github code-yeongyu/oh-my-openagent v5.1.14

3 hours ago

Permission checks can no longer switch themselves off. Up to 5.1.13, a failure while the permission system started (a misspelled permissionPreset in settings or on the command line, a null permission rule, or an unreadable approvals file) left every tool call running with no permission check, and nothing said so. 5.1.14 runs on senpi 2026.10.5, which refuses tool calls with Permission setup failed: <reason> until the setting is fixed. If you can't update yet, check that permissionPreset names a preset that exists and that no permission rule is null. (senpi#2617, senpi#2618)

Fixed

A first-turn forced tool call that a strict-schema gateway refuses no longer ends the turn. When a gateway answers 400 and names the forced tool (its tools.N position or its quoted name), the request is retried once without forcing; a generic 400, or one naming another tool, still fails as before. Thanks to @rhyme227 for the report. (#9507, senpi#2648)

apply_patch keeps each file's line endings and no longer drops an indented file section. CRLF and mixed-ending files are no longer rewritten to LF, and a file header indented in the patch applies instead of being skipped while the tool reported success. (senpi#2638, senpi#2636)

An NVIDIA-only setup starts on a model its catalog still lists. The previous NVIDIA default was retired upstream; the default is now nvidia/nemotron-3-ultra-550b-a55b. (senpi#2645)

Codex edition (LazyCodex): a language server that isn't installed no longer blocks every edit. LazyCodex's post-edit language-server check answered block with the install guidance on each edit, even after you declined the install; it now follows your install decision, as the Native edition does. (#9509, #9510)

A computer-use permission denial is an error in code mode too. Through a JS or Python eval, a denied computer call came back without the error flag, so a model could miss the denial and keep acting; it now fails the call there as it does on a direct call. (#9475, #9482)

Windows: a delegated task you kill is reported as killed, not as a crash, and memory no longer loses a state write to a briefly held file. A kill is now recognised from the runner's own request instead of from the child's stderr, and memory's atomic state rename retries the few-millisecond hold Windows places on an open target. (#9471, #9501, #9491)

The computer-use doctor check on macOS reports an engine that never replied as a timeout instead of failing with EPERM. Cleaning up the timed-out probe now treats a process group that is already exiting as gone. Thanks to @MoerAI. (#9422, #9464)

Thanks to @MoerAI for moving the task engine's child event channel into senpi-task, where the computer-use component now imports it from. (#9454, #9467)

Changed

omo runs on senpi 2026.10.5 (through 2026.10.4): the permission fix above; an eval kernel (Python, Ruby or Julia) whose interpreter dies is replaced once instead of failing every later cell; idle shared hosts give their cost back; the Claude Agent SDK moves to 0.3.288; and pasting in terminals without bracketed-paste markers works. Full lists: senpi 2026.10.4, senpi 2026.10.5.

The task tool no longer suggests delegating a few reads or small foreground checks. Its description and the ultrawork routing named those as delegation targets, and GPT-6 Astra followed them literally, waiting on children for work it could do in a few calls. (#9499, #9500)

Added

The browser skill follows the browser the OmO desktop app picks for the session. With a connected browser it uses only that browser and says "Connect your browser" when it's missing; with the in-app browser or none chosen it refuses to drive your own browser. It reports what the browser is doing, and asks before an irreversible action in your own browser. In a terminal nothing changes. (#9486, #9502)

Chat connectors and other integrations can keep their own state in the session-gateway database and update it in the same transaction as sending, binding or acknowledging a message. The session-gateway store supports namespaced extensions: compiled operations can update their registered objects and enqueue messages through bindings, bind conversations, or acknowledge outbox rows in one transaction. A persistent ownership registry protects core and other extensions' objects; matching a name prefix never grants access. Core-colliding names, triggers and views are refused. Migrations are coordinated across processes, forbidden schema changes roll back, and a joined enqueue creates its wake marker inside the transaction, so a rollback removes it. Failures return typed refusals without stopping the worker. Core schema v6 adds the extension registry, preserves existing rows and records author.user_id as nullable deliveries.actor_user_id. (#9331, Refs #9143)

A session-gateway store or store extension whose schema is newer than the running omo is refused with gateway_schema_too_new and left untouched: an older binary neither migrates nor lowers the core user_version, and an extension that registers fewer migrations than its stored version keeps its stored version, data and existing registration. (#9331)

  • 2afeed8 Merge pull request #9519 from code-yeongyu/release/v5.1.14-source-state
  • c6992fd docs(changelog): credit #9464 and #9467 in 5.1.14
  • e94eb88 Merge pull request #9464 from MoerAI/fix/9422-probe-group-eperm
  • 2beda8e Merge pull request #9467 from MoerAI/fix/9454-child-extension-event-owner
  • e5e6925 Merge remote-tracking branch 'origin/dev' into fix/9454-child-extension-event-owner
  • 9270b06 Merge remote-tracking branch 'origin/dev' into fix/9422-probe-group-eperm
  • e498c81 Merge pull request #9121 from MoerAI/fix/9119-mock-toolcall-partial
  • 6ff21c8 Merge remote-tracking branch 'origin/dev' into fix/9119-mock-toolcall-partial
  • 4fef77b Merge pull request #9510 from code-yeongyu/fix/9509-codex-lsp-not-installed-nonblocking
  • bc3d91e fix(omo-codex): don't block an edit because a language server is not installed (#9509)
  • f96e400 Merge pull request #9491 from code-yeongyu/fix/9471-memory-rename-contention
  • 251cbfe Merge pull request #9511 from code-yeongyu/test/9495-print-eval-result
  • 430a154 Merge remote-tracking branch 'origin/dev' into fix/9471-memory-rename-contention
  • ae69671 Merge pull request #9501 from code-yeongyu/fix/9471-runner-records-its-kill
  • 3d9102c test(computer-use): show the eval result when a py denial never reaches capture
  • 0cb91b8 Merge remote-tracking branch 'origin/dev' into fix/9471-runner-records-its-kill
  • d5126a2 Merge pull request #9502 from code-yeongyu/dfa/9486-browser-skill-engine
  • 21782e3 fix(browser): close the owned-engine and message-box gaps found in review
  • bed820c test(browser): guard a session class that keeps private state
  • 13ce21d feat(browser): obey the session's browser engine, report state, ask before irreversible actions
  • 31cd7ce Merge pull request #9478 from code-yeongyu/fix/gateway-store-extensions-review-nits
  • ea30c6a docs(thread): v6 extension registry, in-transaction wake markers, and drop the unread services resolve
  • 81d1271 Merge pull request #9331 from code-yeongyu/feat/session-gateway-store-extensions
  • c19eebc docs(changelog): keep the store extension entries under [Unreleased] after 5.1.13
  • 95dc4ff test(thread): give the CREATE_TRIGGER authorizer test an explicit 15 s budget
  • c66bf0e test(thread): dispose the reopened store before removing its directory in the wake-marker tests
  • aef58b5 fix(thread): resolve an extension call's target without asking the store it runs in
  • 5a0e6df test(thread): expect schema version 6 after the extension migration slot joins v5
  • f94b64a fix(thread): keep the send path's single-lookup resolver alongside the shared extension resolver
  • 54a302d test(thread): give wake-driver stores a resolver and real migrations
  • 22f7043 fix(thread): absorb late extension errors as store events
  • 25f7136 fix(thread): commit joined wake markers inside the transaction
  • bd6c00d test(thread): prove joined wake markers and late extension errors are unsafe
  • 5cc5520 test(thread): refuse malformed trigger text at the authorizer's CREATE_TRIGGER branch
  • d35cbde fix(thread): reach node:sqlite only through the store worker's lazy import
  • ce95db7 fix(thread): replay a closed binding's delivered events through joined extension calls
  • 203ae46 test(thread): keep the receipt batch and binding keys under joined extension sweeps
  • 8492d72 docs(thread): extension lock budget, downgrade refusal and retention
  • fd655e9 fix(thread): keep the retention sweep hourly for extension calls
  • dfda2df fix(thread): restore extension registrations on a fresh store worker
  • bd9eda6 fix(thread): resolve extension targets without a tool-surface store after rebasing
  • 52af902 fix(thread): refuse extension schema downgrades without mutating registration
  • 791a3f4 test(thread): exercise direct authorization and document transaction boundaries
  • 1e2f2f4 test(thread): preserve historical v4 writes against a v5 store
  • 377fea3 fix(thread): refuse unsupported newer core schemas without mutation
  • 5323423 fix(thread): normalize object ownership and namespace registration order
  • d09d26c fix(thread): tokenize SQL placeholders without rewriting literals
  • f152372 fix(thread): refuse uncloneable arguments without losing the worker
  • 26907ab fix(thread): share target resolution and isolate postcommit effects
  • f9d554a fix(thread): bound extension operations and revoke stale transactions
  • e1db9cf fix(thread): own automatic indexes by their extension table
  • 78d3f04 fix(thread): persist extension ownership and reject indirect schema access
  • 55c803a feat(thread): run store extensions in joined worker transactions
  • ab2546e feat(thread): define store extension contract and persist actor identity
  • 12b986e Merge pull request #9500 from code-yeongyu/fix/9499-task-tool-delegation-wording
  • 75e8eb3 fix(memory-core): retry a rename Windows refuses while the target is briefly held
  • fc23b5c fix(task): stop describing few-read investigations and small foreground children as delegation targets
  • eff0416 Merge pull request #9490 from code-yeongyu/test/engine-delivery-table-budget
  • 4ae5e47 Merge pull request #9496 from code-yeongyu/fix/9487-settle-waited-bound
  • c8fef3e test(thread): assert the store's lock-wait give-up rule, not a wall-clock ceiling (#9487)
  • 5f82c5e Merge pull request #9482 from code-yeongyu/fix/9475-code-mode-denial-is-error
  • 74d81c4 fix(desktop-tool): a computer permission denial is an error in code mode too (#9475)
  • e022b93 test(desktop-tool): a computer permission denial must surface inside details (#9475)
  • fdc521e Merge pull request #9480 from code-yeongyu/fix/f2-move-only
  • 22ba376 test(thread): give the fifteen-case delivery table an explicit 30 s budget
  • 1e5a18b fix(computer-use): treat EPERM on the timed-out probe group as already gone (fixes #9422)

Thank you to 2 community contributors:

  • @MoerAI:
    • fix(computer-use): treat EPERM on the timed-out probe group as already gone (fixes #9422)
    • Merge remote-tracking branch 'origin/dev' into fix/9119-mock-toolcall-partial
  • @effortprogrammer:
    • fix(thread): resolve an extension call's target without asking the store it runs in
bun add -g omo-ai

Don't miss a new oh-my-openagent release

NewReleases is sending notifications on new releases.