- Short-circuited agent-end handling when a session was still streaming.
- Skipped turn-teardown steps for superseded agent_end events that arrived out of order.
- InputController now dispatched Esc to active viewSession operations, aborting compaction, handoff, and retry directly.
- Removed competing onEscape handler swaps across command and event controllers so overlapping auto/manual flow events no longer overwrote cancellation callbacks.
- Compaction now propagated fetch options and rethrew aborted signals so cancellations were not treated as remote failures.
- Switched extensibility loader imports from namespace-style `zod` imports to named `z` imports in `zod/v4`.
- Updated extensibility type interfaces to use `typeof z` for injected `zod` modules in hook, extension, tool, and command APIs.
- Removed `userMessageId` from `AcpAgent` prompt state and response payloads.
- Removed `models` from new/load/resume/fork session responses and deleted model-state building.
- Removed `unstable_setSessionModel` and routed model changes through `setSessionConfigOption`.
Fell back to the PowerShell clipboard bridge when the native Windows clipboard reader reports no image, preserving Ctrl+V image paste in PowerShell terminals.\n\nFixes #2429
- Added a new `token` CLI subcommand entry to the command registry.
- Implemented a `Token` command to fetch provider credentials with optional raw output and forced refresh.
- Added error handling to report configured providers and exit when no credential is available.
Concurrent omp --session restores after an unclean shutdown crashed
in SqliteAuthCredentialStore.#initializeSchema() with
SQLITE_BUSY_RECOVERY because the multi-statement schema run installed
PRAGMA busy_timeout=5000 AFTER PRAGMA journal_mode=WAL, the first
lock-taking statement during WAL recovery. Bun's default busy_timeout
is 0, so the lock conflict surfaces immediately.
- packages/ai/src/auth-storage.ts: hoisted PRAGMA busy_timeout to a
standalone first statement, dropped it from the multi-statement
schema run, wrapped SqliteAuthCredentialStore.open() in a 4-attempt
exponential-backoff retry loop on the SQLITE_BUSY family, and the
exhausted-retry error now includes the DB path. Exported
isSqliteBusyError(err) (matches code prefix 'SQLITE_BUSY').
- packages/coding-agent/src/session/agent-storage.ts: same hoist and
the existing retry loop now uses isSqliteBusyError so
SQLITE_BUSY_RECOVERY / _SNAPSHOT / _TIMEOUT also trigger backoff.
- Hoisted busy_timeout before journal_mode=WAL in every other shared
SQLite open path: history-storage, autoresearch/storage,
memories/storage, github-cache, report-tool-issue (auto-QA),
catalog/model-cache; stats/db.ts now sets busy_timeout at all.
- packages/ai/test/auth-storage-sqlite-busy.test.ts pins the contract:
isSqliteBusyError matches every BUSY extended code (rejects
SQLITE_LOCKED, non-errors, strings); open() leaves the connection in
WAL mode (proves busy_timeout ran before journal_mode); open() retries
through synthetic SQLITE_BUSY_RECOVERY; non-BUSY errors (SQLITE_CORRUPT)
short-circuit; exhausted retries throw an error mentioning the DB path
with exactly 3 sleeps for a 4-attempt budget.
Fixes#2421
The bank id used to be hashed from
`git.repo.resolveSync(cwd)?.repoRoot ?? path.resolve(cwd)`, so adding or
removing a `.git` anywhere above the working directory silently
repointed the same conversation to a new bank and stranded its
memories. Same cwd `/home/x/projects/repo` flipped between
`projects-<hash>` and `repo-<hash>` depending on whether the parent
directory still looked like a repo.
`packages/coding-agent/src/mnemopi/config.ts` now hashes
`path.resolve(cwd)` directly. Session startup also widens the recall
set with any sibling bank under `<dbDir>/banks/` whose
`working_memory` rows already carry the active cwd in
`metadata_json.$.cwd`, so memories stranded by the old, less-stable
derivation become visible again on the next session without manual
migration.
Fixes#2412
Pre-fix `loadSkills` in `extensibility/skills.ts` gated the OMP-native
`agents` provider (the canonical `~/.agent[s]/skills` and project-walkup
`.agent[s]/skills`) on the `anyBuiltInSkillSourceEnabled` fall-through —
the OR of `enableCodexUser`/`enableClaudeUser`/`enableClaudeProject`/
`enablePiUser`/`enablePiProject`. A user who turned off the named
third-party toggles to clean noise from other CLIs silently lost their
own canonical OMP-native skills, so typing `/` showed no `/skill:<name>`
entries for `~/.agents/skills/*/SKILL.md`.
- Added `skills.enableAgentsUser` and `skills.enableAgentsProject` to
the settings schema (default true) and to the `SkillsSettings` shape.
- Routed `isSourceEnabled` to the new toggles for `provider === "agents"`
(per level). The fall-through still covers providers without a
dedicated toggle (`claude-plugins`, `opencode`, `gemini`, `github`, …);
agents joins claude/codex/native at the named-source layer where it
always belonged.
- Updated `docs/skills.md` to document the new toggles and the corrected
enablement rule.
- Refactored `test/skills.test.ts` to share a `DISABLE_ALL_BUILTIN_SKILLS`
helper (so the isolation tests stay correct when new toggles are
added) and added two regression tests: one asserting that the
pre-fix scenario (named third-party toggles off, agents defaulted) now
loads `~/.agents/skills/<name>/SKILL.md`, and one pinning the explicit
`enableAgentsUser: false` opt-out.
Fixes#2401
- InputController now clears typed editor text and triggers a render when Esc is pressed with content, then resets the double-Esc timer.
- The double-Esc selector path was updated to reset the terminal display before opening tree or branch message selectors.
- Escape handling tests were expanded with settings setup/teardown to verify default, branch, and draft-clearing Esc scenarios.
Format multi-line, tab-indented AST patterns by collapsing whitespace
to single spaces, preventing them from distorting the single-line status
description in the UI.
- Re-polled steering at the loop yield boundary and included it in the pre-stop pending batch so late messages are processed immediately.
- Added session-side draining for stranded queued messages, scheduling an auto-continue when a prompt settles and follow-ups or steers remain.
- Added a regression test for late steering injection at yield and updated mid-turn collab prompt handling to keep steering messages in the pending display queue until consumed.
- Changed the link grammar from `<roomId>#<key>` / `host[:port]/r/<roomId>#<key>` to dot-joined `<roomId>.<key>` in `formatCollabLink`/`parseCollabLink` (`packages/coding-agent/src/collab/protocol.ts`) and the collab-web mirror (`packages/collab-web/src/lib/link.ts`): RFC 3986 forbids a raw `#` inside a fragment, so strict URL stacks (macOS Foundation behind terminal click-to-open) percent-encoded the second `#`.
- Kept legacy `#`-joined links parseable via `BARE_LINK_RE` and added lenient `%23` → `#` decoding for mangled deep links.
- Updated the `ConnectScreen` placeholder, `app.tsx` deep-link comment, `DEFAULT_RELAY_URL` doc in `packages/wire`, `docs/collab.md` examples, and both package CHANGELOGs.
- Extended `crypto.test.ts` and `link.test.ts` with dot-joined, legacy-hash, and `%23`-mangled link coverage.
- Added optional `useless` flags to tool result types and payload builders.
- Added `pruneUseless` and `dropUeless` options to control uneventful result pruning.
- Changed compaction and shake passes to prune or ignore non-error useless tool results.
- Changed conversation serialization to omit useless toolCall/toolResult pairs from output.
- Added coverage for useless tagging, pruning, and serialization behavior.
Restored the default double-Esc action to the editable message-history selector and covered the default controller route with a regression test.
Fixes#2396
- Removed the obsolete `bun-imports.d.ts` file from `packages/coding-agent/src`.
- Consolidated the `*.css`, `*/template.js`, and `*.generated.js` module text-import declarations into `types/assets/index.d.ts`.
- Added a focused-agent left-key input listener that consumes double left taps when the input is empty.
- Routed focused session left-tap behavior through #handleFocusedLeftTap so it matches the Esc-style unfocus timing.
- Updated tests/fixtures for the new listener flow and refreshed a hashline block-edit error assertion.
- Added a SessionFocusController to switch transcript and input context between main and subagent sessions.
- Added agent-hub Enter activation and double-left return behavior for focused local agents.
- Added view-session-based event and render logic to avoid stale focus-session state.
- Added status-line focused agent display with ghost icon and focused-mode border dimming.
- Updated `codexResets.autoRedeem` from a boolean to `unset`/`yes`/`no` in schema and settings types, with updated description text.
- Adjusted Codex auto-reset evaluation to skip checks in `no` mode and to prompt once in `unset` mode before spending, while preserving immediate spend for `yes`.
- Migrated legacy boolean config values to tri-state during settings load and added tests for mode defaults, helper behavior, and migration results.
- Added `src/export/share.ts`: `/share` now snapshots the session JSON, gzips and seals it with a fresh AES-256-GCM key, and pushes the blob to a secret gist or the share server (1 MB cap with image/string/entry truncation via `sealToFit`); links are `<serverUrl>/<id>#<key>` with the key only in the fragment.
- Added `share-loader.js` and `scripts/generate-share-viewer.ts` building the static viewer the relay serves at `GET /s/<id>`: it fetches the sealed blob, decrypts in-browser, and hands the JSON to the export template via `window.__OMP_SESSION_DATA__`.
- Reworked the `/share` command in `command-controller.ts`/`builtin-registry.ts` off the plaintext-gist HTML upload, exported `LoadedCustomShare`, and exposed the session `SecretObfuscator` getter on `AgentSession` for redaction.
- Added `share.serverUrl` and `share.redactSecrets` settings backed by `DEFAULT_SHARE_URL` from pi-wire.
- HTML exports now embed subagent transcripts: `collectSubSessions` walks `<session>/<AgentId>.jsonl` recursively into `SessionData.subSessions`, with `includeSubSessions` opt-out and the exported `buildSessionData` reused by share snapshots.
- Added `share.test.ts` (snapshot/seal/server-url contracts) and `export-subsessions.test.ts`.
- Replaced the committed `template.generated.ts` with Bun text imports (`with { type: "text" }`) of `template.html/css/js` plus the gitignored `tool-views.generated.js`, composed in a memoized `getTemplate()` in `src/export/html/index.ts`.
- Deleted `scripts/generate-template.ts` and the unused `template.macro.ts`; removed the stale package-level `.gitignore` and the `biome.json` exclusion for the generated file.
- Wired root `prepare` to `generate-docs-index` + new `build-tool-views` script and coding-agent `prepack` to rebuild tool views before `bundle-dist`, so source runs and publishes never need a manual generate step.
- Added narrow ambient text-module declarations (`*.css`, `*/template.js`, `*.generated.js`) to `bun-imports.d.ts`; `*.html` stays untyped because bun-types claims it as `HTMLBundle`, so the import casts at the use site.
- Updated `DEVELOPMENT.md` and `docs/porting-from-pi-mono.md` references; the rewritten import block transiently carries `loadEntriesFromFile`, consumed by the next commit's sub-session loader.
- Added `packages/collab-web/src/tool-render/`: a per-tool React renderer suite (one view per built-in tool) with common `ToolView` chrome, a `tv-` CSS design system, a registry, and an `<omp-tool-view>` web-component wrapper (`element.tsx`, `standalone.tsx`).
- Switched collab-web transcript `ToolCard` to the per-tool renderers instead of the generic args/result JSON dump, and threaded a `ToolRenderHost` through `Transcript`/`AgentDrawer`/`app.tsx` so task-card agent chips drill into the matching subagent drawer.
- Added `scripts/build-tool-views.ts` plus the `build:tool-views` script bundling the renderers (React included, `</script` escaped) into the gitignored `coding-agent/src/export/html/tool-views.generated.js`.
- Modernized the coding-agent HTML export chrome in `template.html/css/js` to the tool-card design language and added the `<template-tool-views/>` injection point.
- Showed the standard done checkmark for completed rows in the `job` tool renderer; its changelog line shares a changed run with the restyle entries.
- The session-operations doc gained two adjacent lines; the subagent-transcript one belongs to the upcoming /share commit but is inseparable from the tool-view line.
- Added detached spawn metadata to lifecycle, progress, and executor session payloads so task and evaluator runs can mark background jobs.
- Updated subagent session tracking and HUD rendering to only show active detached spawns.
- Extended HUD tests to verify non-detached sync and eval spawns are excluded while detached flags propagate through events.
- Moved `fastembed` and `onnxruntime-node` to optional peerDependencies.
- Fixed bundled installs that could not resolve `onnxruntime_binding.node`.
- Added shared `runtime-install` utilities for on-demand module resolution.
- Added tests for runtime-resolution parsing and exact peer-version checks.
- Changed collapsed progress rendering to keep the most recent live agents visible, adding a summary line for folded-away rows.
- Updated collapsed result rendering to preserve failed and aborted agents in the visible set while trimming other completions.
- Refreshed job polling text to document waiting on all running jobs when `poll` is omitted and added tests for both collapsed progress and result display behavior.
- Extended `parseCollabLink` test coverage to reject 16-byte and 40-byte fragments instead of only rejecting short keys.
- Added coverage for full-link fragments to ensure key and write token are parsed when present.
- Updated `GuestClient` test setup so `welcomeFrame` carries a `readOnly` flag into snapshot assertions.
- Enabled read-only mode by wiring snapshot.readOnly through AgentDrawer and Composer to block prompts and controls.
- Added read-only indicators in the header and participant titles for view-only sessions.
- Added SEO and app metadata assets by updating index.html head tags, manifest, robots.txt, and sitemap.xml.
- Updated brand presentation by adding new favicon/OG assets and switching theme tokens to new OMP colors.
- Added write-token generation and validation to distinguish writable and read-only guests.
- Added deep-link support using `https://<relay>/#<link>` with 32/48-byte collab secrets.
- Added full-link and key-only semantics where full links grant writes and key-only links are view-only.
- Added /collab view/status/stop command updates with read-only participant status and join hints.
Gated the Model scope banner suffix on the original scope's explicitThinkingLevel flag and switched the display source back to the pre-default ScopedModel[] so non-explicit scope entries no longer render the global default thinking level.
Fixes#2385
Respect startup.quiet when building the interactive model-scope notification so quiet launches do not emit startup chrome for large enabledModels scopes.\n\nFixes #2386
Fixed the interactive Model scope formatter so unset thinking levels omit the suffix and explicit levels render as id:level.
Added regression coverage for the startup banner list formatter.
Fixes#2385
- Moved completion/hint builder functions and BUILTIN_SLASH_COMMANDS materialization into slash-commands/builtin-registry.ts.
- Removed those builder definitions from extensibility/slash-commands and shifted type exports to the types module.
- Updated interactive-mode to import BUILTIN_SLASH_COMMANDS from builtin-registry instead of the extensibility wrapper.
Individual conflict resolution now bypasses the LSP writethrough to prevent formatting from corrupting other unresolved marker blocks and to avoid noisy diagnostics in partially resolved files.
- Recomputed `tools.discoveryMode: "auto"` in the deferred MCP closure in `sdk.ts` once the real tool count is known: a toolset crossing the threshold now flips discovery on, registers and activates `search_tool_bm25`, and skips `activateAll` instead of force-activating every MCP tool.
- Guarded the deferred MCP task against disposed sessions: added `AgentSession.isDisposed` and `enableMCPDiscovery()`, and the late connect now calls `disconnectAll()` instead of refreshing tools onto a dead session.
- Cleared `#fastPathKey`/`#fastPathItems` in `AssistantMessageComponent.invalidate()` so theme/symbol changes rebuild reused Markdown children instead of keeping stale captured themes.
- Memoized unusable read summaries as a `false` sentinel in `read.ts` so the per-session LRU no longer retains full sources of unsummarizable files.
- Broadened `HAS_REF_DEF` in `markdown.ts` to match backslash-escaped reference labels (`[a\]b]: x`) and cleared frozen stream-lex state on blank `setText()`.
- Added regression tests: deferred auto-discovery flip and mid-connect dispose (`sdk-mcp-auto-discovery.test.ts` + `many-tools-mcp.ts` fixture), fast-path child rebuild on invalidate, and escaped-ref-def incremental-lex equivalence.
Reviewer flagged that the bracketed-paste path is untrusted terminal input —
ANSI escapes, control chars, newlines/tabs, or a multi-hundred-char path
would corrupt the status line (per AGENTS.md TUI sanitization rules) and
leak the absolute home-dir path.
The new ENOENT diagnostic now feeds the path through sanitizeText (strip
ANSI/C0/C1 controls), collapses CR/LF/TAB to single spaces, runs it
through shortenPath (collapse home → '~'), and truncateToWidth-clamps it
to TRUNCATE_LENGTHS.CONTENT (80) before interpolating into either the SSH
or local status string. Added a third assertion to the repro test
defending the contract: ANSI/control bytes never reach the status, and
the displayed path is bounded below the input length.
Refs PR #2376