From 17df89086ba3e79a098994fb95031f8379957ea8 Mon Sep 17 00:00:00 2001 From: "fcremo (Filippo Cremonese)" Date: Tue, 21 Apr 2026 17:54:40 +0200 Subject: [PATCH 1/2] fix: disable bunfig.toml and .env autoloading in compiled binary Compiled Bun binaries unconditionally load bunfig.toml and .env from the current working directory at runtime, before any application code runs. Since omp is a coding agent that runs from arbitrary project directories, it picks up foreign project configs -- most critically preload directives that cause immediate crashes, but also a potential security issue since preloads execute arbitrary code. Add --no-compile-autoload-bunfig and --no-compile-autoload-dotenv to the bun build --compile invocations (available since Bun v1.3.3). Note: source installs via 'bun install -g' are still affected because 'bun run' has no equivalent flag. That remains an open issue. --- packages/coding-agent/package.json | 2 +- scripts/ci-release-build-binaries.ts | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/packages/coding-agent/package.json b/packages/coding-agent/package.json index bdb3eba05..fd53eedac 100644 --- a/packages/coding-agent/package.json +++ b/packages/coding-agent/package.json @@ -31,7 +31,7 @@ "omp": "src/cli.ts" }, "scripts": { - "build": "bun --cwd=../stats scripts/generate-client-bundle.ts --generate && bun --cwd=../natives run embed:native && bun build --compile --define PI_COMPILED=true --external mupdf --root ../.. ./src/cli.ts --outfile dist/omp && bun --cwd=../natives run embed:native --reset && bun --cwd=../stats scripts/generate-client-bundle.ts --reset", + "build": "bun --cwd=../stats scripts/generate-client-bundle.ts --generate && bun --cwd=../natives run embed:native && bun build --compile --no-compile-autoload-bunfig --no-compile-autoload-dotenv --define PI_COMPILED=true --external mupdf --root ../.. ./src/cli.ts --outfile dist/omp && bun --cwd=../natives run embed:native --reset && bun --cwd=../stats scripts/generate-client-bundle.ts --reset", "check": "biome check . && bun run check:types", "check:types": "tsgo -p tsconfig.json --noEmit", "lint": "biome lint .", diff --git a/scripts/ci-release-build-binaries.ts b/scripts/ci-release-build-binaries.ts index 8eb2d961b..0e9bd42b2 100644 --- a/scripts/ci-release-build-binaries.ts +++ b/scripts/ci-release-build-binaries.ts @@ -67,11 +67,11 @@ async function buildBinary(target: BinaryTarget): Promise { console.log(`Building ${target.outfile}...`); await embedNative(target); if (isDryRun) { - console.log(`DRY RUN bun build --compile --define PI_COMPILED=true --root . --external mupdf --target=${target.target} ${entrypoint} --outfile ${target.outfile}`); + console.log(`DRY RUN bun build --compile --no-compile-autoload-bunfig --no-compile-autoload-dotenv --define PI_COMPILED=true --root . --external mupdf --target=${target.target} ${entrypoint} --outfile ${target.outfile}`); return; } - await $`bun build --compile --define PI_COMPILED=true --root . --external mupdf --target=${target.target} ${entrypoint} --outfile ${target.outfile}`.cwd( + await $`bun build --compile --no-compile-autoload-bunfig --no-compile-autoload-dotenv --define PI_COMPILED=true --root . --external mupdf --target=${target.target} ${entrypoint} --outfile ${target.outfile}`.cwd( repoRoot, ); } From 5072d3df113725e515e77ab3c03d105315e85965 Mon Sep 17 00:00:00 2001 From: can1357 Date: Thu, 23 Apr 2026 22:54:40 +0200 Subject: [PATCH 2/2] docs: add compiled binary autoload changelog --- packages/coding-agent/CHANGELOG.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/packages/coding-agent/CHANGELOG.md b/packages/coding-agent/CHANGELOG.md index 89ed66b81..0efa6f0ee 100644 --- a/packages/coding-agent/CHANGELOG.md +++ b/packages/coding-agent/CHANGELOG.md @@ -8,6 +8,7 @@ ### Fixed +- Fixed compiled `omp` binaries to ignore project-local `bunfig.toml` and `.env` autoloading at startup, preventing unrelated project config from crashing or preloading code into the CLI - Fixed edit tool diff and replace operations to report missing-file failures as `File not found: ` errors instead of raw filesystem ENOENT errors - Fixed `local://` URL path leak on Linux where `//` collapsing to `/` produced `local:/path` forms that bypassed the internal protocol handler and leaked as filesystem paths, breaking plan mode file resolution - Fixed Tavily web search silently returning off-topic news articles when `--recency` was set. The provider was unconditionally coupling `topic: "news"` to recency, which scoped Tavily's index to news publications and excluded documentation, release notes, GitHub, and all non-news technical content. Technical queries with `--recency` now return the correct corpus. @@ -7115,4 +7116,4 @@ Initial public release. - Git branch display in footer - Message queueing during streaming responses - OAuth integration for Gmail and Google Calendar access -- HTML export with syntax highlighting and collapsible sections \ No newline at end of file +- HTML export with syntax highlighting and collapsible sections