- Added Fireworks provider onboarding with API-key login and credential storage.
- Added Fireworks provider registrations across stream, types, descriptors, and OAuth registries.
- Mapped Fireworks public model IDs to wire IDs for OpenAI-completion requests.
- Extended OpenAI-compatible detection to treat api.fireworks.ai as supported for streaming and max_tokens.
- Updated model catalog handling with Fireworks models plus context-window/max-token inheritance and metadata updates.
- Added Fireworks model reference loading and fallback logic to preserve best context and token caps.
- Simplified diagnostic grouping output in the LSP utility to use plain `## file` headers.
- Adjusted AstEdit, AstGrep, and Grep tools to emit file headings without the `└─` tree prefix.
- Removed the GrepTool context legend text and its related guard variable from output construction.
- Replaced `AgentTool` `nointent` and `deriveIntent` with a unified `intent` option that supports `omit`, `optional`, `require`, or a callback function.
- Updated agent tool schema injection and execution paths to inject `_i` as required/optional/omitted and to derive intent through the new `intent` callback.
- Aligned atom-edit tests with the updated default sed behavior (`g` now off by default and explicit `g: true` for global replacement).
- Added `nointent` and `deriveIntent` to `AgentTool`, and made intent-schema injection honor `PI_NO_INTENT` plus per-tool opt-outs.
- Updated tool execution and streaming UI handling to derive a fallback intent when `_i` is absent, without aborting on derivation failures.
- Marked several coding tools as `nointent` and added `deriveIntent` callbacks where needed, then relaxed prompt language to indicate intent is present on most tools.
- Replaced Puppeteer imports and package references with puppeteer-core, adding @puppeteer/browsers where needed for explicit browser management.
- Updated the browser tool to prefer a detected system Chrome/Chromium executable and respect PUPPETEER_EXECUTABLE_PATH before launch.
- Implemented lazy, on-demand Chromium download via @puppeteer/browsers with cached executable resolution and fallback error handling.
Fixes#797
- Updated `read` selector parsing for file and URL reads to accept optional leading `L` and `+` count-style ranges.
- Adjusted truncation notices and schema/help text to emit and suggest `sel` offsets without the `L` prefix, including continuation and suggestion messages.
- Updated hashline/output parsing and related tests to recognize the new `sel` formatting in truncation notices.
- Updated `formatMatchLine` to emit `*` for matched lines, a leading space for context, and a `|` anchor/content separator.
- Revised grep/hashline mismatch messages and prompts to describe the new marker and separator format.
- Aligned affected atom and hashline tests with the updated match-line prefixes and separators.
- Added `AgentRegistry` singleton with session registration/unregistration and IRC routing metadata for peer lookups.
- Added IRC messaging prompts and tooling with `irc.enabled` setting, `list/send` tool paths, and peer roster rendering.
- Changed `/btw` to session-side `runEphemeralTurn`, added background IRC exchange flushing, and fixed empty-input checks.
- Added unit tests for IRC tool and BtwController ephemeral behavior, including disabled, busy, not-found, and abort cases.
- Added a unified `job` prompt and removed `poll` and `cancel-job` prompts, documenting merged async actions.
- Renamed `PollTool` to `JobTool` and replaced `poll`/`cancel_job` tool exports with a unified `job` tool.
- Expanded `JobTool` schema to accept `poll` and `cancel` IDs, adding cancel-first execution for cancel-only requests.
- Consolidated poll/cancel rendering in `renderJob`, mapping `await`, `poll`, and `cancel_job` keys to the unified job renderer with action badges.
- Updated bash/task prompts and tests to use `job` for polling and cancellation flows, including JobTool auto-background checks.
- Added `note` support to todo-write with `op: "note"` and required `text` input.
- Added optional `notes: string[]` to todo models and preserved notes in cloning and session task mapping.
- Implemented `op: "note"` append flow and markdown `>` block serialization/parsing for todo import/export.
- Updated HUD todo rendering to append superscript `+N` note markers and show in-progress note bodies.
- Documented note operation, required text field, and note rendering rules in todo-write docs and changelog.
- Updated atom edit location parsing to treat "$" as a file-wide target for prepend, append, and sed, and rejected "^" as a supported locator.
- Added a new sed_file operation that runs line-wise substitutions across the full file, preserving ordering and trailing-newline semantics while failing when no lines match.
- Removed per-entry path overrides from atom resolution and made read selector parsing return "none" for unrecognized selectors to defer handling to specialized readers.
- Added live poll progress updates emitted every 500ms while jobs run for intermediate UI refreshes.
- Added a poll tool TUI renderer with status counts, duration, and result/error previews.
- Fixed final poll output to use current job snapshots, improving status and duration/reporting accuracy.
- Removed `pi-natives` chunk language classifier modules and all core chunk subsystems (kind, state, render, edit, resolve).
- Removed chunk-mode CLI/read/edit entrypoints, including `read` command and chunk mode registration/prompt tooling.
- Removed chunk selectors from `read` and `grep` tools, switching behavior to raw/L-range handling.
- Fixed poll wait parsing to keep defaulting to `30s` when the provided value is empty.
- Updated the todo-write prompt to require phase names to use roman-numeral ordinals and reject nonconforming identifiers.
- Refreshed the sample todo JSON invocations to use prefixed phase names such as `I. Foundation`, `II. Auth`, and `III. Verification`.
- Aligned the todo-write phase schema examples with the new roman-numeral phase naming convention.
- Added a new `async.pollWaitDuration` setting with enum values for 5s to 5m and defaulted it to 30s.
- Updated PollTool to parse the configured wait duration and include a timeout in the job-promise race before returning.
- Revised the poll tool prompt to describe timeout return behavior and discourage indefinite unproductive polling.
- Added `sed` atom editing with `g`, `i`, and `F` flags, path/anchor parsing, and conflict handling updates.
- Changed hashline and grep/read output to `LINE+ID|content` with `>` match prefixes and `:` context prefixes.
- Fixed atom anchor parsing for path-qualified locs, hyphenated single anchors, and content hints after `|` or `:`.
- Updated prompts, changelog, and tests to document and validate the new hashline and `sed` formats.
- Consolidated all former gh_* tools into a single GithubTool that routes execution by a required op field.
- Replaced gh_* tool registrations and render dispatch with `github`, including renderer key and header updates.
- Removed deprecated gh-* tool prompt files and added a unified github.md prompt covering per-op inputs and outputs.
- Updated settings-schema and ci-green prompt guidance to reference the unified github tool and `run_watch` operation.
- Updated tests and tool imports to use `GithubTool`/`githubToolRenderer` with op-based payloads and assertions.
- Changed the todo-write parameter schema from a bare operations array to an object containing an `ops` array.
- Updated request parsing and renderer logic to consume `params.ops` and `args.ops` when processing todo operations.
- Updated session and unit tests to invoke todo_write with wrapped `{ ops: [...] }` payloads.
- Limited strict tool candidates to a named allowlist instead of all opt-in tools.
- Fixed `minItems` stripping to target object-typed schema nodes, not just arrays.
- Enabled strict mode on all remaining coding-agent tools now that the allowlist guards eligibility.
- Applied HASHLINE_CONTENT_SEPARATOR in AstEditTool output so hashline entries share a shared delimiter.
- Set AstEditTool and AstGrepTool strict defaults to false for more permissive tool call input handling.
- Added `HASHLINE_CONTENT_SEPARATOR` and switched hashline formatting to colon separators across hashline helpers.
- Updated hashline prefix regexes in `edit/modes/hashline.ts` to require `:` and stop accepting tab separators.
- Updated `read.ts` and `write.ts` hashline prepending/stripping to match `LINE+ID:` content prefixes.
- Updated `match-line-format.ts` and hashline read-mode docs to document and emit `LINE+ID:content` lines.
- Updated GrepTool result-limit messaging to include a concrete next skip hint.
- Updated grep tool test assertion to verify the new skip-hint limit message.
- Changed `todo_write` to an ordered `op`-array model with `replace`, `start`, `done`, `rm`, `drop`, `append`.
- Removed legacy multi-field todo payloads and updated tests/fixtures to use ordered `{op, task?, phase?, items?}[]` args.
- Reworked todo operation execution to apply entries sequentially and validate missing or unknown task/phase IDs.
- Updated todo rendering to use `todo.content` only and changed bash artifact labels from `full result` to `raw output`.
- Consolidated grep, ast-grep, and ast-edit on required `path`, replacing `glob`/`lang`/`sel` with inline file, dir, glob, list, and URL targets.
- Changed ast-grep and grep schemas to require a single `pat` string and use `skip` pagination instead of array patterns or offsets.
- Updated argument validation to reject empty `path` and invalid `skip`, and routed grep context to session settings only.
- Updated tool prompts and tests to reflect new path globbing semantics and `first N` truncation output text.
- Updated inline argument formatting in formatArgsInline to truncate key/value pairs by width and show ellipsis when values overflow.
- Fixed JSON-tree output to hide harness-internal INTENT_FIELD and __partialJson keys from top-level tool argument rendering.
- Fixed multiline scalar rendering and empty-structure display paths in renderJsonTreeLines after tree-prefix traversal changes.
- Disabled strict schema enforcement on AskTool to relax request validation.
- Removed the optional `cwd` field from Python tool parameters and used `session.cwd` for warmup and execution context.
- Updated atom edit test fixtures to pass `set` as arrays instead of scalar strings.
- Updated `CustomToolAdapter` to read `strict` from the wrapped tool instead of hard-coding it.
- Disabled strict validation for `LspTool` and `ResolveTool` by setting their `strict` flags to false.
- Updated `YieldTool` to set `strict` false in its fallback path and remove the local strict accumulator.
- Added a regression test for tool argument coercion that preserves quoted edit arrays while stripping optional null fields.
- Updated footer branch-watcher initialization to clear cached branch state when resolving git head fails.
- Set the report_tool_issue tool definition to non-strict mode for looser argument handling.
- Added an optional strict field to CustomTool definitions to support non-strict execution mode.
- Set strict to false across built-in AgentTool and custom tool registrations, including browser, calculator, GitHub, image generation, and related utilities.
- Updated inspect-image tests to reflect the relaxed strict setting on the tool.
- Added `CodeFrameMarker` and `formatCodeFrameLine()` to centralize code-frame gutter formatting.
- Extended diff rendering to preserve `|` and `│` separators, aligning gutter markers and line numbers.
- Reworked AST, grep, hashline, Vim, and diff renderers to use shared line formatting with computed `lineNumberWidth`.
- Updated atom editing flow and tests, including `resolveAtomEntryPaths` migration and new loc-based/edge-case coverage.
- Adjusted benchmark runner early-stop configuration by passing `buildEarlyStop` through prompt collection.
- Added `openai` and `openai-codex` as image providers and let `providers.image=auto` prefer GPT images.
- Updated settings, selector, and SDK wiring so OpenAI image providers pass through `setPreferredImageProvider`.
- Replaced Gemini-only image tooling with `image-gen` and added OpenAI/Codex hosted-image execution with SSE parsing.
- Added image-gen and handoff tests, including final-yield no-compaction regression and OpenAI payload/header assertions.
- Changed hashline/atom parsing to require full `line+suffix` anchors and emit full-anchor guidance on failures.
- Updated atom/hashline prompt docs, `atom.test.ts`, and changelog entries to require exact full anchors like `160sr`.
- Added preformatted `displayContent` for read/grep/ast tools and switched renderers to prefer it in TUI output.
- Updated mismatch and grep/ast renderers to show context with `*` markers and gutter lines, removing legacy helpers.
- Expanded hashline and chunk bigram tables to 647 entries and moved chunk checksums to a 40-item namespace.
- Changed hashline anchors from `LINE#ID`/`:` to concatenated `LINEID`\t forms across parsing and tool outputs.
- Removed line-number padding and routed diff/read/grep/renderer output through raw numbers, tabs, and `toDisplayLine` formatting.
- Renamed atom ops to `pre`/`post`, removed `ins`, and updated schemas, prompts, and tests for new insertion behavior.
- Added `examples` support to `StringEnum` schemas and propagated it to tool metadata.
- Added concise descriptions and example values across coding-agent tool schemas for clearer guidance.
- Documented the new StringEnum examples capability in `packages/ai/CHANGELOG.md`.
- Cast `real` to `HASHLINE_BIGRAMS` elements in `staleBigramFor` test setup.
- Updated reviewer prompt field descriptions to refer to file paths generally instead of absolute paths.
- Reworded notebook and write tool metadata to remove absolute-path constraints.
- Added system guidance to prefer cwd-relative paths for path-style tool arguments.
- Added `between` atom edits with `after`/`before` anchors and logged them in changelog docs.
- Added `between` docs to prompt tooling, including two-anchor exception and anchor-order rules.
- Added `between` validation to reject stale anchors, invalid ranges, overlap, and nested interior edits.
- Reworked `applyAtomEdits` to apply `between` operations as bottom-up interior splices and adjacent-line inserts.
- Updated `file_path` schema description in review tool to "Path to the file".
- Added `AtomEdit` tests for `between` parsing and edge-case success/failure coverage.
- Renamed subagent completion flow from `submit_result` to `yield` across SDK tools, prompts, and docs.
- Updated executor/task handling to require and parse `yield` calls, replacing legacy submit-result extraction and state flags.
- Added `subagent-yield-reminder` and updated system prompts to require `yield` with `result.data` or `result.error`.
- Renamed hidden-tool and registration plumbing to `yield`, including discovery helpers and renderer/test surface.
- Added raw read output propagation so read/archive commands bypass anchors, line numbers, and chunk formatting.
- Fixed atom/hashline editing by tightening hashline prefixes and applying grouped anchor edits in stable order.
- Hardened chunk parsing and path handling by using `bigram_end` checks and resolving edit paths via shared `args.path` fallback.
- Updated path-related behavior for chunk, replace, patch, and hashline previews to honor optional edit paths.
- Removed mode-level param validators and replaced them with runtime handling, then removed obsolete validation tests.
- Aligned hashline and chunk token handling to `HASHLINE_BIGRAMS` in `computeLineHash` and parsing regexes.
- Removed hashline file-level `move`/`delete` options from schemas and execution so edits are in-place updates only.
- Hardened hashline prefix parsing to reject non-bigram IDs, preventing false stripping of `#` comment lines.
- Updated `read()`/prompt wording so raw reads skip prefixes and examples now show anchors like `123#th`.
- Updated hashline chunk tests for new `HASHLINE_BIGRAMS` IDs and replaced stale hash constants.
- Canonicalized file and CLI defaults from `read` to `open` across tool registration and prompts.
- Added `resolveToolAlias()` and applied alias-normalized tool selection so legacy `read` maps to `open`.
- Updated runtime, UI, and export layers to treat `open` as first-class while preserving `read` compatibility.
- Renamed read prompt docs to `open.md`/`open-chunk.md` and refreshed system guidance to recommend `open`.
- Updated tool-related tests and expectations from `read` to `open` (including test fixtures and aliases).
- Added command-marker metadata and lifecycle in process execution, including completion markers and exit-code writes.
- Refactored minimization to support `MarkedCommands` mode, token-based detection, and marker-aware stripping.
- Added `onMinimizedSave` and `saveBashOriginalArtifact` to persist full bash-original output artifacts.
- Expanded public exports and marker hooks so external command launch metadata can be controlled by consumers.
- Added AST-based minimizer planning with brush-parser to classify commands before minimization.
- Added original text capture and byte-metric `minimized` telemetry to shell execution results.
- Added minimizer configuration controls, including trust-gated loading via `settingsHash` and limits.
- Added `onMinimizedSave` callback wiring to persist minimized outputs and annotate Bash sinks with artifact IDs.
The SQLite read helper is documented as a structured selector path
with explicit pagination, while raw SQL already has a separate
q=SELECT escape hatch. This change rejects SQL control syntax outside
quoted strings so helper filters cannot override LIMIT/OFFSET, while
still allowing semicolons inside quoted literals such as LIKE '%;%'.
Constraint: Preserve the documented q=SELECT raw SQL path unchanged
Rejected: Replace where= with a new filter DSL | too broad for a regression fix
Confidence: high
Scope-risk: narrow
Directive: Keep table?where=... as a structured helper; if broader SQL is needed, route it through q=SELECT instead
Tested: bun --cwd=packages/natives run build; bun --cwd=packages/coding-agent run check; bun --cwd=packages/coding-agent test test/tools/sqlite.test.ts
Not-tested: Manual interactive omp read invocation against a live SQLite file
The structured SQLite helper interpolates `where=` directly into SQL.
A crafted clause like `where=1=1 LIMIT 1000000 --` could comment out
the helper's bound `LIMIT ? OFFSET ?`, returning the full table in
violation of the documented pagination contract.
Validate where= at the selector boundary and reject SQL comments,
statement terminators, and pagination/attach/pragma keywords. Raw SQL
remains available via ?q=SELECT... for callers that need it.
Fixes#735