- Changed `DEFAULT_RELAY_URL` in `@oh-my-pi/pi-wire` from `wss://relay.omp.sh` to `wss://my.omp.sh` and updated the constants, collab-link, and join-command tests asserting the old origin.
- Added `DEFAULT_SHARE_URL` (`https://my.omp.sh/s`) to pi-wire with its changelog entry; it shares a changed run with the relay constant and is consumed by the upcoming /share work.
- Updated collab-web canonical/OG/twitter URLs in `index.html`, `robots.txt`, `sitemap.xml`, README, and the `local-relay.ts` doc comment to the new domain.
- Refreshed the `/collab` entry in the coding-agent changelog to reference the new relay origin.
- Added detached spawn metadata to lifecycle, progress, and executor session payloads so task and evaluator runs can mark background jobs.
- Updated subagent session tracking and HUD rendering to only show active detached spawns.
- Extended HUD tests to verify non-detached sync and eval spawns are excluded while detached flags propagate through events.
- Changed collapsed progress rendering to keep the most recent live agents visible, adding a summary line for folded-away rows.
- Updated collapsed result rendering to preserve failed and aborted agents in the visible set while trimming other completions.
- Refreshed job polling text to document waiting on all running jobs when `poll` is omitted and added tests for both collapsed progress and result display behavior.
- Extended `parseCollabLink` test coverage to reject 16-byte and 40-byte fragments instead of only rejecting short keys.
- Added coverage for full-link fragments to ensure key and write token are parsed when present.
- Updated `GuestClient` test setup so `welcomeFrame` carries a `readOnly` flag into snapshot assertions.
- Enabled read-only mode by wiring snapshot.readOnly through AgentDrawer and Composer to block prompts and controls.
- Added read-only indicators in the header and participant titles for view-only sessions.
- Added SEO and app metadata assets by updating index.html head tags, manifest, robots.txt, and sitemap.xml.
- Updated brand presentation by adding new favicon/OG assets and switching theme tokens to new OMP colors.
- Added write-token generation and validation to distinguish writable and read-only guests.
- Added deep-link support using `https://<relay>/#<link>` with 32/48-byte collab secrets.
- Added full-link and key-only semantics where full links grant writes and key-only links are view-only.
- Added /collab view/status/stop command updates with read-only participant status and join hints.
Gated the Model scope banner suffix on the original scope's explicitThinkingLevel flag and switched the display source back to the pre-default ScopedModel[] so non-explicit scope entries no longer render the global default thinking level.
Fixes#2385
Respect startup.quiet when building the interactive model-scope notification so quiet launches do not emit startup chrome for large enabledModels scopes.\n\nFixes #2386
Fixed the interactive Model scope formatter so unset thinking levels omit the suffix and explicit levels render as id:level.
Added regression coverage for the startup banner list formatter.
Fixes#2385
- Recomputed `tools.discoveryMode: "auto"` in the deferred MCP closure in `sdk.ts` once the real tool count is known: a toolset crossing the threshold now flips discovery on, registers and activates `search_tool_bm25`, and skips `activateAll` instead of force-activating every MCP tool.
- Guarded the deferred MCP task against disposed sessions: added `AgentSession.isDisposed` and `enableMCPDiscovery()`, and the late connect now calls `disconnectAll()` instead of refreshing tools onto a dead session.
- Cleared `#fastPathKey`/`#fastPathItems` in `AssistantMessageComponent.invalidate()` so theme/symbol changes rebuild reused Markdown children instead of keeping stale captured themes.
- Memoized unusable read summaries as a `false` sentinel in `read.ts` so the per-session LRU no longer retains full sources of unsummarizable files.
- Broadened `HAS_REF_DEF` in `markdown.ts` to match backslash-escaped reference labels (`[a\]b]: x`) and cleared frozen stream-lex state on blank `setText()`.
- Added regression tests: deferred auto-discovery flip and mid-connect dispose (`sdk-mcp-auto-discovery.test.ts` + `many-tools-mcp.ts` fixture), fast-path child rebuild on invalidate, and escaped-ref-def incremental-lex equivalence.
Reviewer flagged that the bracketed-paste path is untrusted terminal input —
ANSI escapes, control chars, newlines/tabs, or a multi-hundred-char path
would corrupt the status line (per AGENTS.md TUI sanitization rules) and
leak the absolute home-dir path.
The new ENOENT diagnostic now feeds the path through sanitizeText (strip
ANSI/C0/C1 controls), collapses CR/LF/TAB to single spaces, runs it
through shortenPath (collapse home → '~'), and truncateToWidth-clamps it
to TRUNCATE_LENGTHS.CONTENT (80) before interpolating into either the SSH
or local status string. Added a third assertion to the repro test
defending the contract: ANSI/control bytes never reach the status, and
the displayed path is bounded below the input length.
Refs PR #2376
- Added optional `isError` markers on inline tool-result and message models.
- Skipped error-marked tool results during swap planning, savings estimation, and live transformations.
- Added tests confirming large error tool results stay text-only and are not considered for inline swaps.
When a local terminal forwards a bracketed-paste containing an image-file
path and the omp process is itself running on the remote end of an SSH
session, the path is on the user's local machine and unreachable from the
remote filesystem. The path-as-text fallback in handleImagePathPaste then
made it look like the image was attached when in fact only a useless
absolute path entered the editor and the bytes never crossed.
Distinguish ENOENT from other read failures: drop the misleading
path-as-text degrade, and surface a clear status that names the file and
— when SSH_CONNECTION/SSH_TTY/SSH_CLIENT indicate the remote end of an
SSH session — points the user at the clipboard image-paste shortcut so
the bytes actually cross. The ImageInputTooLargeError and unknown-error
branches keep their existing fallback so genuine type issues still
yield the user's input back to them.
Fixes#2375
Dynamically assigns segment colors by sweeping across the full HSV hue spectrum based on their track position. This ensures each segment has a distinct, predictable hue and removes the need for explicit `color` assignments.
- Updated the Windows npm shim resolver to resolve shim files against `cwd` and inspect `_prog` before treating a batch wrapper as a node launcher.
- Added a node-only guard so non-node wrappers, such as python shims, fall back to standard cmd.exe execution.
- Adjusted mcp stdio tests with a new non-node shim fixture and a simplified notify race case to validate transport teardown behavior.
Pressing Ctrl+T (toggle thinking-block visibility) — or any other path that calls rebuildChatFromMessages, e.g. the theme/preset selector — during the pre-streaming window after a submission cleared the just-submitted user message until the first assistant token arrived.
startPendingSubmission paints the user message optimistically before session.prompt(...) lands it in session entries; rebuildChatFromMessages reads buildTranscriptSessionContext() which has no record of it yet, so the rebuild erased it and the streaming-component re-add block in toggleThinkingBlockVisibility was a no-op (no stream yet).
Centralize the fix in rebuildChatFromMessages: after rendering the transcript, replay the in-flight optimistic user submission. EventController#handleMessageStart already clears optimisticUserMessageSignature once the real user message_start lands, so the replay is a no-op post-streaming and cannot duplicate. cancelPendingSubmission clears the signature and marks the submission cancelled before its own rebuild, so cancellation paths still wipe the message.
Fixes#2372
- Added SGR mouse routing to wizard scenes for hover, click, and wheel interactions.
- Added pointer-based tab selection and panel wheel scrolling in providers tabs.
- Added splash/outro left-click handling to start and complete the wizard flow.
- Added setup-wizard tests for mouse routing, splash click entry, and local coordinates.
Updated thinking visibility toggles to refresh assistant blocks in place instead of rebuilding the transcript, preserving pending user submissions and loaders before streaming starts. Added a regression test for the Ctrl+T pre-stream gap.\n\nFixes #2370
Restored cmd.exe's lookup order on Windows so an unqualified MCP command (e.g. server.cmd) checks the configured cwd before iterating PATH, keeping a project-local shim from being shadowed by a same-named global one.
- Implemented model-specific frame-size billing for Anthropic, OpenAI, and Google.
- Changed compaction shape resolution to bind model variants to ideal frame sizes.
- Updated tests and docs to reflect new frame-size and budget behavior.
Resolved Windows npm-generated .cmd MCP shims to their Node entrypoint before spawning so CodeGraph keeps ownership of stdio instead of disconnecting behind a transient cmd.exe wrapper.
Fixes#2367
- Updated snapcompact selectors and previews to pass `ShapeTarget` into `resolveShape` so `auto` is model-tuned.
- Applied `providerFrameBudget` in session compaction so generated archives stay within provider image caps.
- Replaced inline hard-coded image limits with `providerImageBudget` and skipped rasterization at cap.
- Added OpenRouter inline-transformer tests for cap exhaustion and existing-image budget exhaustion behavior.
Sent Hindsight retain timestamps with local timezone offsets and supplied timestamps for automatic and queued retains. Added regression coverage for client serialization and backend timestamp propagation.\n\nFixes #2363
- Repointed `SHAPES.anthropic` and the `anthropic-messages`/unknown-API fallback in `resolveShape` at the `6x12-dim` variant: production mono eval on claude-fable scored f1 .840 vs .877 for the repeated grid (within noise at n=25) at 37% lower cost, with no refusals.
- Reworded the `snapcompact.shape` descriptions in `settings-schema.ts` to drop per-provider eval-winner claims from the variant help text.
- Updated `snapcompact.test.ts` (new `6x12-dim` default render/compact assertions, `8x8r-bw` exercised via `resolveShape`), `snapcompact-inline.test.ts` frame math for the new geometry, and the `docs/compaction.md` shape sentence.
- Amended the snapcompact `[Unreleased]` entry that said the Anthropic default stayed `8x8r-bw` and added the default-switch entry.
- Added `ToolRenderer.provisionalPendingPreview` in `renderers.ts` and consulted it from `ToolExecutionComponent.isTranscriptBlockCommitStable`, replacing the 15.11.6 blanket gate that marked every collapsed pending preview commit-unstable.
- Marked only the tail-window previews the result render re-anchors as provisional: the edit streamed-diff tail (`edit/renderer.ts`), bash/ssh command caps (`createShellRenderer`, `sshToolRenderer`), and eval cells with interleaved outputs (`evalToolRenderer`).
- Restored mid-stream scrollback commits for every other pending preview, so tool calls taller than the viewport (e.g. a task call's context/assignment markdown) no longer read as cut off until the result lands.
- Added a regression test in `tool-live-region-scrollback.test.ts` scroll-appending a tall collapsed streaming task call into native scrollback mid-stream.
- Resolved retired effort-tier variant ids in `model-resolver.ts` through the hand-table aliases (`resolveVariantAlias`, `resolveBareVariantAlias`) plus the `X-thinking` → `X` grammar (`stripThinkingVariantToken`), with exact matches always winning while a raw id is live and explicit `:effort` suffixes transferring unchanged.
- Re-keyed models.yml `modelOverrides` and rate-limit selector suppressions from raw member ids onto the collapsed model in `model-registry.ts` (`normalizeSuppressedSelector`, lazy `hasLiveModel` checks so live raw ids keep their own overrides).
- Collapsed custom/config provider model lists at registry rebuild via `collapseBuiltModelVariants`, folding config-defined `X`/`X-thinking` twins into one entry.
- Extended `model-registry.test.ts` and `model-resolver.test.ts` with effort-tier variant collapsing and alias-resolution coverage.
- Updated fuzzy-search indexing to track compact word starts and required phrase matches to start at word boundaries.
- Adjusted token scoring and compact/phrase matching rules so exact and boundary-aware matches now rank above noisy substring matches.
- Filtered session search results to drop weak pure-fuzzy matches unless they contained literal tokens, and updated ranking tests for the new behavior.
- Added `handleUsageResetCommand` support to list and redeem usage reset credits.
- Refactored `/usage` into `show` and `reset` subcommands and removed `/reset-usage`.
- Handled ACP/TUI `/usage` flows so `show` reports usage and `reset` redeems credits.
- Kept selected theme setting values dirty-colored while selected in the UI list.
- Added `parentToolCallId` and `index` fields to subagent session records and propagated them from task lifecycle and progress events.
- Reworked subagent ordering to sort by parent-group order, spawn index, and stable creation order so out-of-order updates no longer reshuffled active HUD rows.
- Updated task execution to pass spawn indices through sync and async paths, switched the `tool.task` icon to Octicons tasklist, and added a registry test for out-of-order progress ordering.
- Added commit-stability signaling to transcript blocks and marked tool previews as unstable until expanded or finalized.
- Updated transcript scrollback promotion to derive live commit state only for blocks reporting commit-stable rows.
- Added tests ensuring provisional pending edit previews are never committed while durable live rows still promote after the stability window.
v15.11.4 introduced stateful previous_response_id chaining on the
official OpenAI endpoint. The in-provider retry classifier matched only
the generic stale-id phrasing ('previous response ... not found |
invalid | expired | stale'), missing the Zero Data Retention 400
'Previous response cannot be used for this organization due to Zero
Data Retention.'. The error therefore bypassed the categorical-disable
path, so the chain was reset (not disabled), the next successful turn
re-armed it, and every other turn 400'd in a loop.
Add a dedicated isOpenAIResponsesZeroDataRetentionError detector and a
markOpenAIResponsesChainZeroDataRetention helper that disables chaining
on the first hit (skipping the three-strike circuit breaker). The
in-call retry now drops 'store: true' from the replay so the request is
semantically valid for ZDR orgs, and reasoning continuity is preserved
by the existing include: ['reasoning.encrypted_content'] flag.
AgentSession.#isStaleOpenAIResponsesReplayError gains the ZDR phrasing
too, so any ZDR error that does bubble past the provider retry resets
the Responses session and retries at zero backoff instead of falling
back to a different model.
Fixes#2341
- Added usage snapshot persistence in sqlite with hour-bucket upsert behavior.
- Added listUsageHistory query support with optional provider and sinceMs filters.
- Added usage CLI history mode with `--history` and `--days` and trend rendering.
- Added changelog documentation for usage trend inspection and no-history exit behavior.
- Added an anchored Subagents HUD renderer that formats active subagent sessions as `Id: description` rows.
- Integrated a new interactive-mode container and observer-driven render path so the HUD updates with session events and clears when no subagents are active.
- Exported `formatTaskId` for shared HUD formatting and added tests covering active-only filtering, fallback task/progress text, and line truncation.