Anthropic counts sessions by metadata.user_id. Without this fix, OMP
generated fresh random entropy on every API request, inflating the
session count and preventing backend attribution to the authenticated
account.
Changes:
packages/ai:
- resolveAnthropicMetadataUserId() now accepts JSON-format user_id
matching real Claude Code's getAPIMetadata shape
({ session_id, account_uuid, ... }). Previously only the legacy
cloaking format was accepted on OAuth, causing stable caller-supplied
values to be silently discarded.
- AnthropicOAuthFlow.exchangeToken() and refreshAnthropicToken() now
populate OAuthCredentials.{accountId, email} from the token response
account block, removing the need for a separate /api/oauth/profile
round-trip.
- AuthStorage.getOAuthAccountId(provider, sessionId) returns the OAuth
accountId for the session-sticky credential, used to build
account_uuid in metadata.user_id. Guards against misattribution for
API-key, runtime-override, env-key, and fallback-resolver paths that
do not record a session credential.
packages/agent:
- Agent.metadataForProvider(provider) resolves request metadata for
the given provider via the installed resolver, or returns the static
metadata value. The plain metadata getter now returns only the static
value; provider-aware resolution is explicit.
- Agent.setMetadataResolver(fn) installs a (provider: string) resolver
evaluated per LLM request in agent-loop, after getApiKey records the
session-sticky credential, so account_uuid reflects the credential
actually used.
- AgentLoopConfig.metadataResolver is called with config.model.provider
after getApiKey, overriding the static metadata field.
packages/coding-agent:
- AgentSession.#syncAgentSessionId installs a metadata resolver that
builds { user_id: JSON.stringify({ session_id, account_uuid? }) },
matching the Anthropic session attribution format. account_uuid is
only included for provider="anthropic" to avoid leaking the OAuth
identity to third-party Anthropic-format-compatible providers.
- sessionId getter prefers providerSessionId when supplied via
AgentSessionConfig so all API paths (getApiKey, direct calls,
metadata resolver) share the same provider-facing session ID.
- prepareSimpleStreamOptions stamps session metadata on direct calls
(runEphemeralTurn, compaction, branch summary, title generation) so
they share the same session bucket as Agent.prompt requests.
- generateBranchSummary and generateSessionTitle accept a
(provider: string) metadata resolver evaluated after their own
getApiKey call for correct credential attribution.
- Updated ExtensionUIContext, InteractiveModeContext, and InteractiveMode to require editor factories to return CustomEditor instances.
- Removed the runtime compatibility guard and warning for non-CustomEditor implementations in setEditorComponent.
- Removed the test that verified rejection of non-CustomEditor factories in interactive-mode editor-component tests.
Files loaded via the omp-legacy-pi-file: namespace bypass Bun's normal
node_modules lookup because the importer lives in a custom namespace,
so an extension that imports its own bundled dependencies (e.g.
`import parseDuration from "local-duration-parser"`) failed with
`Cannot find package`. Pre-resolve bare specifiers in the onLoad step
against the importer's directory so extensions can ship their own
node_modules. Relative, absolute, node:, and URL specifiers are left
untouched, preserving the existing legacy @mariozechner/pi-* remap
path.
- Implemented hashline stale-anchor recovery using cached reads and a 3-way merge fallback.
- Updated hashline execution and preflight checks to retry mismatched anchors through cache recovery.
- Added file-read cache support with per-session LRU snapshots and contiguous/sparse record APIs.
- Integrated read and search tools with the shared cache to record candidate lines for recovery.
- Added tests for stale-anchor recovery flows and FileReadCache session, null, overlap, and eviction behavior.
- Expanded read tool range calculations to include optional leading and trailing context lines around user-requested offsets and limits.
- Added shared context range expansion logic so line-slice and streaming reads return anchor-safe windows while preserving existing truncation behavior.
- Updated read-tool tests to assert boundary-offset, limit, and combined offset-limit reads now include the expected ±3 lines of context.
- Updated `hashline.md` to document brace-boundary edit patterns for block replacement, signature-only edits, and safe interior insertions.
- Added common-failure guidance on range boundaries, duplication checks, truncated anchors, and preferring narrower ops over wide replacements.
- Adjusted the anti-pattern example to match the corrected replacement range behavior.
- Added a Python `analyze.py` CLI with `tools`, `edits`, and `followups` session-stats subcommands.
- Added `sync.py` ingestion with `~/.omp/stats.db`, migration SQL, and incremental JSONL resume logic.
- Replaced `stats:run` in `package.json` with `stats:sync` and new `stats:edits`, `stats:tools`, and `stats:followups` scripts.
- Removed the Rust session-stats crate files (`Cargo.toml`, `main.rs`, `common.rs`, `cmd_*.rs`) and their old command logic.
- Removed `.gitignore` ignores for `scripts/session-stats/Cargo.lock` and `scripts/session-stats/edit-analysis.csv`.
- Updated eval tool guidance to show Python `asyncio.run(...)` usage.
Some extensions/plugins still import the legacy @mariozechner/pi-* package names (pi-agent-core, pi-ai, pi-coding-agent, pi-tui) instead of @oh-my-pi/pi-*. Register a single Bun.plugin on first plugin/extension load that rewrites those specifiers to the current @oh-my-pi/pi-* equivalents, including the @mariozechner/pi-coding-agent/extensibility/{extensions,hooks} sub-exports. No filesystem mutation, no symlinks, no proxy files.
Fixes#973
Add an explicit openai-models-list discovery type for custom providers while keeping lm-studio as a compatible alias. Custom providers can now point baseUrl at an OpenAI-compatible /v1 endpoint, provide an api key, and auto-populate models via GET {baseUrl}/models.
Discovered models merge cleanly with user-defined models from models.yml/models.json, so YAML entries still win for display name and token limits. The provider picker now explains when discovery succeeds but returns zero models, and when the configured /models endpoint responds with 404.
Fixes#970
Interactive /mcp test only consulted getMCPConfigPath("user"|"project")
configs and missed servers defined in standalone .mcp.json. /mcp reauth
already resolved through #findConfiguredServer, which includes that
fallback path. Route /mcp test through the same resolver so both
commands enumerate the same set of servers.
Fixes#956
The custom status line rendered cache_read with the input icon and
cache_write with the output icon — backwards relative to Anthropic's
cache_creation_input_tokens (write) / cache_read_input_tokens (read)
semantics. Swap the icon pairings in status-line/segments.ts and the
labels in status-line-segment-editor.ts to match.
Fixes#953
RenderMermaid is disabled by default and emits terminal text rather
than SVG/PNG; complex sequence diagrams with alt/else blocks become
hard to read at default widths. Add docs/render-mermaid.md covering
enablement (renderMermaid.enabled), config knobs (useAscii, paddingX,
paddingY, boxBorderPadding), output expectations, and limitations.
Link the new guide from the coding-agent README.
Fixes#961
runSplitCommit reset the index and then re-staged each split via
git.stage.hunks, but stage.hunks builds its file map from the current
diff. After the reset, newly created files were untracked again and
absent from that map, throwing "No diff found for <path>" mid-split.
Preserve the original staged diff so new files remain locatable
through every split iteration.
Fixes#966
- Added an intent function to EvalTool that generated a label from provided input.
- Parsed input with parseEvalInput and joined each cell title or language fallback into a newline string.
- Returned "evaluating" when input was missing or could not be parsed.
- Added an instruction in the Python eval prompt explaining that notebook cells run in an IPython kernel with a live event loop.
- Documented that users should use top-level `await` directly and avoid `asyncio.run(...)` due to the running event loop.
- Kept the existing failure-handling guidance unchanged while clarifying async execution behavior for Python cells.
- Updated system prompts to require every active turn to end with a tool call and clarified that reminders should default to resuming work unless the task was complete or genuinely blocked.
- Reworked the yield-reminder text to disallow fake blocker reasons and to permit continued tool-calling instead of forced immediate yields.
- In `runSubprocess`, applied `toolChoice` only on the final yield retry by adding an `isFinalRetry` check before sending the reminder.
- BuildWorkspaceTree now attempts to list files via `git ls-files` and builds a child index for tree rendering, avoiding native recursion when git output is available.
- `buildDirectoryTree` gained an optional `childIndex` path map, `tryListGitFiles` now applies a 3s timeout and falls back to existing native scan on failure or timeout.
- Added a workspace-tree test that verifies git-backed listing skips gitignored entries while including tracked workspace files.
- Added a 5-second `Promise.race` deadline around `buildAgentsMdSearch` and `buildWorkspaceTree` in `createAgentSession` to prevent startup blocking on slow scans.
- Changed startup handling to forward `undefined` to `ToolSession` when scans time out so `buildSystemPromptInternal` can re-run them through its existing `withDeadline` path.
- Added a static-import rewriter that converts common import clauses into dynamic `await import(...)` expressions before VM wrapping.
- Provided `require` and `createRequire` globals in the JS VM context using a cwd-based resolver.
- Added executor tests confirming rewritten imports run correctly and that `require`/`createRequire` are exposed with expected behavior.
Subagents previously re-ran buildAgentsMdSearch and buildWorkspaceTree on
every spawn, repeating the slowest part of system-prompt construction for
each task tool invocation. On large/pathological repos those scans
exceeded the 5s preparation deadline and tripped the per-subagent
'system prompt preparation timed out' warning.
Forward the parent's already-resolved AgentsMdSearch and WorkspaceTree
through createAgentSession (alongside the existing contextFiles, skills,
and promptTemplates inheritance):
- Add agentsMdSearch and workspaceTree to CreateAgentSessionOptions;
createAgentSession short-circuits the parallel scan promises when
these are provided.
- Resolve them with contextFiles before constructing ToolSession; expose
on ToolSession so the task tool can read the parent's values.
- Thread them through ExecutorOptions (task/executor.ts) into the
subagent's createAgentSession call, and pass them from the task tool
(task/index.ts) on both the worktree-isolated and non-isolated paths.
- Added hideThinkingSummary options across stream, agent, and session payload paths.
- Routed Coding-Agent hideThinkingBlock toggles to agent hideThinkingSummary during session updates.
- Updated OpenAI, Azure OpenAI, and Codex requests to omit reasoning.summary when hide/ summary is null.
- Reworked system-prompt preparation with per-step timeouts, fallback defaults, and step-level warnings.
- Updated the read tool docs to define URL selectors as `:50`, `:50-100`, and `:50+150` and to document the `https://host/:port` form for URLs with explicit ports.
- Changed URL selector parsing to use the file-style numeric range format, treated `raw` as a separate token, and updated the invalid zero-line message to direct users to `:1`.
- Refined embedded URL selector extraction to validate the base URL first and then match selectors against the new numeric range regex.
- Added `supportsMultipleSystemMessages?: boolean` to `OpenAICompat` for configurable multi-system handling.
- Added OpenAI-compat host detection, allowing per-host multiple-system defaults and explicit override control.
- Updated `convertMessages` to merge system prompts when disabled, while preserving separate system messages when enabled.
- Added tests for merged-vs-split system prompts, MiniMax/Qwen strict-template behavior, and override defaults.
- Added a new `scrubProcessEnv` helper in `procmgr` to remove macOS malloc logging variables from `process.env` before spawning.
- Invoked the helper at coding-agent CLI startup so bun sub-processes no longer inherit the problematic environment.
- This prevented the recurring `MallocStackLogging` warning from appearing in child process stderr output.
- Added optional `/loop` `count|duration` command arguments and wired `command.args` into loop handling.
- Implemented `loop-limit` parsing and runtime types/helpers for iteration and duration budget limits with validation.
- Updated interactive mode to enforce loop limits per iteration, check duration expiry, and clear budget state on disable.
- Added loop-limit parse/runtime tests and fixed `/loop` arg errors plus macOS `MallocStackLogging` environment leakage.
- Rendered diff content before the truncation notice instead of after.
- Updated hidden lines label to show count with "+" prefix.
- Added fallback label when no lines are hidden.
- Removed the read CLI argument and tool schema field so read requests no longer accept custom timeouts.
- Updated URL read handling to stop forwarding timeout values and execute URL reads without a timeout parameter.
- Standardized URL read fetching to a fixed 30-second timeout and dropped timeout metadata from URL call rendering.
- Removed [blocked]-focused instructions from failure handling and pre-yield checks in the system prompt.
- Eliminated the separate completion-honesty block and folded stronger end-to-end-completion language into the contract sections.
- Reworded output and critical-response guidance to focus on continuous progress and completion-only yielding.
- Added a readonly intent property to the write tool implementation.
- The intent now returned a contextual message using `args.path` when available, otherwise a generic "writing" label.
- Exported hashline section interfaces and helpers, including a new section-diff API for external callers.
- Refactored `computeHashlineDiff` to split input sections, propagate split errors, and delegate each section via helper.
- Added context-highlight caching and batched highlighting for unchanged lines, with `replaceTabs` fallback on unknown files.
- Fixed hashline streaming preview so completed sections stay visible when a new `@PATH` header appears mid-stream.
- Added hashline streaming tests for section persistence, malformed trailing `+ 7`, and dual sections.
- Adjusted streaming preview formatting to render the tail section using a computed start index and hidden-line count.
- Passed language into streaming formatting to syntax-highlight visible lines and include aligned line-number gutters.
- Updated the hidden-lines notice to handle singular vs plural earlier-line counts correctly.
- Added a new `orchestrate.md` prompt under `src/prompts/commands` defining an orchestrator workflow, verification gates, and anti-patterns.
- Imported and rendered the prompt in `src/task/commands.ts` as `orchestrateMd`.
- Appended the new prompt to `EMBEDDED_COMMANDS` so it is registered with existing embedded command templates.
- Updated the hashline prompt to require replacement ranges to cover entire statements or expressions, preventing broken syntax when applying changes.
- This clarified how replacement anchors should be chosen for function calls, literals, blocks, and control-flow branches.
- Updated the write tool preview renderer to syntax-highlight visible lines and annotate them with line-number gutters.
- Changed the file metadata output to an inline line-count suffix on the header and removed the separate metadata row.
- Adjusted preview truncation to show the first lines first while preserving hidden-line hints for collapsed output.
- Added a new completion-honesty section to the coding-agent system prompt with stricter delivery constraints.
- The prompt now requires all acceptance criteria to be met before completion, prohibits scope reduction without approval, and forbids delivering stubs, placeholders, or fake implementations as finished work.
- Verification language was tightened so completion claims must reflect actual verification and not be inflated by partial checks.
- Added `.ipynb` detection and editable-cell conversion utilities, including merge/serialize helpers in `edit/notebook`.
- Rerouted hashline, patch, and replace edit flows, plus read/write paths, through notebook-aware helpers before persistence.
- Removed the dedicated `notebook` tool, its schema flags, renderer, and built-in registration/settings checks.
- Updated notebook read behavior, docs, and tests so `.ipynb` reads return editable `# %%` cells and edits reserialize to JSON.