* Implemented Smithery MCP Searchable Registry
* refactor(coding-agent): consolidated MCP registry search and improve error handling
- Extracted `parseCommandArgs` and `stripControlChars` utilities to reduce duplication in MCP command controller. Replaced custom URL opening logic with centralized `openPath` utility across OAuth and registry flows.
- Enhanced Smithery auth error handling to gracefully degrade on file read failures with logging instead of throwing, and improved chmod error reporting. Normalized Smithery API base URL to strip trailing slashes.
- Improved registry search pagination to fetch multiple pages until sufficient results are found, with semantic mode support to preserve API relevance ranking. Deduplicated entries by identity key and applied local sorting only in non-semantic mode.
---------
Co-authored-by: can1357 <me@can.ac>
- Fixed URI template matching to handle empty string expansions in MCP resource queries.
- Fixed LM Studio URL validation to preserve invalid baseUrl instead of applying localhost fallback.
- Fixed MCP notification epoch handling to prevent unsubscribe calls when old subscriptions resolve after re-enabling.
- Extracted hardcoded LM Studio base URL to named constant for improved maintainability.
- Refactored notification epoch check logic for improved code clarity and readability.
- Normalize LM Studio discovery URLs to avoid duplicated /v1 segments
- Harden status-line PR cache with branch+repo context validation and guarded async writes
- Apply Foundry auth precedence correctly and preserve system trust roots when custom CA is provided
- Split Copilot premium multiplier handling by plan tier while preserving agent-initiated zero billing
- Catch MCP notification refresh failures and route read_resource via deterministic full template matching
- Add regression tests for each fix cluster and keep targeted suites green
* feat(mcp): resource notifications, subscriptions, and read_resource builtin tool
- Add MCP resource subscription lifecycle (subscribe/unsubscribe on connect/disconnect)
- Wire mcp.notifications setting with live toggle support
- Add debounced followUp injection for resource change notifications
- Add global read_resource builtin tool with server resolution by URI/template scheme
- Add MCP prompt commands (buildMCPPromptCommands) with array content support
- Add server instructions injection into system prompt with attribution
- Add mcp.notificationDebounceMs configurable setting
Client (client.ts):
listResources, listResourceTemplates, readResource with pagination
subscribeToResources, unsubscribeFromResources
listPrompts, getPrompt, serverSupportsPrompts
serverSupportsResources, serverSupportsResourceSubscriptions
Manager (manager.ts):
Notification dispatch with subscribed-URI guard
Concurrent refresh deduplication via pending promise map
setNotificationsEnabled with subscribe/unsubscribe toggle
Tests:
client-resources.test.ts (31 tests)
client-prompts.test.ts (20 tests)
mcp-read-resource.test.ts (13 tests)
* fix(mcp): address PR review - eager prompt init and stale subscription cleanup
P1: Make setOnPromptsChanged eagerly fire for servers that already
have prompts loaded. The callback is registered after MCP discovery
has already loaded prompts and fired the hook, so without this the
handler is never called on the common startup path. The fix is in
the manager itself (not the caller), eliminating the race condition
regardless of when the callback is wired.
P2: Unsubscribe removed resource URIs on resource refresh.
refreshServerResources was subscribing to the new URI set and
overwriting #subscribedResources without unsubscribing URIs that
were previously subscribed but no longer present, leaving stale
subscriptions active on the server.
* fix(mcp): add resources and prompts to /mcp help text and subcommand completions
* feat(mcp): add /mcp notifications command
Shows per-server notification capabilities with subscription state:
- Lists supported notification types (tools/list_changed, resources/list_changed,
prompts/list_changed) with check marks
- Shows resources/subscribe status with active subscription count
- Lists subscribed URIs with green ticks when notifications are enabled
- Displays overall enabled/disabled state (mcp.notifications setting)
* fix(mcp): address PR review comments on race conditions and stale state
- Await subscribe/unsubscribe in refreshServerResources so the refresh
promise doesn't resolve before subscriptions are settled, preventing
a second refresh from racing and overwriting tracking state (P2 #3)
- Guard setNotificationsEnabled subscribe .then() against a disable
that happens while the subscribe request is in-flight (P2 #5)
- Re-check mcp.notifications setting inside debounce setTimeout
callback so toggling off mid-window actually suppresses the
follow-up message (P2 #4)
- Fire onToolsChanged and onPromptsChanged callbacks in
disconnectServer so stale slash commands and tool registrations
are cleaned up when a server is removed (P2 #2)
---------
Co-authored-by: Miroslav Drbal <miroslav.drbal@gendigital.com>
* Add PR number segment to status bar
Add a new 'pr' status line segment that shows the GitHub PR number
(e.g., #1234) as a clickable OSC 8 hyperlink when the current branch
has an associated pull request.
- Async lookup via 'gh pr view', cached per branch
- Invalidates on branch change via .git/HEAD watcher
- Falls back to hidden segment when no PR exists or gh unavailable
- Supports all theme presets (unicode, nerd font, ascii)
- Added to all preset layouts after the git segment
* Skip PR lookup on default branch, resolve dynamically
* Extract git-utils, add tests for parseGitHubRepo and parseDefaultBranch
* Fix PR lookup race condition, invalidation churn, and dotted repo names
- Guard #cachedPr writes against branch change during in-flight lookup
- Stop clearing PR cache in invalidate() (only .git/HEAD watcher should)
- Allow dots in GitHub repo names in parseGitHubRepo regex
* Simplify PR lookup: use gh pr view, try upstream/HEAD for default branch
- Replace gh pr list --head with gh pr view (requires gh repo set-default)
- Remove manual remote URL resolution — gh handles it
- Default branch detection falls back to upstream/HEAD when origin/HEAD is unset
- Fixed exit_plan_mode handler to abort active agent turn before opening plan approval selector, ensuring proper session cleanup.
- Added test to verify abort is called before handleExitPlanModeTool in exit_plan_mode event handling.
- Add KagiProvider implementation (Search API v0)
- Register kagi in SearchProviderId type, provider map, and fallback order
- Add kagi to tool schema enum, SearchParams type, and settings UI
- Register KAGI_API_KEY in service provider map
- Update CHANGELOG
- Added `authServerUrl` field to `AuthDetectionResult` to capture MCP OAuth server metadata.
- Added `extractMcpAuthServerUrl()` function to parse and validate `Mcp-Auth-Server` header URLs from OAuth errors.
- Enhanced `discoverOAuthEndpoints()` to accept optional `authServerUrl` parameter and query `/.well-known/oauth-protected-resource` endpoint.
- Improved OAuth metadata extraction to handle multiple `clientId` field variations (`clientId`, `default_client_id`, `public_client_id`).
- Extracted metadata parsing logic into reusable `findEndpoints()` helper function supporting multiple OAuth metadata formats.
- Added comprehensive test coverage for OAuth endpoint discovery, header parsing, and error validation.
Fixes#235
- Add `rate-limit-utils.ts` to classify 429/503 errors (Quota, Rate Limit, Capacity)
- Fix `google-gemini-cli` to fail-fast on 429s instead of getting stuck in internal retries
- Update `isUsageLimitErrorMessage` regex in `AgentSession` to catch all Google-specific error variations
- Implement smart backoff timings (30m for quota, 30s for rate limit, 45s+jitter for capacity)
- Remove 0% hiding logic in `/usage` to always display account rotation pool
- Add comprehensive unit tests for rate limit parsing and provider behavior
- Replaced timeout-based cancellation with AbortSignal-based cancellation in ask tool for unified abort handling.
- Added signal parameter to UIContext select() and input() methods to support external cancellation propagation.
- Fixed race condition in dialog overlay handling by replacing direct resolve() calls with settled flag wrapper.
- Added comprehensive test coverage for ask tool cancellation behavior across user-initiated and timeout scenarios.
- Added render_mermaid tool to convert Mermaid diagrams to ASCII output with configurable rendering options.
- Added renderMermaid.enabled setting to control availability of the render_mermaid tool.
- Changed Mermaid rendering from PNG terminal graphics to ASCII text format across theme and TUI components.
- Migrated mermaid utilities from pi-tui to pi-utils package with new ASCII rendering functions.
- Removed PNG-based mermaid rendering APIs (getMermaidImage, renderMermaidToPng) in favor of ASCII alternatives.
- Added transcript export option to debug menu that writes visible TUI conversation to a temporary text file.
- Implemented handleDebugTranscriptCommand in CommandController to render chat messages, strip ANSI codes, and write to temp directory.
- Updated InteractiveModeContext interface and InteractiveMode to expose the new debug transcript command handler.
/plan without args still toggles plan mode on/off as before.
/plan <prompt> enters plan mode and immediately starts planning
with the given prompt, skipping the extra enter-then-type step.
COLORFGBG reflects the actual terminal profile colors, while
detectMacOSAppearance() reports the OS-level dark/light setting.
When a user runs a dark terminal on macOS light mode (or vice versa),
COLORFGBG gives the correct answer. The previous ordering caused omp
to load the light theme in dark terminals when macOS was in light mode.
Detection priority is now:
1. Mode 2031 (terminal DSR) - most authoritative
2. COLORFGBG env var - reflects terminal profile
3. macOS system appearance - OS-level fallback
4. Default to dark
- event-controller: check async state for inlined image read results
instead of hardcoding isBackgroundRunning=false
- ui-helpers: fall through to render text blocks when read results
contain both images and text
- terminal-capabilities: return null for unknown PI_FORCE_IMAGE_PROTOCOL
values instead of silently falling through to fallback detection
- Replaced external dependencies with native Bun APIs: glob, TOML parsing, and HTML parsing.
- Removed 7 unused dependencies (file-type, glob, ignore, marked, zod, ms, @types/ms) and simplified package.json.
- Migrated mermaid cache key type from string to bigint using Bun.hash.xxHash64() for efficient hashing.
- Deleted ignore-files utility module and removed rootDir/ignoreMatcher parameters from loadFilesFromDir().
- Implemented inline MIME type detection for images, reducing sniff buffer from 4100 to 12 bytes.
- Added `tools.maxTimeout` setting to enforce global timeout ceiling across all tool calls.
- Centralized per-tool timeout constants and clamping logic into `tool-timeouts.ts` module.
- Extracted `clampTimeout()` function to standardize timeout enforcement across bash, python, browser, ssh, and fetch tools.
Add cross-platform terminal dark/light mode detection using the Mode 2031
VT extension (DECSET 2031). On startup, query the terminal's current
appearance with CSI ? 996 n, then subscribe to live appearance change
notifications with CSI ? 2031 h. When the OS or terminal switches between
dark and light mode, the terminal sends a DSR that triggers an automatic
theme re-evaluation.
Previously, detectTerminalBackground() only checked the COLORFGBG
environment variable once at launch — a static value that never updates
when the system appearance changes mid-session. The SIGWINCH listener
only fires on terminal resize, not on appearance changes.
Mode 2031 is supported by Ghostty, Kitty (0.38.1+), Contour (0.4.0+),
VTE/GNOME Terminal (0.82.0+), and tmux (3.6+). Unsupported terminals
silently ignore the escape sequences and fall back to the existing
COLORFGBG heuristic.
* fix: use --no-optional-locks for background git status calls
Prevent index.lock contention by adding --no-optional-locks to all
git status --porcelain calls. This is the same approach VSCode uses
in its built-in git extension (GIT_OPTIONAL_LOCKS=0).
The status-line component polls git status every ~1s to show
staged/unstaged/untracked counts. Without --no-optional-locks,
each call acquires index.lock for an opportunistic index refresh,
which blocks concurrent git operations (pull, rebase, commit) run
by the user or by omp's own tool execution.
The git-status documentation explicitly recommends this:
'Scripts running status in the background should consider
using git --no-optional-locks status'
References:
- git docs: https://git-scm.com/docs/git-status (BACKGROUND REFRESH)
- git commit adding the flag: https://github.com/git/git/commit/27344d6
- VSCode's fix: GIT_OPTIONAL_LOCKS=0 in extensions/git/src/git.ts:2716
- Claude Code same issue: https://github.com/anthropics/claude-code/issues/11005
- GitExtensions same issue: https://github.com/gitextensions/gitextensions/issues/5066
- VSCode issue #31069: https://github.com/microsoft/vscode/issues/31069
* style: fix biome formatting for long lines in worktree.ts
Add an optional `oauth` config block on MCP server entries in mcp.json,
allowing explicit `clientId` and `callbackPort` values for servers that
don't expose these through auto-discovery (e.g. Slack).
The `oauth.clientId` is used as a fallback — if the server's error
response or well-known metadata includes a client_id, that takes
precedence. The `callbackPort` defaults to 3000 when not specified.
- Added topP, topK, minP, presencePenalty, and repetitionPenalty sampling control options to StreamOptions and AgentOptions interfaces.
- Implemented getter and setter properties on Agent class for runtime configuration of model sampling parameters.
- Added UI configuration and preset value providers for five new sampling parameters in coding-agent settings schema and components.
- Integrated sampling control parameters through proxy layer and agent session configuration for end-to-end provider support.
After plan approval, handleClearCommand() creates a new session with a
fresh artifacts directory. The local:// URL is session-scoped, so the
renamed plan file in the old session local dir was unreachable from
the execution session.
Write the plan content to the new session local dir after the session
switch so the titled plan artifact resolves correctly.
Support Perplexity web search via session cookies extracted from
the desktop app (Electron/AppImage). Accepts either a raw cookie
string or a bare session token value.
Auth resolution order: PERPLEXITY_COOKIES > agent.db OAuth > PERPLEXITY_API_KEY
The #getGitStatus() method fires an async `git status --porcelain` but
only updates the TTL timestamp after the async completes. In large repos
where git status takes seconds, every TUI render cycle during that window
spawns a new process — cascading into hundreds of concurrent git processes,
exhausting file descriptors and creating .git/index.lock contention.
Add a #gitStatusInFlight boolean guard that ensures exactly one git status
process runs at a time. Use a finally block to unconditionally reset the
guard and refresh the TTL to completion time.
The disabledServers mechanism introduced in 4bfa3b0c (Merge branch
'pr-82', 2026-02-16) was defeated by a level guard added after merge:
servers with _source.level === "user" were exempt from the disabled
check. This meant servers discovered from ~/.claude.json (which the
Claude provider tags as level "user") were never actually filtered out,
even when present in disabledServers.
Remove the level guard so disabledServers applies unconditionally. This
is safe because the /mcp disable command already uses updateMCPServer
(setting enabled: false inline) for servers defined in omp own configs;
the disabledServers path only fires for third-party discovered servers.
Also fix the /mcp list display to cross-filter discovered servers
against the disabled list, preventing a server from appearing both as
"connected" and "disabled" when the MCP manager has stale state.
- Guard Container.render() to ensure width >= 1 for ALL components
- Guard TwoColumnBody.rightWidth with Math.max(0, ...)
- Validate description type before passing to native function
- Fall back to truncation when width <= 2
Fixes crash when opening extensions in narrow terminals.
- Consolidated @oh-my-pi/pi-utils subpath imports into single package root import across 100+ files.
- Moved tryParseJson utility from local web scrapers module to @oh-my-pi/pi-utils package for centralized JSON parsing.
- Renamed loadSkillsFromDir to scanSkillsFromDir and refactored skill discovery to use fs.promises.readdir instead of glob-based approach.
- Replaced custom parseJSON with tryParseJson across discovery modules for consistent error handling.
- Removed emitCustomToolSessionEvent method and cleanupSshResources function, consolidating shutdown logic into dispose method.
- Updated glob pattern construction to use GlobBuilder with literal_separator(true) for improved path handling.
- Added a `display.tabWidth` setting to control default tab rendering.
- Integrated `.editorconfig` resolution for c ontext-aware tab indentation.
- Updated native text processing to use the resolved tab width for calculations.
- Improved tab visualization in diffs and other UI elements for consistency.
- Introduced OAuthManualInputManager and routed callback-server logins to await pasted redirect URLs with a visible tip.
- Extended /login slash command to submit redirect URLs, block overlapping logins, and covered manual callbacks in tests.
- Propagated onManualCodeInput through OAuth provider login helpers with a default authorization prompt.
- Resolved docs index generation paths using path.resolve relative to the script directory.
- Added getTodoPhases() and setTodoPhases() methods to ToolSession API for in-memory todo phase management.
- Added getLatestTodoPhasesFromEntries() export to retrieve todo phases from session history entries.
- Changed todo state management from file-based (todos.json) to in-memory session cache with automatic persistence.
- Changed todo phases to sync from session branch history during branching and rewriting operations.
- Removed file-based todo loading logic and replaced with session-based todo phase retrieval throughout codebase.
- Renamed the `notes://` protocol to `local://` for better clarity.
- Updated all internal references, prompts, and tool documentation.
- Migrated plan storage paths to use the new `local://` scheme.
- Replaced plan:// protocol with notes:// for session-scoped artifact storage and plan finalization.
- Added title parameter to exit_plan_mode tool to enable plan file renaming during approval workflow.
- Implemented NotesProtocolHandler for notes:// URL scheme with path traversal protection and session fallback.
- Added renameApprovedPlanFile function to handle plan artifact finalization with validation and error handling.
- Updated system prompt documentation to reference notes:// protocol and internal URL schemes for artifact access.