Skip to content

docs(prd): 0018 take what omp got right - #538

Merged
ralyodio merged 1 commit into
mainfrom
worktree-prd-omp-features
Sep 25, 2026
Merged

ralyodio merged 1 commit into
mainfrom
worktree-prd-omp-features

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

PRD 0018, drawn from reading omp (oh-my-pi) after #536 added it as an engine.

What it proposes

omp is the most interesting harness in the engine set, but most of it is not ours to take. The Rust core, in-process ripgrep, LSP and DAP are engine internals, and moshcode inherits those by wrapping omp. What is worth taking is the handful of omp ideas that are only half-built, because omp can only ever apply them to omp:

  • Cross-engine handoff (P0). omp imports sessions from Claude Code and Codex, one direction, into itself. moshcode wraps eleven engines, so the same idea is a bus rather than an import. Closes the OpenFleet lineage gap PR 502 left, since a handoff is exactly that edge.
  • moshcode cost limits / cost route (P0/P1). Spend is already reported. Remaining headroom is not, and that is the number that matters on one Anthropic key shared across 13 production vaults.
  • Stream rules at the PTY layer (P1). omp corrects one model, its own. A rule on pty.mjs is engine-agnostic by construction.
  • auth serve (P1), so no engine process reads a credential from a .env.
  • Session branching into a herd pane, grievances, cleanse (P2).

Why it is cheap rather than speculative

Three things are already in the tree: cost.mjs parses every engine's transcript format, pty.mjs sits below every engine's output stream, and cost.mjs already reports spend.

Two are already done and the PRD records them so they are not re-proposed: completion.mjs generates no-drift completions from cli-schema.mjs, and advisor.mjs is advis0r.com equity research rather than an advisor model, so that name is taken.

Conformance

Follows profullstack.com/stack: MCP bridge on every verb, hqtui rather than a localhost web dashboard (omp's stats -p is a browser page), node --test, and no em dashes.

Also in this diff

Regenerating the index with prd.mjs corrected a stale row. 0017 has said Accepted on disk while README said Draft.

Testing

node --test test/prd.test.mjs test/prd-index-cell.test.mjs test/tui-prd-errors.test.mjs passes, 39/39.

🤖 Generated with Claude Code

Cross-engine session handoff, stream rules at the PTY layer, and provider
limits folded into `moshcode cost`, drawn from omp (oh-my-pi) after #536
added it as an engine.

Grounded in three things already in the tree: cost.mjs already parses every
engine's transcript format, pty.mjs already sits below every engine's output
stream, and cost.mjs already reports spend but not headroom. Records two
non-starters so they are not re-proposed: completion.mjs already generates
no-drift completions from cli-schema.mjs, and advisor.mjs is advis0r.com
equity research rather than an advisor model, so that name is taken.

Conforms to profullstack.com/stack: MCP bridge on every verb, hqtui rather
than a localhost web dashboard, node --test, and no em dashes.

Regenerating the index with prd.mjs also corrected a stale row: 0017 has
said Accepted on disk while README said Draft.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

0 finding(s) in the 2 file(s) this pull request changes.

Nothing in the files this pull request changes.

101 pre-existing finding(s) elsewhere in the repository — **HIGH/CRITICAL**: 8 | **MEDIUM**: 82 | **LOW**: 11

Not introduced by this pull request. The full set is in the Security tab.

Severity Rule Location
HIGH js-ssrf-outbound-request apps/pwa/public/sw.js:45
HIGH tls-verification-disabled apps/pwa/src/lib/moshpit-gateway.mjs:299
HIGH sh-remote-script-execution install.sh:86
HIGH sh-remote-script-execution install.sh:90
HIGH sh-remote-script-execution install.sh:258
HIGH sh-remote-script-execution install.sh:269
HIGH sh-remote-script-execution install.sh:275
HIGH tls-verification-disabled src/dns.mjs:766
MEDIUM sql-template-interpolation apps/pwa/src/lib/moshpit-certs.mjs:44
MEDIUM sql-template-interpolation apps/pwa/src/lib/moshpit-certs.mjs:82
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:139
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:153
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:179
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:373
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:377
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:422
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:671
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:867
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:869
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:928

…and 81 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 7005b8d into main Sep 25, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant