- Added `maxToolCallsPerTurn` support to `AgentOptions` and `AgentLoopConfig`, with Agent getter/setter and serialized state wiring.
- Implemented stream-loop cap handling by normalizing bad values and halting after `toolcall_end` reaches the limit.
- Added `ANTHROPIC_TOOL_CALL_BATCH_CAP`=8 and wired session cap sync on init, model changes, and restore.
- Added tests that truncated a 10-call stream to 8 tool calls, and verified non-Claude models resolve no cap.
- Extracted `#loadModelsFromCurrentRegistryState()` for pure in-memory reads.
- `#loadModels()` now calls `registry.refresh()` only when no scoped models are set.
- Background provider refresh reuses the extracted method to avoid a redundant whole-registry reload after network round-trip.
- Added assertions verifying `registry.refresh` is called exactly once per selector lifecycle.
- Decoupled provider tab changes from immediate model refresh by scheduling background provider refreshes with a 120ms debounce.
- Added refresh-state tracking and spinner-based status text so the tab bar updates while a provider refresh is in progress.
- Updated model-selector tests to verify tab switches stay responsive, refreshes are delayed, and loading spinner frames appear before completion.
- Added `discovery.type: proxy` that hits `GET /v1/models` and routes each model via `supported_endpoint_types` (`anthropic` → `/v1/messages`, `openai` → `/v1/chat/completions`).
- Made provider-level `api` optional when `discovery.type` is `proxy`, since wire protocol is derived per-model.
- Increased discovery fetch timeout from 250ms to 10s to accommodate remote proxies.
- Documented proxy discovery configuration in `docs/models.md`.
- Previously only stripped dangling tool_use blocks from the trailing assistant turn; now scans all assistant turns on the resolved path.
- Builds a set of paired tool result IDs upfront to identify dangling calls anywhere in the message list.
- Adds a test covering a mid-path dangling turn alongside a correctly paired turn that must be preserved.
- Stripped `redactedThinking` blocks (encrypted, no downgradeable plaintext) from trailing assistant turns during context rebuild.
- Cleared `thinkingSignature` on `thinking` blocks so the encoder downgrades them to plain text, avoiding Anthropic's "modified latest assistant message" rejection.
- Extended existing test to cover signed/redacted thinking alongside dangling tool calls.
- Reverted in-progress/completed todo icons to pre-15.5.12 checkbox glyphs instead of status glyphs.
- Extended dangling tool_use cleanup to also strip `redacted_thinking` blocks and clear `thinking` signatures on the trailing assistant turn, fixing 400 handoff rejections from Anthropic on navigation.
- Removed todo spinner interval state and rendering hooks from InteractiveMode, and in-progress or active-matched todos now use the static running glyph.
- Removed spinner-driven matcher caching and render updates from todo list generation so running state is based on direct content matching.
- Added build-session context tests that remove dangling assistant `toolCall` entries and drop trailing assistant turns that contain only tool calls.
- BuildSessionContext now normalized a trailing assistant turn by removing dangling `toolCall` blocks when rewound or restored onto that turn.
- It dropped the assistant turn entirely when only tool calls remained to prevent reconstruction from reintroducing synthetic aborted tool results.
- Enhanced markdown rendering to insert a painted theme swatch before matching inline hex colors in prose and code spans.
- Skipped short numeric-only 3- and 4-digit values in plain text so issue-like references do not get swatches.
- Added `colorSwatch` to symbol themes and added tests for swatch rendering and surrounding-style preservation.
- Used cacheRead + cacheWrite + input as the denominator for an accurate hit rate.
- Previous logic excluded uncached input tokens, overstating the hit rate for providers that report all three fields.
- DeepSeek (cacheWrite=0) still yields correct hit/(hit+miss) with the new formula.
- Removed Ghostty-specific hardware-cursor forcing from TUI preference resolution and dropped the redundant terminal-cursor marker flag.
- Updated interactive mode editors to use `ui.getShowHardwareCursor()` so cursor mode now follows actual hardware-cursor visibility.
- Reworked terminal regressions tests to assert Ghostty respects the requested cursor preference and only emits cursor-show output when enabled.
- Rendered the plan review "keep context" selector label with the session context usage percentage when available.
- Kept the fallback label unchanged when context usage data was unavailable.
- Added coverage asserting both the percentage label and fallback label in plan review tests.
Fixes#1458
- Dropped local `renderJsonTree` and `formatJsonScalar` in favor of the shared `renderJsonTreeLines` used by tool args, MCP results, and subagent output.
- Removed `Object(N)`/`Array(N)` type labels and per-output `JSON output N` headers; type icons and bare keys are used instead.
- The `display[N]` header is now shown only when a cell emits more than one `display()` value.
- Added prompt_cache_hit_tokens / prompt_cache_miss_tokens parsing in
parseChunkUsage for DeepSeek's prompt cache format where
prompt_tokens = hit_tokens + miss_tokens.
- DeepSeek formula: input = prompt_tokens - hit_tokens (= miss, billed input),
total = input + output + hit_tokens (avoid double-counting miss in cacheWrite).
- Added cache_hit status line segment showing cache hit rate:
rate = cacheRead / (cacheRead + cacheWrite) x 100%.
- Added cache_hit to all status line presets.
Bun 1.3 compiled modules report the bunfs mount root from import.meta.dir, not their source-layout module directory. The prior helper walked four directories above that value and escaped the embedded root.
Append packages to the compiled bunfs root, while keeping a guarded suffix path for future module-specific import.meta.dir semantics. Update regression tests to pin the compiled-root behavior observed by a bun build --compile probe.
Fixes#1514
External extensions importing @oh-my-pi/pi-* values (e.g. AssistantMessageEventStream from @oh-my-pi/pi-ai) failed on Windows compiled binaries with "Cannot find package $bunfs\\root\\packages\\...". Shim paths in LEGACY_PI_PACKAGE_ROOT_OVERRIDES were built from a hardcoded POSIX literal "/$bunfs/root/packages"; Win32 normalised the leading slash to a backslash and the path never resolved against the real bunfs mount (<drive>:\\~BUN\\root\\...).
Derive the bunfs package root by walking four directories up from import.meta.dir (which oven-sh/bun#15766 confirms returns the platform-native bunfs path inside the binary). All override targets now go through path.join, so separators stay native on Windows, Linux, and macOS.
Fixes#1514
- Preserved Alt and Ctrl+Alt letter ESC-prefix matching when kitty_protocol_active is true to support mixed tmux and Kitty keyboard modes.
- Parsed two-byte ESC sequences before legacy sequence lookup so mixed-mode Meta pairs are treated as Alt letter keys instead of legacy aliases.
- Updated native and TUI key tests to verify Alt+letter and Alt+Shift+letter parsing and matching while enhanced mode is active.
Fixes#1511
- Replaced snapshot internals with full-file records and removed contiguous/sparse snapshot APIs.
- Added file-hash normalization, computed `computeFileHash`, and updated grammar/messages to 4-hex tags.
- Simplified recovery by checking whole-file hashes first, then applying merge-replay fallback after mismatches.
- Updated coding-agent tools to use `record`/`recordFileSnapshot` and skip hash headers for unsnapshotted large files.
- Expanded patcher and snapshot tests to verify 4-hex anchors, hash deduplication, and cache-capped behavior.
- Replaced bare `A B` range headers with `replace N..M:`, `delete N..M`, `insert before N:`, `insert after N:`, `insert head:`, and `insert tail:`.
- Removed `&A..B` repeat rows; insert-before/after ops now express the same intent explicitly.
- Empty replace bodies now error instead of deleting; `delete` is the canonical deletion op.
- Updated grammar, prompt, docs, tests, and all call sites to the new syntax.
- Replacement hunks now drop duplicated closing delimiters restated in the payload but surviving just outside the range.
- Ranges that swallow a structural closer the payload omits now spare that closer instead of deleting it.
- Each repair surfaces a `delimiter-balance` warning through `ApplyResult.warnings`.
- Brackets inside strings, template literals, and comments are skipped to avoid false positives.
Ghostty/cmux continued to show trails after hiding the hardware cursor because OMP switched to a blinking software cursor glyph. Keep editor cursor markers enabled when hardware cursor display is requested, but hide the actual hardware cursor on Ghostty; this gives the TUI a cursor position without emitting any cursor glyph. Also preserve the history-anchor cursor exit before public insertText, as flagged in PR review.
Constraint: Ghostty leaves visible trails for both hardware bar cursors and blinking software cursor cells during rapid input-row repaints.
Rejected: Only removing SGR blink | PTY writes still emitted the cursor glyph, so glyph afterimages could still accumulate.
Rejected: Ignoring the PR comment | public insertText callers bypass typed-character history-exit behavior.
Confidence: high
Scope-risk: moderate
Directive: Keep cursor-marker mode separate from actual hardware cursor visibility; callers that decide editor rendering must not use getShowHardwareCursor as a proxy.
Tested: bun test packages/tui/test/editor.test.ts packages/tui/test/render-regressions.test.ts; bun test packages/tui/test/*.test.ts; bun run check; Ghostty-env PTY capture of installed omp while typing abcdef emitted zero cursor-show writes, zero blink SGR, and zero input cursor glyph bytes before shell restore.
Four refinements to the sticky Todos panel on top of the live SessionObserverRegistry linkage:
- Cube animates whenever any visible open todo is "live" (in_progress, or a still-pending todo with a matching in-flight subagent). The previous subagent-only gate left lone in_progress rows on the static '⟳' fallback; ticking on an orphan in_progress row is the correct "still open" signal.
- 'normalizeForTodoMatch' now collapses any non-alphanumeric run to one space, so subagent descriptions with '#', '.', ':' etc. match todo content that omits the punctuation. Fixes the case where 3 subagents were spawned but only 2 of 3 matching todos lit up because the matcher's normalizer collapsed whitespace but left '#' intact.
- New '#reconcileTodosWithSubagents' runs on every observer-registry change and auto-checkmarks any pending/in_progress todo whose content matches a 'status === "completed"' subagent description. Failed/aborted subagents intentionally don't auto-flip - those stay open for the user (or next agent turn) to decide.
- All-done close animation: when every visible task is closed, fold the panel away over ~1.4s. A 900ms celebratory frame holds the bright bold "Todos ✓" header so the user can read the final checkmarks, then a fade through 'muted' / 'dim' with rows progressively dropped from the bottom. '#todoClosingState' state machine plays the animation exactly once per open->all-closed transition and aborts cleanly if a new open task arrives mid-animation.
Verification:
bun test test/tools/todo-write.test.ts → 24 pass / 0 fail (one new case for # punctuation tolerance)
bun run check → biome + tsgo clean
The always-on Todos panel above the editor pinned to the first 5 tasks of the active phase, so each todo_write flip mutated at most one row (color + strikethrough) and the +N more hint only shrank at end-of-phase. Marking task 1 done left tasks 6,7,... invisible until tasks 1-5 were all closed.
Introduce selectStickyTodoWindow(tasks, maxVisible=5) — returns up to 5 open (pending / in_progress) tasks in original phase order plus the count of remaining open tasks for +N more. When every task is closed, falls back to the trailing window (with +N more suppressed) so the panel keeps useful context until getActivePhase walks to the next phase. The collapsed branch of #renderTodoList now uses it; the expanded branch is untouched.
PluginManager.link symlinks the package into <plugins>/node_modules
and records it in omp-plugins.lock.json, but never writes to
<plugins>/package.json#dependencies. getEnabledPlugins iterated only
the dependency map, so the documented `omp install ./local-extension`
workflow (delegated to plugin link) succeeded but its sibling skills/,
hooks/, tools/, etc. stayed invisible after install.
Iterate the union of package.json#dependencies and
omp-plugins.lock.json#plugins so symlinked-only packages surface
alongside npm/marketplace installs. Lockfile entries whose
node_modules tree has since been deleted (stale link) are skipped
silently. Linked-only setups with no <plugins>/package.json at all
now work too.
Per-PR review feedback: https://github.com/can1357/oh-my-pi/pull/1498
Marketplace and `omp plugin link` installs write to
`<plugins>/node_modules/` rather than to `extensions:` in settings,
so the original PR still missed their sibling skills/, hooks/,
tools/, commands/, rules/, prompts/, .mcp.json sub-trees. Wire
listOmpExtensionRoots to enumerate getEnabledPlugins(cwd, { home })
in addition to CLI-injected and settings-driven roots.
Adds an optional { home } parameter to getEnabledPlugins so the
discovery loader can pass through LoadContext.home for tempdir-rooted
tests. The getPluginsNodeModules/getPluginsPackageJson/
getPluginsLockfile helpers gain the same optional home overload so
they mirror getPluginsDir.
Per-PR review feedback: https://github.com/can1357/oh-my-pi/pull/1498
Bug 1: capability loaders in src/discovery/builtin.ts only walked
.omp/ and ~/.omp/agent/, so extension packages registered via
extensions: in settings or --extension on the CLI shipped their
skills/, hooks/pre|post/, tools/, commands/, rules/, prompts/, and
.mcp.json silently — the docs at omp.sh/docs/extension-authoring
advertise the opposite. Add a new omp-plugins discovery provider that
scans every configured extension package directory for those
sub-trees, plus a small omp-extension-roots helper that resolves the
union of settings-driven and CLI-injected roots. main.ts injects CLI
extension paths via injectOmpExtensionCliRoots before any capability
load.
Bug 2: install was never registered as a top-level subcommand, so
`omp install ./my-extension` was rewritten to `launch install
./my-extension` and forwarded to the LLM as an initial prompt. Add a
top-level install command that routes local paths to plugin link and
remote specs to plugin install. Extract the command table into
src/cli-commands.ts so tests can introspect registered subcommands
without triggering cli.ts's top-level await.
Fixes#1496
- Added a new ultrathink mode module with standalone, case-insensitive detection, rainbow editor highlighting, and a hidden notice payload.
- Updated `CustomEditor` and the shared TUI `Editor` to support optional zero-width text decoration and apply the `ultrathink` styling during input rendering.
- Extended `AgentSession` prompt handling to append the hidden ultrathink notice after user turns in both streaming and non-streaming message flows, excluding synthetic messages.
- Mocked the Vertex stream E2E test to override the home directory and clear GOOGLE_APPLICATION_CREDENTIALS so token resolution uses metadata credentials instead of local ADC files.
- Updated wafer and model-registry test expectations to match current model metadata values (Qwen3.7 Max and claude-opus-4-8).
- Added a `hashRecognized` field to `MismatchDetails` and `MismatchError`, defaulting it to `true` for compatibility.
- Updated stale mismatch rejection messaging to distinguish drifted hashes from session-absent hashes with explicit guidance.
- Propagated `hashRecognized: snapshot !== null` in `Patcher` and added tests for both mismatch branches.
The memory pipeline hardcoded `Effort.Low` (stage1) and `Effort.Medium` (phase2
consolidation) when calling `completeSimple`. On models whose supported efforts
exclude those levels (e.g. `deepseek/deepseek-v4-pro` → [high, xhigh]),
`completeSimple → mapOptionsForApi → resolveOpenAiReasoningEffort →
requireSupportedEffort` threw "Thinking effort low is not supported by
<provider>/<model>" and every stage1 job was recorded as failed, blocking phase2
and producing no memory artifacts.
Route both call sites through `clampThinkingLevelForModel(model, requested)` —
the same helper already used by compaction (#1182). For `[high, xhigh]` both
`low` and `medium` lift to `high`; non-reasoning models continue to receive
`undefined`, preserving prior behaviour.
Fixes#1480
Limited bunfs package-root overrides to compiled-binary mode so non-compiled installs (monorepo, source-link, node_modules) keep resolving legacy pi roots through Bun's package resolver instead of a hardcoded source-tree path.
Refs #1474
Retried original legacy specifiers after canonical peer fallback fails so direct plugin imports with only legacy-scoped peer dependencies continue to load.
Listing the coding-agent's own ./src/index.ts as a bun --compile extra entrypoint silently breaks the CLI binary startup. Added a dedicated legacy-pi-coding-agent-shim.ts that re-exports the canonical barrel, registered the shim instead of the package index, and updated the compat resolver to point pi-coding-agent at the shim path.