Commit Graph

43 Commits

Author SHA1 Message Date
can1357 eff714c750 Merge remote-tracking branch 'origin/farm/16f7ef23/ssh-helper-timeouts' 2026-07-02 23:43:11 +02:00
roboomp ec6c31a737 fix(tool): detected macos sshfs mounts without mountpoint
Added a macOS stat-device fallback for SSHFS mount detection so already-mounted remotes do not trigger a second sshfs invocation when mountpoint is unavailable.

Added a focused regression test and changelog entry.

Fixes #4319
2026-07-02 14:28:21 +00:00
roboomp 08899a4392 fix(ssh): bound pre-command SSH helpers with ptree.exec timeout
runSshSync and runSshCaptureSync in connection-manager.ts invoked ssh
through the Bun shell with .quiet().nothrow() but no timeout and no
abort signal. They sit on the ensureHostInfo -> probeHostInfo /
ensureConnection path that runs *before* SshTool.execute applies the
user-supplied command timeout, so an unreachable host or wedged
control-master hung the tool forever.

Switch both helpers to ptree.exec with a 30s timeout,
allowNonZero: true, allowAbort: true, and stderr: "full". The
timeout is a parameter (default 30_000) so tests can override with a
short bound; both helpers still return their existing failure-result
shape (exitCode / stdout / stderr), so ensureConnection can surface a
'Failed to start SSH master ...' error instead of blocking.

Add a regression test that stages a fake ssh binary trapping SIGTERM
and sleeping 300s, then confirms both helpers return within a bounded
window with a non-zero exit code.

Fixes #4232
2026-07-02 08:32:52 +00:00
roboomp f16d618ca2 fix(ssh): recover transferShell when host marker probe fails
When csh/tcsh aborts the initial host-info marker probe before emitting
PI_HOST_PROBE=, the previous fallback returned os/shell unknown without
ever checking whether sh -lc still worked. That kept ssh:// rejecting a
POSIX-capable host (P2 from PR #3722 review).

The marker-missing fallback now runs probeTransferShell before returning.
If sh/bash/zsh round-trips the transfer marker, the fallback carries
transferShell and derives os from that probe's uname -s output. Windows
compat unames (MINGW/MSYS/Cygwin/Windows) still classify as windows so
ssh:// keeps refusing Windows hosts.

Added osFromUname coverage for Linux, GNU/Linux, Darwin, Windows compat
unames, and unknown payloads.
2026-06-28 12:01:49 +00:00
roboomp 7b937104bd fix(ssh): scan stderr for the transfer-shell marker too
The host-info probe already recovers its marker from stderr (some
remotes have dotfiles that swap fd 1/2), but `probeTransferShell` only
scanned `probe.stdout`. That left `transferShell` unset on those
hosts and made `ssh://` refuse a POSIX-capable remote (P2 from PR
#3722 review).

Extracted the both-streams scan into `findProbeMarker(stdout, stderr,
marker)` and routed the transfer probe through it: stdout first,
stderr as the rescue. Same recovery contract as the host probe.

`TRANSFER_PROBE_MARKER` exported alongside `findProbeMarker` so the
recovery branch is unit-testable without touching disk.

Tests: covers stdout-only, stderr-only, both-streams-prefer-stdout,
and neither-stream.
2026-06-28 11:57:49 +00:00
roboomp 207734e915 fix(ssh): dispatch transfer snippets through verified transferShell
The previous fix gated on a verified `transferShell` but still let
OpenSSH hand the snippet to whatever `$SHELL` happens to be on the
remote. On a fish/csh/tcsh host the new gate would accept the host,
then fail anyway because the login shell can't parse `if [ ... ]; then
...` (P1 from PR #3722 review).

Each transfer command (read, write, stat, list) is now wrapped in
`<transferShell> -c '...'` via a shared `wrapInPosixShell` helper, so
the snippet is parsed by the same shell OMP's capability probe verified
can run it. `ensurePosixRemote` returns the verified shell so each
call site can do the wrap. `ssh-executor.ts`'s identical Windows-compat
helper is consolidated onto the same primitive (`buildCompatCommand` /
`quoteForCompatShell` removed).

Stays POSIX-clean across all four call sites; `-c` (not `-lc`) since
the snippets only call absolute builtins and don't need login-profile
setup. Capability *probing* still uses `-lc` to mirror the user env.

Test additions: one case asserts every dispatch starts with
`bash -c '...'` and embeds the original POSIX snippet (read/write/stat/list)
when transferShell is bash and login shell is unknown; another covers
the `sh -c` happy path.
2026-06-28 11:52:44 +00:00
roboomp c4ed1614eb fix(ssh): gate ssh:// transfers on verified POSIX shell capability
Replace the login-shell-name allowlist in `ensurePosixRemote` with a
capability check against a newly probed `transferShell`. The host probe
runs `sh -lc` / `bash -lc` / `zsh -lc` against the remote and records
the first candidate whose printf marker round-trips; `uname -s` from the
same probe also refines the OS classification when the first probe could
not resolve it.

Three compounding problems fixed:

- The host probe parsed only the first stdout line, so login-shell
  banners or any startup noise would land ahead of the payload and
  classify the host as `shell: "unknown"`. The probe now frames its
  payload with a `PI_HOST_PROBE=` marker (see `extractProbePayload`)
  and scans both streams for the marker line.
- `shouldRefreshHostInfo` did not treat `{os: "linux", shell: "unknown"}`
  as stale, so a single bad classification stuck and kept failing
  later `ssh://` operations. It now refreshes any non-Windows cache
  entry without a verified `transferShell`.
- The transfer guard refused the host on the self-reported login-shell
  name. It now gates on `info.transferShell`, which is the shell OMP
  actually verified can run `head`/`cat`/`mv`/`test`/`ls`. The
  refusal message names the capability we couldn't confirm.

`HOST_INFO_VERSION` bumped 3 → 4 so existing caches re-probe and pick
up `transferShell`. `parseHostInfo` exported so the cache round-trip
of `transferShell` is testable without touching disk.

Fixes #3719
2026-06-28 11:45:25 +00:00
Tommaso Fontana dfd0fe3cfa fix(omp): reject ssh:// query/fragment and non-POSIX login shells (#3553 review)
remotePathFromUrl now rejects a URL query string or fragment, so a mistyped ssh://host/tmp/a?draft no longer silently operates on /tmp/a; a literal ?/# in a remote filename must be percent-encoded (%3F/%23).

ssh:// transfers now require a sh/bash/zsh login shell. fish can't parse the POSIX transfer snippets and csh/tcsh apply ! history expansion to the command line, so they're refused (use the ssh tool). Host-shell detection no longer misclassifies fish/csh/tcsh as sh (basename allowlist over endsWith), and HOST_INFO_VERSION is bumped to re-probe caches that stored the old classification.
2026-06-26 23:01:49 +02:00
Tommaso Fontana 8ad45254c6 fix(omp): use portable dirname in ssh write staging (#3553 review)
dirname is an operand-only POSIX utility (no options), so 'dirname -- "$t"' is non-portable on macOS/BSD (the -- is treated as an operand). The temp path is always absolute, so the end-of-options guard is unnecessary; drop it. mkdir -p -- stays (mkdir conforms to the Utility Syntax Guidelines and supports --).
2026-06-26 20:41:36 +02:00
Tommaso Fontana 3117f69627 fix(omp): search >4MiB virtual resources + reject trailing-slash ssh writes (#3553 review)
- search: native grep silently skips files above NATIVE_GREP_MAX_FILE_BYTES (4 MiB), so the RE2 virtual path dropped matches for large virtual resources (history://, big artifacts). searchVirtualResources now falls back to a JS RegExp matcher for oversized content (the pre-RE2 behavior) while keeping native parity for normal sizes; buildVirtualMatches still rebuilds context/ranges.
- ssh write: a trailing-slash target (ssh://h/dir/) is now rejected before staging, so the mkdir -p parent-creation no longer leaves a directory behind on a refused write.
2026-06-26 20:41:36 +02:00
Tommaso Fontana ff756807f7 fix(omp): ranged virtual search cap + ssh write parent dirs (#3553 review)
- search: the native virtual probe capped matched-line detection at INTERNAL_TOTAL_CAP before range filtering, so a ranged virtual selector (ssh://h/log:5000-5100) over a file with >2000 earlier matches returned nothing. The probe now uses the line-count bound for ranged resources so range filtering sees every hit.
- ssh write: writeRemoteFile staged into a temp beside the destination before creating parents, so writing a new nested path failed with 'No such file or directory'. It now mkdir -p's the parent before staging, matching local write, keeping the directory/special-file refusal checks.
2026-06-26 20:41:36 +02:00
Tommaso Fontana e4ceebb258 feat(omp): list ssh:// directories via read
- `read ssh://host/dir` lists a remote directory one level deep; `ssh://host/` lists the remote root
- add statRemotePath + listRemoteDir; resolve reads first and classifies on error (directory -> one-level listing, dirs-first, dotfiles included)
- directory resources carry isDirectory + immutable and expose no sourcePath
- search refuses a virtual (no-sourcePath) directory resource instead of grepping the listing text
- writeRemoteFile refuses a directory destination and cleans up its temp on that path
2026-06-26 20:41:35 +02:00
Tommaso Fontana f9ece90853 fix(omp): harden ssh:// URL handler per PR review
- buildSshTarget rejects destinations beginning with "-" (SSH argument-injection / local RCE guard)
- gate ssh:// read/search/write at the exec approval tier; substring scan covers search's pre-expansion delimited paths and write's hashline-wrapped paths
- validate the entire materialized buffer as UTF-8 instead of only the first 8 KiB prefix
- write peels read selectors (raw/conflicts) so it targets the same file read does, and rejects line-range/malformed selectors instead of silently stripping them
- write to a uniquely named remote temp; document symlink-replacement on write as a v1 limit
2026-06-26 20:41:35 +02:00
Tommaso Fontana c63171b909 feat(omp): add ssh:// URL support to read, search, and write 2026-06-26 20:41:35 +02:00
roboomp d2bc4b02d2 fix(coding-agent): preserved windows ssh key stat checks
Kept missing-file and directory identity validation on Windows while skipping only the Unix mode-bit rejection.

Added regression tests for Windows missing and directory identity paths.

Fixes #2850
2026-06-17 12:24:19 +02:00
roboomp 1b202c9f14 fix(coding-agent): skipped windows ssh key mode check
Skipped Unix mode-bit validation for ssh identity files on native Windows while preserving the stricter check for Unix-like platforms.

Added regression coverage for Windows ssh argument building with permissive low mode bits and for Unix rejection of group/world-readable keys.

Fixes #2850
2026-06-17 12:24:19 +02:00
can1357 f2137becb8 fix: fixed prompt parsing, startup tracing, and help-command behavior
- Fixed help rendering so `--help` no longer triggers unrelated command loaders.
- Fixed startup span logging to emit markers only with PI_DEBUG_STARTUP set.
- Fixed logger startup trace behavior for `:start`, `:done`, and `:fail` phases.
- Fixed prompt template processing with cached raw-template compilation and safer formatting.
- Optimized symbol and tag parsing in prompt templates via manual parsers.
2026-06-10 02:17:35 +02:00
roboomp 80a47a8329 fix(ssh): report abort after process exit
Preserve cancellation semantics when a user interrupt unblocks SSH stream drains after the mux client already exited.

Fixes #2180
2026-06-09 09:54:15 +00:00
roboomp daee87f00e fix(ssh): cancelled controlmaster stream waits
Return promptly when the ssh executor receives a user interrupt while ControlMaster-owned streams remain open.

Fixes #2180
2026-06-09 09:46:52 +00:00
Gerben Meijer 694f5e9a54 Refresh SSH hosts without restart 2026-05-16 00:20:00 +02:00
can1357 28b9ce7a0c feat(coding-agent): added middle-elision caps to OutputSink truncation
- Added `tools.artifactHeadBytes` and `tools.outputMaxColumns` settings with defaults in `SETTINGS_SCHEMA`.
- Expanded `OutputSink` with `headBytes`/`maxColumns` and middle truncate logic with elision markers and tracking.
- Updated output-meta to resolve sink settings, emit truncation metrics, and use `truncateMiddle` for spills.
- Integrated head and column limits into JS/Python/Bash/SSH/read output flows, with `:raw` skipping read truncation.
- Documented new output middle-elision and column-cap behavior in `CHANGELOG.md`.
- Added truncation tests for `OutputSink`, `truncateMiddle`, and read-tool line handling.
2026-05-13 11:19:11 +02:00
jiwangyihao 375ef060a7 fix(coding-agent): avoid SSH ControlMaster on Windows 2026-05-11 12:36:55 +08:00
Gerben Meijer b8f5a3d890 fix(coding-agent): hash SSH control sockets by connection 2026-05-02 17:14:18 +02:00
can1357 6d07944654 refactor: migrated binary detection to $which() utility across codebase
- Replaced all Bun.which() calls with $which() utility from @oh-my-pi/pi-utils across 22 files.
- Removed findBashOnPath() wrapper function from procmgr.ts, consolidating binary path resolution.
- Updated AGENTS.md documentation to reflect new $which() API usage pattern.
- Centralized binary detection logic through shared utility, reducing code duplication.
2026-04-08 05:28:22 +02:00
can1357 334b47094f fix: ssh conn to not trigger mux/channel-open failures
Fixes #154
2026-02-26 11:54:08 +01:00
can1357 fb150a9e39 fix(coding-agent): redirect ssh stdin to avoid mux fd errors
Fixes #154.
2026-02-24 02:59:42 +01:00
can1357 a83175c94c refactor: migrated imports to unified package root and consolidated skill discovery logic
- Consolidated @oh-my-pi/pi-utils subpath imports into single package root import across 100+ files.
- Moved tryParseJson utility from local web scrapers module to @oh-my-pi/pi-utils package for centralized JSON parsing.
- Renamed loadSkillsFromDir to scanSkillsFromDir and refactored skill discovery to use fs.promises.readdir instead of glob-based approach.
- Replaced custom parseJSON with tryParseJson across discovery modules for consistent error handling.
- Removed emitCustomToolSessionEvent method and cleanupSshResources function, consolidating shutdown logic into dispose method.
- Updated glob pattern construction to use GlobBuilder with literal_separator(true) for improved path handling.
2026-02-23 20:59:17 +01:00
can1357 abf8c1efc9 refactor: unslop common utilities 2026-02-22 11:01:11 +01:00
can1357 e41ebe61ec feat(coding-agent): added SSH host management with CLI and slash commands
- Added SSH host management feature with `ssh` CLI command and `/ssh` slash command for add, list, and remove operations.
- Added SSH configuration support at project (.omp/ssh.json) and user (~/.omp/agent/ssh.json) scopes with host discovery from project files.
- Added SSH host configuration flags: --host, --user, --port, --key, --desc, --compat, and --scope for flexible host setup.
- Removed automatic line relocation on stale hash references; now fails with error instead.
2026-02-19 12:52:43 +01:00
can1357 fcd7ff4f84 refactor(dirs): centralized directory path utilities into @oh-my-pi/pi-utils/dirs module
- Extracted directory path utilities from multiple packages into a centralized '@oh-my-pi/pi-utils/dirs' module.
- Moved 30+ path helper functions (getAgentDir, getConfigRootDir, getPluginsDir, getMCPConfigPath, etc.) from scattered locations into a single shared utility module.
- Consolidated APP_NAME, CONFIG_DIR_NAME, and VERSION constants into the centralized dirs module for reuse across packages.
- Updated 70+ import statements across packages/ai, packages/coding-agent, packages/stats, and packages/tui to use the new centralized module.
- Removed local path construction logic and replaced with utility function calls for improved maintainability and consistency.
- Deleted packages/coding-agent/src/extensibility/plugins/paths.ts as its functions were moved to the centralized dirs module.
2026-02-13 15:06:05 +01:00
can1357 acf8ab5225 style: stylistic changes 2026-02-10 07:39:39 +01:00
can1357 16ed34ebed feat(utils): refactored stderr handling API from boolean option to enum-like option
- Changed stderr handling API from `exposeStderr` boolean option to `stderr: "full" | null` enum-like option for clearer intent.
- Refactored ChildProcess constructor to accept stderr parameter directly instead of options object for simpler API.
2026-02-05 11:07:48 +01:00
can1357 1f7c4f6f90 refactor(stream-parsing): restructured stream utilities to use Web standard APIs and generic SSE parsing
- Refactored SSE stream parsing to use generic `readSseJson` utility instead of domain-specific handlers across multiple packages.
- Migrated from Node.js Buffer API to Web standard APIs (Uint8Array, TextDecoder, DataView) for cross-platform compatibility.
- Simplified stream transformation pipeline by consolidating multiple stream operations into unified `createTextLineSplitter` utility.
- Refactored `ptree.ts` to remove complex stream pumping infrastructure and simplify stderr handling with direct async iteration.
- Rewrote stream utilities to operate at binary level with byte-level parsing for improved efficiency and reduced string allocations.
- Updated TypeScript configuration to include DOM.AsyncIterable type definitions for async iterable DOM API support.
2026-02-05 10:59:47 +01:00
can1357 ec801665bc refactor(env): migrated environment variables from OMP_ to PI_ prefix and centralized access via getEnv()
- Migrated environment variable access from direct process.env to centralized getEnv() utility function across all packages.
- Renamed environment variable prefix from OMP_ to PI_ throughout codebase (e.g., OMP_CODING_AGENT_DIR -> PI_CODING_AGENT_DIR).
- Removed automatic environment variable migration from PI_ to OMP_ prefixes via migrate-env.ts module.
- Removed env setting from configuration schema and applyEnvironmentVariables() method from settings.
- Updated CI/CD build configuration to use PI_COMPILED flag instead of OMP_COMPILED.
- Changed venvPath property in PythonRuntime from nullable (string | null) to optional (string | undefined).
2026-02-05 02:55:01 +01:00
can1357 6260ad6216 refactor(pi-utils): simplified ptree API and consolidated spawn variants into single function
- Simplified ptree API by removing spawnGroup and spawnAttached variants, consolidating into single spawn function.
- Replaced AsyncQueue class with simpler pushStream utility function for stream management.
- Refactored ChildProcess class to use AbortController instead of callback-based signal handling.
- Renamed captureText method to wait and execText function to exec for clearer API semantics.
- Removed mode parameter from exec function, eliminating distinction between spawn modes.
- Updated all call sites across coding-agent to use simplified ptree API.
2026-01-28 23:49:15 +01:00
can1357 6db649c9ed feat(coding-agent): added configurable ask timeout/notifications and centralized process execution
- Added configurable ask timeout and notification settings to control ask tool behavior and user notifications.
- Added AskSettings interface with timeout (in seconds, default 30) and notification method properties to settings manager.
- Added ask timeout and notification configuration options to settings UI with values for timeout (off, 15, 30, 60, 120 seconds) and notification methods (auto, bell, osc99, osc9, off).
- Refactored process execution across multiple tools (exec, fetch, grep, read, youtube scraper) to use centralized ptree.execText() API instead of custom implementations.
- Refactored ChildProcess class in ptree to use public readonly properties and Promise.withResolvers() for cleaner exit handling.
2026-01-28 22:27:07 +01:00
can1357 c22a1025ef refactor(pi-utils): migrated process spawning from cspawn to spawnGroup/spawnAttached with async resource management
- Migrated process spawning from `cspawn` to `spawnGroup` and `spawnAttached` APIs with explicit resource management using TypeScript's `using` statement.
- Refactored `ChildProcess` class to support process group management with new `isProcessGroup` getter and `[Symbol.dispose]()` method for automatic cleanup.
- Removed `cspawn` from public API exports in pi-utils, replacing it with `spawnGroup` and `spawnAttached` functions.
- Simplified `ChildProcess.kill()` method signature by removing signal parameter and eliminated `killAndWait()` method in favor of async disposable pattern.
- Converted `killChild` function to async implementation using Bun's `$` template and sleep-based polling for process termination.
2026-01-28 21:12:28 +01:00
can1357 779ca4872b style(deps): migrated from Prettier to Biome and updated formatting rules
- Removed Prettier configuration files (.prettierignore and .prettierrc) and migrated formatting to Biome.
- Updated Biome configuration from version 2.3.11 to 2.3.12 and changed arrowParentheses rule from 'always' to 'asNeeded'.
- Pinned @biomejs/biome dependency to exact version 2.3.12 in package.json and bun.lock.
- Applied consistent arrow function formatting across 489 files by removing unnecessary parentheses around single parameters.
- Removed blank lines after comment blocks and reorganized imports for consistency across the codebase.
2026-01-24 04:20:19 +01:00
can1357 51d39e7eea refactor(imports): migrated node module imports to namespace imports
- Converted named imports from node modules (fs, path, os) to namespace imports across all packages.
- Extended extension loader error handling with isEacces and hasFsCode type guards.
2026-01-24 03:37:59 +01:00
can1357 e22d123009 refactor(fs): migrated remaining sync file operations to async
- Converted readdirSync, readFileSync, and statSync to async readdir, readFile, stat across skills and agent discovery.
- Made scanDirectoryForSkills async and refactored custom directory scanning to use Promise.all for concurrent processing.
- Updated agent discovery to use fs/promises for async file reading and refactored helper patterns.
- Added AgentParsingError exception class for better error handling during agent parsing.
- Added filesystem error type guards (isEnoent, isEacces, isPerm, etc.) to pi-utils for safe error checking.
- Added color manipulation utilities to pi-utils for accessibility features.
- Added color-blind mode setting to settings manager.
- Migrated plugins, settings, and config modules from sync to async file operations.
- Updated error handling to use new pi-utils type guards for type-safe checking.
2026-01-24 03:18:03 +01:00
can1357 f66e5dba9b build(config): refactored build and TypeScript configuration with Bun loaders
- Removed WASM generation script; use Bun `wasm?raw` loader for imports.
- Added bunfig.toml with loaders for `.md`, `.py`, and `.wasm?raw` text imports.
- Added types/assets/index.d.ts for global TypeScript module declarations.
- Unified TypeScript configuration with tsgo-based checking across monorepo.
- Removed build and WASM steps from install and publish pipelines.
2026-01-24 00:03:52 +01:00
can1357 0fe761dc4b build(deps): refactored TypeScript and package configuration across monorepo
- Added tsconfig.publish.json files to all packages with optimized publish-time configuration.
- Updated all package.json scripts with prepublishOnly hooks for correct type checking during publish.
- Added @oh-my-pi/omp-stats path mappings to root tsconfig.json for consistent imports.
- Added WASM generation script for photon module and integrated into install:dev script.
2026-01-23 13:46:06 +01:00
can1357 cb5bbbf382 refactor(coding-agent): flattened directory structure, eliminated core/ folder
- Eliminated core/ directory (252 files, 23 subdirs → distributed)
- Reduced max nesting from 9 levels to 5 levels
- Promoted tool subdirs to top level: exa/, lsp/, patch/, task/, web/
- Merged web-scrapers/ + web-search/ into web/{scrapers,search}/
- Flattened modes/interactive/ to modes/
- Split execution/ into: ipy/ (python), exec/ (bash), ssh/
- Renamed ipy/python-*.ts to ipy/*.ts (executor, kernel, etc.)
- Flattened cursor/exec-bridge.ts to cursor.ts
- Created logical groupings: config/, session/, extensibility/, export/
- Updated all imports across 500+ files
2026-01-23 12:24:47 +01:00