!a or !approve - approve first pending bypass for this agent
!d or !deny - deny first pending bypass for this agent
!b or !bypass - list pending bypass requests for this agent
o session/agent bypass - shows only that agent's requests
o session/agent approve - approves first request from that agent
o session/agent deny - denies first request from that agent
o session bypass - shows all requests (unchanged)
Agent names may contain colons (e.g., src:ollie), so slash must
be the primary separator. Colon separator is only for the rare
case where session names contain slashes.
default/src:ollie now correctly parses as:
session = default
agent = src:ollie
- Sanitize tmux session name (replace / and : with -)
- Include agent name in tmux session for uniqueness
- Quote context arg in spawned o commands
- Use colon separator for robustness
- session:agent works as alternative to session/agent
- Colon takes precedence (allows slashes in session names)
- Quoted arguments with spaces now work: o "my session:agent" prompt
- Removed set -- $* which broke quoted arguments
- Updated help with examples
o sess approve [id] - approve pending, optionally verify id
o sess deny [id] - deny pending, optionally verify id
Shows request id in output: [42] approving: cmd
Errors if specified id doesn't match pending request.
Works at session or agent context (bypass is session-level).
Reads pending request from session/{s}/bypass, extracts ID,
writes '{id} approve' or '{id} deny' to resolve.
CreateEmpty now returns (session, created, error): if a session with the
given name already exists it is returned untouched instead of erroring,
and only a freshly created session receives the provided cwd/workflow/
variant. The o script no longer suppresses errors from session/new, so
real failures surface while re-creating an existing session stays a
no-op success.
Make the namespace explain itself instead of requiring prior knowledge.
- ctl is self-describing: reading it (empty write) or writing 'help'
returns the valid verbs with one-line descriptions; an unknown verb
errors with the valid list. Refactor dispatch to an ordered []ctlCmd
carrying descriptions; drop the undocumented '.' alias and the
drift-prone hardcoded help verb. Keep 'i' (drop 'inject') for fast
injects. o's ctl usage now reads the live listing.
- Errors carry severity + remediation. backend.ClassifyError maps the
typed errors to transient/config/fatal with a one-line fix; the error
event renders [[[error:<severity>]]] and a 'remediation:' line so a
human knows whether to wait or intervene.
- Add a human status file: 'thinking · 12s', 'calling shell · 3s',
'idle' — distinct from the machine-facing raw state. Wire the TUI bar
to it.
- Bare 'o' shows an overview of running sessions/agents with status, so
you don't need to know any names to get oriented.
Tests: dispatch help/unknown/routing, ClassifyError severity table.
Session names like 'r7.20' caused 'duplicate session' errors because
tmux interprets dots as window.pane separators.
Fix: Use '=' prefix for exact match in all tmux -t arguments.
From tmux(1): 'If the session name is prefixed with an =, only an
exact match is accepted.'
- Add quirks package for stupid model behavior workarounds
- ShellInvokesNativeTool blocks shell(cmd="tool_name") patterns
- Add client_9p tool: native wrapper for ollie-9p operations
- Block ollie-9p in shell — use client_9p instead
- Update all prompts to use client_9p, not shell+ollie-9p
- Clarify 9P namespace is complete (tools are NOT in 9P)
- Registry.All() lists all available tools for validation
Paths starting with / are treated as root-relative, ignoring
the current context prefix. This allows accessing root-level
files/directories even when in a session or agent context.
Example: o myproj/coding ls /bypass # list root bypass/ dir
Simplify context parsing:
- o <cmd> Root level
- o <session> <cmd> Session level
- o <session>/<agent> <cmd> Agent level
The slash disambiguates between session and agent context,
eliminating the need for 'session' and 'agent' keywords.
Examples:
o myproj ls # session level
o myproj/coding prompt # agent level
Refactor o CLI to use explicit context selectors:
- o <cmd> Root level
- o session <sname> <cmd> Session level
- o agent <sname> <aname> <cmd> Agent level
Environment variables $session and $agent can substitute for
positional args for backwards compatibility.
Update acme scripts to use new interface:
o agent $OLLIE_SESSION $OLLIE_AGENT prompt
- backend: add CWD field to GenerationParams for environment state
- kiro: pass session CWD to kiroCurrentEnvState instead of hardcoded '/'
- agent/runtime: set GenParams.CWD from session cwd in BuildRuntime
- o new: create sessions and agents via 9P filesystem
- o prompt: support piped stdin for non-interactive use
/tools — lists loaded tools
/tool_load X — loads a tool by name
System prompt updated to instruct the agent to use ctl for tool
management instead of writing to a tools file.
/models now lists available models for the agent's backend via ctl.
One fewer file in the agent namespace. The root-level models file
(all backends) remains unchanged.
The ctl file is now a Request handler: write a command, read the
response. Commands with no args return current state:
/model → prints current model
/agent → prints current profile
/cwd → prints working directory
/name → prints agent name
/model X → switches model, returns new model
/compact → compacts, returns 'ok'
o ctl now uses 'ollie-9p rdwr' to get the response.
This enables /model (no args) to show the current model from
any frontend.
The slash prefix in prompts now routes directly to the agent's ctl
file. No special-cased commands in the agent — the ctl handler is the
single command surface:
/stop, /compact, /clear, /model X, /inject X, /agent X, /cwd X
New ctl commands:
inject <text> — overwrites any pending inject (replaces /i and /irw)
agent <name> — switch agent profile (moved from commands.go)
Agent methods added: Compact(), Clear(), SwitchProfile() — called by
the ctl handler, testable independently.
HandleCommand is now a thin trampoline: strip /, run 'o ctl <rest>'.
commands.go reduced from 155 to 50 lines.
REPL: / → o ctl, !q/!quit → exit TUI.
The sandbox escape mechanism is a bypass, not privilege elevation.
The old name caused the agent to confuse it with sudo.
- elevate/ → bypass/ (package, types, tests)
- elevate_notify.go → bypass_notify.go
- Namespace: /elevate → /bypass, session/*/elevate → session/*/bypass
- Tool arg: "elevated" → "bypass"
- Env: OLLIE_ELEVATE_SOCKET → OLLIE_BYPASS_SOCKET
- File: elevate-policy.yaml → bypass-policy.yaml
- All docs, prompts, and scripts updated
- Merge readloop into read -l (loop mode)
- Remove chatstream command (TUI uses 'o read chat' directly)
- Rework ctl: o ctl <cmd> [session] [agent] — dispatches to
session ctl for kill/pause/resume, agent ctl for the rest
- Add trap EXIT to kill background statewait loop (fixes zombie)
- Remove -1 compatibility flag from generate
- Remove no-op bracketed paste bind from prompt REPL
- Fix /i help text: 'inject prompt (mid-turn or queued)'
- Update all help text to reflect current commands
- Delete agent/usage_log.go — wrote JSONL to disk but nothing read it
- Remove appendUsageLog call from turn.go
- Remove dead 'offset' from AGENT_FILES tab-completion list
- TUI: grep markers+fences from o log (single read, not streaming)
- fifo.in + fifo.out → single fifo (write enqueues, read dequeues)
- cost + usage + ctxsz → single stats (key=value lines)
- Remove connection (no consumers, heartbeat handles it)
- Remove dead prevPrompt field and write (prompt.prev gone from spec)
- Clean AGENT_FILES: remove state, context, tail (all already absent
from spec, were only in the tab-completion list)
chat — strips [[[...]]] markers and source fences at the byte level.
Partial lines pass through immediately for true streaming. Terminals
and text editors use this.
chat.raw — full block-structured stream with markers and fences.
GUIs that parse blocks (KDE, web) use this.
The TUI no longer pipes through grep (which was line-buffering and
killing char-by-char streaming since Aug 4).
The stripMarkers state machine processes each chunk from the server:
- Complete lines starting with [[[ and ending with ]]] → dropped
- Fence lines (```...) → dropped (open toggles in-fence state)
- Partial lines (no trailing \n) → always emitted immediately
- Everything else → passed through