Move internal/backend and internal/config to pkg/ so external consumers
can import them. Remove cmd/ollie and internal/tui — they now live in
the separate ollie-tui repo which imports ollie as a library.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
internal/mcp → pkg/mcp (MCP client, concrete)
internal/tools → pkg/tools (Executor interface + MCPExecutor)
internal/exec → pkg/tools/execute (builtin sandbox executor, split by tool)
Split exec.go into executor.go (sandbox runner), pipe.go (BuildPipeline/PipeStep),
tool.go (ReadTool), and code.go (execute_code is Executor.Execute with trusted=false).
All three packages are now importable by consumers outside this module.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Each backend now owns its active model via Model()/SetModel(). ChatStream
no longer takes a model string — callers use SetModel to configure it.
AgentCoreConfig.ModelName sets the backend model at construction time via
SetModel, then the field can be dropped from the live agentCore struct.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Everything not part of the agent<->frontend contract is now unexported:
- contextConfig/Builder/Stats, loopConfig, toolExecutor, confirmFn,
run, state, toolResult — internal loop/session machinery
- buildFirstPrompt, systemPrompt, builtinTools — impl details
- agentCore struct (NewAgentCore returns Core)
- Session methods (saveTo, history, rollback, compact, etc.)
- AgentEnv internal fields (mcpExec, exec, confirm, tools, etc.)
App-level utilities moved from pkg/agent to cmd/ollie:
- resolveBackendName, defaultModelForBackend, newSessionID,
agentConfigPath
RestoreSession now takes int (ctxOverhead) directly, eliminating
the need for contextConfig to be public.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
AgentCore (the Core interface impl) belongs in internal/agent alongside
the loop, session, and state it orchestrates — not in a separate one-file
package.
To break the resulting import cycle (agent → pkg/core → agent), define
Event and EventHandler natively in pkg/core instead of aliasing from
internal/agent. The agent loop now imports pkg/core for these types.
Usage token tracking is internal to the loop and no longer emitted as
an event (no consumer used it).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Hooks are a generic lifecycle concept — not specific to any frontend.
core.Hooks, core.HookAgentSpawn/UserPromptSubmit/Stop constants, and
Hooks.Run() now live in pkg/core and are usable by any implementation.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
WatchSignals and CtrlCExitWindow are generic — any frontend can use them.
Removing them from the TUI package keeps tui focused on terminal I/O only.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- backend/codewhisperer{,_internal}.go: full Amazon CodeWhisperer
backend implementation — binary AWS event stream decoding, SQLite
auth for both enterprise OIDC and personal social/GitHub flows, OIDC
token refresh, and message encoding to the Kiro wire format
- backend/anthropic.go, copilot.go: new backends wired into New()
- backend/new.go: register anthropic, copilot, kiro/codewhisperer cases
- backend/openai.go: add extraHeaders hook for future use
- agent/loop.go: surface non-standard stop reasons as errors instead of
silently dropping them
- main.go: defaultModelForBackend() sets a sensible default per backend
(ollama→qwen3.5:9b, openrouter→deepseek/deepseek-v3.2,
anthropic→claude-sonnet-4-5, kiro→auto); /backend switch now also
resets the model to avoid stale foreign model IDs causing
ValidationException; add -prompt flag for non-interactive batch mode
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Drop charmbracelet/bubbletea, bubbles, and lipgloss. Replace the full-screen
Elm-architecture TUI with goq's readline-based approach:
- go-multiline-ny for readline input with history and bracketed paste
- splitInput persistent bottom band during agent turns (pulse separator,
queue display, Ctrl-U/W/Backspace, /queued pop/clear)
- Signal handling: Ctrl-C cancels the current turn; double-Ctrl-C exits
- Plain text agent output (no ANSI formatting yet)
- All existing slash commands preserved; /queued integrated
New files: splitinput.go, splitinput_windows.go, bracketed_paste.go,
rerender_input.go, queued_commands.go, signals.go, signals_unix.go,
signals_windows.go
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Prevents context explosion on new sessions in repos with large READMEs
or many files. Both are truncated at a clean line boundary with a
trailing "...(truncated)" marker.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Removes start_line/end_line range support from file_read. The tool now
always reads the full file and caches by path; re-reading the same path
is a hard error. file_write's precondition check is simplified to
"path was read this session" rather than range coverage. Removes the
lineRange, fileReadResult, rangesOverlap, and rangesCover helpers.
Also tightens the system prompt: bots should use grep/execute_code for
exploration and reserve file_read for pre-write context.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Augments the initial user message with git ls-files output (falling back
to a recursive walk that skips hidden files when not in a git repo) and
the contents of README.md if present, so the agent has real workspace
context from the start instead of guessing which files exist.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Whole-file writes on existing files are the primary source of
corruption: a bot that assembled file content from multiple partial
reads can silently duplicate or mangle sections. The blast radius is
unbounded.
New rule:
- Existing files: start_line/end_line required; whole-file write
returns a hard error directing the bot to use range writes
- New files (not on disk): whole-file write is the only option and
remains allowed
Updated file_write tool description to state the rule up front.
Simplified the guard block: the coverage/read check for existing files
now only applies to range writes (the only permitted case).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
qwen3:8b is too obtuse for agentic use; qwen3.5:9b is better at
instruction following and tool use at roughly the same size.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The "no tools" stall condition (totalToolCalls==0 && hadContent) fired
whenever the bot replied in plain text without calling any tools, which
is the normal completion path. The UI would then see agentStalled before
the done message and never transition back to agentIdle.
Removed the "no tools" stall; only the max-steps limit case is a real
stall worth surfacing.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Compact was gated on EvictedMessages(), which only returns messages
that have spilled past the 120k char soft limit. Normal sessions never
hit that threshold, making /compact a permanent no-op.
New approach: compact ALL messages older than the tail window (i.e.
everything computeTailStart puts before the protected tail), regardless
of budget. This makes /compact always useful.
Added OlderMessages(), TailWindow(), and SystemMessages() to
ContextBuilder to support the rewrite cleanly.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Session persistence:
- Sessions saved to ~/.config/ollie/sessions/{id}.json after each
completed agent turn and after /compact
- --session <id> flag resumes a saved session, auto-loading its agent
- /sessions command lists saved sessions with agent and goal preview
- /clear and /agent switch generate a new session ID
- Session ID shown at startup
Dedup:
- file_read: overlap check now returns a hard error (was a warning
prepended to the result); check uses requested range, not actual
read range, to avoid redundant dispatchFileRead on overlap
- tool calls: duplicate (name, args) now returns a hard error; key
is only recorded on successful execution
/compact: Compact() now returns the summary text; displayed in the
UI so the user can verify quality; session saved after compact
Write-then-write:
- After a successful file_write, repopulate fileRanges with the
written range so a follow-up write to the same region does not
require a re-read
- Whole-file writes record exact new line count from content;
range writes record the written [start, end] with totalLines=0
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- file_write: allow creating files that don't exist on disk without a
prior read; the guard only applies to existing files
- rangesCover: initialize cur = ws-1 so coverage check starts at the
target range, not line 0 (range writes to e.g. lines 50-100 were
incorrectly blocked even when exactly that range had been read)
- remove fileReadMaxLines (500-line pagination cap); range tracking
makes the truncation unnecessary
- add /agents command: lists .json configs in agentsDir, marks active
agent with *
- add main_test.go: table-driven tests for rangesOverlap and rangesCover
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
"Be proactive / explore first" is generic behavior — moved to systemPromptBase.
Agent prompts now contain only use-case-specific rules (code exploration,
context reads before writing, skill discovery for anvillm-agent).
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
- All four agents: require full source enumeration before explaining code,
and full context reads before writing or modifying code
- default, default-sp, yolo: remove skill discovery references (anvillm only)
- anvillm-agent: retains skill discovery, adds the same code rules
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
- Revised system prompt with concrete prohibitions against verbosity and
premature stopping
- Added GenerationParams (max_tokens, temperature, frequency/presence penalty)
threading from agent config through backend ChatStream calls
- Added stall detection: emits "stalled" role on max-steps hit or zero tool
calls with content, surfaces as "stalled" in status bar
- Added per-session file read range tracking: warns on overlapping re-reads,
blocks file_write unless the target range was previously read
- Added general tool-call dedup: warns on exact (name, args) repeats for
non-file tools
- Both caches invalidated on /compact and /clear; file read cache invalidated
per-path on file_write
- Updated all agent configs with documenting defaults for new generation params
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Client gains a Close() method that closes stdin (giving the subprocess
a clean EOF) then kills and reaps the process. Executor.Close() calls
Close() on all registered clients. agentEnv now carries the mcpExec so
the /agent command can close the outgoing executor before building the
new one.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- /compact: summarizes evicted context messages via LLM call, replaces
them with a single summary system message
- /clear: resets session and display
- ContextBuilder.EvictedMessages(): returns messages outside bounded window
- Session.Compact(): drives the summarization and history replacement
- Stop agentCh pump while waiting for user confirmation (prevents
context cancellation on confirm reply)
- System prompt: hard directive to use file_read/file_write instead
of shell commands for file operations
- Update tool descriptions to match
- file_read and file_write require explicit y/n confirmation before executing
- New agentConfirming UI state with confirm [y/n] status bar indicator
- y/yes approves, n/no denies, anything else denies and falls through to
normal prompt handling
- file_read output includes line numbers for precise file_write targeting
- Fix tool output display: remove per-line squashWhitespace (preserves indentation)
- file_write description hints to preserve formatting