- Derived descriptors, default-model map, env keys, login list, and refresh dispatch from one ProviderDefinition per provider.
- Disabled OpenAI Codex stream obfuscation and interrupted whitespace-only tool-call argument deltas.
- Derived auth-broker callback ports and paste-code login set from the registry.
- Renamed `TodoWriteTool` to `TodoTool` and its source/prompt files.
- Updated tool registration, schema, renderers, and gating to `todo`.
- Adjusted cursor provider native tool names and tests to match.
- Renamed strike-animation constants and `todo-error-reminder` type.
- Imported isPromise from node:util/types in four modules.
- Replaced four instanceof Promise checks with isPromise calls for more reliable promise detection.
- Relocated compaction, branch-summarization, pruning, and utils from coding-agent to packages/agent/src/compaction.
- Moved OpenAI remote compaction helpers from packages/ai to the new compaction module.
- Added handoff.ts with extractHandoffDocument, createHandoffContext, and renderHandoffPrompt helpers.
- Exposed new entries.ts with standalone SessionEntry types so coding-agent no longer owns them.
- Added canonical `pi.zod` schema API exports and removed TypeBox package exports/imports.
- Migrated Tool schema typing from TypeBox to shared `TSchema`/Zod flow with legacy TypeBox compatibility.
- Updated AI provider adapters and MCP/agent builders to convert tool params through `toolWireSchema()`.
- Reworked schema validation from AJV to Zod-safe parsing with `fromTypeBox`, `toolWireSchema`, and meta schema checks.
- Removed export leakage by demoting many helper and const symbols to module-local scope.
- Renamed underscore-prefixed internals and cache fields, then updated related references and `satisfies never` checks.
- Deleted obsolete logic branches and helpers, including harmony-stream interruption flow and unused benchmark runtime helpers.
- Updated Biome config and manifests by broadening lint coverage and removing an unused `@napi-rs/cli` dev dependency.
- Adjusted tests and utilities to use renamed test helpers and remove redundant private test-only helpers/locals.
Adds a new `rpc-ui` mode that extends the existing headless RPC mode with
interactive tool support (ask tool, extension UI dialogs, etc.).
In plain `rpc` mode the session has `hasUI=false` and no UI context is
wired, so interactive tools are disabled. `rpc-ui` mode sets `hasUI=true`
and wires a single shared `RpcExtensionUIContext` instance into both the
tool context store and the extension runner. Both consumers share the same
`pendingExtensionRequests` map and output closure, so `extension_ui_response`
messages received on stdin are routed to the correct waiting promise
regardless of which code path (tool or extension) created the request.
Changes:
- `args.ts`: add `rpc-ui` to the `Mode` union and the parse guard
- `launch.ts`: expose `rpc-ui` in the OCLIF flag definition and help text
- `main.ts`: propagate `rpc-ui` through all RPC-mode guard conditions and
pass `setToolUIContext` to `runRpcMode` when the mode is `rpc-ui`
- `rpc-mode.ts`: accept optional `setToolUIContext` callback; create one
shared `RpcExtensionUIContext` instance and pass it to both the tool
context store and the extension runner
The server-side OAuthCallbackFlow callback window is 300_000 ms, but the
client starts its #send timer before the RPC command is dispatched. By
the time the callback server actually starts, some time has already been
consumed on the client side. If the user takes the full callback window
plus token exchange, the client 300_000 ms timeout fires first, rejects
login(), cleans up the onOpenUrl listener, and the server response
arrives into a discarded pending entry.
Use 600_000 ms (10 min) on the client — double the server window. The
server will always return an error or success response within its own
window, so this timeout is purely a safety net against server crash or
connection loss and never fires during a normal login.
Replace the static RPC_LOGIN_PROVIDERS allowlist with runtime detection
based on callback ordering.
Providers that support headless login (OAuthCallbackFlow) always call
onAuth first (emit the browser URL), then onManualCodeInput only as a
fallback for manual redirect-URL entry. Providers that require interactive
input (API-key paste, device-flow prompts, GitHub Enterprise URL) call
onPrompt before any onAuth fires.
onPrompt now branches on authEmitted:
- false (onPrompt before onAuth): reject immediately with a clear 'not
supported in RPC mode' error. The rejection propagates through
authStorage.login and is caught by the try/catch, returning an error
response. No deadlock.
- true (onPrompt after onAuth, inside OAuthCallbackFlow's fallback race):
return a never-settling promise so the race defers to the callback
server. A rejection here would be swallowed as null by .catch() and
spin the while(true) loop.
New providers self-classify by their actual call order with no list to
maintain.
OAuthCallbackFlow.#waitForCallback races the browser callback against
onManualCodeInput and catches any rejection as null. When onPrompt
threw, the catch turned it into null, the while(true) loop saw a
falsy result, and immediately re-invoked onManualCodeInput — a tight
spin that starved the callback server and made browser-callback logins
hang until timeout even when the user completed auth successfully.
Replace the throw with a never-resolving Promise<string>. The race
then blocks waiting for the callback server to deliver the code,
with no busy-looping. When the server-side login eventually
times out or the browser callback arrives, the pending promise is
abandoned and GC'd.
Addresses: https://github.com/can1357/oh-my-pi/pull/987#discussion_r3213450206
#send uses a hard-coded 30s timeout. OAuth flows require the user
to open a browser, authenticate with the provider, and wait for the
redirect — easily 1-3 minutes. Callers would see a spurious timeout
rejection while the server-side callback server was still live and
the user was still mid-flow.
Add optional timeoutMs parameter to #send (default 30_000, all
existing callers unaffected) and pass 300_000 from login().
Addresses: https://github.com/can1357/oh-my-pi/pull/987#discussion_r3213435093
RpcClient#handleLine was dropping extension_ui_request frames
(no isAgentEvent match → early return). Callers of login() had
no way to learn the auth URL, so the callback-server flow never
got a browser visit and the command hung until timeout.
- Add isRpcExtensionUiRequest type guard
- Add #extensionUiListeners set to RpcClient
- Dispatch extension_ui_request frames through that set in #handleLine
- login() accepts optional { onOpenUrl } callback; registers/
deregisters a listener scoped to the command's lifetime
Addresses: https://github.com/can1357/oh-my-pi/pull/987#discussion_r3213428270
- RpcCommand: add get_login_providers and login { providerId }
- RpcResponse: add typed responses for both commands
- RpcExtensionUIRequest: add open_url { url, instructions } event
(fire-and-forget; host opens the URL in system browser)
- rpc-mode: handle get_login_providers (returns provider list with
per-provider authenticated status) and login (drives authStorage.login
using RpcExtensionUIContext for onPrompt dialogs and notify for
onProgress; emits open_url for the auth page URL)
- rpc-client: add getLoginProviders() and login(providerId) methods
- Converted systemPrompt APIs and state types to ordered `string[]` across agent, AI, and coding-agent surfaces.
- Added `normalizeSystemPrompts` and applied it to context normalization before building provider request payloads.
- Updated AI providers to emit separate normalized prompt blocks/messages instead of a single merged system prompt.
- Removed dedicated `projectPrompt` state and remapped that context into system-context buckets in session, dump, and token accounting.
- Aligned tests and changelogs to pass and assert `systemPrompt` as arrays with ordered prompt semantics.
Include the current ContextUsage payload in get_state responses so RPC clients can render context-window status without in-process AgentSession access.
- Standardized missing-file read errors and now return `File not found: <path>` for absent edit targets.
- Centralized AI provider, usage, and OAuth helpers into shared modules to remove duplicated logic.
- Migrated OAuth/API-key login flows to shared factory helpers and removed inline prompt/token-exchange code.
- Reused shared tools and formatter utilities for discovery, stream tails, LSP batching, and source formatting.
- Consolidated repeated test helpers and fixtures into shared modules, replacing inline helper duplicates.
- Removed `SearchDb` APIs and `searchDb` fields, dropping db-backed state from native and agent sessions.
- Replaced crate export `fff` with `fd`, moving fuzzy-find bindings into `fd.rs`.
- Removed `SearchDb`/picker fast-path logic from `glob` and `grep`, simplifying scan flow and dropping db args.
- Removed `SearchDb`/`getSearchDb` wiring from extension, tool, and task context constructors across coding-agent.
- Added over-indentation validation warnings in chunk-edit normalization for suspicious `~` body line formatting.
- Removed `bytes`, `fff-grep`, `fff-search`, and `blake3` deps, adding `grep-searcher = "0.1"`.
- Added `/rename <title>` slash command to set explicit session names and update header/tab titles.
- Added `session_name` status segment with hash-derived accent color for session titles.
- Fixed shell execution failure sanitization to preserve all `execResult` fields after redacting stderr.
- Fixed tool execution completion output to pass original `toolResult` text instead of sanitized `content`.
- Add /rename <title> slash command to set an explicit session name,
updating the session header, terminal tab title, and status line
- Add session_name status segment: displays the session name on the
right side of the status bar with a stable djb2-hash-derived accent
color unique to each name; shown in all presets when a name is set
- Add setSessionName source tracking ('user' vs 'auto'): auto-generated
titles are silently ignored once the user has explicitly set a name,
preventing the async title generation from overwriting a /rename
- Sanitize session names at storage time: strip C0/C1 control characters
(including ANSI ESC) via static #sanitizeName before storing, blocking
escape sequence injection into the TUI, terminal title, and session file
- Extend sanitizeStatusText to cover the full C0/C1 range as
defense-in-depth (superset of the previous \r\n\t-only strip)
- Use stored (sanitized) name for showStatus message and terminal title
in handleRenameCommand, not the raw user input
- Guard terminal title update in auto-title path via titleSource === 'auto'
so a user rename is never overwritten by a late-resolving LLM call
- Reset #titleSource in #newSessionSync so each new session starts fresh
- Thread source parameter through AgentSession.setSessionName wrapper;
extension API and RPC set_session_name treated as 'user' intent
Closes#658
- Document session name getter/setter methods in extensions.md
- Add stub methods to ExtensionProxy that throw if called before init
- Add delegating implementations to ExtensionProxyInit
- Wire up getSessionName and setSessionName in extension runtime
- Add method signatures to ExtensionContext interface and type
- Add getSessionName to session manager API
- Add getSessionName and setSessionName to all mode contexts:
- ACP agent
- Extension UI controller (also updates terminal title)
- Print mode
- RPC mode
- Refactored chunk tree initialization to use explicit prologue/epilogue byte boundaries instead of None values.
- Extracted chunk resolution logic to use split_selector_crc_and_region() helper for improved code reuse.
- Reorganized package.json exports across multiple modules (autoresearch, cli, dap, edit, modes) for better API surface clarity.
- Updated test expectations for Go receiver method rendering and chunk selector formats to match refactored output.
- Consolidated notebook conversion logic and removed unused _createErrorToolResult helper function.
- Improved leading trivia preservation in chunk edits by detecting and maintaining line prefix whitespace.
- Added host tool execution framework with HostTool, HostToolContext, and host_tool() factory for custom tool integration.
- Added RpcConcurrencyError exception and _PromptLifecycleCoordinator to enforce single-flight constraint on prompt lifecycle methods.
- Enhanced JSON parsing with 10 validation helpers and enum frozensets for safe field extraction with detailed error messages.
- Replaced manual event/error list management with _BoundedHistory for bounded-size history with offset tracking.
- Added deep JSON cloning to prevent external mutations of stored payloads and improved UTF-8 error handling in subprocess stderr.
- Added custom_tools parameter to RpcClient and set_custom_tools() method for runtime tool registration.
- Added typed event listeners and granular event handling for all RPC notification types.
- Added set_todos RPC command and todoPhases session state field for todo phase management.
- Added RpcClient initialization parameters (thinking, tools, no_session, rpc_defaults) for startup configuration.
- Added install_headless_ui() method and todo management methods (get_todos, set_todos, clear_todos).
- Added TodoItem and TodoPhase dataclasses with parser functions for structured todo representation.
- Added RPC mode behavior: disables session title generation by default and resets workflow settings to built-in defaults.
- Added `wait_for_picker_scan()` function to search_db module with cancellation token support for polling picker scan completion.
- Integrated picker-based file search into glob matching logic with `collect_files_from_picker()` helper to reuse shared SearchDb picker results.
- Refactored fff and grep modules to use centralized `wait_for_picker_scan()` wrapper instead of direct FilePicker calls, improving cancellation handling.
- Propagated SearchDb instance through agent session initialization and input controller to enable unified file picker coordination across search operations.
- Added autoresearch extension with autonomous experiment loop supporting init, run, and log experiment tools for metric-driven optimization.
- Added widget placement system enabling extensions to position UI components above or below the editor via ExtensionWidgetOptions.
- Added dashboard controller with interactive overlay for viewing experiment results, metrics, and progress with keyboard navigation.
- Removed auto-correction logic for off-by-one range edits in hashline editor to preserve user intent in patch operations.
- Added state reconstruction utilities to parse autoresearch.jsonl logs and rebuild experiment state across sessions.
- Added comprehensive type definitions and helper utilities for metric parsing, ASI validation, and process management.
- Added `close()` method to SessionManager and AuthStorage for proper resource cleanup and finalization of prepared statements.
- Added `initiatorOverride` option support in OpenAI and Anthropic providers for message attribution control.
- Fixed resource leaks in RpcClient timeout handling by centralizing timeout creation with unref() and adding explicit clearTimeout() calls.
- Fixed AgentSession disposal to call SessionManager's `close()` method for guaranteed resource cleanup instead of fallback flush.
- Updated all test suites to properly dispose AuthStorage instances in cleanup hooks to prevent resource leaks between tests.
- Introduced Effort enum and ThinkingConfig metadata for per-model reasoning capabilities with min/max effort levels.
- Migrated thinking level API from string-based ThinkingLevel to structured Effort enum across agent and AI packages.
- Added model-thinking module with effort mapping, policy application, and semantic versioning utilities for provider-specific thinking modes.
- Removed supportsXhigh() function and replaced effort clamping with model-aware validation using ThinkingConfig metadata.
- Expanded models.json with thinking configuration objects for 50+ models including Claude, Gemini, and OpenAI variants.
- Added Python analysis scripts for edit tool usage patterns and tool invocation stream processing.
- Extracted thinking module with ThinkingEffort, ThinkingLevel, and ThinkingMode types to centralize reasoning configuration across packages.
- Migrated ThinkingLevel type from pi-agent-core to pi-ai package with new validation functions parseThinkingLevel() and getAvailableThinkingLevel().
- Consolidated thinking level constants and descriptions into reusable exports (ALL_THINKING_LEVELS, THINKING_MODE_DESCRIPTIONS) for consistent UI display.
- Removed local thinking-effort-label utility and replaced formatThinkingEffortLabel() with centralized formatThinking() function from pi-ai.
- Refactored thinking mode handling to distinguish ThinkingSelector (user-facing with 'off' option) from ThinkingEffort (provider-level).
Replace flaky time-based heuristic (sleep + 500ms race) with a proper
ready-signal protocol. The RPC server now emits {"type":"ready"} on
stdout when initialized, and the client waits for that signal instead
of guessing based on timing.
Fixes CI failure where the process took longer than 600ms to reach
provider validation (due to auth discovery + model registry refresh),
causing start() to resolve even when the process was about to exit.
- Added `--no-rules` CLI flag to coding-agent to disable rules discovery and loading.
- Added `rules` option to CreateAgentSessionOptions to allow custom rules configuration.
- Added `sessionDir` option to RpcClientOptions and implemented Symbol.dispose() for resource cleanup.
- Removed tarball-based task loading; migrated to directory-based fixtures with required inputDir and expectedDir properties.
- Refactored runner to use RpcClient resource management with `using` statement and simplified fixture handling.
- Consolidated type definitions and removed tarball.ts module in favor of streamlined task interface.
New RPC command that atomically aborts the current turn and starts
a new one with the given message, avoiding the race condition of
separate abort + wait + prompt calls.
Fix session.abort() not clearing promptInFlight flag due to
microtask ordering (waitForIdle resolves before promptWithMessage
finally block), which left isStreaming true and blocked subsequent
prompts.