Two fixes on top of the paged transport:
- Near-limit v2 framing no longer materializes the full base64 transport:
chunk lines are generated lazily from a single serialization, the 64 MiB
reassembly ceiling is enforced via Buffer.byteLength before any
full-payload allocation, and RPC stdout writes drain with backpressure
one physical line at a time. Peak RSS for a 63 MiB response drops
~686 MB -> ~521 MB; a rejected 80 MiB response drops ~507 MB -> ~259 MB
(parity with the v1 path).
- get_messages_page errors now carry a machine-readable code
(session_busy | stale_cursor). Both bundled clients' high-level
getMessages() drains discard partial pages and fall back to the legacy
snapshot on either code — previously a cursor invalidated by a
background mutation (e.g. an appended bash message) threw instead of
falling back. Direct page calls remain strict.
Servers may allow the unauthenticated MCP handshake yet protect individual
tool calls via _meta["mcp/www_authenticate"]. The 'reauthorization is not
required' guard would silently abort the tool-challenge reauth path.
Three read paths raced background model discovery on cold start:
1. `get_available_models` RPC (rpc-mode.ts) read the registry
synchronously and returned a partial catalog containing only
statically-bundled models.
2. `set_model` RPC (rpc-mode.ts) read the registry synchronously and
rejected discovery-backed selectors with "Model not found".
3. `--model <provider>/<pattern>` CLI flag deferred retry (sdk.ts:2078)
resolved synchronously after extension registration, before
discovery-backed providers had populated `#models`.
Paths 1 and 2 are fixed by exposing the existing in-flight background
refresh promise (`#backgroundRefresh`, already tracked and cleared by
`refreshInBackground`) via a new public
`ModelRegistry.awaitBackgroundRefresh()` method, and awaiting it at each
RPC read site. No-op when no refresh is in flight (warm sessions
unaffected).
Path 3 mirrors the cold-cache race fix already applied to the
default-role fallback on this branch (issues #6114, #6162, sdk.ts:2343):
when a deferred pattern is unresolved and any discoverable provider is
registered, run a cache-aware `refresh("online-if-uncached")` pass
before the retry. Reuses the existing discovery machinery rather than
introducing a new ordering dependency.
The `omp models` CLI never had this bug because it awaits
`modelRegistry.refresh()` directly before listing.
Behavioral characteristics:
- **Warm-session fast path preserved**: when no refresh is in flight
(`#backgroundRefresh === undefined`), `await undefined` resolves in a
microtask. No regression for sessions that don't need discovery or
have already settled.
- **Failure isolation preserved**: `refreshInBackground()` already
swallows discovery errors via `.catch(...)`, so `awaitBackgroundRefresh()`
resolves even when discovery fails — callers then read whatever models
made it into `#models` (built-in + cached). No new failure modes.
- **Scoped**: doesn't change `refreshInBackground()` semantics. Adds a
new read-only awaiter with minimal API surface. Reuses the
well-established `refresh("online-if-uncached")` pattern for the
deferred retry path.
Reproduction (get_available_models RPC, with any discovery-backed
provider configured in `~/.omp/agent/models.yaml`):
cd ~
{
sleep 1
printf '%s\n' '{"id":"m1","type":"get_available_models"}'
sleep 5
} | timeout 15 omp --mode rpc-ui --approval-mode yolo 2>/dev/null \
| grep '"id":"m1"' | jq '.data.models | {count: length, providers: ([.[].provider]|unique)}'
Before: discovery-backed provider absent from the response on cold start.
After: discovery-backed provider present.
Reproduction (--model CLI flag, same config):
omp --mode rpc-ui --model <discovery-provider>/<model-id> --approval-mode yolo
Before: exits 1 with "Model \"<discovery-provider>/<model-id>\" not found".
After: starts rpc-ui session with the requested model selected.
/usage and omp usage now report Synthetic (synthetic.new) quota state
via GET /v2/quotas (free, does not consume quota): the rolling 5-hour
request limit with per-tick regeneration rate, and the weekly credit
quota in USD. Applies to API-key credentials for the synthetic
provider; every payload section is parsed defensively since only
subscription is documented.
- Provider sign-in, theme, and web-search lists now shrink their visible row window to fit available height.
- Decorative chrome (sign-in hint, theme mock preview) yields to the list when space is tight.
- SelectList and OAuthSelector expose `setMaxVisible`/`setMaxHeight` so hosts can refit lists after construction.
- Implemented native UTF-16 text processing in Rust diff module with support for unpaired surrogates.
- Removed `similar` crate from Rust workspace and `diff` npm package from coding-agent, hashline, and natives.
- Removed jsdiff fallback wrappers and `isWellFormed()` guards from TypeScript diff implementations.
- Added comprehensive test suite for native diff functions covering random inputs and edge cases including surrogates and emoji.
- Renamed model `codex-auto-review` to `gpt-5.3-codex-spark` with updated pricing and context window.
- Merged the executor-reported fallback flag into the live-session badge path so a Fireworks Fast to base degrade (which arms no session retry state) keeps its provenance.
- Added a live-row regression test for a fallback that populates no retryFallbackModel.
Fixes#6316
- Threaded a resolvedModelIsFallback flag through AgentProgress and SingleResult.
- Set the flag from the executor retry-fallback handlers and settled results.
- Rendered the observer/no-session hub path as fallback -> provider/model.
- Added an observer-only fallback-badge regression test.
Fixes#6316
The new global smart-paste listener reused handleImagePaste(), whose
image branches insert [Image #N] into the hidden main editor when a
login/API-key prompt is focused. Mirror the enhanced-paste behavior:
show 'Image paste is not supported in this prompt' and skip image-path
detection so only clipboard text reaches the focused prompt.
Session entries keep AgentMessage objects strongly reachable for the whole
session, so WeakMap entries for compacted-away history pinned their
components' rendered layout caches forever. Rebuild now retains only
components for messages the new transcript context actually renders.
- Exposed the active retry fallback selector from live agent sessions.
- Rendered fallback rows with an explicit marker and resolved provider/model.
- Added an end-to-end fallback-to-Agent-Hub regression assertion.
Fixes#6316
Cold-opening a large read-only Advisor transcript froze the TUI for tens
of seconds: AgentTranscriptViewer.render() called the full
container.render() before ScrollView clipped, laying out every synthetic
`Session update` input as full Markdown. A 6.5 MiB __advisor.jsonl
blocked the first frame ~27s in a repro.
Synthetic (agent-attributed) inputs now render as a CollapsedSyntheticMessageComponent:
one dim summary row (heading, size, line count, ctrl+o hint) that builds
the heavy UserMessageComponent Markdown only on expand. Blocks above the
viewport never pay layout on cold open; the raw observability data in
__advisor.jsonl is untouched. Real user prompts stay fully rendered.
Fixes#6308
Shared the bundled task prewalk default between runtime execution and the Agent Control Center. Added dashboard regression coverage for task.prewalk.
Fixes#6306
The fullscreen Plan Review overlay stayed mounted, focused, and fully
interactive after a choice was picked. showPlanReview's finish() resolves
the choice promise but deliberately defers the hide until #approvePlan
(guarded for #5688/#5319/#5689), so during slow async approval work — e.g.
context compaction — arrow keys still moved the cursor and repeat
Enter/Esc were silently swallowed by the settle guard, with the
fullscreen buffer masking all progress underneath. Users on Ghostty and
macOS Terminal read this as "/plan is frozen".
The overlay now flips to a committed state the moment a choice fires:
handleInput is a no-op, and the render shows a "<choice> — submitting…"
indicator plus an "applying your selection" footer. The deferred-hide
timing is untouched, so the existing stale-buffer and focus guards stay
intact.
Fixes#5926
- Dismissed the fullscreen plan review and settled its pending choice when a turn-ending provider error is pinned.
- Added regression coverage for restored editor focus and visible error presentation.
Fixes#6086
The TUI /usage matrix sorted each quota window's account columns
independently by used fraction, so the positional `account N` labels
denoted different credentials on each row. An account exhausted on one
window but light on another (e.g. a Kimi Code account's 5h limit)
rendered its exhausted bar under a sibling that still had quota, making
the section `% free` and capacity numbers look wrong.
Order account columns once per provider (worst-first) and hold that
order stable across every window row.
Fixes#6067