Evidence record / omp

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the signals and issues that cite it, below.

2026-09-21-omp-collab-relay-sessions-a-view-only-link-could-steer-the-session-after-a-host-reconnect-fixe

Collab (relay sessions): a view-only link could steer the session after a host reconnect; fixed in 18.2.1. Auto-hosting arrived in 18.1.20. Answers the contract’s relay question from the docs: the relay is maintainer-operated at my.omp.sh, not self-hostable in production, content-blind by design, and the link is the credential. The defect meant a view link was not reliably read-only before 18.2.1. The capability: with collab.autoStart every interactive session can host itself at start, and omp collab list / omp collab link hand out URLs from a local Unix-socket registry, so a phone or dashboard reaches any running session.

Channel: tagged-release. Half: both. Date: 2026-09-09 (fix commit), 2026-09-15 (released); 2026-09-13 (autoStart).

Operator consequence: Treat every view link issued on OMP before 18.2.1 as a control link and stop those rooms. Leave collab.autoStart at off unless you want every session reachable by link; control makes each session steerable by anyone holding its URL. Guests can prompt the host’s agent, which runs the host’s tools under the host’s approval mode.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-omp-collab-relay-sessions-a-view-only-link-could-steer-the-session-after-a-host-reconnect-fixe

Profile citations

  • omp / claim / collab-view-link-could-steer

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact