release aidev SIG 3/5

Oh My Pi 17.2.1: opt-in security workflow, session imports, remote model discovery fixes

Patch release with an opt-in native security workflow subsystem (scan plans, Codex subscription affinity, SARIF/canonical findings), session imports from Claude and Codex (/resume @claude / @codex), Anthropic OAuth requests now matching Cowork's claude-desktop profile, and fixes for remote llama.cpp/Ollama endpoint discovery and extension validation for createEditTool/createWriteTool imports.

PUBLISHED2026-07-30
OBSERVED2026-08-21
AGE26d
SOURCES1
  • Security workflow (security.enabled, default off): immutable scan plans, exact-account Codex subscription affinity, task-worker review, canonical findings/coverage/SARIF publication, project-scoped history, explicit dispositions, read-only security:// resource namespace, and Codex Security cloud operations integration.
  • Session imports: --from-claude and --from-codex flags, also /resume @claude and /resume @codex.
  • Anthropic OAuth: now reproduces Cowork's claude-desktop request profile including client/runtime metadata, beta selection, system/billing attestation, 64K output cap, and stable HTTP/1.1 header ordering.
  • OAuth credential resolution: exact resolution by durable credential ID, no ranking/rotation/fallback.
  • Fixes: remote llama.cpp/Ollama endpoints now use generous discovery timeout; Ollama cache rows scoped to normalized endpoint; omp install extension validation now exports createEditTool/createWriteTool; Python eval loopback tool bridge no longer routed through macOS system HTTP proxies.
  • Wayland: computer tool probes root drawability at init and fails fast with actionable message on rootless XWayland.
  • postmortem.quit config option for safe shutdown after terminal disconnect.

COMMUNITY

No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.