docs(release): expand v4.2.3 CHANGELOG and add OmO logo to README.ru.md
- CHANGELOG: detail BUG-A/B (team-mode delivery), BUG-C/D (runtime-fallback event/finish blind spots), BUG-E (parent-wake same-source reservation), BUG-F (markerless workspace rules); the packages/rules-core and packages/ast-grep-mcp extractions; the prompt-async-gate hold default change; the new symlink-escape security fix; the rules-core isolation note; and the v4.3.0 deferred items (prompt-async-gate.ts split, @ast-grep/napi stale dep cleanup). - README.ru.md: add the OmO logo block so the Russian README matches README.md / README.ja.md / README.ko.md / README.zh-cn.md.
This commit is contained in:
@@ -7,10 +7,48 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
||||
|
||||
## [4.2.3] - Unreleased
|
||||
|
||||
### Added
|
||||
|
||||
- `packages/rules-core`: new workspace package extracting rule discovery, matching, caching, and nested AGENTS.md context utilities. Part of the ROADMAP multi-harness package layering refactor.
|
||||
- `packages/ast-grep-mcp`: native `src/tools/ast-grep` removed and replaced with a package-backed MCP server. User-facing tool names `ast_grep_search` / `ast_grep_replace` are preserved via MCP namespacing (server `ast_grep` + tools `search`/`replace`). `disabled_tools` continues to honor the legacy names.
|
||||
- `setSisyphusRuleDeprecationLogger` export from `@oh-my-opencode/rules-core` lets the host inject its logger so the core package stays free of harness-source imports.
|
||||
- `ROADMAP.md` documents the multi-harness package layering refactor and contribution flow (`ROADMAP` label).
|
||||
|
||||
### Changed
|
||||
|
||||
- `prompt-async-gate`: `DEFAULT_PROMPT_ASYNC_POST_DISPATCH_HOLD_MS` default raised from 250 ms to 2_000 ms (8x) to absorb slower-provider `session.error` arrivals before reservation release. The constant remains a public export; callers can still override via `postDispatchHoldMs` per dispatch. [`docs/reference/prompt-async-gate-rfc.md`](docs/reference/prompt-async-gate-rfc.md) updated accordingly.
|
||||
- `team-mode`: `team_send_message` ambiguous-failure path now releases the reservation, commits on success-path mark failures, preserves live delivery holds, and decouples resume history from session routing (BUG-A / BUG-B).
|
||||
- `runtime-fallback`: recognises every OpenCode progress event shape (`message.part.updated`, `message.part.delta`, `message.updated`) and boolean/completed finish markers, preserves accepted pending retries, and detects finish-only tool waits (BUG-C / BUG-D).
|
||||
- `background-agent`: parent-wake on same-source reservation now re-enqueues instead of dropping the wake (BUG-E).
|
||||
- `rules-core`: `findRuleFiles` falls back to `workspaceDirectory` when no project root marker is found (BUG-F).
|
||||
- `cli doctor`: lists all built-in MCP servers (`websearch`, `context7`, `grep_app`, `lsp`, `ast_grep`) and bootstraps the LSP MCP fallback script when no CLI binary is present.
|
||||
|
||||
### Fixed
|
||||
|
||||
- `rules-core` **security**: project rule files and directories can no longer escape the workspace via symlinks. `findRuleFilesRecursive` and the project-single-file path now require every realpath to remain within the scan boundary, blocking attacks where a hostile repo points `.github/copilot-instructions.md` (or any `.omo/rules` entry) at host secrets such as `~/.ssh/id_rsa`. Tests track the boundary contract in [`packages/rules-core/src/index.test.ts`](packages/rules-core/src/index.test.ts).
|
||||
- `test-isolation`: rules-injector storage and fixture home isolated per-test; cross-suite leak diagnostic regression test added.
|
||||
- `ast-grep-mcp`: absolute paths whose `realpath` stays inside the workspace are now accepted (covered by red test); `path` entries are normalized via `resolve` + `realpath` and rejected for null bytes, leading `-`, and out-of-workspace traversal.
|
||||
|
||||
### Reverted Breaking Changes
|
||||
|
||||
- Restored `.sisyphus/rules` and `~/.sisyphus/rules` rule-source discovery that was silently removed in v4.2.2..HEAD. They now load with LOWEST priority among project rule sources and emit a deprecation warning. **Planned removal in v4.3.0**: migrate to `.omo/rules` and `~/.omo/rules`.
|
||||
|
||||
### Internal
|
||||
|
||||
- `packages/rules-core` no longer imports `../../../src/shared/logger`. ROADMAP's "core has no harness dependencies" invariant is now upheld; the host injects its logger from `src/hooks/rules-injector/rule-file-finder.ts` as a module-level side effect.
|
||||
- `README.ru.md` gains the OmO logo to match `README.md` / `README.ja.md` / `README.ko.md` / `README.zh-cn.md`.
|
||||
- CLA signatures added for PR #4176, #4180, #4181, #4186.
|
||||
|
||||
### Known Limitations (deferred to v4.3.0)
|
||||
|
||||
- `src/shared/prompt-async-gate.ts` is 885 LOC, well past the 250-LOC architectural ceiling. Splitting it into `prompt-reservations`, `prompt-queue`, `prompt-message-state`, `prompt-dispatch-runner`, and a thin facade is queued with the broader multi-harness refactor.
|
||||
- Root `package.json` still declares `@ast-grep/napi` and the doctor still checks the NAPI dependency even though the native tool is gone. Cleanup ships with the next ast-grep harness pass.
|
||||
|
||||
### Documentation
|
||||
|
||||
- Added [`ROADMAP.md`](ROADMAP.md) describing the package layering refactor and multi-harness direction.
|
||||
- Added OmO logo to [`README.ru.md`](README.ru.md) for parity with the other localized READMEs.
|
||||
|
||||
## [4.2.1] - Unreleased
|
||||
|
||||
### Fixed
|
||||
|
||||
@@ -31,6 +31,8 @@
|
||||
|
||||
<div align="center">
|
||||
|
||||
<a href="https://github.com/code-yeongyu/oh-my-openagent#oh-my-openagent"><img src="./.github/assets/omo-logo.png" alt="OmO" width="200" /></a>
|
||||
|
||||
[](https://github.com/code-yeongyu/oh-my-openagent#oh-my-openagent)
|
||||
|
||||
[](https://github.com/code-yeongyu/oh-my-openagent#oh-my-openagent)
|
||||
|
||||
Reference in New Issue
Block a user