tool_load was a built-in intercept in the agent loop — the only
'tool' that didn't run in toolsrv. Removed entirely:
- Intercept in loop.go (25 lines)
- Script + .meta in data/tools/
- autoLoad references in agent configs
Loading tools is now exclusively via ctl (which already existed):
echo 'tool_load X' | ollie-9p write .../ctl
System prompt updated to show the ctl pattern.
- file_grep.meta: replace /home/user/project with /abs/path
- system_prompt.md: use $XDG_CONFIG_HOME instead of ~
- agent-copilot.md: use relative path in code block example
The sudo credential broker was never functional and added complexity
without value. This removes:
- Sudo field from bypass Request structs (broker, client, toolsrv)
- Sudo parameter from EvaluateRequest interface and implementations
- Sudo/ResetsCounter fields from MetaFile and Variant structs
- sudo: true from system_logs.meta variants
- All sudo documentation from writing-tools.md, tool-registry.md,
core.md, evolution.md, and misc.md
Bypass remains fully functional for sandbox escapes. Tools that need
elevated privileges should handle that internally or be run manually.
- KillAll(): sends SIGKILL to all running proc groups on clean shutdown
- Pdeathsig: SIGKILL ensures child procs die if toolsrv crashes
- Shell tool: use subshell + set +e for streaming without exit propagation
- Fix integration test to match new error format
This is the connection-based ownership model: toolsrv death = proc death.
The session owns the toolsrv process, so session death cascades to all procs.
- Timeout: timeout=0 means no deadline (was defaulting to 30s)
- Signal: send to process group (-pgid) not just process; SIGTERM no longer
cancels context (only SIGKILL does); cmd.Cancel sends SIGTERM with 5s WaitDelay
- Streaming: background procs stream output in real-time via procWriter;
shell tool no longer buffers all output into a bash variable
- Proc tree: olliesrv exposes proc/{id}/out, proc/{id}/ctl, proc/{id}/status
as proper 9P directory (was broken flat file)
- Connection: proc handlers dial fresh toolsrv conn per request via
Session.DialToolServer() to avoid deadlocking the agent's blocked conn
- Stat format: key=value (exited=true, exit_code=N, id=N) matching client parser
- GC: procs auto-removed 10min after LastRead (exited procs only)
- Rename: PID -> ID throughout (synthetic, not OS PID)
- Ctl commands: term (SIGTERM), kill (SIGKILL), signal <n>, dismiss
- System prompt: correct ollie-9p commands for proc management
Dispatch-level flags are now injected into every tool's JSON schema
at runtime via injectDispatchFlags(). No need to declare them in
individual .meta files — they're universal.
Removed redundant declarations from shell.meta (now injected globally).
Only tools that explicitly declare scope="write" get path-based
parallelism. Unset scope is now global (full barrier), avoiding the
"path is a lie" problem where a tool has a path arg but modifies
other files (e.g., lsp_rename).
Tools must opt in to parallelism:
- scope=read: never conflicts
- scope=write: conflicts on same path only
- scope=global (or unset): serialization barrier
Added scope=write to file_edit.meta and file_write.meta.
Rename ToolInfo.ReadOnly bool → ToolInfo.Scope string with three values:
- "read" — path-scoped read, never conflicts (always parallel)
- "write" — path-scoped write, conflicts on same file path only
- "global" — full serialization barrier, runs alone
Tools declare scope in their .meta file. If unset, inferred from path
arg presence (write if path exists, global otherwise).
This correctly classifies lsp_rename as global (cross-file workspace
edits) despite having a path argument. The path arg in lsp_rename is
a symbol coordinate, not a resource scope.
All .meta files updated: readOnly:true → scope:read,
readOnly:false → scope:global, lsp_rename gets scope:global.
tool_load must be handled specially by the agent runtime because tools
run inside toolsrv's sandbox and cannot load other tools into
themselves. The runtime now intercepts tool_load calls and directly
invokes ToolServer.LoadTool().
This is the only built-in tool - all others are external scripts.
Paths starting with / are treated as root-relative, ignoring
the current context prefix. This allows accessing root-level
files/directories even when in a session or agent context.
Example: o myproj/coding ls /bypass # list root bypass/ dir
Simplify context parsing:
- o <cmd> Root level
- o <session> <cmd> Session level
- o <session>/<agent> <cmd> Agent level
The slash disambiguates between session and agent context,
eliminating the need for 'session' and 'agent' keywords.
Examples:
o myproj ls # session level
o myproj/coding prompt # agent level
Refactor o CLI to use explicit context selectors:
- o <cmd> Root level
- o session <sname> <cmd> Session level
- o agent <sname> <aname> <cmd> Agent level
Environment variables $session and $agent can substitute for
positional args for backwards compatibility.
Update acme scripts to use new interface:
o agent $OLLIE_SESSION $OLLIE_AGENT prompt
Add acme-ollie-ensure helper that:
- Creates 'acme' session if it doesn't exist
- Creates agent named by cwd hash (like kate's approach)
- Updates agent cwd if it already exists
All acme commands now call acme-ollie-ensure before sending
prompts, so they work without manual session setup.
Add acme scripts for interacting with ollie:
- AskFile: describe the current file
- Explain: explain selected code
- Document: add documentation comments
- Fix: fix selected code
- Refactor: refactor selected code
- AddTests: write unit tests for selection
- SendVerbatim: send selection as-is
Scripts use the acme 9P filesystem to read selections and pipe
prompts to ollie via 'o prompt'.
Also update justfile to install/uninstall the acme scripts.
- backend: add CWD field to GenerationParams for environment state
- kiro: pass session CWD to kiroCurrentEnvState instead of hardcoded '/'
- agent/runtime: set GenParams.CWD from session cwd in BuildRuntime
- o new: create sessions and agents via 9P filesystem
- o prompt: support piped stdin for non-interactive use
/tools — lists loaded tools
/tool_load X — loads a tool by name
System prompt updated to instruct the agent to use ctl for tool
management instead of writing to a tools file.
/models now lists available models for the agent's backend via ctl.
One fewer file in the agent namespace. The root-level models file
(all backends) remains unchanged.
The ctl file is now a Request handler: write a command, read the
response. Commands with no args return current state:
/model → prints current model
/agent → prints current profile
/cwd → prints working directory
/name → prints agent name
/model X → switches model, returns new model
/compact → compacts, returns 'ok'
o ctl now uses 'ollie-9p rdwr' to get the response.
This enables /model (no args) to show the current model from
any frontend.
The slash prefix in prompts now routes directly to the agent's ctl
file. No special-cased commands in the agent — the ctl handler is the
single command surface:
/stop, /compact, /clear, /model X, /inject X, /agent X, /cwd X
New ctl commands:
inject <text> — overwrites any pending inject (replaces /i and /irw)
agent <name> — switch agent profile (moved from commands.go)
Agent methods added: Compact(), Clear(), SwitchProfile() — called by
the ctl handler, testable independently.
HandleCommand is now a thin trampoline: strip /, run 'o ctl <rest>'.
commands.go reduced from 155 to 50 lines.
REPL: / → o ctl, !q/!quit → exit TUI.
The sandbox escape mechanism is a bypass, not privilege elevation.
The old name caused the agent to confuse it with sudo.
- elevate/ → bypass/ (package, types, tests)
- elevate_notify.go → bypass_notify.go
- Namespace: /elevate → /bypass, session/*/elevate → session/*/bypass
- Tool arg: "elevated" → "bypass"
- Env: OLLIE_ELEVATE_SOCKET → OLLIE_BYPASS_SOCKET
- File: elevate-policy.yaml → bypass-policy.yaml
- All docs, prompts, and scripts updated
- Merge readloop into read -l (loop mode)
- Remove chatstream command (TUI uses 'o read chat' directly)
- Rework ctl: o ctl <cmd> [session] [agent] — dispatches to
session ctl for kill/pause/resume, agent ctl for the rest
- Add trap EXIT to kill background statewait loop (fixes zombie)
- Remove -1 compatibility flag from generate
- Remove no-op bracketed paste bind from prompt REPL
- Fix /i help text: 'inject prompt (mid-turn or queued)'
- Update all help text to reflect current commands
- Delete agent/usage_log.go — wrote JSONL to disk but nothing read it
- Remove appendUsageLog call from turn.go
- Remove dead 'offset' from AGENT_FILES tab-completion list
- TUI: grep markers+fences from o log (single read, not streaming)
- fifo.in + fifo.out → single fifo (write enqueues, read dequeues)
- cost + usage + ctxsz → single stats (key=value lines)
- Remove connection (no consumers, heartbeat handles it)
- Remove dead prevPrompt field and write (prompt.prev gone from spec)
- Clean AGENT_FILES: remove state, context, tail (all already absent
from spec, were only in the tab-completion list)
chat — strips [[[...]]] markers and source fences at the byte level.
Partial lines pass through immediately for true streaming. Terminals
and text editors use this.
chat.raw — full block-structured stream with markers and fences.
GUIs that parse blocks (KDE, web) use this.
The TUI no longer pipes through grep (which was line-buffering and
killing char-by-char streaming since Aug 4).
The stripMarkers state machine processes each chunk from the server:
- Complete lines starting with [[[ and ending with ]]] → dropped
- Fence lines (```...) → dropped (open toggles in-fence state)
- Partial lines (no trailing \n) → always emitted immediately
- Everything else → passed through
backends.conf now supports a top-level 'backend = name' line that
selects the default backend for new sessions. Lookup order:
1. backends.conf 'backend = ...'
2. OLLIE_BACKEND env var (fallback)
3. session-level backend= parameter (override)
No env file needed for backend/model config anymore.
Each backend is now configured via ~/.config/ollie/backends.conf:
[openrouter]
key = sk-or-v1-...
model = qwen/qwen3-235b-a22b
[anthropic]
key = sk-ant-...
Each backend knows its own default URL (openrouter → openrouter.ai/api,
anthropic → api.anthropic.com, etc). Only key and optional model needed.
Env vars (OLLIE_OPENAI_KEY, OLLIE_ANTHROPIC_KEY, etc) still work as
fallback for backward compatibility, but backends.conf is the canonical
config path going forward.
- Delete openAIName() (URL no longer determines backend identity)
- Delete geminiKey() (config handles fallback)
- Install template with mode 600 (contains API keys)
- Only install template if user hasn't created their own
Switch from 'read -e' to plain 'read' so multi-line paste can be
captured. Readline was consuming pasted lines individually.
Increase drain timeout to 100ms.
- Add 'o log [-n N]' to read last N lines from agent log (default 1000)
- Rename 'o tail' to 'o chatstream' for clarity
- Update TUI to show log history before streaming chat
Tools like file_write, file_edit, and shell now reset the agent's step
counter when called successfully. This allows the agent to continue
working without hitting the soft step-budget guardrail as long as it's
making active progress (writing files, running commands) rather than
looping on research/reading.
Changes:
- Add ResetsCounter bool to ToolInfo and MetaFile structs
- Parse resetsCounter from .meta JSON files
- Reset step counter in agent loop when ResetsCounter tool succeeds
- Add resetsCounter: true to file_write, file_edit, shell
- Reduce maxSteps from 50 to 25 (resetsCounter makes this safe)
- Remove "hooks" blocks from all 8 agent JSON files (copilot, default, driver, explorer, librarian, navigator, taskmanager, theo)
- Remove beads shell one-liner from prompt arrays in default.json and driver.json
- Hooks mechanism is dead code; these empty blocks are just noise
- Remove all OLLIE_*_PATH vars (TOOLS_PATH, CFG_PATH, DATA_PATH, etc.)
Use XDG_CONFIG_HOME/ollie/* and XDG_DATA_HOME/ollie/* instead
- Replace OLLIE_<TAG>_LOG per-component logging with single OLLIE_LOG={level}
- Replace OLLIE_USAGE_LOG with XDG_DATA_HOME-based path
- Replace OLLIE_OLLAMA_URL with standard OLLAMA_HOST (or omit entirely)
- Rename protocol markers: OLLIE_LISTEN_READY → ListenReady, OLLIE_9P_OPEN → Open
- Remove freeloader hooks from agent configs
- Update sandbox YAMLs to use XDG paths instead of OLLIE_*_PATH tokens
- Update shell tools to use $(dirname "$0") fallback instead of OLLIE_TOOLS_PATH
- Update docs and prompts accordingly
Wrap bold escape sequences in \001/\002 markers so readline
correctly tracks cursor position. Fixes Ctrl+U, Ctrl+W, and
other readline kill commands after typing several characters.
- Remove auto-resolution of session/agent (was slow, unexpected)
- Path classification determines required context level immediately
- Errors are fast and actionable with clear fix instructions
- Root-level paths work without any context
- o env now just prints export statements without requiring context
Supports C-a, C-e, C-u, C-k, M-b, M-f, arrow keys, etc.
Sent prompts and slash commands are added to readline history
so up-arrow recalls previous inputs.
o kill: kills the active session.
Prompt REPL now supports slash commands:
/stop, /compact, /kill, /clear, /model X, /backend X, /cwd X, /help
Slash commands are handled locally without sending to the agent.
o tui: launches a 4-pane tmux layout with:
- chat stream (left, large)
- statewait monitor (top-right, reactive)
- spare shell with session/agent exported (bottom-right)
- prompt REPL (bottom, full width)
o stop: shorthand for 'o ctl stop' to interrupt a running agent.
Nodes in the 9P namespace can now declare alternate names (Aliases)
that resolve during Twalk but are invisible in directory listings.
Session dirs alias their immutable RunnableID(), agent dirs alias
their ID(). Clients can use session/{uuid}/agent/{uuid}/... paths
that remain valid across renames.
Changes:
- fs/fsnode.go: Add Aliases []string field, Alias() NodeOption
- fs/builder.go: findChild checks aliases via matchAlias helper
- fs/sessionfiles.go: Session dirs get Alias(s.RunnableID())
- fs/agentfiles.go: Agent dirs get Alias(a.ID())
- fs/spec.go: Add /aliases file (read-only alias→path table)
- fs/rootfiles.go: readAliases handler
- fs/lifecycle.go: buildIndex includes immutable ID in session/idx
- doc/edsl.md: Document Aliases field and behavior
- prompts: Update session/idx format documentation
The KDE GUI submodule now uses immutable IDs in all 9P paths,
fixing disconnected indicators after session rename.
session/{id}/agent/{aid}/plan → ollie-9p write
session/$OLLIE_SESSION_ID/agent/$OLLIE_UNAME/plan
UNAME is the agent's immutable ID, matching the agent directory
name. Using ollie-9p write instead of a mounted filesystem path.
plan now lives at session/{id}/agent/{aid}/plan instead of
session/{id}/plan. Moved the Leaf declaration from fs/sessionfiles.go
to fs/agentfiles.go. Updated both prompt docs to match.
Each lsp_*.meta now lives in tools/lsp/cmd/<name>/ alongside
main.go, rather than in data/tools/. The lsp-tools just target
was updated to install both the binary and its .meta sidecar.
AGENTS.md updated to document the pattern for compiled tools.
Add a tool_load tool that writes a tool name to the session's 9P
tools file via ollie-9p, enabling on-demand tool loading.
Reduce autoLoad lists in default.json and theo.json to bare
essentials — everything else is loaded via tool_load.
skill_list and skill_load are now external shell scripts (data/tools/).
Removed from builtins: SkillList, SkillLoad, SkillActive.
Removed: toolsrv/skills.go, tools/builtin/skill.go, WithSkillsRegistry,
SkillsRegistry accessor, ListSkillsTools.
ollie-remote no longer initializes a skills registry.
The demarcation: built-ins mutate agent internals (tool schema, context
injection). Skills are just file reads — no special treatment needed.
skill_list and skill_load are now simple shell scripts that read
SKILL.md files from OLLIE_SKILLS_PATH. No built-in registry needed.
skill_load returns the file body as tool result (tier:hot, survives compaction).
skill_active dropped — model uses skill_list instead.
Logseq 2.0.1 has bug #12413 where POST /mcp always returns 400.
Switched to the REST API at POST /api which works correctly.
Requires OLLIE_LOGSEQ_TOKEN env var.
Commands: listPages, getPage, searchBlocks, listTags, listProperties,
upsertNodes, getCurrentGraph
Adds system_logs with two variants:
- journalctl (systemd hosts): unit, since, lines, grep
- dmesg (any Linux): source, lines, grep
Both declare sudo: true — privilege escalation is handled by dispatch.
Also adds OR support in match conditions: array values mean any must
pass. Combined with AND across keys:
{"binary": ["journalctl", "systemd-cat"], "os": "linux"}
= (journalctl OR systemd-cat) AND linux