4774
- Deleted the IPv6-wildcard coexistence test: on Linux `::` binds dual-stack
by default, so the flow's 127.0.0.1 bind genuinely conflicts and port
fallback is correct there — the test premise only holds on macOS.
- Stale /launch assertion no longer requires the freed ephemeral port to stay
unbound (parallel test files reclaim it); it now asserts the stale authorize
URL is never served again.
- Extracted version verification logic into a reusable function accepting an explicit binary path.
- Updated shim takeover to verify the newly placed executable path directly instead of re-resolving via PATH.
- Added `resolveReleaseDist` and `shouldForceBinaryUpdate` to parse package manifests and gate major updates to binary releases.
- Implemented `updateViaShimTakeover` in `update-cli.ts` to seamlessly replace Windows script launchers with standalone binaries.
- Added comprehensive unit tests covering release distribution parsing, binary force updates, and script-shim takeover behavior.
After a prewalk hand-off plus mid-run compaction, the openai-responses input
builder re-encoded replayed assistant turns via convertResponsesAssistantMessage,
demoting their reasoning to <think> output_text and emitting no reasoning item.
DeepSeek (opencode-go) then rejected the thinking-mode continuation with
400 "The reasoning_text in the thinking mode must be passed back to the API"
and OMP looped on the unchanged request.
The encoder now synthesizes a reasoning_text reasoning item for every replayed
assistant turn when the target requires reasoning replay in thinking mode
(requiresReasoningContentForAllAssistantTurns / requiresReasoningContentForToolCalls),
carrying surviving thinking text when present, mirroring the chat-completions
reasoning_content safety net. Gated on reasoning being active for the request,
so non-DeepSeek Responses targets and reasoning-disabled turns are unaffected.
Fixes#8248
- Define a centralized `USER_AGENT` constant in `@oh-my-pi/pi-utils` formatted as `omp/<version>`.
- Replace hardcoded and platform-specific user agent strings across AI providers, catalog scrapers, tools, and search providers with the unified `USER_AGENT`.
- Add unit tests for update-cli binary release distribution gating.
- Default reasoning.summary to auto in openai-codex requests to ensure summaries are emitted by the backend.
- Gate stream_options reasoning_summary_delivery behind the PI_CODEX_CONCURRENT_SUMMARIES environment variable opt-in.
- Update tests in openai-codex-responses-lite to verify default summary behavior and opt-in concurrent delivery controls.
- Updated user agent and openrouter titles in packages/ai from Oh-My-Pi to omp.
- Integrated getOpenRouterHeaders into image generation tool requests in packages/coding-agent.
- Updated provider documentation and test assertions to reflect the rebrand.