Skip to content

Bump omercnet/omp to 1.3.0 - #161

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
bump/omercnet/omp-1.3.0
Open

github-actions[bot] wants to merge 1 commit into
mainfrom
bump/omercnet/omp-1.3.0

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

omercnet/omp: {"kind":"npm","package":"@omercnet/paseo-omp","version":"1.2.0","resolved":"https://registry.npmjs.org/@omercnet/paseo-omp/-/paseo-omp-1.2.0.tgz","integrity":"sha512-ueZede5D34hoNrdF4y6DBaomErA+hHcv+bcz0Sd6eArQKqF8L6ecKXdBe2tEZd3Ev8uQwxMHuiDQhMBx3q6gOw=="} -> {"kind":"npm","package":"@omercnet/paseo-omp","version":"1.3.0","resolved":"https://registry.npmjs.org/@omercnet/paseo-omp/-/paseo-omp-1.3.0.tgz","integrity":"sha512-XWhtFVbCZujr9trSQZWdfR5XqLuKtO10BR+o9vykNaR6Hwh0Siweom8mmokwqxscLXIp/yYfWlf2OBbY9WMpQQ=="}
Provenance verified: built from https://github.com/omercnet/paseo-plugins/tree/HEAD/paseo-omp at 8e8dfa1aebbe7c23673f344e75d93dfac91daba9.
Submitted by @omercnet.

Merging approves this version. The published index keeps pointing at the previous one until then.

Artifact diff
diff -ruN a/package/README.md b/package/README.md
--- a/package/README.md	1985-10-26 08:15:00.000000000 +0000
+++ b/package/README.md	1985-10-26 08:15:00.000000000 +0000
@@ -2,7 +2,7 @@
 
 Community OMP integration for Paseo. The plugin registers the distinct `omp-plugin` provider plus named profile providers and coexists with Paseo's bundled `omp` provider.
 
-> **Alpha preview:** persistence and protocol contracts are tested, but upgrades may still require re-importing sessions created by an earlier preview.
+> **Stable:** see [Support](SUPPORT.md) for supported versions and known limitations, and review release notes for any migration requirements before upgrading.
 
 ## Demo
 
@@ -38,7 +38,7 @@
 - [Compatibility, limitations, and support](SUPPORT.md)
 - [Test matrix and release verification](TESTING.md)
 - [Core-provider issue and parity audit](docs/core-provider-issue-audit.md)
-- [Alpha release checklist](docs/alpha-release-checklist.md)
+- [Release checklist](docs/release-checklist.md)
 
 The plugin uses public Paseo 0.9 and 0.10 provider and client contracts and registers distinct `omp-plugin` and `omp-plugin-<profile>` identities; it does not modify the bundled `omp` provider.
 
diff -ruN a/package/client/omp-config-surface.tsx b/package/client/omp-config-surface.tsx
--- a/package/client/omp-config-surface.tsx	1985-10-26 08:15:00.000000000 +0000
+++ b/package/client/omp-config-surface.tsx	1985-10-26 08:15:00.000000000 +0000
@@ -195,6 +195,19 @@
     </>
   );
 }
+
+function ToolBoundaryCard({ styles }: { styles: OmpConfigStyles }) {
+  return (
+    <SectionCard styles={styles} title="Tool access boundary (fail-closed)">
+      <Text style={styles.muted}>
+        A session toolPolicy (exact preapproval grants) is rejected at startup. OMP set_host_tools
+        cannot preserve those grants exactly, and the plugin never broadens them. Use paseoTools to
+        scope which caller-scoped Paseo tools reach OMP as MCP host tools. Use disallowedTools only
+        for known native OMP built-ins: unknown names are rejected, and it never filters MCP tools.
+      </Text>
+    </SectionCard>
+  );
+}
 function toneColor(theme: PluginSurfaceProps["theme"], tone: BinaryHealthSummary["tone"]): string {
   if (tone === "ok") return theme.colors.statusSuccess;
   if (tone === "warning") return theme.colors.statusWarning;
@@ -1136,6 +1149,7 @@
       {view === "plugin" ? (
         <>
           <PluginConfigurationSection styles={styles} />
+          <ToolBoundaryCard styles={styles} />
           {!cwd ? <ProviderLaunchSettingsSection theme={theme} /> : null}
         </>
       ) : null}
diff -ruN a/package/client/quota-popover.tsx b/package/client/quota-popover.tsx
--- a/package/client/quota-popover.tsx	1985-10-26 08:15:00.000000000 +0000
+++ b/package/client/quota-popover.tsx	1985-10-26 08:15:00.000000000 +0000
@@ -101,6 +101,9 @@
   return (
     <View style={styles.root}>
       <Text style={styles.muted}>{storeLabel(store)}</Text>
+      <Text style={styles.muted}>
+        Last recorded usage from the local agent database, not read live from the provider.
+      </Text>
       {currentProvider && !hasCurrent ? (
         <Text style={styles.muted}>
           {`No recorded quota yet for ${quotaProviderLabel(currentProvider)} (this session's provider).`}
diff -ruN a/package/index.client.tsx b/package/index.client.tsx
--- a/package/index.client.tsx	1985-10-26 08:15:00.000000000 +0000
+++ b/package/index.client.tsx	1985-10-26 08:15:00.000000000 +0000
@@ -351,7 +351,7 @@
         workspaceId: entry.workspaceId,
         agentId: agent.id,
         button: {
-          title: "OMP provider quotas",
+          title: "OMP provider quotas (last recorded usage, not live)",
           icon: quotaProviderIcon(entry.quotaProvider, "unknown"),
           label: "Quota",
           visible: false,
diff -ruN a/package/package.json b/package/package.json
--- a/package/package.json	1985-10-26 08:15:00.000000000 +0000
+++ b/package/package.json	1985-10-26 08:15:00.000000000 +0000
@@ -1,6 +1,6 @@
 {
   "name": "@omercnet/paseo-omp",
-  "version": "1.2.0",
+  "version": "1.3.0",
   "type": "module",
   "description": "Paseo integration for OMP, including its direct provider and workspace tooling.",
   "license": "MIT",
@@ -51,16 +51,16 @@
     "typecheck": "tsc --noEmit -p tsconfig.client.json && tsc --noEmit -p tsconfig.server.json && tsc --noEmit -p tsconfig.tests.json"
   },
   "dependencies": {
-    "@getpaseo/protocol": "0.11.0-beta.3",
+    "@getpaseo/protocol": "0.11.0-beta.5",
     "@modelcontextprotocol/sdk": "1.30.0",
     "yaml": "^2.9.0"
   },
   "devDependencies": {
     "@biomejs/biome": "^2.5.10",
-    "@getpaseo/cli": "0.11.0-beta.3",
-    "@getpaseo/client": "0.11.0-beta.3",
-    "@getpaseo/plugin": "0.11.0-beta.3",
-    "@getpaseo/server": "0.11.0-beta.3",
+    "@getpaseo/cli": "0.11.0-beta.5",
+    "@getpaseo/client": "0.11.0-beta.5",
+    "@getpaseo/plugin": "0.11.0-beta.5",
+    "@getpaseo/server": "0.11.0-beta.5",
     "@oh-my-pi/pi-agent-core": "18.2.0",
     "@oh-my-pi/pi-coding-agent": "18.2.0",
     "@tanstack/react-query": "^5.102.3",
diff -ruN a/package/server/package-version.ts b/package/server/package-version.ts
--- a/package/server/package-version.ts	1985-10-26 08:15:00.000000000 +0000
+++ b/package/server/package-version.ts	1985-10-26 08:15:00.000000000 +0000
@@ -1,2 +1,2 @@
 /** Release Please keeps this bundle-safe constant aligned with package.json. */
-export const PASEO_OMP_PACKAGE_VERSION = "1.2.0"; // x-release-please-version
+export const PASEO_OMP_PACKAGE_VERSION = "1.3.0"; // x-release-please-version
diff -ruN a/package/server/provider/catalog.ts b/package/server/provider/catalog.ts
--- a/package/server/provider/catalog.ts	1985-10-26 08:15:00.000000000 +0000
+++ b/package/server/provider/catalog.ts	1985-10-26 08:15:00.000000000 +0000
@@ -49,7 +49,7 @@
   { id: "xhigh", label: "XHigh", description: "Extra-high reasoning" },
   { id: "max", label: "Max", description: "Maximum reasoning" },
 ];
-export const OMP_MAX_CATALOG_MODELS = 256;
+export const OMP_MAX_CATALOG_MODELS = 4096;
 
 export function selectOmpModels(
   models: readonly OmpModel[],
diff -ruN a/package/server/provider/omp-rpc-transport.ts b/package/server/provider/omp-rpc-transport.ts
--- a/package/server/provider/omp-rpc-transport.ts	1985-10-26 08:15:00.000000000 +0000
+++ b/package/server/provider/omp-rpc-transport.ts	1985-10-26 08:15:00.000000000 +0000
@@ -887,7 +887,7 @@
       : isHistory
         ? 400_000
         : pending.command === "get_available_models"
-          ? 16_384
+          ? 131_072
           : 2_048;
     const violation = jsonBoundViolation(
       boundedFrame,
diff -ruN a/package/shared/omp-models.ts b/package/shared/omp-models.ts
--- a/package/shared/omp-models.ts	1985-10-26 08:15:00.000000000 +0000
+++ b/package/shared/omp-models.ts	1985-10-26 08:15:00.000000000 +0000
@@ -5,7 +5,7 @@
 
 const OMP_MODEL_TEXT_LIMIT = 256;
 const OMP_MODEL_SELECTOR_LIMIT = OMP_MODEL_TEXT_LIMIT * 2 + 1;
-const OMP_MODEL_LIST_LIMIT = 256;
+const OMP_MODEL_LIST_LIMIT = 4_096;
 const OMP_MODEL_INPUT_LIMIT = 16;
 const OMP_THINKING_LEVEL_LIMIT = 16;
 const OMP_THINKING_LEVEL_TEXT_LIMIT = 32;

This version has no OVERVIEW.md. The registry requires one to update a listing; the bump cannot merge until the repository adds it.

Inline validation failed. See the Bump workflow log.

@github-actions github-actions Bot added the bump Pinned artifact update label Oct 7, 2026
@paseo-bot paseo-bot Bot added the needs-maintainer Requires a maintainer decision label Oct 7, 2026

@paseo-bot paseo-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Needs from you: answers

  1. Accept the build command node scripts/prepare-dependencies.mjs for this listing, because from an npm install it finds no catalog and installs nothing? (yes)
  2. If you accept it, is the outcome changes requested for the missing OVERVIEW.md, the same as the other omercnet bumps (#159, #160, #162)? (yes)

REVIEW.md rejects a command that installs a package the lockfile does not fix. scripts/prepare-dependencies.mjs:8-16 walks up from the plugin directory looking for a package.json with a catalog field. Only if it finds one does it run npm install --omit=dev --ignore-scripts --no-package-lock --workspaces=false (scripts/prepare-dependencies.mjs:42-50), which resolves yaml ^2.9.0 without a lockfile. In Paseo's npm install layout the nearest package.json above the package is Paseo's installation manifest, which has no catalog, so the script returns at line 41 unless a package.json higher up on the host has one. The script is unchanged from the listed 1.2.0. The policy doesn't settle a command that is a no-op in practice, so this goes to you.

@omercnet, whatever the answer above, this version also needs OVERVIEW.md next to paseo-plugin.json in paseo-omp/, published in the package, before a bump can merge. It replaces the registry copy plugins/omercnet/omp.md, whose first line calls the plugin an alpha preview while 1.3.0's README calls it stable. The shape is in REVIEW.md.

Review data

  • Artifact: npm @omercnet/paseo-omp 1.3.0 (from 1.2.0), https://registry.npmjs.org/@omercnet/paseo-omp/-/paseo-omp-1.3.0.tgz. npm provenance names omercnet/paseo-plugins at 8e8dfa1aebbe7c23673f344e75d93dfac91daba9, built by .github/workflows/release-please.yml on main.
  • Integrity: SHA-512 of both tarballs matches the record (old and new pin), npm's dist.integrity, and the provenance subject digest.
  • Validation: npm test passes (140/140). node scripts/validate.ts --online --changed fails with one error: omercnet/omp/OVERVIEW.md is required.
  • Extracted and inspected: both tarballs (96 files each), extracted and diffed locally. README.md changes "Alpha preview" to "Stable"; client/omp-config-surface.tsx:199-210 adds a static "Tool access boundary" card whose claims match server/provider/host-tools.ts:242-246 and server/provider/config-normalization.ts:49-55; client/quota-popover.tsx:104-106 adds static text; model list limits rise from 256 to 4096 (server/provider/catalog.ts:52, shared/omp-models.ts:8) and the get_available_models response cap from 16 KiB to 128 KiB (server/provider/omp-rpc-transport.ts:890); package.json moves runtime @getpaseo/protocol and dev @getpaseo/* to 0.11.0-beta.5.
  • Install-time commands: paseo-plugin.json build is node scripts/prepare-dependencies.mjs, read in full and described above; byte-identical to 1.2.0. No manifest install. package.json has no preinstall, install, postinstall, or prepare.
  • Dependencies: runtime @getpaseo/protocol 0.11.0-beta.5 (Paseo's protocol types, depends on zod and semver, no install scripts), @modelcontextprotocol/sdk 1.30.0, yaml ^2.9.0; only the protocol version changes. The monorepo has bun.lock and no npm lockfile: all 1076 registry entries carry sha512 integrity, with no git or tarball sources.
  • Hosts: none added; only the existing github.com links.
  • Credentials and environment: none added; existing reads such as PASEO_OMP_RUN_DIR in server/paths.ts are unchanged.
  • Filesystem: no change.
  • Execution: none added. Existing spawn calls in server/provider/omp-rpc-process.ts, server/provider/omp-rpc-transport.ts, server/provider/mcp-transport.ts, and server/provider-diagnostics.ts start OMP and MCP processes, unchanged. No eval, new Function, or dynamic import().
  • Runtime installs: none.
  • Source match: every file is byte-identical to paseo-omp/ at 8e8dfa1 except package.json, where catalog: specifiers are replaced by the root catalog's versions. Readable TypeScript, nothing bundled.
  • Listing media: plugin-manager.png and workspace-settings.png, each HTTP 200 image/png.
  • Overview: missing in the 1.3.0 package and in paseo-omp/ at 8e8dfa1; the registry copy still says alpha preview.
  • Decision: needs-maintainer, on question 1.
  • Reviewed commit: f0b773febc0a22d5400c7c9262d94628fc474abb

@paseo-bot paseo-bot Bot mentioned this pull request Oct 8, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bump Pinned artifact update needs-maintainer Requires a maintainer decision

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants