- Replaced insufficient file size checks with comprehensive validation for ZIP header and length limits.
- Added explicit rejection for archives that would exceed ZIP32 entry counts, name lengths, or total offsets.
- Added validation for central directory size to prevent overflow before generating the EOCD record.
- Implemented structured markdown role headings and tool result merging to improve conversation readability.
- Added explicit `<out>` tags for tool result wrapping and enhanced rendering for thinking blocks.
- Refactored authentication snapshot validation to use manual structural checks instead of schema dependencies.
- Fixed instability in settings overlay scrolling and addressed assistant message splitting issues.
- Removed the `fflate` dependency in favor of using `node:zlib` for ZIP operations.
- Updated documentation and internal code comments to reflect the transition to native `node:zlib` DEFLATE support.
- Replaced `fflate` dependency with `node:zlib` and manual ZIP framing in `src/utils/zip.ts`.
- Implemented lazy loading for site-specific scrapers to reduce cold-start latency.
- Unified ZIP compression and extraction logic to use native `zlib` stream decoders.
- Optimized ZIP member decoding by implementing memory-safe length-bounded inflation.
- Restrict the advisor from providing redundant insights, context, or second opinions.
- Prohibit restating information or problems already visible to the agent via its own tools.
- Prevent repetition of previously provided advice to minimize noise.
- Refactor deep imports by targeting specific sub-modules in `@oh-my-pi/pi-ai` to reduce barrel file overhead.
- Utilize jitless ArkType scopes in schema definitions to reduce startup JIT codegen costs by approximately 65%.
- Reorganize internal `auth-storage` exports to maintain clean boundaries between core and broker-specific functionality.
- Centralized archive operations into a new `utils/zip.ts` module with unified support for ZIP, tar, and tar.gz formats.
- Optimized ZIP reading using lazy, ranged central-directory access and implemented ZIP64 support for large files.
- Hardened archive extraction with directory traversal protection and configured memory limits for loading and extraction.
- Refactored tool-specific logic to utilize the new centralized utility and deleted the redundant `archive-reader.ts`.
- Refactor replay safety logic to specifically prevent retries when a tool call is present in the assistant message.
- Enable retries for transient stream errors occurring during partial text or thinking sequences, ensuring consistency when no tool call has been completed.
- Add regression tests to verify that transient socket closures are successfully recovered while completed tool calls remain protected from redundant retries.
- Add an epoch counter to `AdvisorRuntime` to discard in-flight advisor batches when a reset or disposal occurs.
- Introduce `resetAdvisorSessionState` to clear advisor-specific queues, latches, and pending cards, ensuring pre-reset state does not interfere with new conversations.
- Extend `YieldQueue.clear` to support conditional clearing by entry kind.
- Replaced raw TypeScript documentation map with a lazily-inflated gzip blob.
- Reduced bundled binary/npm package size by approximately 0.9MB.
- Encapsulated index logic into `docs-index.ts` to separate header metadata from content.
- Added `postpack` and robust `try/finally` patterns in build scripts to ensure clean artifacts.
- Implemented disk-based fallback during development to maintain existing developer experience.
- Implemented a bridge to the `bun:jsc` remote inspector API.
- Added a debug interface action to start the inspector and expose the connection endpoint.
- Included logic to dynamically reserve available ports and reliably probe the socket state due to inherent platform-dependent limitations in the underlying API.
- Avoided value-imports of `puppeteer-core` in main startup files to prevent eager loading of the browser-data dependency graph.
- Used `import type` and literal string checks to defer `puppeteer-core` initialization until browser tools are actually invoked.
- Added a test to verify that `puppeteer-core` and `@puppeteer/browsers` remain off the eager startup import graph.
- Externalized additional heavy dependencies to reduce bundle size and improved minification settings in the build script.
- Added a command to the setup script to link the omp binary into the global bun bin directory.
- Updated the omp script documentation to reflect the new installation method.
- Switched to unique, timestamped backup file paths to avoid file lock collisions during binary replacement.
- Implemented a best-effort strategy for backup deletion, allowing successful updates even if the previous process image remains locked.
- Added a cleanup routine for sweeping stale backups, including legacy files, during each update attempt.
Limited the optional LM Studio /api/v0/models metadata lookup with an abort timeout and started the catalog request independently so OpenAI-compatible servers without the native endpoint still refresh. Added a regression for hung native metadata probes.\n\nFixes #2945
- Expired the per-credential usage report cache after recording observed OpenCode Go spend.\n- Threaded provider base URL into OpenCode Go cost recording so the invalidation targets the same cache key /usage uses.\n- Added regression coverage for refreshing cached OpenCode Go limits immediately after a completed turn.\n\nFixes #2942
Treat shell-style leading variables such as $HOME as normal chat text instead of Python eval input. Keep local Python shortcuts available through explicit $ <code> and $$ <code> prefixes.\n\nFixes #2944
Queried LM Studio native /api/v0/models metadata during catalog and runtime discovery so type=vlm models advertise image input. Added regressions for both provider-manager and runtime discovery paths.\n\nFixes #2945
- Added an OpenCode Go usage provider that synthesizes 5h, weekly, and monthly cap windows from OMP-observed request costs.\n- Recorded OpenCode Go assistant request costs against the active credential so /usage can report local cap utilization.\n- Added regression coverage for fresh keys and observed spend aggregation.\n\nFixes #2942
- Routed the /model TUI slash command back to the full model setup picker.
- Kept /switch on the temporary session model selector and updated slash-command coverage.
Fixes#2933
- Integrated comprehensive loop guard support for DeepSeek and assistant prose patterns, including configurable stream checks.
- Implemented Moonshot Flavored JSON Schema (MFJS) normalization for improved tool compatibility and enum type inference.
- Added support for Ollama reasoning effort backfilling and Grok-specific service tier cost tracking across providers.
- Expanded model catalog with new entries and unified compatibility logic for improved OpenRouter API integration.
Restored StringEnum's plain string enum wire schema and returned legacy coding tool placeholders that let createAgentSession keep the real built-in tools active.
Fixes#2858
Added compatibility exports for legacy plugin validation, including defineTool, StringEnum, TypeBox bare imports, frontmatter helpers, SettingsManager, and createCodingTools.
Updated SDK settingsManager alias handling and regression coverage for the affected shim surfaces.
Fixes#2858
- Sanitized newlines from agent hub display text to ensure single-line output.
- Enforced line clamping during render to prevent terminal wrapping.
- Added test coverage to verify output truncation and newline removal.