- executeElevated: use e.sessionID instead of os.Getenv (process-global
env is empty in multi-session olliesrv)
- executeElevated: merge envExtra into broker env map so session-scoped
vars are visible to elevated commands
- Replace per-turn rate limit with x/time/rate leaky bucket:
burst of 3, refills 1 token per 10s. Only denials/timeouts consume
tokens; approvals are free.
Proxies SSH agent requests to the real agent, intercepting
Sign/SignWithFlags for approval via the same broker flow
(notification + persist). Key fingerprints can be persisted
to auto-approve future sign requests.
- Add pubsub.Bus to agent; all events published on "event" topic
- Remove EventHandler param from Submit (and internal methods)
- Queue() self-drains via goroutine when agent is idle
- /i submits directly when idle, injects when running
ReadTool now reads from OLLIE_TOOLS_PATH (default ~/.local/share/ollie/tools)
as a plain filesystem path, compatible with 9pfuse mounts or symlinks.
ToolsPath() is exported and used to expand tool descriptions and the
system prompt template at runtime.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Vendor anvillm/pkg/sandbox into internal/sandbox, updating config
paths from ~/.config/anvillm to ~/.config/ollie. Remove anvillm
from go.mod.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Drop charmbracelet/bubbletea, bubbles, and lipgloss. Replace the full-screen
Elm-architecture TUI with goq's readline-based approach:
- go-multiline-ny for readline input with history and bracketed paste
- splitInput persistent bottom band during agent turns (pulse separator,
queue display, Ctrl-U/W/Backspace, /queued pop/clear)
- Signal handling: Ctrl-C cancels the current turn; double-Ctrl-C exits
- Plain text agent output (no ANSI formatting yet)
- All existing slash commands preserved; /queued integrated
New files: splitinput.go, splitinput_windows.go, bracketed_paste.go,
rerender_input.go, queued_commands.go, signals.go, signals_unix.go,
signals_windows.go
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Extracts execute_code into a shared ollie/exec package so anvillm-mcp
and ollie's agent loop can both use it. Includes sandboxed execution,
dangerous-pattern validation with per-Executor rate limiting, 9P tool
reading, and pipeline construction.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>