Add semantic skill matching using all-MiniLM-L6-v2 sentence embeddings.
Skills are automatically injected into user turns based on relevance.
New packages:
- embedding: ONNX-based text embedding with MiniLM model
- skills: skill discovery, embedding cache, and semantic matching
Integration:
- InitSkillIndex called at startup in fs.NewRoot
- matchSkills called per-turn in executeTurn
- Matched skills injected in <context> block alongside user prompts
Makefile:
- install-models target downloads model and ONNX runtime
- Model files stored in ~/.local/share/ollie/models/
Config:
- Threshold: 0.2 cosine similarity
- Limit: 3 skills per turn
- Skill dirs: ~/.kiro/skills (user), ~/.config/ollie/skills (installed)
- Add quirks package for stupid model behavior workarounds
- ShellInvokesNativeTool blocks shell(cmd="tool_name") patterns
- Add client_9p tool: native wrapper for ollie-9p operations
- Block ollie-9p in shell — use client_9p instead
- Update all prompts to use client_9p, not shell+ollie-9p
- Clarify 9P namespace is complete (tools are NOT in 9P)
- Registry.All() lists all available tools for validation
user-preferences.md is meant to be prepended to every user message,
not part of the system prompt. Moved from 'prompt' to 'userPrompts'
in: author, conductor, default, foreman, panelist, reviewer.
Other agents already had it in the correct location.
Timeout fix:
- Add Timeout field to ToolInfo (protocol) and MetaFile (metadata)
- proc.go respects tool-declared timeout before falling back to 30s default
- subagent_spawn.meta declares timeout=0 (no timeout) so the tool is
never killed prematurely while waiting for the sub-agent to finish
- Tool schema declares timeout with 'do not set' guidance to prevent
the LLM from adding a short timeout
Premature response fix:
- Inject behavioral prefix into sub-agent prompt: complete all work
before responding, report results not intentions
- Sub-agent's final text is returned to parent; this instruction ensures
it contains accomplished work, not a plan
- runWorkflow accepts a variant parameter; sources {workflow}-{variant}.conf
as env vars before exec'ing the script
- Session stores variant; persisted and restored
- session/new accepts variant= parameter
- 'run' ctl command accepts optional variant as second arg
- workflows file now lists variants: name<TAB>default,variant1,...
- review workflow reads AUTHOR_PROFILE/REVIEWER_PROFILE env vars
- Add review-code.conf and review-writing.conf example variants
All tool logic lives in the multicall main.go at each family root.
Move .meta files to data/tools/ (single canonical location).
Expand test-core to cover all tools.
- Add MEMO_TOOLS=1 env var to memo script; when set, all printed
instructions reference native tool names instead of memo paths
- Set MEMO_TOOLS=1 in all memory tool .meta wrappers
- Add memory_nap tool for compressions
- Add memory_zoom tool for tree navigation
- Add part/T pagination args to memory_wake
- Update system prompt to use memory_zoom tool call
- Fix inject ctl: submit as user message when agent is idle
Server:
- session/idx now outputs: session-id, session-name, paused, connected, remote, cwd
- session/{s}/agent/idx now outputs: session-id, agent-id, agent-name, parent-id, depth, state
- Add error if parent agent not found during sub-agent spawn
GUI:
- refreshSessions() reads session index, then agent/idx per session
- Auto-select first top-level agent (depth 0) instead of first in list
- SessionModel tracks agent expansion separately from session expansion
- Agents with children show expand/collapse arrows and are collapsible
- Add hasChildren role to SessionModel
Tools:
- subagent_spawn now passes parent= argument for proper depth tracking
- Remove hardcoded max_depth=5, use server default of 1
- Makefile installs shell script tools from data/tools/
KRunner:
- Update to parse new session/idx format
- Workflows are executable scripts in data/workflows/
- New 'workflows' 9P file lists available workflows
- Goal file stores text; writing triggers workflow if status allows
- goalstatus file for status read/write, goalwait for blocking
- Session ctl accepts 'run [workflow]' command
- Session now owns CWD; agents inherit via callback
- Conductor workflow: creates agent, primes with instructions, exits
- GUI workflow combo reads from workflows, not agents
- Persistence includes goal, goalstatus, workflow, and session CWD
Write to session/{s}/goal to set a session-level objective.
A conductor agent is spawned automatically in the background,
decomposes the goal, spawns sub-agents, and reports completion.
- goal file: write sets goal + starts conductor; read returns status
- goalwait file: blocks until goal status changes (BlockOnce)
- Conductor writes status=complete/blocked back to goal when done
- Session.Goal() / SetGoal() / GoalSignal() on Session struct
The step budget mechanism is gone. Agents run until they finish,
are interrupted by the user, or (for sub-agents) hit the timeout.
No replacement. The human is the kill switch.
Enforce three limits on sub-agent spawning:
- depth (default 1): sub-agents cannot spawn their own sub-agents
- parallelism (default unlimited): cap concurrent children per parent
- timeout (default 600s): sub-agents are killed after 10 minutes
Top-level agents are never constrained by timeout.
Also: refactored parseAgentNewRequest to return a struct instead of
4 positional values. Added depth/activeChildren fields to Agent.
OLLIE_SUBAGENT_DEPTH env var set on sub-agents.
Deferred: remove maxSteps (replace entirely with timeout).
- Move user-preferences.md from data/prompts/ to data/agents/.
- Remove it from prompt arrays in all agent JSON configs.
- Add userPrompts field referencing the file via $XDG_CONFIG_HOME path.
- Update justfile install target accordingly.
Sub-agents now clone the parent agent's conversation history into
their initial context. The tool script passes parent=$OLLIE_UNAME
automatically. Mechanically identical to session restore — uses
RestoreHistoryFromMessages on the parent's Messages().
Replace D-Bus fire-and-forget with blocking ollie-9p rdwr to
agent/new. The tool now:
- Blocks until the sub-agent completes
- Returns the sub-agent's reply directly
- Scope: read (multiple spawns run in parallel)
- Tier: hot
Removed: D-Bus dependency, session renaming, JIT config cleanup.
tool_load was a built-in intercept in the agent loop — the only
'tool' that didn't run in toolsrv. Removed entirely:
- Intercept in loop.go (25 lines)
- Script + .meta in data/tools/
- autoLoad references in agent configs
Loading tools is now exclusively via ctl (which already existed):
echo 'tool_load X' | ollie-9p write .../ctl
System prompt updated to show the ctl pattern.
- file_grep.meta: replace /home/user/project with /abs/path
- system_prompt.md: use $XDG_CONFIG_HOME instead of ~
- agent-copilot.md: use relative path in code block example
The sudo credential broker was never functional and added complexity
without value. This removes:
- Sudo field from bypass Request structs (broker, client, toolsrv)
- Sudo parameter from EvaluateRequest interface and implementations
- Sudo/ResetsCounter fields from MetaFile and Variant structs
- sudo: true from system_logs.meta variants
- All sudo documentation from writing-tools.md, tool-registry.md,
core.md, evolution.md, and misc.md
Bypass remains fully functional for sandbox escapes. Tools that need
elevated privileges should handle that internally or be run manually.
- KillAll(): sends SIGKILL to all running proc groups on clean shutdown
- Pdeathsig: SIGKILL ensures child procs die if toolsrv crashes
- Shell tool: use subshell + set +e for streaming without exit propagation
- Fix integration test to match new error format
This is the connection-based ownership model: toolsrv death = proc death.
The session owns the toolsrv process, so session death cascades to all procs.
- Timeout: timeout=0 means no deadline (was defaulting to 30s)
- Signal: send to process group (-pgid) not just process; SIGTERM no longer
cancels context (only SIGKILL does); cmd.Cancel sends SIGTERM with 5s WaitDelay
- Streaming: background procs stream output in real-time via procWriter;
shell tool no longer buffers all output into a bash variable
- Proc tree: olliesrv exposes proc/{id}/out, proc/{id}/ctl, proc/{id}/status
as proper 9P directory (was broken flat file)
- Connection: proc handlers dial fresh toolsrv conn per request via
Session.DialToolServer() to avoid deadlocking the agent's blocked conn
- Stat format: key=value (exited=true, exit_code=N, id=N) matching client parser
- GC: procs auto-removed 10min after LastRead (exited procs only)
- Rename: PID -> ID throughout (synthetic, not OS PID)
- Ctl commands: term (SIGTERM), kill (SIGKILL), signal <n>, dismiss
- System prompt: correct ollie-9p commands for proc management
Dispatch-level flags are now injected into every tool's JSON schema
at runtime via injectDispatchFlags(). No need to declare them in
individual .meta files — they're universal.
Removed redundant declarations from shell.meta (now injected globally).
Only tools that explicitly declare scope="write" get path-based
parallelism. Unset scope is now global (full barrier), avoiding the
"path is a lie" problem where a tool has a path arg but modifies
other files (e.g., lsp_rename).
Tools must opt in to parallelism:
- scope=read: never conflicts
- scope=write: conflicts on same path only
- scope=global (or unset): serialization barrier
Added scope=write to file_edit.meta and file_write.meta.
Rename ToolInfo.ReadOnly bool → ToolInfo.Scope string with three values:
- "read" — path-scoped read, never conflicts (always parallel)
- "write" — path-scoped write, conflicts on same file path only
- "global" — full serialization barrier, runs alone
Tools declare scope in their .meta file. If unset, inferred from path
arg presence (write if path exists, global otherwise).
This correctly classifies lsp_rename as global (cross-file workspace
edits) despite having a path argument. The path arg in lsp_rename is
a symbol coordinate, not a resource scope.
All .meta files updated: readOnly:true → scope:read,
readOnly:false → scope:global, lsp_rename gets scope:global.
tool_load must be handled specially by the agent runtime because tools
run inside toolsrv's sandbox and cannot load other tools into
themselves. The runtime now intercepts tool_load calls and directly
invokes ToolServer.LoadTool().
This is the only built-in tool - all others are external scripts.
Paths starting with / are treated as root-relative, ignoring
the current context prefix. This allows accessing root-level
files/directories even when in a session or agent context.
Example: o myproj/coding ls /bypass # list root bypass/ dir
Simplify context parsing:
- o <cmd> Root level
- o <session> <cmd> Session level
- o <session>/<agent> <cmd> Agent level
The slash disambiguates between session and agent context,
eliminating the need for 'session' and 'agent' keywords.
Examples:
o myproj ls # session level
o myproj/coding prompt # agent level
Refactor o CLI to use explicit context selectors:
- o <cmd> Root level
- o session <sname> <cmd> Session level
- o agent <sname> <aname> <cmd> Agent level
Environment variables $session and $agent can substitute for
positional args for backwards compatibility.
Update acme scripts to use new interface:
o agent $OLLIE_SESSION $OLLIE_AGENT prompt
Add acme-ollie-ensure helper that:
- Creates 'acme' session if it doesn't exist
- Creates agent named by cwd hash (like kate's approach)
- Updates agent cwd if it already exists
All acme commands now call acme-ollie-ensure before sending
prompts, so they work without manual session setup.
Add acme scripts for interacting with ollie:
- AskFile: describe the current file
- Explain: explain selected code
- Document: add documentation comments
- Fix: fix selected code
- Refactor: refactor selected code
- AddTests: write unit tests for selection
- SendVerbatim: send selection as-is
Scripts use the acme 9P filesystem to read selections and pipe
prompts to ollie via 'o prompt'.
Also update justfile to install/uninstall the acme scripts.
- backend: add CWD field to GenerationParams for environment state
- kiro: pass session CWD to kiroCurrentEnvState instead of hardcoded '/'
- agent/runtime: set GenParams.CWD from session cwd in BuildRuntime
- o new: create sessions and agents via 9P filesystem
- o prompt: support piped stdin for non-interactive use
/tools — lists loaded tools
/tool_load X — loads a tool by name
System prompt updated to instruct the agent to use ctl for tool
management instead of writing to a tools file.
/models now lists available models for the agent's backend via ctl.
One fewer file in the agent namespace. The root-level models file
(all backends) remains unchanged.
The ctl file is now a Request handler: write a command, read the
response. Commands with no args return current state:
/model → prints current model
/agent → prints current profile
/cwd → prints working directory
/name → prints agent name
/model X → switches model, returns new model
/compact → compacts, returns 'ok'
o ctl now uses 'ollie-9p rdwr' to get the response.
This enables /model (no args) to show the current model from
any frontend.
The slash prefix in prompts now routes directly to the agent's ctl
file. No special-cased commands in the agent — the ctl handler is the
single command surface:
/stop, /compact, /clear, /model X, /inject X, /agent X, /cwd X
New ctl commands:
inject <text> — overwrites any pending inject (replaces /i and /irw)
agent <name> — switch agent profile (moved from commands.go)
Agent methods added: Compact(), Clear(), SwitchProfile() — called by
the ctl handler, testable independently.
HandleCommand is now a thin trampoline: strip /, run 'o ctl <rest>'.
commands.go reduced from 155 to 50 lines.
REPL: / → o ctl, !q/!quit → exit TUI.
The sandbox escape mechanism is a bypass, not privilege elevation.
The old name caused the agent to confuse it with sudo.
- elevate/ → bypass/ (package, types, tests)
- elevate_notify.go → bypass_notify.go
- Namespace: /elevate → /bypass, session/*/elevate → session/*/bypass
- Tool arg: "elevated" → "bypass"
- Env: OLLIE_ELEVATE_SOCKET → OLLIE_BYPASS_SOCKET
- File: elevate-policy.yaml → bypass-policy.yaml
- All docs, prompts, and scripts updated
- Merge readloop into read -l (loop mode)
- Remove chatstream command (TUI uses 'o read chat' directly)
- Rework ctl: o ctl <cmd> [session] [agent] — dispatches to
session ctl for kill/pause/resume, agent ctl for the rest
- Add trap EXIT to kill background statewait loop (fixes zombie)
- Remove -1 compatibility flag from generate
- Remove no-op bracketed paste bind from prompt REPL
- Fix /i help text: 'inject prompt (mid-turn or queued)'
- Update all help text to reflect current commands
- Delete agent/usage_log.go — wrote JSONL to disk but nothing read it
- Remove appendUsageLog call from turn.go
- Remove dead 'offset' from AGENT_FILES tab-completion list
- TUI: grep markers+fences from o log (single read, not streaming)
- fifo.in + fifo.out → single fifo (write enqueues, read dequeues)
- cost + usage + ctxsz → single stats (key=value lines)
- Remove connection (no consumers, heartbeat handles it)
- Remove dead prevPrompt field and write (prompt.prev gone from spec)
- Clean AGENT_FILES: remove state, context, tail (all already absent
from spec, were only in the tab-completion list)
chat — strips [[[...]]] markers and source fences at the byte level.
Partial lines pass through immediately for true streaming. Terminals
and text editors use this.
chat.raw — full block-structured stream with markers and fences.
GUIs that parse blocks (KDE, web) use this.
The TUI no longer pipes through grep (which was line-buffering and
killing char-by-char streaming since Aug 4).
The stripMarkers state machine processes each chunk from the server:
- Complete lines starting with [[[ and ending with ]]] → dropped
- Fence lines (```...) → dropped (open toggles in-fence state)
- Partial lines (no trailing \n) → always emitted immediately
- Everything else → passed through
backends.conf now supports a top-level 'backend = name' line that
selects the default backend for new sessions. Lookup order:
1. backends.conf 'backend = ...'
2. OLLIE_BACKEND env var (fallback)
3. session-level backend= parameter (override)
No env file needed for backend/model config anymore.