- Implemented in-house, zero-dependency utility modules in `pi-utils` covering DOM manipulation, markdown parsing, templating, browser automation helpers, and terminal buffers.
- Migrated packages across the repository to consume the new internal utilities and `omptype` schema validators instead of external dependencies.
- Removed multiple external runtime and development dependencies including Zod, Marked, LRU cache, Turndown, and Puppeteer browser packages.
Closed worker and cmux run signals before yielding for floating-rejection drainage. Stale promise continuations can no longer begin page navigation after evaluated code returns.
Classified only marked browser failures and evaluated-run stack frames as run-owned rejections. Unrelated tab-worker failures now remain on the worker guard's fatal path.
Used a run-scoped Promise subclass instead of mutating native combinator methods. Evaluated code can now freeze its Promise constructor without breaking cleanup or later browser runs.
Observed Promise.all and Promise.race results derived from browser calls during each evaluated run. User catch continuations that rethrow browser failures now fail the owning run without changing native await behavior.
Logged late user continuation failures in cmux runs and delayed worker rejection folding until request-interception cleanup completed. This closes both windows where missing awaits could be silently dropped.
Logged user continuation rejections that settle after their browser run has ended. This preserves the completed result while making missing awaits visible instead of silently dropping them.
Tracked whether user continuation callbacks create each descendant rejection. Browser errors that user code rethrows now fail the owning run instead of being contained as propagated helper failures.
Scoped browser-error markers to each run and contained only propagated browser failures. Routed floated user continuations into failed runs and added worker coverage for native await plus every continuation method.
Observed every browser facade continuation so fire-and-forget helper
timeouts cannot wedge or kill a tab worker. Preserved native Promise
identity for callers and test matchers.
Selected PUPPETEER_EXECUTABLE_PATH before probing system browser installations so compatible headless-shell binaries remain usable by the shared daemon.
Added an isolated Windows candidate-selection regression probe.
Fixes#7601
The grep/glob multipath detector probed the raw joined string with lstat
and only split when the probe reported "missing" (ENOENT/ENOTDIR).
ENAMETOOLONG was classified as "unknown", which suppressed the split, so
a semicolon-delimited path list long enough to exceed NAME_MAX or
PATH_MAX collapsed to one literal path and failed with
"Path not found: <whole list>" even though every entry existed.
Classify ENAMETOOLONG as "missing" in probeLiteralPathExists and
delimitedPathPartResolves (a too-long string can never name a real
single entry), and broaden glob's stat catch so the raw errno never
reaches the caller.
Fixes#7597
Detected path-embedded OMP line selectors when reporting Cursor read results and stopped treating ranged payload lengths as whole-file totals.
Exposed exact source line counts from EOF-reaching read results and covered both the wire response and read metadata contracts.
Fixes#7590
- Preserved escaped control characters for the downstream reinterpretation safety decision.
- Covered the backslash-escaped git inline shell-alias bypass.
Fixes#7552
- Treated double-quoted shell-control chars like single-quoted ones so a -c/-e reinterpretation option still gates them.
- Covered the double-quoted git inline shell-alias bypass.
Fixes#7552
- Replaced the raw character guard with quote-aware scanning while retaining command substitution and unquoted shell-control protections.
- Added regression coverage for the reported Cargo benchmark filter.
Fixes#7552
- Introduce `@oh-my-pi/omptype` as a new ArkType-compatible schema validation package featuring a lazy JIT runtime, JSON Schema emission, and compatibility adapters.
- Replace `arktype` across workspace packages and test utilities with `@oh-my-pi/omptype`.
- Add benchmark suites, tests, and documentation for the new validation engine and adapters.
- Update workspace build, test runner, and release configurations to include the new package.
Add the executable names and absolute paths that are unique to Ungoogled
Chromium to the Linux branch of systemChromiumCandidates(), including the
system-wide and per-user Flatpak shims for
io.github.ungoogled_software.ungoogled_chromium.
The entries are appended after the existing ones, so a stock Chrome or
Chromium install still wins and PUPPETEER_EXECUTABLE_PATH keeps working
exactly as before.
Closes#7509
Retained pending pipeline state across blank and comment-only continuation
lines, and parsed Bash's |& operator as a single pipe boundary. Added
regression coverage for both forms and aligned the Bash interceptor docs.
Fixes#7496
The 17.2.2 compound-fragment matching splits commands on every unquoted
operator including `|`, so a downstream pipe stage like `grep x` in
`printf 'x\n' | grep x` became a standalone interception candidate and was
routed to the `grep` tool, which searches paths and cannot consume the
previous stage's stdout.
`extractFlatShellCommandSegments` now flags each segment that receives piped
stdin from a single unquoted `|`, and `interceptionCandidates` skips those:
a stdin-consuming stage cannot be replaced by a path-based dedicated tool.
Standalone (`grep pattern path`), first-stage (`grep x file | wc`), and
`&&`/`||`/`;`-sequenced commands still match.
Fixes#7496
Publish terminal daemon completions to the session that started the
process so idle agents can resume without polling hub status.
Persist every unacknowledged generation with a stable completion ID and
immutable snapshot. Replay the collection after reconnect or broker
recovery, and clear each event only after the owning client acknowledges
it.
Signed-off-by: Christian Stewart <christian@aperture.us>
inspect_image resolved @vision with resolveModelFromString, which dropped the
:high thinking selector, and passed no reasoning to the oneshot. The
google-gemini-cli mapper then emitted thinkingBudget: 0, which thinking-only
Gemini models reject with HTTP 400. Resolve the role's explicit thinking
selector, clamp it to the model's supported efforts, and forward it as the
oneshot reasoning.
Fixes#7448
- The pi-utils/mime subpath fix made the computer worker graph lazy-safe,
so the dynamic-import dispatch added for laziness is no longer needed;
cli.ts and the bundled-host fixture statically import
startComputerWorker() per the no-inline-import rule.
- worker-entry keeps the selector-guarded direct-source auto-start; the
worker-selector test now pins the exported hook contract. Verified
--no-addons CLI startup stays addon-free and the bundled/compiled
worker-host tests pass.
- The PR #7205 merge left cli.ts statically importing startComputerWorker,
dragging the computer worker graph (and pi_natives via the pi-utils
barrel) into normal CLI startup; --version died under --no-addons and
dotenv loaded before profile bootstrap. worker-entry is now a
self-starting side-effect module dispatched via dynamic import like
every other worker selector, and utils/clipboard.ts imports the mime
constant from its submodule instead of the barrel.
- Repointed the clipboard test spy at @oh-my-pi/pi-natives/clipboard —
spying the barrel never intercepted the subpath the code imports, so
the real native bridge ran (X11 timeouts on headless CI).
- Refreshed the pinned HTML export template digest and the scout gate
phrase the system-prompt rewrite changed.