- Enabled inline prompt execution by allowing /loop to accept a trailing follow-up message.
- Added support for compound duration formats (e.g., 1h30m) within limit specifications.
- Updated logic to distinguish between limit tokens and prose to maintain backwards compatibility for unbounded loops.
- Refactored loop argument parsing to return both duration/count limits and optional string prompts.
- Privatized the legacy `nextToolChoice` method to `#nextHardToolChoice` to ensure all tool-choice directives flow through the unified `nextToolChoiceDirective` entry point.
- Eliminated redundant dual entry points for fetching tool choices, which previously bypassed the soft pending-preview lifecycle.
- Updated test suites to consume `nextToolChoiceDirective` where appropriate to maintain consistency with internal agent-loop logic.
The #3063 fix introduced a second mutating step — `bun update <name>` —
that rewrites bun.lock before extension validation runs. Three failure
paths could still leave the rejected commit pinned in the lockfile or
active tree:
- Extension validation throwing after `bun update` had refreshed
bun.lock — rollback restored package.json and node_modules/<name>
but never touched bun.lock.
- Feature validation (`omp plugin install pkg[ghost]`) throwing
outside the rollback block entirely.
- Runtime-config save failing after a successful install with no
rollback path.
Snapshot bun.lock alongside package.json before `bun install` runs and
route every post-install step (resolution, update, package.json read,
feature validation, extension validation, runtime-config save) through
one outer catch that restores all three (package.json + bun.lock +
node_modules/<name> from snapshot). `#rollbackFailedInstall` now
tolerates an unresolved `actualName` for failures that throw before
the dep key is known.
Three regression tests in plugin-install-validation.test.ts pin the
new contract: bun.lock restoration after a git reinstall fails
validation, bun.lock removal when it didn't exist pre-install, and
rollback on an unknown feature request.
Addresses review feedback on #3069.
bun install <spec> respects the existing bun.lock pin when the spec is
unchanged and never re-resolves the remote ref, so re-running
`omp plugin install github:owner/repo` on an already-installed plugin
reported success while silently keeping the user on the original
resolved commit (1ms no-op, no network).
PluginManager.install now follows a git re-install with
`bun update <name>` to force re-resolution of the ref against the
upstream. First-time installs (no prior dep entry) skip the update —
the initial bun install already fetches HEAD. bun update failures
trigger the same rollback path as validation failures.
Fixes#3063
Forwarded peekPendingInvoker and clearPendingInvokers from the production toolSession literal so the resolve tool can dispatch staged previews and drain stale gates in real CLI sessions, not only in unit tests.
Added a regression test exercising the production wiring through AgentSession and a phantom-gate drain via a no-invoker facade.
Fixes#3061
Cleared pending-preview markers when resolve has no runnable handler so a stale gate cannot keep forcing resolve after the invoker is gone.
Added regression coverage for apply and discard draining stale pending markers.
Fixes#3061
- Introduced `withEmptyCompletionRetry` utility to manage bounded retries with exponential backoff for empty streaming responses.
- Integrated completion validation across Anthropic and OpenAI providers to ensure robust handling of intermittent empty outputs.
- Updated `omp bench` and `omp dry-balance` to correctly resolve extension-contributed providers and report content-less runs as failures.
- Added comprehensive unit and regression tests to validate retry logic, provider resolution, and failure reporting metrics.
Kept observing a status-line usage fetch after the startup timeout so late successful reports still refresh the quota segment instead of being hidden behind the timeout backoff.\n\nFixes #3057
Deferred the status-line quota refresh off the render path and raced it against a short startup timeout so slow Anthropic usage lookups cannot pin interactive startup. Added regression coverage for non-synchronous refresh startup and timeout backoff.\n\nFixes #3057
- Tighten invalidation logic to only trigger when a demonstrably warm cache (previously read) goes cold.
- Ignore cold transitions following write-only turns to prevent spurious markers during initial cache warming or after natural TTL expiry.
- Update test suite to verify that consecutive cold turns following an initial write do not trigger invalidation alerts.
- Improved thinking loop detection logic by refining text normalization and treating stalls as retryable errors.
- Instrumented the agent session to recognize thinking loop markers within retryable error conditions.
- Automated the clearing of stale error banners upon successful auto-retry execution.
- Added comprehensive test coverage for chunked thinking loop errors and banner management.
- Moved authentication logic to `perplexity-auth.ts` to share logic between search providers and CLI commands.
- Updated authentication priority to prefer browser cookies over OAuth tokens during search operations.
- Modified the `token` CLI command to display active OAuth tokens when both an OAuth token and an API key are configured.
- Added comprehensive unit tests in `perplexity.test.ts` to verify authentication priority and precedence.
- Replaced usage of `ReturnType<typeof setTimeout>` and `ReturnType<typeof setInterval>` with the explicit `Timer` type across the codebase.
- Updated several type definitions and function signatures to use concrete types instead of inferred return types for improved clarity and maintainability.
The PR fixed the -32601 hang for the defined server->client refresh
requests but missed two real spec methods of the identical class:
workspace/inlineValue/refresh (LSP 3.17) and workspace/foldingRange/refresh.
A server emitting either still received Method not found and could stall.
Add both to the void-ack chain and extend the regression test.
- Implement JSON repair and strict argument validation to sanitize raw payloads and redact sensitive information from agent event logs.
- Add automatic authentication fallback for benchmark model resolution to ensure consistent performance testing across providers.
- Refactor search tool API parameters by replacing `i` with a case-sensitive `case` boolean flag for clarity.
- Update session history formatting to ensure empty objects are consistently serialized as `{}` instead of empty strings.
- Renamed the global `INTENT_FIELD` constant from `_i` to `i`.
- Updated documentation strings, type annotations, and test expectations across packages to reflect the new field name.
- Ensured consistent usage of the constant in tool schema construction and intent serialization.
- Fixed `SYSTEM.md` integration to correctly include custom-rendered sections like rules and skills.
- Consolidated system prompt validation by requiring `<skills>` tag presence instead of specific prose.
- Removed redundant system prompt math-formatting tests and orphaned task batch documentation tests.
- Replaced regex-based markdown detection with a stateful parser in `detectLiveReflowingMarkdown`.
- Correctly ignore table delimiters and mermaid markers when they appear inside fenced code blocks.
- Added tests to verify that code blocks containing markdown-like syntax do not prevent commit stability.
- Prevent object reference sharing between agent snapshots and stream events by deep-cloning tool-call arguments.
- Stabilize GFM tables and Mermaid diagrams during streaming by delaying transcript block commits until content finalization.
- Implement session resume safety to prevent crashes when working directories are missing.
- Add comprehensive test suites to verify streaming commit stability and immutable snapshot isolation.
- Introduced `abortableSource` as a lighter, direct-reader async generator.
- Removed the `createAbortableStream` public API to eliminate unnecessary stream wrapper layers.
- Updated internal stream processing to use `abortableSource` for improved memory and performance.
- Replaced O(n) `Array.shift()` calls with O(1) head-index tracking in `RawSseDebugBuffer`.
- Implemented lazy compaction to reclaim the dead-prefix memory only when the leading window grows sufficiently large.
- Added comprehensive tests to verify ordering, dropped count accuracy, and buffer limits under heavy load.
- Export `directoryExists` in `utils` to safely validate working directories before traversal.
- Update `SessionManager` and startup logic to fallback to the launch directory if a session's recorded working directory no longer exists.
- Add regression tests to ensure sessions now correctly adopt the launch directory instead of crashing on missing paths.
Skip the secondary loadSystemPromptFiles capability walk when the caller already controls block 0 via customPrompt/resolvedCustomPrompt, so project/user SYSTEM.md cannot silently augment a CLI --system-prompt override.
Fixes#3014
handleServerRequest fell through to a JSON-RPC -32601 Method not found for several defined server -> client requests (window/showMessageRequest, window/showDocument, workspace/{semanticTokens,inlayHint,codeLens,codeAction,diagnostic}/refresh). Servers that block on a real reply -- the same failure class as the client/registerCapability hang fixed in #3029 -- could stall waiting for an acknowledgement that never came.
Reply with the spec no-op result instead: null for showMessageRequest / *Refresh, { success: false } for showDocument. Headless omp cannot honour the UI surface, but it still owes a defined response.
Fixes#3044
ModelRegistry registers a built-in llama.cpp discovery as `provider:
"llama.cpp"` (model-registry.ts:1063), so a reverse-proxied or
public-DNS llama.cpp endpoint never trips the loopback heuristic and
was still falling through to no append-only context.
Add "llama.cpp" to LOCAL_INFERENCE_PROVIDERS, refresh the docstring
on `hasLocalLoopbackBaseUrl` (it covers user-defined providers; built-
in local ids are caught by the allowlist), and extend the test to
exercise a public-host llama.cpp baseUrl so the allowlist path is
covered independently of the loopback heuristic.
Refs #3033
Ollama, LM Studio, and llama.cpp / vLLM all do byte-prefix KV cache reuse
on the model server side. The agent loop's non-append-only path rebuilds
the system prompt and tool catalogue on every turn through fresh
allocations (`normalizeTools`, `convertToLlm`, optional memory-backend
`beforeAgentStartPrompt` injection), which dirties enough leading bytes
to invalidate the cache and force a full prompt re-evaluation.
`shouldAutoEnableAppendOnlyContext` previously only recognized DeepSeek
and Xiaomi Token Plan. Extend the auto-detect:
- Allowlist the known local-server provider ids (`ollama`,
`ollama-cloud`, `lm-studio`).
- Detect user-defined local servers by parsing `baseUrl`: loopback,
RFC1918 private IPv4, and `.local` mDNS hostnames.
- Keep the existing `compat.supportsStore` opt-in escape hatch and the
explicit `provider.appendOnlyContext: on`/`off` override paths.
Regression coverage in `append-only-context-mode.test.ts` exercises
each new positive case plus negative samples (172.15/172.32 just outside
RFC1918, public hosts, malformed URLs).
Fixes#3033
After `shutdownMnemopiEmbedClient()` clears `#worker` (session dispose, or
worker crash), mnemopi still holds the cached `LocalEmbeddingModel` wrapper.
The next embed re-spawned a fresh subprocess that had never received
`init`, and the bare `embed` request tripped the "embed before init" guard,
breaking local embeddings for the rest of the process.
- Carry `model` + `cacheDir` in every `embed` IPC; bind both into the
`MnemopiSubprocessEmbeddingModel` closure when the wrapper is created.
- Worker calls `ensureLoaded(model, cacheDir)` in `handleEmbed` (idempotent
for the same key, so steady-state embeds pay nothing). Drops the
"embed before init" guard — `embed` self-initializes.
- Promotes the internal `WorkerHandle` interface to `MnemopiEmbedWorkerHandle`
so the test seam can construct a fake worker.
- New regression test drives a fake worker, terminates + re-embeds the SAME
cached wrapper, and asserts every embed message still carries the bound
`(model, cacheDir)`.
Per review on #3034.