Detected path-embedded OMP line selectors when reporting Cursor read results and stopped treating ranged payload lengths as whole-file totals.
Exposed exact source line counts from EOF-reaching read results and covered both the wire response and read metadata contracts.
Fixes#7590
The shared `recall` tool description instructs a follow-up `read memory://<id>`,
but the memory:// handler resolves only `root` and mnemopi ids. Under
memory.backend=hindsight, following the tool's own docs hit the generic
"Unknown memory namespace" error that only mentions mnemopi, causing repeated
failed reads and derailment.
Make the handler backend-aware: when a memory://<id> read arrives while a
Hindsight session is active and no mnemopi state can serve it, throw a
corrective error pointing at `recall`/`reflect` so a stray read self-corrects
in one turn.
Fixes#7587
OpenAI-compatible endpoints such as Synthetic advertise vision support through a top-level input_modalities array. Include that response field alongside direct input and nested architecture.input_modalities, with regression coverage for a catalog-absent id.
Warm context-v2 rows cached before server input-modality parsing pinned vision-capable ids at input: ["text"] until a forced refresh. Bump the namespace to context-v3 so the modality fix takes effect on the next online-if-uncached refresh, and add a regression proving v2 rows are orphaned.
Keep the richer LM Studio /api/v0/models input metadata ahead of the thin OpenAI-compatible row while retaining row-first behavior for generic openai-models-list discovery. Add a regression covering a text-only /v1/models row paired with a native VLM record.
discoverOpenAIModelsList never consulted the /v1/models row's input
field, so custom virtual tier ids absent from the bundled catalog fell
through to the ["text"] fallback and showed images: no even when the
server advertised input: ["text","image"]. Parse the direct input array
and OpenRouter-style architecture.input_modalities from the response row,
preferring server-reported modalities over native metadata and the
bundled reference.
Fixes#7583
Two recall paths shared the hasRecalledForFirstTurn flag: the agent_start
subscription (maybeRecallOnAgentStart, fire-and-forget with an unawaited
background prompt rebuild) and beforeAgentStartPrompt (awaited before the
turn builds). When the event path consumed the flag first,
beforeAgentStartPrompt returned undefined and the recalled context reached
the model only if the background rebuild had already landed -- on a fast
turn it had not, so autoRecall intermittently never reached the model.
Make beforeAgentStartPrompt the sole injection path and drop the racing
agent_start recall.
Fixes#7568
- Preserved escaped control characters for the downstream reinterpretation safety decision.
- Covered the backslash-escaped git inline shell-alias bypass.
Fixes#7552
- Treated double-quoted shell-control chars like single-quoted ones so a -c/-e reinterpretation option still gates them.
- Covered the double-quoted git inline shell-alias bypass.
Fixes#7552
- Replaced the raw character guard with quote-aware scanning while retaining command substitution and unquoted shell-control protections.
- Added regression coverage for the reported Cargo benchmark filter.
Fixes#7552
- Introduce `@oh-my-pi/omptype` as a new ArkType-compatible schema validation package featuring a lazy JIT runtime, JSON Schema emission, and compatibility adapters.
- Replace `arktype` across workspace packages and test utilities with `@oh-my-pi/omptype`.
- Add benchmark suites, tests, and documentation for the new validation engine and adapters.
- Update workspace build, test runner, and release configurations to include the new package.
- Split the Python bridge signal: the raw abort reaches tools (so
subagents die with the turn) while a shielded signal governs how long
the host waits, so a cancel can no longer settle a cell on top of a
still-running isolation merge.
- Mirrored the contract in the JS runtime: abort in-flight tool calls
immediately, then drain any deferExternalAbort phase before killing
the worker, and refuse new bridge calls once cancelled.
- Held a finished worker result until the run's tool calls drain. A
floated agent() previously settled the cell at once, dropping the
run's abort listener and leaving the subagent running with nothing
able to cancel it.
- Added regression coverage for all three, each verified to fail
without its fix.
Load project Codex MCP entries before user entries so a disabled project server claims its dedupe key before a same-named user server can survive.
Added regression coverage for project-over-user disable precedence.
Fixes#7538
Carry enabled = false through discovery so loadAllMCPConfigs' suppress
path can claim the dedupe key (keeping a same-named lower-priority
source disabled) and honor the user force-enable allowlist. Dropping the
entry outright defeated both.
Fixes#7538
Add the executable names and absolute paths that are unique to Ungoogled
Chromium to the Linux branch of systemChromiumCandidates(), including the
system-wide and per-user Flatpak shims for
io.github.ungoogled_software.ungoogled_chromium.
The entries are appended after the existing ones, so a stock Chrome or
Chromium install still wins and PUPPETEER_EXECUTABLE_PATH keeps working
exactly as before.
Closes#7509
- Rejected local model discovery at the configured deadline even when fetch ignored abort.
- Covered pending-transport behavior with deterministic fake timers.
Fixes#7482
- Added native `FileLock` bindings supporting cross-process advisory locking on Linux, Unix, and Windows.
- Replaced directory-based file locking and custom stale-lock reclamation with OS-backed native locks.
- Updated TypeScript declarations, native bindings, and package documentation for the new API.
- Added comprehensive unit tests and fixtures validating single-owner constraints and process death handoff.
- Moved the coding-agent lock-directory primitive to @oh-my-pi/pi-utils/file-lock
and migrated settings, MCP config-writer, and security store imports.
- Replaced the stats aggregator's parallel ~200-line token/breaker lock protocol
with the shared primitive: dead owners reclaimed immediately, live-but-wedged
owners after STATS_SYNC_LOCK_STALE_MS, unstamped acquisitions after the new
acquireStaleMs grace (10s).
- Shared primitive now treats EPERM kill probes as live owners.
- Rewrote the stats lock-reclamation regressions against the shared protocol
and moved the file-lock contract test into pi-utils.
Align isUnexpectedStopCandidate with #isEmptyAssistantStop: only a signed (non-whitespace thinkingSignature) thinking-only stop is a candidate. Unsigned thinking-only stops stay with the empty-stop retry path and its cap, so unexpected-stop classification no longer re-handles a turn the empty-stop cap already gave up on.
Fixes#7499
isUnexpectedStopCandidate only counted non-whitespace text blocks, so a stopReason:"stop" turn whose sole content was a signed thinking block bypassed the unexpected-stop guard entirely. #isEmptyAssistantStop treats signed thinking as terminal (not empty), so such stops fell through both recovery handlers and the agent silently stopped mid-task.
Count non-whitespace thinking blocks as candidates and feed the thinking text to the classifier when no text block is present.
Fixes#7499
Agent Hub previously pre-rendered every registry row and resolved each
row's observer via getSessions().find, which copy-sorts the full observer
map. On large rosters that made open/selection/age-tick O(all rows) and
observer lookup near O(N^2 log N).
- Add SessionObserverRegistry.getSession(id) for O(1) Map lookup
- Lazy-render hub rows around the selection within the terminal line budget
- Keep ordering, selection, status counts, overflow, badges, and task lines
- Add 10k-row regression covering bounded getSession/render work