Commit Graph

10399 Commits

Author SHA1 Message Date
can1357 02d4de9453 test(git): validated git configuration hardening against security bypasses
- Added test suite to verify git configuration overrides for auth tokens.
- Validated that repo-local git configurations cannot override security-critical settings such as proxy, sslVerify, and credential helpers.
- Confirmed that smart-HTTP path-specific overrides are correctly applied to prevent proxy-based MITM attacks.
- Ensured system CA locations remain untouched to prevent disruption of TLS verification.
2026-06-24 15:30:29 +02:00
can1357 1344be8ae7 fix(python/robomp): restricted URLs starting with a hyphen in proxy server
- Added a check to reject remote URLs that begin with a hyphen to prevent command-line option injection.
- Updated the test suite to verify that option-shaped URLs are correctly blocked.
2026-06-23 20:26:44 +02:00
can1357 c58f72d943 chore: update changelogs 2026-06-23 20:22:31 +02:00
can1357 aed01caaae Merge remote-tracking branch 'origin/farm/8a720b5a/mcp-tools-omit-unused-optional-args' 2026-06-23 20:22:15 +02:00
can1357 6591fc29a3 Merge remote-tracking branch 'origin/farm/49543f98/fix-task-maxconcurrency-zero-unbounded' 2026-06-23 20:22:11 +02:00
can1357 94060e8d6f Merge remote-tracking branch 'origin/farm/b1c3c65a/fix-llama-cpp-context-window' 2026-06-23 20:22:07 +02:00
Can Bölük 93d730c01d Merge pull request #3330 from can1357/farm/4a0fd941/fix-bunfs-root-homebrew-arm64
fix(coding-agent): handled `<bunfs-root>/<binary>` in __computeBunfsPackageRoot
2026-06-23 20:21:08 +02:00
can1357 c752aee69d security(python-robomp): implemented git remote validation and credential hardening
- Sanitized git subprocess environment variables to prevent leakage of parent authentication tokens.
- Enforced strict HTTPS protocol restrictions and source validation for all git repositories.
- Implemented secure remote URL handling to neutralize malicious push URLs and prevent credential exfiltration.
- Applied scoped token injection during git operations to restrict token exposure to intended targets.
2026-06-23 20:19:14 +02:00
runbgp bc41b2ed3e fix(robomp): refused token-bearing git ops to attacker-controlled origins
- Extracted `_pat_safe_remote` and rejected HTTP(S) origins with embedded credentials or mismatched host/repo.
- Guarded `clone` via `_assert_clone_url_safe` on the caller-supplied `clone_url` (pool has no `origin` yet).
- Asserted origin safety before `fetch`, `fetch_ref`, and `fetch_pr_head` inject the PAT header.
- Appended POSIX `--` separator in `omp_local` so prompts starting with `-` aren't parsed as flags.
- Added proxy tests covering attacker-origin fetch rejection and unsafe `clone_url` refusal.

Co-authored-by: can1357 <me@can.ac>
2026-06-23 19:57:15 +02:00
roboomp 57b4ee1eaf style: bun run fix 2026-06-23 16:04:50 +00:00
roboomp 03dae3814f fix(coding-agent): preserved bunfs double-slash in shim paths
`__computeBunfsPackageRoot` now returns `//root/packages` for the Bun 1.3.14
`//root/<binary>` import.meta.dir shape, but production immediately joined that
root with shim and package segments through `path.join`, which collapses the
POSIX double-slash bunfs mount back to `/root`. That still made override
validation miss the embedded shim files.

Added a bunfs join helper that preserves the `//root` mount prefix after joining
production descendants, wired `bunfsPath` through it, and extended the #3329
regression test to assert the full typebox shim path stays under
`//root/packages/...`.

Fixes #3329
2026-06-23 16:04:43 +00:00
roboomp f278ea6a9c docs(coding-agent): corrected #3329 wording — release asset, not Homebrew
The reporter clarified that the failing binary is the pre-built
`omp-darwin-arm64` release asset from GitHub Releases; Homebrew is only a
local-tap wrapper that downloads that asset. The fix already covers every
cross-compiled `<bunfs-root>/<binary>` shape, but the source/test docstrings
and changelog blurb framed it as a Homebrew-build-specific bug. Updated those
three call sites to name the release asset and note the Homebrew tap as a
downstream consumer of the same binary; no code change.
2026-06-23 16:00:15 +00:00
roboomp 5766952c20 style: bun run fix 2026-06-23 15:57:01 +00:00
roboomp aa393099a3 fix(coding-agent): handled <bunfs-root>/<binary> in __computeBunfsPackageRoot
Bun 1.3.14 reports `import.meta.dir` as `<bunfs-mount>/<binary-basename>` for
the compiled entry on some hosts — e.g. the Homebrew darwin-arm64 build sees
`//root/omp-darwin-arm64` instead of the bunfs root alone. The pre-fix path
joined `metaDir` with `"packages"` and baked the binary basename into every
bunfs path, so the typebox / legacy-pi shim overrides failed `existsSync`
validation, `resolveCanonicalPiSpecifier` fell through to a bunfs
`Bun.resolveSync` that also could not find the module, and every third-party
`@oh-my-pi/pi-*` extension was silently dropped.

`__computeBunfsPackageRoot` now detects the trailing binary-basename segment
(`path.basename(path.dirname(metaDir)) === "root"`) and strips it off the
original `metaDir` via string slicing rather than `path.join`, so Bun's
bunfs-native `//root` and `B:\~BUN\root` prefixes survive verbatim
(`path.posix.join` would collapse `//root` to `/root`). The single-segment
`<bunfs-root>` and deep `<bunfs>/packages/coding-agent/src/extensibility/plugins`
paths keep their existing branches.

Regression test added in `legacy-pi-bunfs-root.test.ts` for the POSIX
`//root/<bin>`, POSIX `/$bunfs/root/<bin>`, and Win32 `<drive>:\~BUN\root\<bin>.exe`
shapes.

Fixes #3329
2026-06-23 15:56:52 +00:00
roboomp e431f5caa6 docs(changelog): moved llama cpp fix under unreleased
Move the llama.cpp per-model context window entry from the released 16.1.16 section to [Unreleased] so the next release notes carry it.\n\nFixes #3310
2026-06-23 12:47:10 +00:00
roboomp f552f260f4 fix(providers): avoided llama cpp key resolution on switch
Use a non-resolving discovery context for selected-model llama.cpp metadata refresh so command-backed and OAuth credentials stay lazy during model switches.\n\nFixes #3310
2026-06-23 12:45:35 +00:00
roboomp 15d0e95d6f fix(providers): preserved custom llama cpp limits
Treat same-id custom llama.cpp model contextWindow and maxTokens fields as pinned limits during selected-model metadata refresh.\n\nFixes #3310
2026-06-23 12:32:55 +00:00
roboomp 24adad2890 fix(providers): honored llama cpp model context
Read per-model llama.cpp meta.n_ctx values during discovery, refresh selected models after lazy load, and bypass fresh cache reuse for llama.cpp refreshes so server restarts update context windows.\n\nFixes #3310
2026-06-23 12:23:59 +00:00
roboomp d5677cbc1b style: bun run fix 2026-06-23 10:41:59 +00:00
roboomp e4c52de24d fix(task): normalize fractional spawn concurrency
Normalize the configured semaphore max before deciding whether the spawn

limit is bounded. Fractional values between 0 and 1 now truncate to 0 and

fall through to the unbounded path instead of storing 0 and deadlocking

the first acquire.

Fixes #3305
2026-06-23 10:41:51 +00:00
roboomp 296125cce9 fix(task): treat maxConcurrency 0 as unbounded in spawn semaphore
The session-scoped spawn Semaphore clamped its max via Math.max(1, max), so

task.maxConcurrency: 0 — labeled 'Unlimited' in the settings UI — serialized

subagent spawns one at a time instead of releasing every eligible seat.

The constructor now treats max <= 0 (and any non-finite input) as unbounded

via Number.POSITIVE_INFINITY, so the existing 'current < max' check naturally

permits every acquire. Mirrors the eval parallel()/pipeline() worker-pool

semantics (runEvalConcurrency in eval/concurrency-bridge.ts), which already

treats 0 as 'run every item at once'.

Fixes #3305
2026-06-23 10:37:34 +00:00
roboomp 655ab4347d docs(changelog): moved MCP fix entry to unreleased section 2026-06-23 10:33:38 +00:00
roboomp 60348404a0 fix(mcp): omitted unused optional tool args
Pruned empty optional MCP argument placeholders before tools/call while preserving required fields and meaningful falsy values.

Added regression coverage for active and deferred MCP tools.

Fixes #3302
2026-06-23 10:29:36 +00:00
can1357 af2e53e070 fix(test): align :async: background-retention test with nohup reparenting
`nohup cmd &` is now a transparent background wrapper that double-forks the
operand so it reparents to init (commit 00dcd54597). The shell only tracks
the short-lived intermediate fork, so `$!` is no longer the surviving
process — the prior test read `$!`, then `process.kill(pid, 0)` checked an
already-reaped pid and failed on Linux (the failing CI job).

Split into two contracts:
- plain `&` retention: stays a child of the shell, counted by
  `liveBackgroundJobCount`, kept alive by the retain map; `$!` is the real
  child pid we assert on.
- nohup reparenting: the operand writes its own pid before `exec`ing the
  long sleep, and that (post-exec-stable) pid is asserted to survive across
  turns — independent of `$!`.
2026-06-23 09:45:11 +02:00
can1357 2c3e0d79a4 chore: bump version to 16.1.16 2026-06-23 08:22:21 +02:00
can1357 a6bdef85a2 feat(ai): added support for reasoning items in replay sanitization
- Added `sanitizeOpenAIResponsesReasoningItemForReplay` to process reasoning-type items by stripping unique identifiers and filtering properties.
- Updated the main sanitization utility to route reasoning items through the new logic.
2026-06-23 08:18:59 +02:00
can1357 2787b6dff7 chore: update changelogs 2026-06-23 08:18:29 +02:00
can1357 774da9c490 Merge remote-tracking branch 'origin/farm/4763e132/anthropic-context-management' 2026-06-23 08:08:14 +02:00
can1357 00dcd54597 feat: implemented reparenting for backgrounded wrappers
- Introduce `detach_reparent` parameter to command execution to support process reparenting.
- Add `detach_session_reparent` to Unix command extensions using a double-fork technique to orphan processes from the shell descendant tree.
- Update background pipeline logic to automatically apply reparenting when unwrapping transparent wrappers like `nohup`.
- Remove unused `command_is_resolvable` helper.
2026-06-23 08:06:54 +02:00
can1357 c6fcc155a2 fix: nohup 2026-06-23 06:51:11 +02:00
can1357 c311c30cad fix(coding-agent): resolved local image protocol and process handling
- Standardized `local://` image processing to prevent file corruption during decoding.
- Refactored local path resolution logic to enforce safety constraints and path containment.
- Implemented an image fast-path in `ReadTool` to correctly render local images before text decoding.
- Added comprehensive test coverage for image rendering, text compatibility, and path security.
- Resolved an event loop hang associated with `omp --resume` operations.
2026-06-23 05:16:25 +02:00
can1357 26443eefac fix(coding-agent): terminated process on cancelled startup resume picker
- Force process exit when the startup session picker is cancelled instead of returning.
- Prevent hanging the event loop caused by long-lived startup handles such as theme listeners and timers.
- Add regression test case to verify clean process termination upon picker cancellation.
2026-06-23 05:15:08 +02:00
roboomp c04fa89569 fix(ai): skipped context management for vertex rawpredict
Vertex Claude rawPredict expects Anthropic beta flags in the JSON body as anthropic_beta. The Anthropic stream path can only add context-management-2025-06-27 as an HTTP header there, so sending context_management would make reasoning requests fail.

Omit context_management and its beta header for google-vertex Anthropic models while preserving thinking itself, and add regression coverage to the rawPredict routing test.

Fixes #3288
2026-06-23 01:54:33 +00:00
roboomp 5291b2f5a0 fix(ai): skipped context management for injected clients
Injected Anthropic clients bypass buildAnthropicClientOptions, so this package cannot add the context-management beta header their SDK instance would need before accepting context_management.clear_thinking_20251015.

Omit context_management for options.client requests while preserving thinking itself, and add regression coverage for injected-client payload shaping.

Fixes #3288
2026-06-23 01:42:53 +00:00
roboomp 6b3c7ad376 fix(ai): advertised context-management beta for api-key thinking
Anthropic rejects context_management.clear_thinking_20251015 without the context-management-2025-06-27 beta header. OAuth requests carried it via claudeCodeAgentBetaDefaults; API-key requests pushed the new context_management field without the beta, so the server rejected them.

Push the beta into extraBetas alongside the field for every API-key thinking request, and exclude the GitHub Copilot proxy (which strips Anthropic betas and demotes thinking blocks upstream) from emitting the field.

Fixes #3288
2026-06-23 01:35:42 +00:00
roboomp c686c1c803 fix(ai): kept anthropic thinking context
Sent context_management.keep=all for all enabled Anthropic thinking requests so API-key and Anthropic-compatible providers preserve replayed reasoning blocks across turns.

Added regression coverage for budget and adaptive thinking payloads.

Fixes #3288
2026-06-23 01:31:31 +00:00
can1357 92d03466b7 Merge branch 'farm/c8a3da70/fix-resume-delete-scroll' into resume picker
Resolve the session-selector.ts conflict by integrating the delete-dialog
content-slot fix (#3283) on top of the fullscreen mouse-picker refactor.

The branch swapped the delete-confirmation dialog INTO a single content
slot (replacing the SessionList) so the picker is always
`chrome + max(list, dialog) + chrome` and never overflows the viewport.
Adjustments baked into this merge:

- Wrap the SessionList in `#contentSlot` and keep the dialog swapping into
  that slot, but preserve the new fullscreen path: mouse hit-testing,
  the pinned footer (`#footerLines`/`#footerStart`), and fill-height
  trimming all still work because the render offset now tracks
  `#contentSlot` (the list lives one level down).
- Keep both CHANGELOG entries (picker mouse/fullscreen + #3283 fix) and
  the ported scroll-stability regression test.
2026-06-23 02:46:56 +02:00
can1357 cffb804d3a feat(coding-agent): added mouse support and fullscreen rendering to session picker
- Enabled fullscreen overlay rendering for the terminal session picker.
- Implemented full mouse support including wheel-based scrolling and click-to-select functionality.
- Anchored the session picker footer to the bottom of the viewport to correct UI flickering.
- Added comprehensive unit tests for mouse interaction and layout constancy during resizing.
2026-06-23 02:25:30 +02:00
roboomp e266782604 fix(session-selector): swap delete dialog into SessionList slot
Earlier rounds shrank the SessionList by the dialog's row count to keep
the picker inside the viewport, but the SessionList could only claw back
whole session rows and bottomed out at zero entries. On a narrow
terminal with a long session title the dialog still wrapped past what
the SessionList could free, the picker overflowed the viewport, and the
TUI committed the header into native scrollback.

The picker now hosts the SessionList inside a single contentSlot
Container. Opening the delete confirmation swaps the dialog INTO that
slot (replacing the SessionList); closing it swaps the SessionList back.
The dialog therefore competes only with the SessionList's rendered
budget, not with the SessionList AND the picker chrome, so the picker
frame stays bounded by terminalRows even when the dialog wraps to many
rows. SessionList's external-reserve plumbing is no longer needed and is
removed.

Addresses PR #3285 second-round review feedback.
2026-06-23 00:05:53 +00:00
roboomp 964dc480c9 fix(session-selector): derive delete-dialog reserve from rendered height
The first round of the issue #3283 fix reserved a fixed 12 SessionList
rows for the delete confirmation dialog. On a narrow terminal or against
a long session name, HookSelectorComponent's Markdown title and help
text wrap past 12 rows; the picker would still overflow even after the
SessionList shrank to zero entries, and the TUI committed the picker
header into native scrollback again.

SessionSelectorComponent now overrides render() to measure the dialog's
actual rendered height at the live width before super.render() walks
the children, and pushes that as the SessionList's external-row reserve.
The dialog's own Container memoization makes the extra pre-render
essentially free.

Addresses PR #3285 review feedback.
2026-06-22 23:56:25 +00:00
can1357 c4e23fed15 fix(coding-agent/tools): enabled live stdout streaming for running cells
- Update the eval tool to stream stdout chunks directly into the active cell's output buffer while the process is still running.
- Prevent long-running cells from appearing empty in the UI by surfacing incremental output before the backend resolves.
- Add regression tests to ensure streamed output is captured mid-execution and reconciled with final results.
2026-06-23 01:46:45 +02:00
can1357 6ff37e346a feat(coding-agent): extended --thinking CLI flag options
- Added `off` and `auto` as valid inputs for the `--thinking` CLI flag.
- Centralized thinking level definitions in `CLI_THINKING_LEVELS` to keep flag options, shell completions, and validation in sync.
- Configured CLI parsing to reject `inherit` as an explicit input to prevent unintended configuration suppression.
2026-06-23 01:46:36 +02:00
can1357 1dd78b207e feat(coding-agent): removed unused eval helper functions
- Removed deprecated eval prelude helpers `append`, `tree`, `diff`, `sort`, `uniq`, and `counter` from all supported runtimes.
- Cleaned up runtime implementations, protocol definitions, and UI rendering logic associated with the removed helpers.
- Updated project documentation, prompts, and test suites to reflect the reduced helper API surface.
- Recorded functional changes in the package changelog.
2026-06-23 01:39:24 +02:00
roboomp ecdff42513 fix(session-selector): keep /resume header pinned after delete
The delete-confirmation dialog mounted as a sibling below the picker's
bottom border briefly grew the picker past the terminal height. The TUI's
append-only renderer committed the picker's top rows (header + first
sessions) into native scrollback to fit the dialog within the viewport.
When the dialog closed and the picker re-rendered shorter, `windowTop`
stayed pinned at `#committedRows`, leaving the picker stranded below the
committed prefix — the user saw the header scrolled off the top.

SessionList now exposes `setExternalReserveRows`; SessionSelectorComponent
reserves the dialog's worst-case height while the dialog is mounted so
the picker's total rendered output stays within the terminal viewport
and the TUI never commits its rows.

Fixes #3283
2026-06-22 23:38:11 +00:00
can1357 ec16b09c76 chore: bump models 2026-06-23 01:05:40 +02:00
can1357 060f4004e7 feat(coding-agent): refactored eval tool to single-step execution
- Transitioned the eval tool from batch multi-cell execution to a single-step input structure with flat parameters.
- Updated core agent logic, UI components, and documentation to support state persistence across incremental eval calls.
- Restricted bash tool capabilities by requiring explicit use of `read` or `find` instead of `ls` or `find`.
- Added support for Ruby and Julia language runtimes to the eval tool and associated web renderers.
2026-06-23 00:59:58 +02:00
can1357 899c0ef08b feat: simplified todo tool to single operation interface
- Refactored `todo` tool to accept a single operation object instead of an `ops` array.
- Implemented parameter normalization to maintain backward compatibility with legacy array-based tool calls.
- Updated tool instructions, documentation, and UI rendering components to reflect the new interface.
- Added compatibility tests to verify rendering and execution for both legacy and current operation formats.
2026-06-23 00:54:54 +02:00
can1357 873e62c816 feat(coding-agent/edit): implemented visual row budgeting for streaming diff renders
- Updated streaming diff renderer to use visual line wrapping instead of line count for preview budget.
- Introduced width-aware slicing to ensure displayed content stays within the provided UI bounds.
- Refactored cache salt parameters to incorporate width for consistent rendering across window resizes.
2026-06-23 00:38:24 +02:00
can1357 2ff005a354 fix(coding-agent/modes): resolved escape key handling under kitty keyboard protocol
- Update input handler to recognize CSI-u escape sequences using `matchesKey`.
- Ensure legacy bare escape sequences remain supported in environments without the protocol.
- Add test coverage for both CSI-u and legacy escape inputs.
2026-06-23 00:36:54 +02:00
can1357 9569e355b7 refactor(coding-agent/edit): introduced a dynamic row budget for the diff
- Introduced a dynamic row budget for the diff preview to prevent overflow during streaming.
- Integrated `previewWindowRows()` into the cache key to ensure proper re-rendering upon viewport resizing.
- Simplified tail window logic to consistently apply the preview budget.
2026-06-23 00:35:23 +02:00