- Introduce `@oh-my-pi/omptype` as a new ArkType-compatible schema validation package featuring a lazy JIT runtime, JSON Schema emission, and compatibility adapters.
- Replace `arktype` across workspace packages and test utilities with `@oh-my-pi/omptype`.
- Add benchmark suites, tests, and documentation for the new validation engine and adapters.
- Update workspace build, test runner, and release configurations to include the new package.
Publish terminal daemon completions to the session that started the
process so idle agents can resume without polling hub status.
Persist every unacknowledged generation with a stable completion ID and
immutable snapshot. Replay the collection after reconnect or broker
recovery, and clear each event only after the owning client acknowledges
it.
Signed-off-by: Christian Stewart <christian@aperture.us>
inspect_image resolved @vision with resolveModelFromString, which dropped the
:high thinking selector, and passed no reasoning to the oneshot. The
google-gemini-cli mapper then emitted thinkingBudget: 0, which thinking-only
Gemini models reject with HTTP 400. Resolve the role's explicit thinking
selector, clamp it to the model's supported efforts, and forward it as the
oneshot reasoning.
Fixes#7448
- The pi-utils/mime subpath fix made the computer worker graph lazy-safe,
so the dynamic-import dispatch added for laziness is no longer needed;
cli.ts and the bundled-host fixture statically import
startComputerWorker() per the no-inline-import rule.
- worker-entry keeps the selector-guarded direct-source auto-start; the
worker-selector test now pins the exported hook contract. Verified
--no-addons CLI startup stays addon-free and the bundled/compiled
worker-host tests pass.
- The PR #7205 merge left cli.ts statically importing startComputerWorker,
dragging the computer worker graph (and pi_natives via the pi-utils
barrel) into normal CLI startup; --version died under --no-addons and
dotenv loaded before profile bootstrap. worker-entry is now a
self-starting side-effect module dispatched via dynamic import like
every other worker selector, and utils/clipboard.ts imports the mime
constant from its submodule instead of the barrel.
- Repointed the clipboard test spy at @oh-my-pi/pi-natives/clipboard —
spying the barrel never intercepted the subpath the code imports, so
the real native bridge ran (X11 timeouts on headless CI).
- Refreshed the pinned HTML export template digest and the scout gate
phrase the system-prompt rewrite changed.
- Replaced monolithic desktop native bindings and action batching with a modular cross-platform backend structure supporting Wayland, X11, macOS, and Win32.
- Updated the computer tool schema and supervisor to execute persistent JavaScript script runs with timeout clamping and asynchronous tool calling.
- Integrated accessibility (AX) tree snapshotting, node querying, and bounds-based hit testing across platform desktop layers.
- Added native clipboard bindings and updated coding-agent prompts, renderers, and tests to validate script-based computer workflows.
- Added an LSP multiplexer server, protocol definitions, and daemon lifecycle management to route traffic across sessions.
- Introduced `lsp.shared` settings configuration and SDK session creation support for shared language servers.
- Migrated shared daemon ensure helpers into a central launch module with updated import references.
- Added comprehensive unit tests and fake LSP server fixtures covering muxing, sharing, caching, and restarts.
- Serialized group and ungroup operations to prevent duplicate tab group creation races.
- Queued and serially drained tab grouping requests in the relay bridge to prevent overlapping RPCs.
- Mirrored tab group titles to session storage and healed duplicate groups during background service worker recovery.
- Renamed run-cancellation utility to run-scope and updated corresponding module and test references.
- Added window discovery, targeting, and frame validation for macOS, Windows, and Linux platforms.
- Updated computer tool and protocol definitions to support listing and targeting specific application windows.
- Refactored native computer tool exposure to function-only representation across models.
- Updated documentation and test suites to reflect window-scoped computer control capabilities.
Dropped the single-active-run fallback that claimed unrelated stackless rejections in the shared main-process realm, matching the eval inline-mode invariant. Only guest-file stack frames attribute a rejection now; stackless reasons keep the fatal path. Restored the probe to an Error rejection carrying a guest stack.
Fixes#7365
Attributed unmatched rejection reasons when exactly one cmux guest run is active, covering primitive and library-created failures without guessing between concurrent runs. Updated the process probe to reject with a primitive value.
Fixes#7365
Captured browser-run-attributable promise rejections before the global fatal handler and surfaced active failures as tool errors. Retained finished run filenames so late rejections remain isolated without consuming unrelated process failures.
Fixes#7365
Address review feedback on #7344:
- grep/glob/ast_grep descriptions now render via a getter instead of a
construction-time field, so a live task.disabledAgents change (e.g. via
/agents) is picked up on the next prompt rebuild instead of leaving
stale 'Task + scout' guidance cached.
- The workflowz notice now also gates the 'Scout inline FIRST' verb on
line 5, matching the already-gated line 14.
Hard-coded 'scout' references reached the model even when the scout
agent was disabled via task.disabledAgents or absent from the session
spawn list. Gate every such reference on scout actually being spawnable:
the task tool description, the delegation gates, the plan-mode and
workflowz notices, the glob/grep/ast-grep guidance, and the task
specialization advisory. Prompt shape is otherwise unchanged; only
erroneous references to the unavailable subagent are dropped.
Closes#7313
- Implement the OMP Browser Relay extension with WebSocket communication and CDP RPC execution.
- Add browser relay server, daemon management, and bridge multiplexing in the coding agent.
- Introduce CLI commands and settings schema options for configuring and installing the relay.
- Add utility functions and test suites supporting environment parsing and relay lifecycle handling.
xd:// devices dispatch through the write tool, so a read-only call such
as an lsp navigation matched PREWALK_ACTION_TOOLS and armed the one-way
model hand-off while still reasoning about code shape.
dispatchXdevTool now records the wrapped tool's approval tier on the
XdevDispatch, and the prewalk coordinator only treats a device write as
an implementation action at write/exec tier. Direct edit/write are
unchanged.
Fixes#7312
- Prevent xdev state allocation and tool mounting in sessions lacking a write tool.
- Expose discoverable tools top-level instead of auto-granting write transports.
- Added `ensureSharedBrowser` and shared browser acquisition to manage project-shared broker-owned Chromium instances.
- Implemented concurrent duplicate daemon start prevention and single-flight `pendingOpens` deduplication.
- Updated browser handle disposal to disconnect from shared daemons rather than closing them.
- Updated browser documentation and launch specifications to support shared and local headless runs.
waitForManagedBashJob raced job completion against a bare
Bun.sleep(thresholdMs), which cannot be cancelled. When completion,
abort, or steering won the race, the losing Bun.sleep timer stayed
scheduled and ref'd, keeping Bun's event loop alive until the threshold
expired — delaying SDK/headless shutdown and accumulating timers under
fast command rates.
Replace the Bun.sleep with a Promise.withResolvers settled by a
cancellable setTimeout, and route every outcome (including the former
no-signal early return) through one try/finally that clears the timer
and removes the abort/steer listeners.
Add a child-process regression test that runs the real auto-background
path for a fast command against a 30s threshold and asserts the process
exits promptly instead of being held for the full threshold.
Fixes#7235
A tool call aborted mid-batch to service queued steering/peer input emits a synthetic placeholder result with isError:true so the model retries it. The TUI keyed all error styling (red ✘, red frame/text) off that flag, so a normal steering skip rendered identically to a real tool failure.
Mark the skip placeholder with the existing SyntheticToolResultDetails discriminator (source: "interrupt_skipped", executed:false) and render benign skips through the neutral generic card (info glyph, dim text, neutral background), bypassing any bespoke error frame. Genuine failures keep their error styling.
Fixes#7199
Match interceptor regexes against conservative, raw shell command segments
in addition to the complete command, so anchored rules can detect commands
after &&, ||, ;, |, &, and newlines without treating quoted or escaped text
as commands.
Add extractFlatShellCommandSegments() to preserve source text for
user-configured regexes, unlike the token-based approval matcher.
Add skipShellWord() and environment-assignment stripping so rules can match
commands prefixed with NAME=value assignments. Preserve the original command
in interception errors after extracting a leading cd command.
The artifact spill wrapper dropped the read truncation metadata, so a
spilled oversized read lost its next-offset pagination hint, and an
artifact:// read of an already-spilled result was spilled a second time.
Preserve the existing truncation metadata and skip re-spilling artifact
reads.
- Removed copy and delete operations across tokenizer, parser, grammar, and clipboard logic.
- Standardized line-editing operations and block resolvers to use cut exclusively.
- Updated documentation, prompts, and test suites to reflect the removal of copy and delete syntax.
- Implemented clipboard register management, parsing, and execution rules for CUT, COPY, and PASTE operations in the hashline engine.
- Added session-persistent clipboard state and integration across agent session execution, diff previews, and streaming tools.
- Added comprehensive validation, error messages, recovery handling, and test coverage for clipboard and block operations.
launchHeadlessBrowser let puppeteer-core create and delete a temporary
Chrome profile via an unretried rm() from an eager process-exit hook. On
Windows, when an orphaned browser tree still held the profile lock, that
rm threw EBUSY and rejected the eager promise with no handler attached,
crashing OMP with an unhandled rejection during cleanup.
OMP now passes an explicit --user-data-dir, which makes puppeteer treat
the profile as non-temporary (ChromeLauncher.cleanUserDataDir becomes a
no-op), and removes the directory itself on dispose with lock-tolerant
retry, warning and leaving it in place if it stays busy rather than
crashing.
Fixes#7058