Commit Graph
2668 Commits
Author SHA1 Message Date
omp-evalandcan1357 24e0497574 fix(tui): treat dot-relative anchors as multi-path signals in whole-path fallback
Codex review flagged that /tmp/a.png ./b shot.png slipped past the
interior-anchor guard (absolute prefixes only) and fused into one bogus
attach that swallows the paste. Add ./, ../ and .\ as second-path
anchors; bare relatives (dir/b shot.png) stay recoverable because an
interior token/ after a space is exactly the shape of a spaced
directory name (/Users/me/My Photos/shot 1.png). 4 tests pin both
sides of the boundary.
2026-07-26 15:45:31 +02:00
can1357 9000ab0ab3 Merge PR #6582: fix(tui): attach drag-dropped image paths with unescaped spaces (@rcbran) 2026-07-26 15:45:31 +02:00
can1357 87c0aa38bb Merge PR #6558: fix(tui): make provider error blocks expandable via ctrl+o (@roboomp) 2026-07-26 15:45:10 +02:00
can1357 60b0968e1f Merge PR #6484: fix(coding-agent): resume agent after /tree ask re-answer (@roboomp) 2026-07-26 15:41:31 +02:00
can1357 525173615c Merge PR #6500: fix(coding-agent): count only rendered skills in /context accounting (@roboomp) 2026-07-26 15:41:30 +02:00
can1357 0a83d9f364 Merge PR #6570: fix(plan-mode): prefer newest draft during review (@roboomp) 2026-07-26 15:41:30 +02:00
can1357 1ebe2cc63a Merge PR #6608: fix(coding-agent): handle vibe session commands safely (@roboomp) 2026-07-26 15:41:30 +02:00
can1357 a0f03309a9 Merge PR #6588: fix(cli): redact credential settings in config list (@wolfiesch) 2026-07-26 15:41:29 +02:00
can1357 0e3f695a56 Merge PR #6701: fix(coding-agent): stop the live advisor runtime when /settings disables it (@paolomazzitti) 2026-07-26 15:41:28 +02:00
Diogo Soares Rodrigues c7c375f5e1 fix(cursor): settle todo cards whose completion outruns the streamed block
When Cursor packs toolCallStarted and toolCallCompleted into one HTTP/2
chunk, the bridge tool_execution_end (synchronous callback, fired
mid-parse) reaches the interactive controller before the streamed
toolcall_start (queued on AssistantMessageEventStream, delivered a
microtask later). The controller found no pendingTools entry, dropped
the completion, and the card created afterwards animated forever.

Two halves, each necessary:

- Hold an early todo completion in #orphanedToolCompletions and replay
  it when the streamed block creates its component.
- Guard card creation from cumulative message_update frames with the
  turn-scoped #toolTimelineComponents map. Without this, the update
  after the replay re-lists the same toolCall block, finds pendingTools
  empty again, and spawns a second, permanently pending card. This is
  also why emitting a synthetic tool_execution_start from the bridge
  (previous attempt, reverted) could not work.

Both maps are cleared together at the existing transcript-anchor reset
sites. The normal ordering (start first) is covered by a control test.
2026-07-26 09:29:13 -03:00
Diogo Soares Rodrigues cc210094ef fix(cursor): refuse todo dependency graphs and sanitize failure text
Two review findings on the native todo sync.

- TodoItem.dependencies is a graph the local model cannot store: rows
  are keyed by content, carry no id, and hold no edges. An imported
  dependent row files as plain pending and nextActionableTask then
  offers work the server considers blocked. Refuse snapshots with an
  edge pointing at an unfinished row; edges whose blockers already
  finished constrain nothing and still mirror.

- The todo failure warning interpolated the provider error verbatim.
  Collapse and truncate it at the render boundary.

Also documents two known, unfixed defects: an async cursorOnToolResult
transformer resolving after the buffer drain, and the todo card
lifecycle race. Emitting a synthetic tool_execution_start for the
latter was measured and rejected -- the completion deletes the entry it
creates, so the late streamed block adds a second card.
2026-07-26 09:29:13 -03:00
Paolo Mazzitti 81bc0d4368 fix(coding-agent): stop the live advisor runtime when /settings disables it
Disabling the Advisor from /settings persisted the setting but left the
live Advisor runtime running until the session restarted.
SelectorController.handleSettingChange had no case for "advisor.enabled",
unlike other session-managed toggles (autoCompact, steeringMode, ...), so
the change never reached session.setAdvisorEnabled — the same call /advisor
off already uses to stop the runtime immediately.
2026-07-26 12:25:19 +00:00
Wolfgang Schoenberger 914afc0d6c fix(cli): redact credential settings in config list
omp config list printed every configured value, including auth.broker.token,
searxng.token, searxng.basicPassword and dev.autoqaPush.token, in both the
human and --json output. Nobody asked for those specific credentials; the
command dumps everything.

Credentials are marked with a top-level credential flag rather than ui.secret,
because four of them have no settings-panel entry and so have nowhere to put a
UI-level flag. isCredential is the single accessor both the CLI and the panel
consult, so the two spellings cannot produce different behaviour on different
surfaces.

Human output shows dots. JSON omits value and marks the entry redacted instead
of substituting a placeholder, which a consumer could not distinguish from a
real value and might write back.

config get <path> is deliberately unchanged: that is an explicit request for a
single value, and masking it would break a retrieval API with no way to read
your own token back.
2026-07-26 02:58:38 -07:00
roboomp bac71f4654 fix(coding-agent): stopped blocked vibe reset loops
Disable reset-mode loops when vibe mode prevents the required session transition, so the prompt is not resubmitted into the unchanged session.

Added focused regression coverage for the blocked transition.

Fixes #6607
2026-07-25 12:05:54 +00:00
roboomp c8ef3cc8ff fix(coding-agent): handled vibe session commands safely
Blocked interactive session transitions before they reach the AgentSession vibe guard, preserving the active session and rendering the existing exit-vibe warning instead of rejecting the input callback.

Added regression coverage for new, drop, fork, and move transitions.

Fixes #6607
2026-07-25 11:57:53 +00:00
RC Branham f15e3aa897 fix(tui): keep multi-file pastes out of the whole-path fallback
The whole-text-as-path fallback added in the previous commit claimed any
single-line payload starting with an absolute-path anchor, including one
holding several paths. Dragging two files at once emits
`/tmp/a.png /tmp/b shot.png`, which the segment splitter also refuses
because `shot.png` is not explicit, so the fallback fused the pair into
one unresolvable path. `handleImagePathPaste`'s ENOENT branch only
surfaces a status and — unlike its too-large and generic-error branches
— never re-pastes the text, so both paths vanished.

On `main` the bracketed route returned undefined for that payload and
fell through to a text paste, so this was a regression introduced by the
previous commit rather than behavior inherited from the clipboard route.
It is reachable by the same gesture that motivated #6578, with one more
file selected: macOS screenshot names always contain spaces.

`extractWholeTextImagePath` now rejects payloads carrying a second
absolute-path anchor after unescaped whitespace. The anchor alternation
moves into a shared `ABSOLUTE_PATH_PREFIX_SOURCE` so the leading-anchor
and second-anchor tests cannot drift apart across the POSIX, `~/`,
`file://`, UNC and Windows-drive families. Escaped whitespace is exempt,
since the escape is the terminal asserting the space belongs to the path.

Guarding the shared helper rather than the bracketed caller also settles
`extractImagePathFromText`, whose JSDoc already claimed multi-path text
falls through to a text paste while the fallback leaked around it.

Ambiguous input — a directory whose name ends in a space, as in
`/tmp/odd dir /sub/x.png` — is treated as multi-path and pastes as text:
a text paste loses nothing, a bogus attach loses everything.

11 tests added covering each anchor family, tab separation, the
escaped-space exemption and the unchanged splitter-success path.
2026-07-25 03:48:12 -04:00
RC Branham 178af71d3e fix(tui): attach drag-dropped image paths with unescaped spaces
The bracketed-paste (drag-drop) image route required every whitespace-split
segment to look path-like, so a raw macOS screenshot path (spaces unescaped,
per the attachment convention terminals implement) degraded to literal text.
Extract the keybind route's whole-text-as-path pass into a shared helper and
apply it when the segment splitter fails; route the bracketed extractor
through the stripped-marker one so both share identical detection.

Fixes #6578
2026-07-25 01:26:14 -04:00
roboomp 28068f53d3 fix(plan-mode): promoted reviewed plan path into state before refine
handlePlanApproval and the ACP rejection path selected a resolved draft that could differ from PlanModeState.planFilePath but never updated the state, so a refine turn was rebuilt by #buildPlanModeMessage() from the stale path. Both paths now promote the reviewed path into plan-mode state.

Fixes #6569
2026-07-25 01:51:52 +00:00
roboomp a04b315eb2 fix(tui): expand pinned provider errors inline on ctrl+o
While a provider error is pinned in the banner above the editor the inline transcript block is suppressed, so the prior guard skipped re-rendering on Ctrl+O and the full body stayed unreachable until the next turn.

- Track whether the message carries a truncatable error regardless of pinning, so setExpanded re-renders while pinned.
- Render the inline error block in full when expanded even while pinned; keep it suppressed only while pinned and collapsed.
- Disable the streaming fast path whenever the inline error block is drawn.

Fixes #6555
2026-07-25 00:40:23 +00:00
roboomp 62d8b0d3ad fix(tui): initialized provider errors from expand state
New live, rebuilt, and transcript-builder assistant components now inherit the active tool-output expansion state before provider errors render.

Added regression coverage for an error arriving after expanded mode was already enabled.

Fixes #6555
2026-07-25 00:32:52 +00:00
roboomp 104c3ad218 fix(tui): make provider error blocks expandable via ctrl+o
Turn-ending provider errors rendered inline through
AssistantMessageComponent#appendErrorBlock, capped at 8 lines with no
setExpanded method, so isExpandable filtered the component out of the
Ctrl+O tool-output expansion and the truncated tail was unreachable in
the live TUI (full text was persisted but not shown).

- Add setExpanded to AssistantMessageComponent; when expanded the error
  block renders the full body (tabs replaced, blank lines preserved,
  Text word-wraps to width).
- Collapsed view appends a dim "+N more lines (Ctrl+O to expand)" hint so
  the truncation and its remedy are discoverable.
- Only re-render on toggle when the last render produced a truncatable
  error block, so expansion skips ordinary turns.

Fixes #6555
2026-07-25 00:26:40 +00:00
can1357 3c80e6f9cd fix(coding-agent): expose live tool rebuild options 2026-07-24 16:29:27 +02:00
can1357 68e76c6243 fix(coding-agent): preserve shared live tools across rebuilds 2026-07-24 16:26:59 +02:00
can1357 2bc26d3d4c Merge PR #6519: fix(coding-agent): avoid duplicate tools in transcript rebuilds (@roboomp) 2026-07-24 16:26:42 +02:00
roboomp 484fa319eb fix(coding-agent): keep running async task handles during rebuild dedup
The rebuild dedup dropped any preserved pendingTools component whose toolCallId
had a persisted toolResult. A background task's initial async.state=="running"
result is persisted while EventController#handleToolExecutionEnd deliberately
keeps its component in pendingTools so a later tool_execution_update/_end can
settle it. Dropping that still-live handle stranded those updates on the running
snapshot. Only terminal results are now owned by the replay; running async
handles stay preserved. Added a regression covering the running-task case.
2026-07-24 13:53:43 +00:00
roboomp 759e551e8c fix(coding-agent): dropped resolved tools from mid-stream rebuild preservation
rebuildChatFromMessages preserves the live pendingTools components across its
clear+replay so streaming keeps routing into them. That preservation assumed
every pending-tool component was still dangling (its result outside
state.messages). Once a tool's result had landed in the session entries while
its component still lingered in pendingTools (a rebuild racing the
tool-completion event, or a background/displaceable snapshot), the replay
reconstructed the completed block from the persisted toolResult AND the
preserved live component was re-appended, so the same tool block rendered twice.

Resolved tool calls are now dropped from the preserved live set and owned by the
replay; only genuinely in-flight (dangling, replay-stripped) calls are preserved.

Fixes #6516
2026-07-24 13:40:57 +00:00
can1357 de00e7f136 feat(tui): renamed large-paste local refs to paste-N.md
- Large-paste menu now saves pastes as local://paste-N.md instead of
  local://attachment-N, giving the artifact a markdown extension and a
  clearer name.
2026-07-24 12:25:40 +02:00
roboomp e9ae836a46 fix(coding-agent): count only rendered skills in /context accounting
computeNonMessageBreakdown estimated Skills tokens from the unfiltered
session.skills registry and subtracted that from the first system-prompt
block, which only ever contained the rendered (filtered) skills. Hidden
explicit-only skills (hide/disable-model-invocation) and all skills when
the read tool was absent inflated Skills and clamped System prompt to 0.

Add a renderedSkills helper mirroring buildSystemPrompt's filter and use
it for the Skills estimate so the category split matches the provider
prompt.

Fixes #6498
2026-07-24 09:21:58 +00:00
can1357 17735c7786 feat: added x-oai-attestation header for ChatGPT-OAuth Codex requests
- Add `CodexAttestationProvider` hook and `getCodexAttestationHeader` resolver that gates on ChatGPT-OAuth credentials.
- Integrate attestation into WebSocket transport, SSE event stream, and OpenAI compaction requests.
- Wire `setCodexAttestationProvider(generateCodexAttestation)` in model-registry init for OAuth sessions.
2026-07-24 09:17:00 +02:00
can1357 c1d4e38aa6 feat(coding-agent): added live session delegation with turn-based transcript display
- Added `LIVE_DELEGATION_MESSAGE_TYPE` constant and delegation message handling for voice sessions.
- Implemented turn-based transcript coalescing with user and assistant turn counters.
- Added transcript display row with normalized rendering in the live visualizer.
- Refactored controller to send delegation messages via `sendCustomMessage` with configurable frame styling.
- Removed microphone permission error reporting from silence detection logic.
2026-07-24 09:16:50 +02:00
can1357 c9c0882724 feat(audio): replaced Chromium browser audio with native audio stack
- Switched from `miniaudio` to `maudio` Rust crate and added `AudioCapture` and `AudioPlayback` native classes.
- Removed browser-side audio infrastructure including Web Audio API, audio worklet processor, and WebRTC runtime.
- Migrated STT recorder and transcriber modules to use native `AudioCapture` with callback-based streaming.
- Replaced streaming audio player with native `AudioPlayback` that writes PCM directly without TypeScript intermediaries.
- Removed ffmpeg, wav, and platform-specific playback commands from the audio toolchain.
2026-07-24 08:54:16 +02:00
can1357 75cc0a054f feat(coding-agent/tools): added default card fallback for tool rendering
- Extracted #formatToolExecution into a standalone formatDefaultToolExecution module.
- Updated xdev renderXdevCall and renderXdevResult to use the default card when no mounted renderer exists.
- Added fallback rendering that shows tool label, args, and output with appropriate theming.
- Added integration test verifying generic card renders for mounted tools without bespoke renderers.
2026-07-24 08:19:13 +02:00
can1357 af9e8546a9 feat: implemented session account selection and pinning via slash command
- Add `pinSessionOAuthAccount` storage method and active account flag to the auth storage API.
- Introduce session account selector component, controller logic, and interactive mode delegation.
- Implement the `/session pin` builtin slash command with text listing and account pinning capabilities.
- Add unit tests covering session account selection, component navigation, and command handling.
2026-07-24 07:57:55 +02:00
roboomp 7dee729ef7 fix(coding-agent): defer /tree ask re-answer resume until after ui rebuild
Scheduling agent.continue() inside navigateTree started a post-prompt
task before the interactive /tree handler rebuilt its transcript, so a
fast provider's agent_start/turn_start could render against the stale
pre-rebuild UI and then be clobbered by renderInitialMessages.

navigateTree now reports the commit via askReanswerCommitted instead of
resuming, and SelectorController.showTreeSelector calls the new
AgentSession.resumeAfterAskReanswer() only after renderInitialMessages +
reloadTodos, so the resumed turn always renders against the rebuilt
transcript.

Addresses chatgpt-codex-connector review on #6484.
Fixes #6483
2026-07-24 05:27:00 +00:00
can1357 189a3b51f0 fix: defer tiny-title prewarm past the scheduled first paint
requestRender(true) only queues the paint via setImmediate; calling
prewarm() synchronously afterwards put the worker spawn syscall ahead
of the render callback in the same loop turn. Schedule the prewarm
with its own setImmediate (FIFO after the render callback) so the
first startup frame paints before the subprocess spawns.
2026-07-24 06:51:37 +02:00
roboomp 3cdb93cd01 fix(tui): prewarm tiny-title worker off the first-submit hot path
The first interactive submit fired session.generateTitle() before
startPendingSubmission() painted the optimistic user row, and
tinyTitleClient.generate() spawned the local tiny-title subprocess
synchronously in #ensureWorker() before its first await. With a local
providers.tinyModel configured, subprocess-spawn latency therefore landed
ahead of the first frame, stalling the first prompt.

Paint the pending row before starting titling, and prewarm an idle,
unref'd worker at TUI startup via a no-op ping (no model load) so the
first submit reuses a live subprocess.

Fixes #6462
2026-07-24 03:48:43 +00:00
can1357 366bd6203e Merge PR #6392: feat(coding-agent): add usage-aware model fallback (@eggpeat) 2026-07-24 02:25:35 +02:00
can1357 77669aed54 Merge PR #6395: feat: configure xdev prompt docs (@joeshull) 2026-07-24 02:25:35 +02:00
can1357 0689092866 Merge PR #6445: feat(extensions): expose session service tiers (@atyrode) 2026-07-24 02:24:29 +02:00
can1357 9d2456415e fix(acp): propagated initial MCP refresh failure, drained stale chain 2026-07-24 02:24:16 +02:00
can1357 802ca5258c Merge PR #6437: fix(acp): pick up MCP tools that connect after the startup race (@barisdemirdelen) 2026-07-24 02:24:16 +02:00
can1357 32f79dbb48 Merge PR #6444: fix(plan): preserve and line-anchor review annotations (@anatoli-tsinovoy) 2026-07-24 02:24:05 +02:00
can1357 d2db3a9cad Merge PR #6442: fix(coding-agent): return from cancelled /omfg amendments (@anatoli-tsinovoy) 2026-07-24 02:24:04 +02:00
can1357 ca8c9eb69f Merge PR #6396: fix(tts): preserve playback across internal turns (@roboomp) 2026-07-24 02:24:04 +02:00
Brentandcan1357 93af91b7f5 fix(coding-agent): preserve fallback CI contracts 2026-07-24 02:23:51 +02:00
Brentandcan1357 0bfb0bd1e3 feat(coding-agent): add usage-aware model fallback 2026-07-24 02:23:51 +02:00
Joe Shullandcan1357 f4641c165e feat: allowlist xdev prompt docs 2026-07-24 02:23:22 +02:00
can1357 3d64910bb0 feat(coding-agent/live): added realtime voice interaction with Codex Live sessions (experimental)
- Added `src/live/` subsystem with WebRTC transport, protocol parser, session controller, and headless Chromium audio injection.
- Added `LiveVisualizer` component with phase states, transcript display, and animated waveform rendering.
- Added `/live` slash command and `LiveCommandController` to toggle live voice sessions.
- Suppressed local TTS via `vocalizer.suspend()` during live mode to prevent audio conflicts.
- Added live-instructions and agent-final-message prompts for agent messaging context.
- Added `protocol.test.ts` covering event parsing, chunking, and context message construction.
2026-07-24 02:20:43 +02:00
can1357 505af4188f fix(coding-agent/modes): pinned displaceable transcript snapshots to viewport
- Pinned displaceable snapshots like hub waiting polls and todo lists to the viewport during active execution.
- Prevented unpinned spinner ticks from repeatedly committing mutating rows to native scrollback and force-sealing blocks.
2026-07-24 01:25:29 +02:00
can1357 7eeaba0471 refactor(coding-agent/session): restructured monolithic agent session
- Extracted internal handlers and logic from AgentSession into dedicated runner, guard, and coordinator modules.
- Created standalone modules for bash execution, evaluation runners, IRC bridging, and prewalk coordination.
- Established dedicated session components for tracking stats, todos, streams, and retry fallback chains.
- Preserved existing session behavior while significantly reducing monolithic class size and complexity.
2026-07-24 01:24:44 +02:00