- Deleted `bash-normalize.ts` and its tests; output truncation is handled by the streaming tail buffer and artifact spillover.
- Removed `head`/`tail` schema fields from `bashSchema` and `BashToolInput`.
- Updated system prompt and bash tool prompt to forbid `| head`/`| tail` pipes and other anti-patterns, directing the agent to use dedicated tools instead.
The 50ms retry loop in #scheduleBackgroundExchangeFlush had no guard
against session teardown. If dispose() was called while streaming,
the setTimeout callbacks kept firing and attempted emitExternalEvent
on a disconnected agent.
- Add #isDisposed flag; set it at the top of dispose() before any
async teardown so poll ticks that fire mid-teardown bail out cleanly
- Clear #pendingBackgroundExchanges in dispose() to drop queued
messages that will never be rendered
- Widen the attempt() bail condition to include #isDisposed so the
loop terminates even if new messages arrived between the dispose()
clear and the next tick
- Added immutable metadata to protocol handlers and had the router copy each handler's setting onto resolved internal resources.
- Updated read and search tools to honor `resource.immutable`, and made search suppress hashline anchors only for immutable source paths while preserving them for mutable files.
- Expanded internal URL tests to cover mutable local resources and mixed immutable/mutable search input hashline behavior.
- Added explicit prompt markers and wrappers across system templates, including `[env]`, `[role]`, `[coop]`, `[closure]`, and `[now]`.
- Removed `renderTemplate` and `sectionSeparator` flows, deleted `task/template.ts`, and switched to per-task `renderSubagentUserPrompt` rendering.
- Updated system prompt assembly to `shortenPath`-normalize `cwd`, append rendered now metadata, and preserve trailing `[now]` blocks.
- Removed legacy template tests and added prompt-composition tests for ordered `[contract]`->`[project]`->`[now]` blocks and context-only system placement.
- Reworked shared prompt utilities by collapsing consecutive blank lines and removing obsolete `OPENING_HBS`/`LIST_ITEM` helper behavior.
- Removed the brace-only structural bigram helper path from the line hash logic.
- Punctuation-only lines now follow the non-significant-character path using index-seeded xxHash hashing for their hash.
- Updated the hashline line-hash comment to describe that non-significant lines use the line-number-seeded seed.
- Extended splitPathAndSel to detect compound selectors that combine a line range with `raw` in either order.
- Updated read selector parsing to support `:lines:raw` and `:raw:lines` selectors and propagate raw-mode handling through internal URL, archive, and notebook paths.
- Added tests covering compound selector syntax and confirming it returns verbatim content without anchors or line-number prefixes.
- Added a collapsible tools header with chips and intent metadata styles in HTML exports.
- Added eval tool support with cell-level parsing and inferred language syntax highlighting.
- Added dedicated renderers for search, recipe, and irc tool calls and separated `_i` intent from tool args.
- Enhanced edit, ast_edit, find, search, and gh renderers with richer headers, fields, and option badges.
- Changed power-assertion state so assertions were prompt-scoped and no longer blocked after aborts.
- Extended file-display resolution to accept an immutable flag and suppress hashline anchors when immutable sources are requested.
- Plumbed immutable propagation through ReadTool and SearchTool so internal URL reads and searches pass that context.
- Added a regression test confirming artifact:// search output no longer includes hashline anchors.
- Added macOS power assertion settings for idle, system, user, and display with schema defaults.
- Added idle, system, and user options to MacOSPowerAssertionOptions in TS typings and Rust, preserving display.
- Changed agent-session power flow to use begin/end/reset in-flight helpers and avoid manual counter updates.
- Updated power assertions to combine multiple kinds per native handle and support safe repeated-stop behavior.
- Updated unreleased changelog notes to document the breaking behavior and canceled-prompt unblock correction.
- Added `listWorkspace` native binding and API types, exporting bounded workspace trees with AGENTS.md candidates.
- Reworked `buildWorkspaceTree` and `buildDirectoryTree` to call `listWorkspace` with 5s timeout defaults.
- Replaced startup AGENTS.md discovery with workspace-tree-only scanning and removed legacy AgentsMdSearch session plumbing.
- Updated `WorkspaceTree` and system prompt context to expose `agentsMdFiles` and aligned tests/changelog expectations.
- Dropped the `modify` edit type and its `< ANCHORTEXT` / `+ ANCHORTEXT` syntax.
- Removed associated parser rules, regex patterns, apply logic, and tests.
- Deleted the "Append WITHIN a line" example from the prompt docs.
- Added a 30s timeout for extension handlers in runner.ts so stalled callbacks now emit warnings and stop.
- Consolidated duplicated extension handler error handling by routing calls through #runHandlerWithTimeout.
- Introduced a flag to detect when an explicit modelRegistry was supplied to runSubprocess.
- Skipped modelRegistry.refresh() when reusing the parent registry and retained refresh when creating a new one.
- Added a debug log to indicate when a parent modelRegistry is reused and refresh is bypassed.
- Refactored SSE response parsing to read the stream with a single in-progress drain loop.
- Resolved the matching request promise when the expected JSON-RPC result or error arrives and continued dispatching remaining SSE messages on the same stream.
- Adjusted error handling to reject on abort/timeout or missing response and clear the timeout when stream parsing completes.
- Updated task call rendering to use `args.tasks?.length ?? 0` when displaying agent counts.
- Prevented runtime warnings in streaming task calls when the `tasks` array was still undefined.
- Updated the hashline prompt to clarify that anchors must use the file state from the most recent read.
- Added guidance warning not to renumber line references when stacking multiple patch operations.
Reporter screenshot showed a parent session on DeepSeek V4 Pro dispatching
a task subagent that resolved to `qwen3.6-plus-free` — an opencode-zen
model the user had no working credentials for. The dispatch hit a
provider that could not serve the model and surfaced a confusing API
rejection instead of using the parent's already-authenticated model.
Adds `resolveModelOverrideWithAuthFallback`, an auth-aware wrapper
around `resolveModelOverride` that checks the resolved subagent model's
credentials via `modelRegistry.getApiKey` + `isAuthenticated` and
falls back to the parent session's active model pattern when the
primary has no working auth. The parent's active model is plumbed
through `ExecutorOptions.parentActiveModelPattern` from `TaskTool`
into `runSubprocess`. If neither has working auth (or they resolve to
the same model), the primary resolution is preserved so the existing
error path still surfaces a meaningful failure downstream.
Fixes#985
- Model resolver: provider-prefixed `<provider>/<id>` selectors are now
strict. If the provider is known and the exact pair does not resolve,
return undefined instead of silently crossing provider boundaries
(e.g. routing `anthropic/claude-3-7-sonnet` to amazon-bedrock when
the user only has Anthropic auth). Unqualified resolution is unchanged.
- Compaction: when the current model's provider has no credentials,
manual compaction now retries across compaction model candidates and
falls back to an authenticated role; if no usable fallback exists, it
throws a clear provider-specific pre-stream error instead of bubbling
a 503 `auth_unavailable` from the provider stream.
Fixes#986Fixes#980
- Trim logo from 14w to 12w (2-wide legs).
- Diagonal BL→TR gradient instead of per-line LTR.
- Truecolor: 3-stop magenta→violet→cyan path that skips the deep-blue valley.
- 256-color: same 6-stop ramp as fallback.
- Compute the colored logo once at module load instead of per render.
Adds an opt-in onSseEvent callback across HTTP-streaming providers (Anthropic, OpenAI Responses/Completions, Azure OpenAI Responses, OpenAI Codex SSE, Google Gemini CLI, GitLab Duo, Kimi, Synthetic) so callers can inspect raw SSE frames without altering parsed output. Provider fetch wrapping only tees response bodies when an observer is wired; standalone packages/ai consumers without onSseEvent are not penalized.
Adds streamIdleTimeoutMs (env: PI_STREAM_IDLE_TIMEOUT_MS, with PI_OPENAI_STREAM_IDLE_TIMEOUT_MS as a backward-compatible alias). Anthropic now enforces a steady-state idle watchdog (default 120s) in addition to the first-event watchdog. OpenAI Responses, Azure Responses, and Codex (SSE + WebSocket) gain a semantic-progress predicate so response.in_progress-style keepalives no longer keep stalled tool calls alive forever.
Adds a coding-agent debug-panel raw SSE viewer backed by a per-session bounded buffer (1000 records / 512KB) that AgentSession populates unconditionally so users can post-hoc inspect a stuck stream from the TUI.
- Updated the hashline grammar to require a full `LID .. LID` range for block operations.
- Enhanced `parseRange` to reject single-anchor syntax and malformed ranges, and to require duplicated anchors for one-line edits.
- Reworked hashline prompt examples/tests accordingly and added coverage for single-anchor delete/replace forms.
- Replaced regex-based import rewriting in `rewriteStaticImports` with Babel AST parsing.
- Handled default, namespace, named, and side-effect imports, preserving `import ... with` options.
- Returned original source on no top-level imports, parse failures, or unchanged non-import regions.
- Added `@babel/parser` dependency and tests/changelog coverage for top-level static-import rewrite behavior.
- Added `./hashline` package exports and redirected callers to the new hashline entrypoint.
- Moved hashline logic out of `edit/` to `src/hashline` and removed `edit/modes/hashline`/`edit/line-hash` paths.
- Added hashline parsers, anchors, types, and diff helpers with stricter input and mismatch validation.
- Implemented preflight and cache-recovery execution flows to reapply edits and handle stale anchor mismatches.
- Documented the hashline API relocation as breaking changes in `CHANGELOG.md`.
- Clarified the hashline guidance to select a self-contained syntactic unit before narrowing the edit operation.
- Added a multiline destructuring/call example showing the full construct replacement pattern and safer alternatives.
- Updated anti-pattern instructions to reject partial-boundary replacement payloads and continuation-fragment edits.
- Removed hashline anchor auto-rebase logic, including the ±5-line rebase window and `tryRebaseAnchor` fallback.
- Validation now reports hash mismatches directly as hard `HashMismatch` entries and surfaces them via `HashlineMismatchError` without mutating anchor lines.
- Updated the changelog to document anchor auto-rebase removal and the immediate re-read recovery behavior.
- Updated LSP diagnostics output to return "OK" when no issues were found.
- Added a diagnostics-specific render case to show successful status and a success label for "OK" responses.
- Updated the regression test to expect the new "OK" diagnostics output.
- Added asynchronous Kitty conversion for assistant tool images using `convertToPng`, keyed per tool-call entry with cached and in-flight tracking.
- Updated assistant image rendering to prefer converted PNGs for Kitty terminals while preserving existing behavior for other protocols.
- Added a unit test that verifies WebP tool images are converted and rendered as Kitty image output instead of the raw image/webp fallback.
The server-side OAuthCallbackFlow callback window is 300_000 ms, but the
client starts its #send timer before the RPC command is dispatched. By
the time the callback server actually starts, some time has already been
consumed on the client side. If the user takes the full callback window
plus token exchange, the client 300_000 ms timeout fires first, rejects
login(), cleans up the onOpenUrl listener, and the server response
arrives into a discarded pending entry.
Use 600_000 ms (10 min) on the client — double the server window. The
server will always return an error or success response within its own
window, so this timeout is purely a safety net against server crash or
connection loss and never fires during a normal login.
Replace the static RPC_LOGIN_PROVIDERS allowlist with runtime detection
based on callback ordering.
Providers that support headless login (OAuthCallbackFlow) always call
onAuth first (emit the browser URL), then onManualCodeInput only as a
fallback for manual redirect-URL entry. Providers that require interactive
input (API-key paste, device-flow prompts, GitHub Enterprise URL) call
onPrompt before any onAuth fires.
onPrompt now branches on authEmitted:
- false (onPrompt before onAuth): reject immediately with a clear 'not
supported in RPC mode' error. The rejection propagates through
authStorage.login and is caught by the try/catch, returning an error
response. No deadlock.
- true (onPrompt after onAuth, inside OAuthCallbackFlow's fallback race):
return a never-settling promise so the race defers to the callback
server. A rejection here would be swallowed as null by .catch() and
spin the while(true) loop.
New providers self-classify by their actual call order with no list to
maintain.
OAuthCallbackFlow.#waitForCallback races the browser callback against
onManualCodeInput and catches any rejection as null. When onPrompt
threw, the catch turned it into null, the while(true) loop saw a
falsy result, and immediately re-invoked onManualCodeInput — a tight
spin that starved the callback server and made browser-callback logins
hang until timeout even when the user completed auth successfully.
Replace the throw with a never-resolving Promise<string>. The race
then blocks waiting for the callback server to deliver the code,
with no busy-looping. When the server-side login eventually
times out or the browser callback arrives, the pending promise is
abandoned and GC'd.
Addresses: https://github.com/can1357/oh-my-pi/pull/987#discussion_r3213450206
#send uses a hard-coded 30s timeout. OAuth flows require the user
to open a browser, authenticate with the provider, and wait for the
redirect — easily 1-3 minutes. Callers would see a spurious timeout
rejection while the server-side callback server was still live and
the user was still mid-flow.
Add optional timeoutMs parameter to #send (default 30_000, all
existing callers unaffected) and pass 300_000 from login().
Addresses: https://github.com/can1357/oh-my-pi/pull/987#discussion_r3213435093
When a patch introduces a new type that crosses a function/module
boundary (event, message, RPC frame, enum variant, etc.), the reviewer
must locate the dispatch point on the consuming side and confirm the
new type is handled. This class of bug is invisible from the diff alone
because the silent drop lives in untouched routing code.
Motivated by a missed P2 in PR #987: a new open_url extension_ui_request
was emitted by login() but RpcClient#handleLine had no case for it and
silently dropped every frame, leaving callers with no auth URL and the
command hanging until timeout.
RpcClient#handleLine was dropping extension_ui_request frames
(no isAgentEvent match → early return). Callers of login() had
no way to learn the auth URL, so the callback-server flow never
got a browser visit and the command hung until timeout.
- Add isRpcExtensionUiRequest type guard
- Add #extensionUiListeners set to RpcClient
- Dispatch extension_ui_request frames through that set in #handleLine
- login() accepts optional { onOpenUrl } callback; registers/
deregisters a listener scoped to the command's lifetime
Addresses: https://github.com/can1357/oh-my-pi/pull/987#discussion_r3213428270
- RpcCommand: add get_login_providers and login { providerId }
- RpcResponse: add typed responses for both commands
- RpcExtensionUIRequest: add open_url { url, instructions } event
(fire-and-forget; host opens the URL in system browser)
- rpc-mode: handle get_login_providers (returns provider list with
per-provider authenticated status) and login (drives authStorage.login
using RpcExtensionUIContext for onPrompt dialogs and notify for
onProgress; emits open_url for the auth page URL)
- rpc-client: add getLoginProviders() and login(providerId) methods
Real CC's getAPIMetadata includes device_id alongside session_id and
account_uuid. Rather than reading OS machine UUIDs (hardware fingerprinting)
or storing a random persistent ID, derive it as:
sha256("omp-device-id-v1:" + account_uuid).hex()
Properties:
- Indistinguishable from a randomly generated device ID on the wire
- Deterministic per account — survives reinstalls, no persistent storage
- Auditable: derived solely from the OAuth UUID already shared with Anthropic
- Zero hardware access, zero extra I/O
- Omitted for API-key callers (no account_uuid → no hash)