Commit Graph

1126 Commits

Author SHA1 Message Date
can1357 8fe2b8f9ba Merge PR #7311: fix(catalog): honor openrouter deepseek effort metadata (@roboomp) 2026-08-01 21:29:35 +02:00
roboomp 2cfaeb6116 fix(catalog): honored openrouter deepseek effort metadata
- Parsed OpenRouter reasoning effort ladders and defaults during discovery.

- Preserved explicit thinking metadata from models.yml patches.

- Regenerated the catalog and covered both regression paths.

Fixes #7307
2026-08-01 19:06:44 +00:00
can1357 386385f18b fix(coding-agent): skipped xd:// mounting when write tool is not granted
- Prevent xdev state allocation and tool mounting in sessions lacking a write tool.
- Expose discoverable tools top-level instead of auto-granting write transports.
2026-08-01 20:39:08 +02:00
can1357 13a36f7c83 refactor(coding-agent/mcp): changed default MCP request ID format to sequential integers
- Change the default MCP JSON-RPC request ID format from snowflake strings to sequential integers.
- Update server configuration schema, connection equivalence checks, and tests to reflect the new integer default.
2026-08-01 20:33:11 +02:00
can1357 4a83ea86fc Merge PR #7107: feat(mcp): let a server opt into integer JSON-RPC request ids (@kodlian) 2026-08-01 20:13:38 +02:00
can1357 6cf01fe5dc fix(keybindings): preserve explicit shift-up remaps 2026-08-01 20:13:37 +02:00
can1357 aaeb14c850 Merge PR #7149: feat(keybindings): accept shift+up for the steering dequeue (@metaphorics) 2026-08-01 20:13:37 +02:00
Jérémy Marchand 4476940a4a docs(mcp): document requestIdFormat as OMP-specific
The option only exists in OMP's own config format, so the OMP-owned discovery
providers are the only ones that parse it. Say so in the schema description, the
MCPServerConfigBase doc, and the changelog, and name the config paths where
setting it actually takes effect, so nobody expects a server imported from
another tool's config to honor it.
2026-07-31 21:04:02 +02:00
Jérémy Marchand 8560188314 feat(mcp): let a server opt into integer JSON-RPC request ids
Apple's `xcrun mcpbridge` decodes JSON-RPC `id` as an integer only. OMP
mints collision-resistant snowflake strings, so the bridge logs
`mcpbridge.DecodeError Code=1`, never replies, and every request hangs
until it times out (#7053). JSON-RPC 2.0 permits String and Number ids
equally, so both shapes are legal and the string default stays.

Add `requestIdFormat: "string" | "number"` to the shared server config
and honor it in all three transports through one allocator. The string
default is unchanged, so this is inert unless a server opts in.

Verified against Xcode 26.3's bridge: with `"number"`, `initialize`
succeeds and `tools/list` returns all 21 tools; with the default, the
same request times out.
2026-07-31 21:03:05 +02:00
can1357 06649b7407 feat(coding-agent): rewrote codex saved-reset trigger algorithm
- Replaced the reactive weekly-only auto-redeem predicate with a pool-wide
  planner: an expiry-salvage sweep piggybacks on the 5-minute usage
  heartbeat and spends any account's reset that would otherwise expire
  within codexResets.salvageHorizonHours, and the blocked-turn path scans
  all stored accounts with eligibility built from the exact exhausted
  5h/weekly windows (openai/codex#28525), unblocking at the latest reset
  among them.
- Made the live 429's parsed unblock timestamp authoritative for the
  active account (pre-block snapshots survive cache invalidation via
  in-flight adoption and last-good fallback), synthesizing the candidate
  when no usable report exists, and overlaying live credit counts from
  the dedicated credits route since a stale /wham/usage zero is never
  corrected upstream.
- Treated nothing_to_reset, credit_list_failed, and thrown consumes as
  non-terminal: the episode key is released and deferred 30 minutes
  instead of burying a banked credit; redeemResetCredit now spends the
  soonest-expiring credit.
- Added planner unit fixtures plus integration regressions driving the
  real triggers end to end, with an injectable per-session coordinator
  seam and a sweep settlement handle.
2026-07-31 20:39:12 +02:00
metaphorics 54bf138cab feat(keybindings): accept shift+up for the steering dequeue
macOS Terminal.app consumes Option for character composition, so Alt+Up
never reaches the app and the dequeue is unreachable there. Bind Shift+Up
alongside it -- Shift is not intercepted, and the key was unbound in the
input path.

The three overlay handlers that already use shift+up for fast scroll
(scroll-view, model-hub, log-viewer) match keys directly rather than
through the manager, so they never see this binding.

Both default tables move together: the registry in config/keybindings.ts
and DEFAULT_ACTION_KEYS in custom-editor.ts, which silently shadows the
registry when they disagree.
2026-07-31 16:53:11 +09:00
can1357 652647770e feat(coding-agent): added app.live.toggle keybinding and map display reset to alt+l
- Add the `app.live.toggle` keybinding defaulted to `Ctrl+L` to start or stop live voice mode.
- Remap the default display-reset action (`app.display.reset`) from `Ctrl+L` to `Alt+L`.
- Update the live visualizer to listen for stop keys so the toggle chord terminates active sessions.
2026-07-31 00:20:04 +02:00
can1357 ab572106cd Merge PR #7048: feat(security): add OMP-native security scan subsystem (@kmccleary3301) 2026-07-30 17:11:06 +02:00
roboomp fad7e97d53 fix(catalog): scoped Ollama model caches by endpoint
Ollama's online-if-uncached path keyed every endpoint under the same
provider namespace. Changing OLLAMA_BASE_URL or OLLAMA_HOST therefore
reused fresh models routed to the previous endpoint until cache expiry.

Centralize an endpoint-normalized Ollama cache namespace and apply it to
both configured coding-agent discovery and the catalog model manager.
Add coverage proving a default refresh discovers the new endpoint even
while the previous endpoint has a fresh row.

Fixes #7087
2026-07-30 13:31:08 +00:00
roboomp ec2caea840 fix(coding-agent): honor remote llama.cpp/ollama discovery base urls
llama.cpp and Ollama model discovery probed /models and /props with a
250ms timeout tuned for a loopback server. That cap also applied to a
host reached over the network, so a remote or LAN LLAMA_CPP_BASE_URL
(or OLLAMA_BASE_URL/OLLAMA_HOST) with normal round-trip latency timed
out, discovery returned no models, and the picker fell back to stale
127.0.0.1:8080 entries.

Select the probe timeout by host: strictly-loopback base URLs keep the
fast fail so a busy or foreign service on the default port never stalls
startup; every non-loopback host gets a generous discovery budget.

Fixes #7087
2026-07-30 13:19:41 +00:00
Kyle McCleary dba303e2e0 Merge remote-tracking branch 'origin/main' into feat/security-native 2026-07-29 20:31:08 -07:00
Kyle McCleary 089a9963f8 feat(security): OMP-native security subsystem (planner handoff) 2026-07-29 18:47:51 -07:00
can1357 c9c890c49a Merge PR #6858: feat: add opt-in Codex reset fireworks (@joshrzemien) 2026-07-30 01:48:51 +02:00
can1357 2395848f7c Merge PR #6857: feat(coding-agent): add startup changelog display modes (@wolfiesch) 2026-07-30 01:48:51 +02:00
can1357 70e6d2c7dc Merge PR #6680: feat(coding-agent): add opt-in max ceiling for auto thinking (@everton-dgn) 2026-07-30 01:48:51 +02:00
can1357 27cb968359 Merge PR #7007: feat(tools): add a browser.cdpUrl setting for the default automation target (@terrxo) 2026-07-30 01:48:50 +02:00
Wolfgang Schoenberger 757b0938ce fix(coding-agent): tighten startup changelog contracts
(cherry picked from commit e5490279ca0b400b143514e7ef3e38be0686bf31)
2026-07-30 01:42:01 +02:00
Wolfgang Schoenberger a4dc5a094a feat(coding-agent): add startup changelog display modes
(cherry picked from commit bed594fecd1eae1917f3f047f883da5ba83317f9)
2026-07-30 01:41:57 +02:00
can1357 fcc8cce9d9 Merge remote-tracking branch 'refs/remotes/pr/6858' into prep/6858
# Conflicts:
#	packages/coding-agent/src/modes/components/status-line/component.ts
2026-07-30 01:41:54 +02:00
can1357 d2d9c81c84 Merge PR #7012: fix(task): let task.softRequestBudget lower bundled subagent budgets (@terrxo) 2026-07-29 23:09:03 +02:00
Nik Divjak c3011fff3c fix(task): let task.softRequestBudget lower bundled subagent budgets
The soft request budget resolved to `SOFT_REQUEST_BUDGET[agent.name] ??
configured`, so the bundled entries for scout and sonic replaced the
configured value outright. Lowering `task.softRequestBudget` to tighten
the guard therefore did nothing for exactly the two agents that spawn
most often: a scout kept its 100-request budget no matter how small the
user set the knob. Only 0 (disable) and raising the value for
non-bundled agents had any effect.

Treat both numbers as upper bounds and take the smaller one. The bundled
entries stay ceilings, so a runaway scout is still stopped at 100 by
default and existing behavior is unchanged for anyone who has not
lowered the setting; a configured 0 still disables the guard entirely.
Resolution moves into `resolveSoftRequestBudget`, which also normalizes
negative and fractional inputs, so the rule is testable without standing
up a subprocess run.

This composes with `task.maxEffort` on a separate axis: effort caps how
hard each request thinks, this caps how many requests a run may spend.

(cherry picked from commit f0db29f8f725f11390b64ca9342300c482ff5c5d)
2026-07-29 23:09:01 +02:00
can1357 d2283dd301 fix(model-registry): isolate modifier record mutations
(cherry picked from commit 3941103443576a6c8ab91a52e7da4ba1d8521d69)
2026-07-29 23:08:38 +02:00
Abhishek Sharma c7a113c9cb refactor(model-registry): derive projected catalog from an unprojected snapshot
The previous commits patched each rebuild path individually to avoid feeding a
modifyModels hook its own output. That left the invariant implicit and the
provider-scoped path applying only a subset of hooks, which is wrong for a hook
that inspects or suppresses another provider's models.

Keep #unprojectedModels as the canonical pre-projection catalog and derive
#models from it at every mutation point, so projections are always a pure
function of the unprojected base:

- #composeUnprojectedStaticModels builds the catalog; #composeStaticModels
  projects it. A scoped lookup with modifiers registered composes and projects
  the whole catalog before narrowing, matching getAll() followed by a filter.
  Providers without modifiers keep the cheap filtered path.
- Discovery completion, registerProvider, and runtime transport overrides
  update the unprojected snapshot and reproject, instead of mutating an
  already-projected array.
- Runtime metadata patches apply to the unprojected model, then reproject, so
  a later registration cannot discard them.
- Provider lookup snapshots are invalidated wherever the projection changes.

Hooks no longer take a providerFilter: a modifier is a whole-catalog transform
and every rebuild now runs the full ordered set exactly once.

(cherry picked from commit e5d2e9eac7c371cc196e9b362f77d3a5d7bdf507)
2026-07-29 23:08:37 +02:00
Abhishek Sharma e73ab518a0 fix(model-registry): scope registration-time projection to the new provider
registerProvider composed nextModels from the already-projected #models,
stripping only the incoming provider, then reran every stored modifier over
it. Loaders drain registrations one at a time, so the previously registered
provider's projection was fed back into its own hook — an append-style hook
compounded on each subsequent registration.

Apply only the incoming provider's hook. Every other provider's projection is
already present exactly once, and full rebuilds still go through
#composeStaticModels.

(cherry picked from commit b16db642b08cc223b062c0c556f00d46fda2520a)
2026-07-29 23:08:37 +02:00
Abhishek Sharma 88c8c13b6a fix(model-registry): log projection failures and rebuild unprojected before rerunning hooks
Review follow-up on two defects in the original change:

- The throwing-hook fallback wrote to #lastDiscoveryWarnings, which is only
  ever read to dedup a logger.warn inside #warnProviderDiscoveryFailure. No
  log line was emitted, so a broken extension degraded invisibly, and the
  shared key could mask a later discovery failure for the same provider. Log
  via logger.warn with its own dedup map.

- #refreshRuntimeDiscoveries starts from the already-projected #models, and
  the overlay merge only replaces matching provider+id pairs, so a hook's
  projection-only entries survived and were fed back into it. An append-style
  hook duplicated its output on every refresh. Drop each modifier provider
  before the merge so it re-seeds from the unprojected overlays.

(cherry picked from commit b6f841e080d4882a08b8d713de009461b6acc6fe)
2026-07-29 23:08:37 +02:00
Abhishek Sharma d10906c9a8 fix(model-registry): preserve oauth.modifyModels projection across reloads
`registerProvider` applies `oauth.modifyModels` once and assigns the result
straight to `#models`, but only the pre-projection definitions are persisted
in `#runtimeModelOverlays`. Any subsequent static reload rebuilds `#models`
from those overlays and silently drops the projection.

The model selector reloads on every open (`refresh("offline")`), so an
extension provider that projects a credential-aware catalog shows its
correct models everywhere except the picker — the one place users look.
`refreshProvider()` and online discovery completion had the same hole.

Persist the hook per provider and re-apply it wherever `#models` is
recomposed, honouring the `providerFilter` used by scoped lookups. A hook
that throws now degrades to that provider's unprojected catalog instead of
failing the whole composition, so one broken extension cannot empty the
registry.

(cherry picked from commit 33b7c72f225b4253b68bb71ecb3a9186151b18b3)
2026-07-29 23:08:37 +02:00
Nik Divjak 408f0d352f feat(tools): add a browser.cdpUrl setting for the default automation target
Attaching to a long-running browser (a signed-in profile, an Electron app kept
open for a session) meant repeating app.cdp_url on every browser call, and any
call that omitted it silently launched a fresh headless Chromium instead.

browser.cdpUrl supplies that endpoint once. It is a default rather than an
override: app.cdp_url and app.path still win, and an unset or blank value leaves
cmux and headless resolution exactly as before.
2026-07-29 11:28:26 +02:00
joshrzemien a5ee376a70 fix: celebrate unscheduled weekly Codex resets 2026-07-28 01:12:44 -04:00
joshrzemien 1ba1ddacab feat: add opt-in Codex reset fireworks 2026-07-28 00:33:53 -04:00
alexis@epsilver.xyz b58a943a8e fix(coding-agent): address second codex pass on vision mode
- read now derives its image behavior from actual tool availability
  (session.isToolActive) with the mode computation as fallback, so
  restricted sessions whose explicit slate omits inspect_image (e.g.
  subagents) never get metadata-only reads pointing at an absent tool
- reconcile passes the post-change availability into the read
  description sync, keeping the advertised prompt correct across flips
  in both directions and when tool construction fails
- flat quoted-dotted inspect_image.mode is normalized into the nested
  target during migration instead of being silently dropped when a
  legacy flat enabled key is present
- regression tests for all three: availability-driven read behavior,
  flat+flat migration, description advertising
2026-07-27 16:24:02 -04:00
alexis@epsilver.xyz 3854c1c3b1 fix(coding-agent): address codex review on vision mode
- Reconcile inspect_image centrally from setModelWithProviderSessionReset
  so retry-fallback model changes (turn-recovery.ts) that bypass
  syncAfterModelChange cannot leave a stale tool set
- Apply persisted inspect_image.mode changes immediately from the
  settings selector via a new handleSettingChange branch
- Refresh the read tool's advertised description during reconciliation,
  before applyActiveToolsByName rebuilds the prompt, instead of only
  lazily on the next image read
- Fix the flat (quoted-dotted) enabled->mode migration to write the
  nested target form the resolver actually reads
- Add committed regression tests: tri-state x capability matrix,
  override precedence, and enabled->mode migration (nested, flat, and
  explicit-mode-wins)
2026-07-27 16:24:02 -04:00
alexis@epsilver.xyz c33b98e260 feat(coding-agent): capability-aware inspect_image with tri-state mode and /vision toggle
Replace the inspect_image.enabled boolean with inspect_image.mode
(auto|on|off, default auto). In auto the tool is registered only when
the active model lacks native image input, so vision-capable models
(e.g. kimi-code/k3) read images inline with their own capabilities
instead of delegating to a separate vision model. on/off force
registration regardless of model capability.

- New utils/inspect-image-mode.ts resolves the effective state from the
  /vision session override, the persisted setting, and model capability
- read tool re-evaluates the effective state per image read and
  re-renders its description, so it returns decoded image blocks again
  whenever inspect_image is hidden
- /vision [on|off|auto|status] slash command (modeled on /computer)
  overrides the mode for the current session only
- Tool set is reconciled on model switch with a status notice when
  inspect_image appears/disappears
- Legacy inspect_image.enabled true/false migrates to mode on/off
2026-07-27 16:24:02 -04:00
can1357 d16a251777 chore: reorg tests 2026-07-27 16:43:53 +02:00
can1357 0327c776e0 Merge PR #6794: feat(task): add per-spawn effort ceiling (@wolfiesch) 2026-07-27 15:57:47 +02:00
can1357 c60b6971db feat(coding-agent): used static colon separator for working terminal title on windows
- Keep terminal working titles static with a colon separator on Windows instead of scheduling animated spinner updates.
- Update terminal title builder and state machine to check the platform and bypass timer intervals on win32.
2026-07-27 15:04:04 +02:00
Wolfgang Schoenberger bd1605e8f5 feat(task): add per-spawn effort ceiling 2026-07-27 03:39:55 -07:00
can1357 0388946e85 feat(coding-agent/task): added task.enableEffort setting to gate effort parameter
- Introduce task.enableEffort setting defaulting to false to hide per-spawn effort parameters.
- Conditionally include effort in single and batch task schemas and descriptions based on the new setting.
2026-07-27 07:01:09 +02:00
can1357 905fb283df Merge PR #6724: feat(live): add selectable voice setting (@roboomp) 2026-07-27 05:26:35 +02:00
can1357 e2ed58d4d5 Merge PR #4168: fix(inspect-image): bounded per-request timeout on the vision-model call (@roboomp)
# Conflicts:
#	packages/coding-agent/src/config/settings-schema.ts
2026-07-27 04:59:19 +02:00
can1357 73a3fe6983 Merge PR #6745: perf: lazily construct models config schema (@usr-bin-roygbiv) 2026-07-27 04:58:28 +02:00
can1357 4aa5d0b6b2 Merge PR #6726: fix(coding-agent): prevented invalid configs from being overwritten (@Ant39140) 2026-07-27 04:58:25 +02:00
Roy 54ae233ebc refactor(catalog): centralize provider cache IDs 2026-07-27 01:25:13 +00:00
usr-bin-roygbiv fc254b55f3 perf: defer models config schema construction 2026-07-27 01:10:23 +00:00
Roy ce79d59cd5 style(catalog): apply project formatting 2026-07-27 00:48:01 +00:00
Roy 773a0aee6d perf(catalog): materialize bundled models per provider 2026-07-27 00:43:15 +00:00