58fab73699
brush-core's alias expander resolves aliases via `value.split_ascii_whitespace()` (`crates/brush-core-vendored/src/interp.rs:1500`, upstream brush issue reubeno/brush#57): each whitespace piece is dropped into argv as-is, completely bypassing the shell parser. Any alias body containing `(`, `)`, `|`, `&`, `;`, `<`, `>`, or `\`` therefore turns the first piece into the command name, so Fedora's default `alias which='(alias; declare -f) | /usr/bin/which …'` produces `error: command not found: (alias;` for every `which` invocation. The user's shell snapshot is generated by sourcing their real rc-file under `/bin/bash` or `/bin/zsh` (so we can capture functions, options, PATH) and then sourced by brush per-session. `sanitizeSnapshotForBrush` now scans the emitted `alias -- NAME='VALUE'` lines after generation, drops any whose decoded body contains those metacharacters, and rewrites the file in place before caching. Compatible aliases (`ll='ls -l'`, `gc='git --color=auto commit'`, embedded-quote `say='echo '\\''hi'\\'''`) are preserved untouched; dropped names are logged at debug. brush then falls through to whatever lives on `PATH`, which is what the user expected when they ran `which` in the first place. Covered by unit tests for the sanitizer (Fedora-which case, every incompatible-metachar shape, every preserve case) and an integration test that loads a poisoned snapshot and verifies `which sh` now exits `0` with a real path. Fixes #3234
@oh-my-pi/pi-coding-agent
Core implementation package for the omp coding agent in the oh-my-pi monorepo.
For installation, setup, provider configuration, model roles, slash commands, and full CLI reference, see:
Package-specific references:
Memory backends
The agent supports three mutually-exclusive memory backends, selected via the memory.backend setting (Settings → Memory tab, or ~/.omp/config.yml):
off(default) — no memory subsystem runs.local— existing rollout-summarisation pipeline; writesmemory_summary.mdand consolidated artifacts under the agent dir.hindsight— talks to a Hindsight server (Cloud or self-hosted Docker), retains transcripts every Nth user turn, recalls memories on the first turn of a session, and exposesretain,recall, andreflect.
Hindsight quickstart
- Run a Hindsight server (Cloud or
docker run -p 8888:8888 ghcr.io/vectorize-io/hindsight:latest). - Set
memory.backend = "hindsight"andhindsight.apiUrl = "http://localhost:8888"(or your Cloud URL). - Optional environment overrides (env wins over settings):
HINDSIGHT_API_URL,HINDSIGHT_API_TOKEN— connectionHINDSIGHT_BANK_ID,HINDSIGHT_DYNAMIC_BANK_ID,HINDSIGHT_AGENT_NAME— bank addressingHINDSIGHT_AUTO_RECALL,HINDSIGHT_AUTO_RETAIN,HINDSIGHT_RETAIN_MODE— lifecycleHINDSIGHT_RECALL_BUDGET,HINDSIGHT_RECALL_MAX_TOKENS— recall sizingHINDSIGHT_BANK_MISSION,HINDSIGHT_DEBUG
Switching backends mid-session is honoured on the next system-prompt rebuild and the next /memory slash command. Existing users with memories.enabled = true|false are migrated to memory.backend = "local"|"off" exactly once on first launch.