- Kept PCRE2 matching interpreted on macOS across native grep, embedded grep, and embedded rg while preserving JIT elsewhere.
- Added regressions for both reported PCRE2-only crash patterns.
Fixes#7399
- waitForLogEntry raced winston's async flush and JSON.parsed a
partially written line, failing the error-serialization tests on
loaded CI runners; unparseable lines now wait for the next poll.
- Aborting a caller while it was the sole extraction waiter tore the shared
extraction down and deadlocked against the blocked conversion mock, hanging
the CI chunk until SIGKILL.
- Sequenced owner/joiner starts and added an untilAborted spy barrier that
waits for both waiters to attach before aborting.
The flattened descendant list can contain a protected node (the
harness, on a Windows PID-reuse false-descendant) together with that
node's real children, collected by recursing through it. Skipping only
the exact protected pid kept omp alive but still TerminateProcess'd its
unrelated worker/tool subprocesses.
signal_tree/terminate_tree now drop every node whose recorded parent
chain within the enumerated set passes through a protected pid, so a
false descendant of the harness can no longer drag the harness's real
children into the kill set.
Fixes#7452
- The 'N tool calls elided' replay placeholder leaked tool activity while
display.hideToolActivity was on; it is now a visibility-aware component
wired into both the hotkey and /settings toggle paths.
- Added replay + live-reveal regression coverage.
- A reload that drops a module's last require() edge leaves the permanent
hooks serving it from the synchronous snapshot map, which was only
refreshed while the path stayed flagged; an edit after the downgrade
replayed stale bytes. Ensure now re-rewrites and refreshes the snapshot
for every ever-synchronous path on each graph walk.
- Added the mirror reload regression (require edge dropped + source edited).
On Windows the descendant tree used to reap a cancelled bash run is
built from raw th32ParentProcessID links that outlive their recorded
parent. A recycled pid matching the harness's stale parent pid could
surface omp itself (or an ancestor) as a false descendant, and
signal_tree TerminateProcess'd it — killing the session with no
cleanup and no session_exit record when a blocking command hit its
timeout.
Add host_protected_pids() (harness pid plus its resolvable ancestor
chain) and skip those pids in signal_tree and terminate_tree. The
guard is cross-platform: a no-op on Unix, where the descendant walk is
already identity-pinned, and the safety net that keeps a tool timeout
from ever taking down the harness on Windows.
Fixes#7452
- A reload that adds a require() edge to an already-hooked ESM module never
re-registers hooks, and the original async onLoad filter keeps matching;
require() rejects async onLoad results, so the async hook now serves the
pre-rewritten synchronous source inline when one exists.
- Added a same-process reload regression covering the async-to-sync upgrade.
inspect_image resolved @vision with resolveModelFromString, which dropped the
:high thinking selector, and passed no reasoning to the oneshot. The
google-gemini-cli mapper then emitted thinkingBudget: 0, which thinking-only
Gemini models reject with HTTP 400. Resolve the role's explicit thinking
selector, clamp it to the model's supported efforts, and forward it as the
oneshot reasoning.
Fixes#7448
- Added shared Python call and literal serialization utilities with multiline verbatim support.
- Standardized tool inventories to format as an OpenAI-Harmony functions namespace using TypeScript declarations.
- Updated tool normalization and rendering functions to accept options objects and default to Python-syntax examples.
- Refactored Gemini dialect rendering to leverage shared serialization functions directly.
- Normalized result-bearing Codex image items on terminal output events and emitted standard image content.
- Preserved result-bearing image calls during full Responses history replay despite stale provider status.
- Added stream and replay regressions for the Codex path.
Fixes#7445
Completed transcript entries now write through to the OS page cache on
append instead of microtask-batching, supersede in-flight atomic rewrites
with a synchronous full-body publish, and land on the live moveTo path
(source pre-rename, destination post-rename) so a software crash no longer
drops finished user/assistant/tool events. Streaming text remains durable
only at message_end; no fsync/power-loss guarantee is claimed.
Preserved pre-existing MCP_OAUTH_CLIENT_ID and MCP_OAUTH_CLIENT_SECRET values
instead of deleting them after the env-expansion regression test, preventing
later tests in the same Bun process from observing mutated caller state.
Fixes#7440
/mcp reauth read OAuth clientId/clientSecret from the raw, unexpanded config
while URL and resource used expandEnvVarsDeep, so `${VAR}` placeholders were
sent literally to the token exchange. MCPOAuthFlow.exchangeToken() also accepted
any HTTP-success body, storing an empty access token when a provider signals
failure with HTTP 200 (e.g. Slack `{ ok: false, error }`), surfacing only later
as invalid_token.
- Select flow client credentials from runtimeBaseConfig / expanded auth block;
keep the raw placeholder for the persisted config file.
- Reject token responses without a non-empty access_token, including the
sanitized provider error when present.
- Add regression tests for env-expanded reauth credentials and HTTP-200 token
error bodies.
Fixes#7440
Matched fuzzy candidates against immutable source text while excluding ranges already selected for replacement. Inserted replacement content can no longer become a later exact or fuzzy candidate.
Added regression coverage for multiple fuzzy source matches when the replacement contains the original search text.
Fixes#7432
- The pi-utils/mime subpath fix made the computer worker graph lazy-safe,
so the dynamic-import dispatch added for laziness is no longer needed;
cli.ts and the bundled-host fixture statically import
startComputerWorker() per the no-inline-import rule.
- worker-entry keeps the selector-guarded direct-source auto-start; the
worker-selector test now pins the exported hook contract. Verified
--no-addons CLI startup stays addon-free and the bundled/compiled
worker-host tests pass.
Requeued already-processed ESM modules when a later CommonJS require upgraded them to synchronous loading, propagating the sync marker through their descendants.
Added an end-to-end regression covering normal discovery before a lazy CommonJS require of the same ESM graph.
Fixes#7402
- Routed streamSimpleOpenAIResponses through the central simple-stream dispatcher.
- Added wire-level coverage for hidden reasoning summary translation.
Fixes#7403
Kept pre-rewritten synchronous ESM sources available to permanent load hooks after the initial extension import settles, while refreshing them on reload.
Added an end-to-end regression for a CommonJS dependency that lazily requires a nested ESM cluster.
Fixes#7402
- Re-exported serializeConversation from the legacy coding-agent package root.
- Aliased the upstream simple OpenAI Responses stream name to OMPs equivalent.
- Added regression coverage for both compatibility exports.
Fixes#7403
- The PR #7205 merge left cli.ts statically importing startComputerWorker,
dragging the computer worker graph (and pi_natives via the pi-utils
barrel) into normal CLI startup; --version died under --no-addons and
dotenv loaded before profile bootstrap. worker-entry is now a
self-starting side-effect module dispatched via dynamic import like
every other worker selector, and utils/clipboard.ts imports the mime
constant from its submodule instead of the barrel.
- Repointed the clipboard test spy at @oh-my-pi/pi-natives/clipboard —
spying the barrel never intercepted the subpath the code imports, so
the real native bridge ran (X11 timeouts on headless CI).
- Refreshed the pinned HTML export template digest and the scout gate
phrase the system-prompt rewrite changed.
- prepareNativeCorePackage's files whitelist predated the native/clipboard
module; the packed tarball lacked it and the coding-agent CLI failed with
'Cannot find module @oh-my-pi/pi-natives/clipboard' in the tarball install
smoke. Verified the packed tarball now contains clipboard.js/.d.ts.
- napi omits the displayServer key when the backend reports None (headless
CI hits the unavailable backend); the declared contract is
displayServer?: string, so assert the value type instead of key presence.
- libc::ioctl takes c_ulong on glibc but c_int on musl; the hardcoded
c_ulong request type broke //:natives-linux-musl-{x64,arm64}. Verified
by cross-checking aarch64-unknown-linux-musl on the CI-pinned nightly.
- libspa-sys hard-links system libpipewire-0.3 via pkg-config, which no CI
or cross triple (musl, arm64) can satisfy; bazel addons already build with
crate_features = [], so shipping builds lose nothing. Linux devs opt in
with --features wayland-pipewire.
- Gated normalize_role_macos and the wayland capture helpers to the configs
that use them; handled the cfg(test) AxHandle variant in AtSpiAx::object.
- Fixed clippy-strict violations (redundant_pub_crate, missing_const_for_fn,
unnecessary_wraps, collapsible_if, map_unwrap_or, needless_return,
needless_pass_by_ref_mut) across the new linux desktop backend.
Extracted the coding-agent scope of PR #7077 (@santhreal): single-pass
placeholder matcher so positional values containing literal $@ or
$ARGUMENTS are never re-expanded. The unrelated utils formatting changes
in that PR were not taken.