- Added optional slot_uid handling to push requests and git operations, validating IDs 1..65535.
- Passed slot-specific subprocess kwargs into git helpers, including safe.directory, HOME, user/group and umask.
- Injected slot-safe repo env helpers to scrub secrets, force git identity, and disable terminal prompts.
- Adjusted workspace and cache permissioning so slot users own workspaces with targeted chmod/chown behavior.
- Added tests for slot UID propagation, safe-directory env, and cross-slot push/retry behavior in unit and e2e suites.
- Added completion-reminder rendering via completion_reminder.md with repo, issue, and workspace context.
- Added task_completion_max_reminders config with default 2 and ROBOMP_TASK_COMPLETION_MAX_REMINDERS alias.
- Added worker completion-reminder flow with triage classification checks and terminal-action handling for bug tasks.
- Added turn-flow tests and internal worker harness updates for prompts, chown handling, and tool-call tracking.
- Added branch-detection logic in `ensure_workspace` to read the currently checked-out branch before reusing a workspace.
- Compared the checked-out branch to the mapped branch and logged a warning when they differed, then preserved the replayed branch.
- Added a regression test that renames a workspace branch and verifies a replayed checkout returns the renamed branch.
- Added an AbortController and wired it into task bindings so host tools can request an immediate worker teardown.
- Implemented a new `abort_task` host tool that audits and logs an internal reason, marks the issue as abandoned, and triggers the abort controller.
- Updated the worker RPC loop to treat abort-triggered process errors as a clean shutdown while still propagating other task failures.
- Set the entrypoint umask to 0002 so created git metadata is group-writable for slot-based resume workflows.
- Extended rename_workspace_branch to accept an optional slot_uid and call _share_git_metadata_with_slots with it after updating the branch.
- Added a sandbox test that verifies renaming a workspace branch refreshes shared git metadata with the provided slot UID.
- Changed repro_record to return only "recorded" after saving a transcript instead of including its workspace path.
- Removed the requirement to reference a transcript path from the repro prompt wording.
- Updated docker-compose to map the stage service to 127.0.0.1:6543 and aligned the repro_record test to assert the exact new return value.
- Added three question auto-close related environment variables to the docker-compose service configuration.
- Configured their defaults to enable auto-close with a 4-hour threshold and 60-second scan interval.
- Implemented question auto-close scheduling with configurable enablement, delay, and scan interval.
- Added reaction lookup and issue-close operations across backend, proxy, and client APIs.
- Extended host tools and app server wiring to append auto-close suffixes, run scheduler, and cancel closures.
- Updated documentation and env examples with question-autoclose settings and behavior notes.
- Added pending_closures persistence and lifecycle handling to claim, finalize, requeue, and cancel rows.
- Added tests covering scheduler, DB, proxy, server, and host-tool cancellation scenarios.
- Standardized triage flow to read issue context, classify before side effects, and separate bug, doc, and non-bug paths.
- Tightened bug-path execution to run repro_record, bun run fix, bun check, commit, then push and open PR.
- Reworked ambiguity handling so agents post one clarifying comment, never guess, and wait for explicit direction.
- Refined follow-up, review, and resume rules to reuse session state, preserve thread context, and amend-push existing PR branches.
- Updated host-tool docs to clarify gh_post_comment fields, bug-label requirements, skip_checks verification, and issue-closure behavior.
- Added `scripts/with-pi-root.sh` to resolve `PI_ROOT` from an explicit checkout, `/work/pi`, or an auto-cloned cache directory, with env knobs for repo, ref, cache path, and auto-update behavior.
- Updated `pi-artifacts`, `rebuild`, and `up` to execute through the new wrapper so Docker build and compose startup share the resolved oh-my-pi root.
- Documented the new resolution flow in `.env.example` and `README.md`, added cache ignore entries, and kept build/runtime config aligned with the resolved root.
- Updated classify_issue validation to audit and include command errors for invalid primary, rationale, and branch_slug inputs.
- Allowed non-bug classifications to ignore unsupported fields (priority, functional, provider, platform) without raising hard errors.
- Aligned prompt guidance and tests to match the new classify_issue tolerance for optional fields.
- Added skip_checks option to gh_push_branch and gh_open_pr to bypass bun pre-publish checks.
- Short-circuited bun fix/check helpers when skip_checks=true and propagated the flag through gh tool calls.
- Changed rename_workspace_branch to accept pr_number and leave branch unchanged during an open-PR rename path.
- Documented skip_checks escape-hatch rules and two-strike gh_push_branch retry restrictions.
- Added tests for skip-check bypass behavior, failed-check suppression, and no-op branch rename with open PR.
- Replaced direct hard-timeout `stop()` calls with a shared cancel hook that invokes `client.stop()` then `client._mark_closed()` using `RpcProcessExitError`.
- Added a cancellation-path workaround for an upstream `omp_rpc` issue where `stop()` alone left `_closed_error` unset and kept `_wait_for_agent_end` blocked until timeout.
- Updated worker tests to verify both hard-timeout and cancel-hook flows call `_mark_closed()` with `RpcProcessExitError`.
- Added an inbound thread flag to tool bindings and set it from PR task context.
- Updated classify_issue and set_issue_labels to return no-op responses when the inbound thread is a PR or the issue is already classified, avoiding GitHub label updates.
- Expanded tests for no-op behavior and prompt text to reflect that triage tools are only used on fresh unclassified issues.
- Rewrote `README.md` with a concise operator-first walkthrough of bot behavior and setup flow.
- Replaced large architecture and security narratives with a compact summary of proxy trust boundaries and run modes.
- Updated CLI and operational examples in `README.md` to match current `bun run`-based workflows and checks.
- Added a Bun/Vite dashboard frontend with App views for status, issues, events, logs, triggers, and working queue.
- Added dashboard backend support by mounting `/static`, serving package assets, and injecting replay config into `index.html`.
- Added client API/state modules for polling, retry, cancel, browse filtering, and config validation in the SPA.
- Replaced `justfile` task orchestration with bun scripts, updating README/AGENTS and command docs.
- Added Docker, Bun config, and ignorefiles to build web assets, copy them into runtime static data, and prune artifacts.
- Added webhook ping helper plus dashboard test fixtures for bootstrap HTML and replay-token substitution.
- Removed `bin/stage-pi.sh` and migrated build orchestration to the new `pi-artifacts` workflow.
- Added `PI_ARTIFACTS_IMAGE`/`PI_IMAGE` handling and rewired `just build` and `rebuild` around `pi-artifacts`.
- Replaced Dockerfile builder stages with a `pi-artifacts` stage and copied node/wheel artifacts from it.
- Updated compose and documentation to pass artifact image args and explain runtime invalidation/rebuild guidance.
- Updated the dashboard retry click handler to bind on document.querySelector("main") instead of the "$" helper.
- Expanded pi staging rsync exclusions to omit generated OS, profiling, and host-specific artifacts to keep the build context stable.
- Adjusted dashboard tests to assert the new main selector binding and the removal of the previous "$\"main\".addEventListener" usage.
- Expanded server tests to verify the dashboard HTML includes retry-related text.
- Adjusted the retry-by-issue test to require a retrieved event before asserting its queued state.
- Skipped triage_issue processing for first-time issues already linked to an open closing PR.
- Allowed triage to continue when list_closing_pull_requests raised a transient GitHubError.
- Skipped repeating closing-PR timeline checks for issues already present in the database.
- Added list_closing_pull_requests tests for connected/disconnected/closed timeline filtering.
- Added triage_issue tests for skip, proceed, error fallback, and repeat-no-requery paths.
- Added async issue-closing PR lookup across backend, client, and /gh/v1/closing_prs with auth and errors.
- Added GitHub timeline parsing to track PR link events and return sorted open linked PR IDs.
- Added batched 500-size processed key lookups and applied returned keys to issue browse payloads.
- Added a hide-processed browse mode with row highlighting and updated empty/count messaging.
- Added worktree-aware bad-ref cleanup to remove owning worktrees before deleting refs.
- Added tests for processed-key queries, browse-flag refresh on cache hit, and bad-ref cleanup.
- Recovered stale PR-to-issue mappings by reloading PR metadata when DB resolution missed and repairing DB branch/PR links.
- Fixed follow-up workspace bootstrap to start from a remote existing_branch when present, instead of silently resetting to default.
- Updated PR review and PR-conversation handlers to handle unmapped bot-owned PRs by creating missing issue rows from recovered PR data.
- Added regression coverage for branch-based issue lookup and remote-branch workspace recovery.
- Routed PR conversation and review-comment webhooks to `issue_key(repo, pr_number)` when origin mapping was missing.
- Added PR-origin context via `origin` in persona outputs for `followup_comment` and `directive`.
- Updated directive and follow-up prompt templates to use `origin.description` when origin issue is unavailable.
- Added get_pull_request() to GitHubBackend and GitHubClient via /repos/{repo}/pulls/{number}.
- Extended PullRequestInfo parsing to include author and head_repo values.
- Added /gh/v1/pull_request proxy route and proxy client forwarding for pull-request retrieval.
- Added tests for get_pull_request payload parsing and proxy client/server round-trip coverage.
- Added optional `branch_slug` handling to `classify_issue` and to tool/prompt guidance.
- Validated `branch_slug` as non-empty kebab-case and rejected invalid values before rename logic.
- Implemented `rename_workspace_branch`, updating local git branches and `workspace.branch` when valid.
- Added branch consistency checks and explicit errors for non-farm, invalid, and rename-failure cases.
- Added `Database.find_issue_by_branch` lookup and persisted renamed branch updates to issue records.
- Added tests for rename success, idempotence, validation errors, and issue-branch persistence.
- Extended the pool fetch path to prune missing git object alternates, delete bad refs reported by git, and retry fetch operations after each repair.
- Added a Database helper to persist issue branch updates and verified fetch repair behavior with a new test that ensures stale alternates and bad refs are removed.
- Added `ROBOMP_TASK_TIMEOUT_HARD_GRACE_SECONDS` and `Settings.task_timeout_hard_grace_seconds` with a 60s default.
- Updated triage/replay to await terminal completion, default `--wait-timeout` from timeout+grace, and return timed_out JSON.
- Added hard-timeout worker handling with per-slot TMPDIRs and RPC stop on expiry to avoid stuck runs.
- Added SlotPool `slot_uids` exposure and queue/sandbox cleanup to reap configured or stale slot processes before release.
- Added tests for new timeout parsing, manual triage waits, queue slot reaping, sandbox process cleanup, and worker hard-timeout behavior.
- Added _prepare_xdg_dirs to create per-workspace .omp-xdg data, state, and cache dirs and passed them into RPC env setup.
- Updated _run_rpc_blocking to use those XDG dirs and chown them for slot users when running as root.
- Muted uvicorn.access entries for high-frequency dashboard polling paths and added worker tests covering both directory creation and chown behavior.
- Added async issue-browse cache with fetch metadata to reuse normalized issue payloads.
- Updated /api/issue/browse to return cached issues, honor `refresh=1`, and expose cache timing metadata.
- Updated dashboard loadBrowse flow with `forceRefresh`, refresh-button binding, and age-based status text.
- Added test helpers and cache-behavior tests for forced refresh, reuse, and webhook updates.
- Added bare_mention_reply() persona text and used it for bare mentions with trace metadata logging.
- Added a `robomp_data` named volume in compose and migrated /data mounts from host `./data` paths.
- Added slot-permission helpers in sandbox setup to share git metadata across retries on Linux roots.
- Added tests validating metadata group-permissions and workspace refresh idempotence for retry slot reuse.
- Added staging in _build_extra_env to copy .agent/.omp config into _AGENT_HOME and normalize permissions.
- Added test_build_extra_env_stages_agent_home to validate staged .agent/.omp files and HOME env behavior.
- Added a short retry loop in entrypoint startup to wait for staged agent config mounts before initializing agent home.
- Implemented a new ANSI-colored PrettyFormatter for compact human-readable stdout log lines.
- Switched stdout logging to the new pretty formatter while keeping JSON output for optional file handlers.
- Added SlotPool initialization to queue test helpers to align WorkerPool fixtures with slot-aware execution.
- Updated cancellation and shutdown queue tests with slot_uid-aware _dispatch stubs.
- Added sandbox tests covering _chown_workspace root/non-root and Linux/non-Linux behavior.
- Added ensure_workspace test coverage that it forwards slot_uid into _chown_workspace calls.
- Expanded _run_rpc_blocking tests to verify HOME/token env handling and slot_uid user/group mapping.
- Replaced queue concurrency gating with SlotPool dispatch for root runs and kept semaphore fallback otherwise.
- Threaded slot_uid through queue dispatch, tasks, and workspace creation for per-slot execution context.
- Configured omp subprocesses and sandbox workspaces to use slot UID/GID for per-slot file isolation.
- Added async SlotPool to acquire and release integer slot UIDs in a reusable pool.
- Enforced unique slot UIDs at init and rejected releases for unacquired slot IDs.
- Implemented blocking-and-reuse semantics via queue-backed slot checkout and check-in.
- Added unit tests for empty pools, UID reuse, duplicate release, duplicate IDs, and concurrency waits.
- Relocated compose mounts to /srv/agent-home-stage and copied staged ~/.agent/.omp config into /srv/agent-home at startup.
- Configured omp-* slot users in entrypoint.sh with dedicated group IDs for per-slot runtime isolation.
- Initialized /srv/agent-home with root-owned perms and tightened /data/robomp.sqlite ownership/mode handling.
- Aligned agent volume mounts to `/srv/agent-home/.agent` and `/srv/agent-home/.omp/agent` paths.
- Added role-aware startup logic so proxy containers bypass `PI_ROOT` validation and run the target command.
- Created `omp` worker users and startup ownership/permissions for `/data` and `/srv/agent-home` directories.
- Hardened existing sqlite artifacts by setting `root:root` ownership and `0600` mode when present.
- Documented mutually exclusive gh-proxy and PAT auth modes in `.env.example`, including required env keys.
- Updated `AGENTS.md` and `README.md` to describe compose env allowlists and mode-specific token placement.
- Clarified `README.md` workflow docs for `gh_push_branch`/`gh_open_pr` and credential redaction via `sandbox.redact_credentials`.
- Added proxy-mode settings loading via load_proxy_settings in src/robomp/config.py to validate required serve-time env.
- Implemented query-aware HMAC signing and verification for request targets in src/robomp/proxy_client.py and src/robomp/proxy/server.py.
- Added hard body size limits in src/robomp/proxy/server.py returning 413 before full read or auth.
- Added origin URL validation in src/robomp/proxy/server.py before git push to block non-github or mismatched repos.
- Added configurable git timeouts in src/robomp/git_ops.py and enforced wall-clock limits in src/robomp/proxy/server.py git handlers.
- Updated src/robomp/git_ops.py push to pin --force-with-lease to refs/remotes/origin/<branch> for safer concurrent push protection.
- Added a pre-run dirty-worktree gate in _run_pre_publish_bun_fix to reject uncommitted edits before `bun run fix`.
- Added regression coverage to ensure gh_push_branch and gh_open_pr refuse dirty workspaces before publishing.
- Adjusted stop() in src/robomp/queue.py to cancel in-flight hookless workers after drain timeout.
- Added _shutdown_cancelled tracking so _run_event only skips failed marking for deliberately interrupted deliveries.
- Ensured unrelated dispatch errors during drain are marked failed instead of being silently requeued.
- Pre-warmed `Database(path)` in `test_admit_submission_enforces_cap_atomically_across_connections` to isolate startup races.
- Configured barrier and thread `future.result` timeouts in the DB cap race test to prevent hangs.
- Added ROBOMP_GH_PROXY_HMAC_KEY/URL wiring so orchestrator calls gh-proxy over signed API paths.
- Added a gh-proxy service and internal robomp_internal network in compose, isolating token-bearing calls.
- Changed robomp container startup to explicit env allowlisting and to fail when GITHUB_TOKEN is present.
- Added proxy-role detection in entrypoint.sh to skip PI_ROOT checks when running robomp.proxy.
- Added docs and operator workflow updates documenting the two-container trust boundary and recovery flow.
- Added proxy HMAC contract tests for valid signatures and 401 responses on missing, bad, and stale headers.
- Added end-to-end tests for proxy request/response mapping across repo, issue, comment, review, and pull-request endpoints.
- Added GitHubProxyClient and ProxyGitTransport git flow tests for clone/push success and head-drift/repo mismatch failures.