- browser tool's existing-tab re-nav defaults to waitUntil: 'load' (matching
new-tab path); identical acquireTab() calls no longer hang on dev servers
- patch tool error path uses caller-supplied relative path; absolute
resolvedPath stays in structured context only ($HOME no longer leaks to TUI)
- splitInternalUrlSel keeps mcp:// resource URIs opaque even when they end in
':raw' or '/:1-50' (McpProtocolHandler matches by verbatim URI)
- find tool: timeout signal honored by onMatch; partial results sorted by
mtime desc; backslash-escaped commas skipped in path-list validation
- DAP throwPreferredDapStartError waits up to 50ms for the underlying
launch/attach error instead of one microtask
- debug tool surfaces 'python missing' and 'pip install debugpy' diagnostics
separately when adapter: 'debugpy' is requested
The size+mtime check from 094273df5 is unreliable on filesystems with
coarse mtime resolution: a same-length rewrite within the same tick
(e.g. "a" → "b") leaves both fields unchanged and falsely trips the
"file content did not change on disk" guard. CI on ubuntu Bun 1.3.14
hit this in the create-then-update aggregation test.
Re-read the file post-write and compare bytes to the previous content
instead — deterministic regardless of FS timestamp granularity.
executePatchSingle returned success based on the writethrough callback
resolving, but the LSP-backed writethrough could resolve to an in-memory
editor buffer while disk stayed unchanged. Capture pre-write mtime+size,
re-stat post-write, and throw a ToolError when nothing changed.
- Replaced all StringEnum(...) usages with z.enum([...]) across tools, examples, and tests.
- Removed StringEnum re-export from @oh-my-pi/pi-coding-agent public API.
- Condensed verbose tool parameter descriptions to minimal lowercase phrases.
- Renamed AuthCredentialStore to SqliteAuthCredentialStore at usage sites.
- Added canonical `pi.zod` schema API exports and removed TypeBox package exports/imports.
- Migrated Tool schema typing from TypeBox to shared `TSchema`/Zod flow with legacy TypeBox compatibility.
- Updated AI provider adapters and MCP/agent builders to convert tool params through `toolWireSchema()`.
- Reworked schema validation from AJV to Zod-safe parsing with `fromTypeBox`, `toolWireSchema`, and meta schema checks.
Addresses the codex review comments on #1015 plus a sweep of adjacent
ACP conformance gaps surfaced while wiring them up.
Tool call + diff metadata
- acp-event-mapper: thread session cwd through and resolve every
`ToolCallLocation` (initial args, in-flight updates, result details)
to absolute paths against it; ACP requires absolute paths for
client-side file mapping.
- edit/modes/patch: emit the destination path for moves in the diff
result so post-edit "open file" actions land on the new file.
Permissions
- agent-session: pass cwd into `extractPermissionLocations` and resolve
raw `path`/`file`/etc. fields against it before sending
`session/request_permission`.
- agent-session: gate the permission wrapper on
`bridge.capabilities.requestPermission && bridge.requestPermission`,
matching the read/write/bash capability+method pattern.
acp-agent
- `authenticate`: validate `methodId` against the methods advertised by
`initialize` and reject anything else, so malformed clients fail fast.
- `setSessionConfigOption(MODE_CONFIG_ID)`: also emit
`current_mode_update` so clients tracking `modes.currentModeId` see
the same transition `session/set_mode` would produce.
- Pass `runtime.notifyConfigChanged` to builtins; emit
`available_commands_update` from a shared `reloadPlugins` helper
reused by `/reload-plugins`, `/marketplace`, and `/plugins`.
- prompt resource handling: route `resource` content with `image/*`
MIME into the `images` array instead of dropping it as an opaque
blob; non-image blobs still fall back to the URI placeholder.
- pass session cwd to the event mapper.
Builtins
- model: call `runtime.notifyConfigChanged()` after a successful
`setModel` so the ACP config selector reflects the new model
immediately.
- mcp: redact query strings and userinfo from MCP server URLs before
emitting them in `/mcp list` (prevents leaking `?exaApiKey=…` style
secrets); wire `manager.setAuthStorage(...)` before `prepareConfig`
in `/mcp test|resources|prompts` so OAuth servers can refresh tokens.
- ssh: reject non-integer `--port` values via a `^\d+$` guard instead
of silently coercing through `Number.parseInt`; list project hosts
first and dedupe user-scope duplicates to match capability-loader
precedence.
- export: reject clipboard aliases (`--copy`, `clipboard`, `copy`)
before passing them to `exportToHtml` as a filename.
- compact / force / move / browser: surface underlying failures via
`usage(errorMessage(...))` instead of letting them crash the command.
- session save|delete: route through the active SessionManager so the
persist writer is consulted and stale storage references are removed.
- marketplace / plugins / reload-plugins: call `runtime.reloadPlugins()`
on install/uninstall/upgrade and enable/disable so slash command
registries and command lists refresh consistently.
- shared.usage: make async and `await runtime.output(...)` so
`sessionUpdate` text is never dropped or reordered.
- types: document the new `reloadPlugins` and `notifyConfigChanged`
runtime hooks.
bash tool
- Use a shared `fireKill()` from the abort listener so `session/cancel`
terminates the remote command immediately instead of waiting for the
next `currentOutput()` round trip.
- Race `currentOutput()` against the abort signal so a stuck
`terminal/output` RPC cannot delay cancellation.
- Kill the terminal before reading final output on timeout so a slow
output read cannot let a timed-out command keep running past the
enforced timeout.
Tests
- acp-agent.test: extend the existing config-option assertions to
verify both `model` and `thinking_level` changes emit
`config_option_update` notifications scoped to the right session.
- acp-builtins.test: cover `/model` emitting both
`notifyTitleChanged` and `notifyConfigChanged`; lock in the parsed
`mcp add` / `ssh add` call shapes so future arg-parser regressions
fail the test instead of silently writing different configs; add a
`reloadPlugins` stub plus a typed `notifyConfigChanged` slot to the
shared test runtime factory.
- acp-stdout-hygiene.test: drain stderr in parallel and assert no
JSON-RPC frame leaks onto it; terminate the spawned process so the
stderr pump resolves deterministically.
CHANGELOG: itemize the above under `[Unreleased] > Fixed`.
CI
- bun run check: clean (TS + Rust)
- bun run test: 4128 pass / 689 skip / 0 fail (TS); 252 pass / 0 fail
(Rust nextest)
- bun run ci:test:smoke: --version / --help / `stats --help` all OK
- EditTool now carries oldText/newText in per-file results for patch, replace, and multi-file aggregation paths
- Renderer updated to display diff content for all edit modes
- Enables downstream consumers (ACP event mapper, TUI) to render accurate diffs
- Added `./hashline` package exports and redirected callers to the new hashline entrypoint.
- Moved hashline logic out of `edit/` to `src/hashline` and removed `edit/modes/hashline`/`edit/line-hash` paths.
- Added hashline parsers, anchors, types, and diff helpers with stricter input and mismatch validation.
- Implemented preflight and cache-recovery execution flows to reapply edits and handle stale anchor mismatches.
- Documented the hashline API relocation as breaking changes in `CHANGELOG.md`.
- Removed hashline anchor auto-rebase logic, including the ±5-line rebase window and `tryRebaseAnchor` fallback.
- Validation now reports hash mismatches directly as hard `HashMismatch` entries and surfaces them via `HashlineMismatchError` without mutating anchor lines.
- Updated the changelog to document anchor auto-rebase removal and the immediate re-read recovery behavior.
- Implemented hashline stale-anchor recovery using cached reads and a 3-way merge fallback.
- Updated hashline execution and preflight checks to retry mismatched anchors through cache recovery.
- Added file-read cache support with per-session LRU snapshots and contiguous/sparse record APIs.
- Integrated read and search tools with the shared cache to record candidate lines for recovery.
- Added tests for stale-anchor recovery flows and FileReadCache session, null, overlap, and eviction behavior.
- Exported hashline section interfaces and helpers, including a new section-diff API for external callers.
- Refactored `computeHashlineDiff` to split input sections, propagate split errors, and delegate each section via helper.
- Added context-highlight caching and batched highlighting for unchanged lines, with `replaceTabs` fallback on unknown files.
- Fixed hashline streaming preview so completed sections stay visible when a new `@PATH` header appears mid-stream.
- Added hashline streaming tests for section persistence, malformed trailing `+ 7`, and dual sections.
- Added `.ipynb` detection and editable-cell conversion utilities, including merge/serialize helpers in `edit/notebook`.
- Rerouted hashline, patch, and replace edit flows, plus read/write paths, through notebook-aware helpers before persistence.
- Removed the dedicated `notebook` tool, its schema flags, renderer, and built-in registration/settings checks.
- Updated notebook read behavior, docs, and tests so `.ipynb` reads return editable `# %%` cells and edits reserialize to JSON.
- Extended boundary duplicate absorption to single structural closing lines (`}`, `)`, `]`) for replacement groups.
- Added delimiter-balance validation so a boundary line drops only when the kept payload matches expected counts.
- Enabled default single-line structural boundary absorption for pure inserts while keeping multi-line absorbs gated by `autoDropPureInsertDuplicates`.
- Added a new `edit.hashlineAutoDropPureInsertDuplicates` boolean setting with default `false` for hashline edits.
- Threaded the setting through tool execution contexts so hashline previews and execution honor the configured option.
- Changed pure-insert duplicate boundary absorption to run only when enabled and added tests for default-disabled and enabled behavior.
- Extended hashline pure-insert absorption to auto-drop 2+ duplicated boundary lines at ANCHOR, BOF, and EOF inserts.
- Surfaced a warning when pure-insert boundary lines are auto-dropped.
- Updated read schema, path utilities, and dispatch to parse selectors from :raw/:L suffixes on path, removing standalone sel usage.
- Changed truncation/error notices to continue with :<nextOffset> and :1 guidance for read and sqlite pagination.
- Added summarizeCode support with tree-sitter summaries, read.summarize settings, and N-API Summary types/exports.
- Added tests and docs updates for path-embedded selectors, summary behavior, and explicit raw/offset SQL/read cases.
- Wrapped hashline execution by merging same-path input sections into one combined section in execution order.
- Applied a new hashline regression test that validates sequential sections against the same file use the original snapshot even when anchors shift beyond rebase limits.
- Added a `= A..B` hashline rule and adjacent-edge guidance to the tool prompt.
- Added `HashlineReplacementGroup` and `HashlineDeleteEdit` with helpers to find anchor-target lines.
- Added `findReplacementGroup()` and duplicate-boundary absorption to normalize edits with synthetic deletes and warnings.
- Added normalization flow into `applyHashlineEdits` before bucketing, and added duplicate-boundary edge-case tests.
- Updated `CHANGELOG.md` with Added and Fixed unreleased notes for hashline boundary-line behavior.
- Added inline hashline parse and apply support for `<` prepend and `+` append operations with prefix+suffix edits.
- Added fail-fast behavior to reject inline modify ops combined with delete or replace on same line.
- Renamed HASHLINE_* and mode symbols to HL_* in prompt tooling, read/search checks, and prompt templates.
- Standardized separators to `PI_HL_SEP`/`HL_EDIT_SEP` and fixed `HL_BODY_SEP='|'`, updating parser formatting behavior.
- Updated benchmark subtype constants and python cleanup test setup to use HL_* values and AgentRegistry mock failure injection.
- Changed the default HASHLINE_CONTENT_SEPARATOR value to a backslash when PI_HASHLINE_SEP is not provided.
- Kept the environment variable override path intact so custom separators continue to work via PI_HASHLINE_SEP.
- Added configurable hashline separator support via `PI_HASHLINE_SEP` with `|` fallback.
- Replaced hardcoded `|` payload markers with `{{hsep}}`/`$HSEP$` in prompts, grammar, and parsing.
- Updated payload parsing to strip shared separator prefixes while preserving whitespace-only prefixes.
- Replaced `resolveLarkLidPlaceholders` with `resolveHashlineGrammarPlaceholders` and added a compatibility alias.
- Updated `collectPayload` to accept a warnings accumulator, detect doubled payload prefixes, and strip one extra leading `|` when all payload lines used the doubled form.
- Changed `parseHashlineWithWarnings` to return collected parser warnings instead of an empty list.
- Added tests confirming auto-stripping, single-line `|` preservation, and mixed-prefix payload behavior.
- Centralized `line-hash.ts` hash regex sources and resolved `atom.lark` via `resolveLarkLidPlaceholders`.
- Expanded `computeLineHash` to emit `>[a-z]` and `[a-z]<` hashes for brace-context anchors.
- Replaced atom/hashline parsers' hard-coded lid regex with shared `HASHLINE_HASH_RE_SRC` and lax counterparts.
- Removed `\\TEXT` continuation handling in atom rewrites and switched multi-line replacements to `+TEXT`.
- Added brace-body insertion warning when `@Lid` on `{`-ending lines inserts at non-body-safe indent.
- Suppressed duplicate auto-rebase warnings and kept unmatched `-`/`+` ranges separate in compact previews.
- Adjusted atom mutation conflict validation to skip throwing on repeated delete edits for the same anchor line.
- Added tests confirming duplicate delete edits on one anchor are idempotent and do not trigger conflicts.
- Added coverage ensuring explicit deletes within replace ranges are treated as redundant and ignored.
- Added a lookahead helper to detect `\` continuation lines after blank lines during range replacements.
- Converted interior blank lines to explicit continuation-sentinel inserts when followed by a continuation, preserving open replacement state.
- Extended atom parser tests to cover implicit blank-`\` handling for range and single-anchor replacements, including trailing-blank termination.
- Updated adjacent-duplicate auto-fix logic to remove a line from each detected pair when bracket balance changed.
- Adjusted the validation to accept the corrected file only after all removals restore original bracket balance.
- Added a regression test for one edit creating duplicate block closers in two unrelated segments and asserting the auto-fix warning.
- Allowed bare `LidA..LidB` to recover a missing-range-delete typo and accepted `|` as a legacy range replacement separator while validating ranges and replacement text.
- Enabled indented hashline statements to parse as replacement edits and added a preflight pass that validates all atom sections before any file write occurs.
- Updated hash-mismatch messaging, prompt wording, and tests to reflect hash-only rebase candidates and the new range/section behaviors.
- Updated the Atom grammar to parse replacement blocks via a set block rule that no longer targets range replacements only.
- Extended continuation preprocessing to allow backslash lines after single-line replace operations (including legacy `@` and `|` forms) while preserving the active-replacement check.
- Added tests and prompt documentation for single-line continuation cases and for rejection of backslash-like text outside an active replacement.
- Added atom edit support for Lid ranges, before-anchor inserts, and no-op Lid=TEXT success handling.
- Expanded hashline recovery to scan shifted hashes, match unique alternates, and emit ±5 anchor-shift hints.
- Added edit failure categorization with per-category counts, percentages, and detailed report lines.
- Added regression coverage for shifted-hash recovery, range continuation, cursor shorthand, and split-file atom ops.
- Reversed atom mode parsing of cursor anchors so "^" now resolved to BOF and "$" to EOF.
- Updated the atom command documentation and examples to reflect the corrected BOF/EOF markers.
- Adjusted parser tests to expect prepend via "^" and append via "$" with corresponding cursor kinds.
- Atom edit application stopped throwing when a `-Lid|OLD` delete anchor's OLD payload mismatched the current line.
- Delete hunks now ignore the OLD payload and rely on Lid hash anchoring for validation and rebasing.
- Atom edge-case tests were updated to verify mismatched OLD payloads are now accepted when hashes still match.
- Removed the guard that rejected edits when multiple mutating anchors were auto-rebased in atom anchor validation.
- Updated atom hash-mismatch tests to show multiple set and delete anchors can rebase together and still return warning messages.
- Auto-split `+@Lid` and `+-Lid` lines in `parseDiffLine` into their intended op plus a blank insert.
- Split non-contiguous delete runs into contiguous sub-runs in `normalizeHunks` and attached inserts to the last run.
- Added regression coverage for op-prefixed auto-splitting and non-contiguous delete insertion placement.
- Rejected malformed atom diff lines (orphan '-' and unrecognized ops) with parse errors.
- Tracked mutating set/delete anchors during validation and errored when multiple stale anchors required auto-rebase.
- Added duplicate-line auto-fix in applyAtomEdits when bracket balance restores, emitting Auto-fixed warnings.
- Updated atom prompts/changelog and expanded tests for unknown ops, auto-rebase, and duplicate-line handling.
- Updated atom mode diff output to use path-prefixed preview text and removed the explicit summary header.
- Changed hashline preview generation to truncate unchanged runs by direct slicing and reduced placeholder spacing for line prefixes.
- Updated hashline preview expectations in tests to match the new compact unchanged-line formatting.
- Added compact Lark grammar processing and applied it to OpenAI custom-format tools before conversion.
- Reworked atom mode into `---PATH` compact commands with new grammar, parser, and rm/mv file operations.
- Updated `hline`/`href`/`hrefr` helper behavior and hashline mismatch guidance using shared anchor state.
- Standardized path formatting with `formatPathRelativeToCwd` across LSP, prompts, and edit/search/write tools.
- Added benchmark run-path handling, including `.gitignore` runs mapping, absolute reports, and safer snapshot output.
- Added tests for compact grammar payloads, atom parsing/execution, renderer streaming, and path-list outputs.
- Removed the newline guard for `replace.with` in atom edit parsing so multiline replacement text is accepted.
- Updated atom tests to assert replacing a matching line with multiline content now succeeds.
- Stopped clearing `optimisticUserMessageSignature` during session-context rendering so interactive status preserves in-progress signatures.
- Required top-level `path` in edit requests, removed per-entry `path` fields, and updated docs/tests to match.
- Updated patch/hashline/atom streaming preview generation to return a single request-level path diff preview.
- Changed edit execution to route patch/replace/atom/hashline through single-path handlers sharing `path`.
- Added `scripts/analyze-edit-formats` Go CLI with reports to audit edit-tool usage from session JSONL logs.
- Replaced atom sed parsing and operations with replace-based edit schema (`find`, `with`, `all`) and `replace_file`.
- Removed bracketed/range locator handling and delimiter-based block APIs, including `splice_block` workflows.
- Restricted Atom locator parsing to one anchor or `$` with line > 0 and enforced line-only targets.
- Updated atom docs and tests to cover the new replace semantics, anchor-only edits, and literal newline limits.
- Removed the `F` sed flag and `literal` field, keeping only `pat`, `rep`, and `g`, and dropped the obsolete `F` test.
- Updated sed parsing, serialization, and error text to remove `splice_block` exclusivity and explain regex escaping.
- Reworked atom prompt format to `<ops>/<splice>/<sed>`, with shared `{path, edits}` calls and strict one-loc/one-verb rules.
- Updated docs (`read.md` and `CHANGELOG.md`) to remove `F:true` anti-patterns and add current `line+hash` and sed behavior guidance.
- Removed `i` and `m` from the Atom sed schema and docs, so sed now accepts only `pat`, `rep`, `g`, and `F` options.
- Updated `SedSpec` parsing and serialization to drop ignore-case and multiline handling.
- Adjusted regex construction to apply sed replacements using only global and literal flags.
- Updated the atom sed schema and parser to accept an optional `m` multiline flag and pass it through as a new `multiline` field.
- Adjusted flag handling so `g` now defaults to false, with formatting and regex construction emitting `g`/`m` only when enabled.
- Kept user guidance aligned by updating atom tool prompt docs with the revised sed defaults and the new multiline option.
- Replaced `atom.sed` string syntax with `{pat,rep,g?,F?,i?}` objects in schema, prompts, and tests.
- Changed sed validation defaults so `pat` is regex, `g` defaults to global replacement, and `F:true` forces literal matching.
- Fixed `sed` edge cases by allowing sequential same-anchor edits, handling zero-length matches, and preserving chaining.
- Updated native build flow to local `--profile` defaults, refactored enum generation, and switched totals to `total_ms`.
Drop three pieces of well-intentioned-but-fragile string mangling that
were quietly mutating model edit content:
- `maybeAutocorrectEscapedTabIndentation` in both hashline and atom edit
modes (plus the `PI_HASHLINE_AUTOCORRECT_ESCAPED_TABS` env toggle and
`isEscapedTabAutocorrectEnabled` helper). Literal `\\t` in edit content
is now preserved verbatim.
- `maybeWarnSuspiciousUnicodeEscapePlaceholder` and the
`runHashlinePreflightSanitizers` wrapper. The warning was misleading:
it flagged `\\uDDDD` as suspicious without distinguishing intentional
literal text from a likely-malformed escape, and it was the only
remaining caller.
- The hand-rolled JSON-unescape fallback in
`decodePartialJsonStringFragment` (renderer.ts). The fallback used
`String.fromCharCode` (mishandling lone surrogates) and only covered a
subset of JSON escapes, so the same fragment decoded one way mid-stream
and a different way after `JSON.parse` succeeded. Now we trim a
trailing partial `\\u`/odd-backslash escape and surface the raw
fragment if `JSON.parse` still fails.