- Introduce CleanseBoardModel and clean up status board rendering logic.
- Decouple CLI and interactive modes with CleanseRunUi interface and core runner.
- Add CleansePanelComponent and controller to manage interactive cleanse overlay.
- Register builtin `/cleanse` slash command and integrate into interactive mode.
- Implement a live status board utility for transient multi-line CLI status displays with TTY fallback support.
- Add progress callback support and forward subagent progress events to runner hooks.
- Update cleanse execution flow to track checker runs, agent progress, and status rendering.
- Add comprehensive unit tests for live board repainting and cleanse progress assertions.
`resolveCliArgv` hoisted a subcommand hidden behind leading global launch
flags to the front and forwarded those flags to the subcommand's own
parser (#2970). Launch-shaped commands (`launch`/`acp`) share the launch
flag surface, but strict-parsing subcommands like `update` declare only
their own flags, so a leading `--cwd` reached `node:util.parseArgs` and
threw `Unknown option '--cwd'`. This bit users whose shell alias/wrapper
runs `omp --cwd <dir> update`.
Leading launch-global flags are now stripped when the hoisted subcommand
is not launch-shaped, and still forwarded for `launch`/`acp`. Shared the
launch-command set with the profile bootstrap to keep one source of truth.
Fixes#8891
Remote OAuth MCP servers dropped out of /mcp under `omp auth-broker
serve` once their access token expired: neither the client nor the
broker could complete the refresh.
- Client: the MCP manager threw on the broker-redacted refresh sentinel
(REMOTE_REFRESH_SENTINEL) instead of asking the broker to refresh. It
now routes redacted MCP refreshes through
AuthStorage.forceRefreshCredentialById, which calls back to the broker
(the real refresh token never leaves the broker host).
- Broker: the serve process had no mcp_oauth:* refresh path, so
POST /v1/credential/:id/refresh answered "Unknown OAuth provider". Its
AuthStorage is now built with a refreshOAuthCredential override that
refreshes MCP credentials with a generic refresh_token grant from the
credential's embedded token endpoint and client id. The background
refresher keeps MCP tokens live through the same path.
Extract shared refreshManagedMcpOAuthCredential and
mcpOAuthServerUrlFromCredentialId helpers so both paths use identical
refresh material selection and RFC 8707 fallback-resource logic.
Fixes#8933
omp update re-threw Bun's raw fetch() UnsupportedProxyProtocol error, telling CLI users to pass verbose:true to fetch() — an instruction unavailable through the CLI. The update fetch catches now detect this failure and report which proxy env var uses an unsupported scheme plus the http/https requirement.
Fixes#8784
resolveUpdateTargetFromPath gated the symlink->realpath resolution on
allowPackageManagers, so binary-only releases (a major bump or an explicit
omp.dist: "binary") wrote to the raw PATH symlink instead of the binary it
resolves to. On an admin shared install where /usr/local/bin/omp is a
root-owned symlink into a group-writable dir this either failed with EACCES
(writing <link>.new into the root-owned dir) or replaced the symlink with a
full copy, stranding the shared install behind a split-brain second binary.
Target selection no longer depends on the release's distribution channel: a
foreign symlink (a non-manager alias, an admin symlink into a shared install)
resolves to its real binary and the launcher is left intact in every channel.
A package-manager launcher (bun/npm) keeps its deliberate in-place takeover on
a binary-only release, detected by re-classifying the launcher as if managers
were allowed rather than by the channel flag. The manager bin dirs are probed
in the binary channel only when the launcher is a symlink, so plain-file
installs stay probe-free.
Fixes#8732
- Add `renderPdfPageScreenshot` to render PDF pages via headless Chromium.
- Update `ReadTool` to intercept legacy PDF image paths and return page screenshots.
- Ensure daemon clients are closed on read command exit.
Detected npm and Bun ownership from the bin link immediate target within each precise global node_modules root. Foreign aliases now update their resolved standalone binary without replacing the alias.
Fixes#8468
Resolved npm and bun bin-entry symlinks before selecting the update method, and preserved foreign aliases by replacing their standalone target.
Fixes#8468
- Replaced time-based sleeps and polling loops with event-driven promise resolvers and fake timers across agent and tool tests.
- Migrated test suites to share in-memory auth storage and fixtures using lifecycle hooks.
- Updated catalog model definitions, metadata, and configurations.
Two overlapping `omp update` runs now share the target only for the
swap + stale-artifact sweep, guarded by withFileLock. This closes the
rollback race the unique-temp fix left open: a concurrent run's sweep
could delete a live run's .bak before its failed verification rolled it
back. The download stays outside the lock (unique temp path, safe to
overlap). Adds a regression covering a failed verification overlapping a
successful update.
Two overlapping `omp update` runs shared the fixed `<binary>.new` temp
path. downloadVerifiedBinary unlinks the target before writing, so the
second run's unlink deleted the first run's still-downloading temp file;
the first kept writing to its open fd (size and digest still passed),
then chmod hit the missing path and aborted with ENOENT.
Give the temp path the same unique per-attempt suffix the backup path
already uses (pid, timestamp, and a new process-local counter that also
covers same-millisecond, same-process collisions). Generalize the stale
backup sweep to also reclaim orphaned `.new` temp files, age-gated by the
download window so a concurrent run's in-progress temp is never deleted.
Fixes#8434
Moved strict --tools validation to the completed session registry so extension modules, custom tool directories, and plugin manifest tools are all eligible while unknown names still fail startup.
Deferred --tools validation until extension discovery, then validated against built-in and registered tool names while preserving strict rejection of unknown names.
Fixes#8421
- Added Anthropic prompt-cache refresh scheduling and state management to keep prompts warm across idle sessions.
- Updated pricing models and database stats tracking to calculate and store cost-weighted cache savings.
- Integrated cache savings metrics and efficiency displays into the stats CLI, dashboard routes, and UI components.
- Added support for package renaming, manifest pointer tracking, and installation migration during CLI updates.
- Add comprehensive Nix flake definitions, derivations, modules, and CI workflows.
- Update tests and executables to resolve binaries from PATH rather than absolute paths.
- Ensure byte reproducibility and zeroed timestamps in embedded dashboard archives.
- Add handling for Nix-managed installations in CLI update checks.
- Added Google provider thinking configuration parameters and force-reasoning-off controls.
- Implemented MCP SSE stream resumption using Last-Event-ID and `SSEResumeError`.
- Added support for TAR old-GNU sparse extension blocks, path length checks, and archive entry overrides.
- Restricted external thinking support to specific models and added semver fallback parsing.
- Added the `--external-thinking` CLI flag alongside model capability checks to gate external thinking tool availability.
- Updated Anthropic and Google transports to honor `forceReasoningOff` for native thinking-off controls.
- Renamed the `thoughts` property and parameter to `notes` across think fixtures, tools, and tests.
- Updated system prompt instructions and test suites to verify transport-specific thinking and tool activation.
- Added discovery subagent and custom checker specifications for alternative toolings across multiple languages.
- Implemented interactive TUI flows for target picking and free-form request discovery.
- Added output parsers for popular static analysis and linting tools.
- Increased default maximum subagents cap and documented the new capabilities.
- Implemented the `omp compress` command with batch processing, file resolution, and concurrency support.
- Added the semantic compression protocol, session factory, and rewrite-approve evaluation loop.
- Included prompt templates, tool descriptions, and comprehensive test coverage for compression targets.
- Generalized the progress reporter module for shared use across CLI commands.
- Added a curated think gallery fixture; the generic fallback carries no
thoughts field, so the streaming state rendered zero lines.
- Seeded the shared test registry with a runtime openai key: the prompt
preflight validates through the registry, not the per-request getApiKey
override, so keyless CI runners threw before reaching the mock server.
- Expected reasoning effort "none" — the only disable level the Responses
wire accepts; "off" is not a wire value.
- Extracted version verification logic into a reusable function accepting an explicit binary path.
- Updated shim takeover to verify the newly placed executable path directly instead of re-resolving via PATH.
- Added `resolveReleaseDist` and `shouldForceBinaryUpdate` to parse package manifests and gate major updates to binary releases.
- Implemented `updateViaShimTakeover` in `update-cli.ts` to seamlessly replace Windows script launchers with standalone binaries.
- Added comprehensive unit tests covering release distribution parsing, binary force updates, and script-shim takeover behavior.
Detected Bun-compiled entry points before preserving source invocations. Added a regression for the virtual bunfs argv shape and documented the fix.
Fixes#8233
The earlier dry-run change moved scope into an options object, silently
ignoring the legacy uninstallPlugin(id, "user") runtime shape still reachable
from compiled or plain-JS callers. Restore scope as the positional second
argument and carry dryRun in a trailing options bag, preserving the existing
call shape while keeping the non-mutating dry-run path.
Fixes#8178
Route marketplace dry-runs through MarketplaceManager's normal pre-mutation
validation so ambiguous or mismatched scopes fail exactly as real uninstalls
do. Move the manager's scope argument into an options object and add a dry-run
option that returns only after all removal planning has succeeded.
Fixes#8178
handleUninstall dropped the parsed dryRun flag and unconditionally called
mktMgr.uninstallPlugin / manager.uninstall, so `omp plugin uninstall
<plugin> --dry-run` removed the plugin on both the marketplace and npm
routes. Propagate dryRun into handleUninstall and short-circuit before
both removal calls, reporting the resolved removal (with its source)
instead of mutating state.
Fixes#8178
Shares a saved session by id prefix or .jsonl path without launching the
agent - same encrypted upload, store selection, and share.redactSecrets
handling as the /share slash command.
- Routed session tool provenance through live and rebuilt transcript render paths.
- Kept same-named extension tools on the generic renderer while preserving native tool rendering.
- Added regression coverage for an external recall result collision.
Fixes#7770
- Implemented in-house, zero-dependency utility modules in `pi-utils` covering DOM manipulation, markdown parsing, templating, browser automation helpers, and terminal buffers.
- Migrated packages across the repository to consume the new internal utilities and `omptype` schema validators instead of external dependencies.
- Removed multiple external runtime and development dependencies including Zod, Marked, LRU cache, Turndown, and Puppeteer browser packages.
Review findings on #7586:
- validate an explicit release version before comparing; the shared
comparator never throws, so 999.bad previously reached every manifest
- ci-release-notes imports the comparator by relative path: the
release_github job runs without bun install
- route Bun cache pruning through compareVersions and delete
compareSemverLikeVersions
- regression test for the release-version guard
Threaded the loopback hostname returned by startServer through the omp stats CLI and /stats slash command so the browser and logged URL target the actual listener instead of localhost.
Fixes#7633