Oh My Pi 17.2.1: opt-in security workflow, session imports, remote model discovery fixes
Patch release with an opt-in native security workflow subsystem (scan plans, Codex subscription affinity, SARIF/canonical findings), session imports from Claude and Codex (/resume @claude / @codex), Anthropic OAuth requests now matching Cowork's claude-desktop profile, and fixes for remote llama.cpp/Ollama endpoint discovery and extension validation for createEditTool/createWriteTool imports.
PUBLISHED2026-07-30
OBSERVED2026-08-21
AGE26d
SOURCES1
- Security workflow (
security.enabled, default off): immutable scan plans, exact-account Codex subscription affinity, task-worker review, canonical findings/coverage/SARIF publication, project-scoped history, explicit dispositions, read-onlysecurity://resource namespace, and Codex Security cloud operations integration. - Session imports:
--from-claudeand--from-codexflags, also/resume @claudeand/resume @codex. - Anthropic OAuth: now reproduces Cowork's
claude-desktoprequest profile including client/runtime metadata, beta selection, system/billing attestation, 64K output cap, and stable HTTP/1.1 header ordering. - OAuth credential resolution: exact resolution by durable credential ID, no ranking/rotation/fallback.
- Fixes: remote llama.cpp/Ollama endpoints now use generous discovery timeout; Ollama cache rows scoped to normalized endpoint;
omp installextension validation now exportscreateEditTool/createWriteTool; Python eval loopback tool bridge no longer routed through macOS system HTTP proxies. - Wayland:
computertool probes root drawability at init and fails fast with actionable message on rootless XWayland. postmortem.quitconfig option for safe shutdown after terminal disconnect.
COMMUNITY
No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.