Commit Graph

1732 Commits

Author SHA1 Message Date
can1357 a3c15d2dec feat(coding-agent/tools): implemented pdf page screenshot rendering
- Add `renderPdfPageScreenshot` to render PDF pages via headless Chromium.
- Update `ReadTool` to intercept legacy PDF image paths and return page screenshots.
- Ensure daemon clients are closed on read command exit.
2026-08-14 14:37:56 +02:00
can1357 04fab5ecb4 feat: replaced custom mupdf wasm pipeline with native function
- Replaced the custom MuPDF-WASM PDF extraction and rendering pipeline with the new `pdfToMarkdown` native function from `@oh-my-pi/pi-natives`.
- Removed legacy MuPDF extraction modules, WASM embedding scripts, and PDF image extraction tools.
- Added OCR warnings and browser/text redirection for unsupported PDF image reads.
- Updated native package definitions, documentation, and test suites for the new PDF inspection capability.
2026-08-14 14:08:28 +02:00
can1357 0d6a7146a3 feat(coding-agent): supported allSettled and any promise combinators in browser scope
- Added `allSettled` and `any` to tracked promise combinators in run scope.
- Updated browser cancellation tests to cover new promise combinators.
2026-08-14 00:11:04 +02:00
roboomp a02f88994b fix(tools): preserve workspace-relative path in read hashline headers
formatReadHashlineHeader collapsed every relative in-workspace path to its
basename, so reading a nested file (e.g. src/settings.json) emitted
[settings.json#tag]. When a same-basename file existed at the session cwd,
a verbatim follow-up edit resolved against the cwd file; Patcher.prepare only
runs snapshot-tag path recovery when the authored path is missing, so the
valid edit was deterministically rejected with "hash is not from this
session". Keep the workspace-relative path, which names the file uniquely and
stays directly resolvable against cwd. Out-of-workspace absolute paths remain
shortened; root-level files are unchanged.

Fixes #8482
2026-08-14 00:04:59 +02:00
roboomp cf1ff14f5f fix(coding-agent): confine browser executable probe to linux
The executable version probe added in ecb22957 ("validate Linux browser
executables") replaced the file-only check in resolveSystemChromium with
isChromiumExecutable, which spawns the candidate `--version` for every
platform. On Windows chrome.exe is a GUI-subsystem binary: `--version`
does not print to a detached stdout and can hand off to a running
instance, opening/activating the user's normal browser window, after
which the probe rejects the candidate and falls back to cached Chrome
for Testing.

Gate the spawn probe on process.platform === "linux" (its intended
platform, where non-Chromium PATH wrappers are the real risk) and trust
the executable-file check on Windows and macOS.

Fixes #8445
2026-08-13 16:28:57 +00:00
can1357 4658662c35 fix(write): keep streaming preview append checks bounded 2026-08-13 01:14:46 +02:00
can1357 9c311d7a7b Merge PR #8040: fix(tui,utils): remove O(N²) hot paths when streaming long tool-call args (@AmecoCoding) 2026-08-13 01:14:45 +02:00
can1357 e49f8f4fb2 test(coding-agent): added shared auth storage and model registry to tests
- Added shared auth storage and model registry for concurrent and eager compaction tests.
- Replaced per-test auth storage creation and cleanup routines with shared lifecycle management.
- Removed local auth storage variables and individual cleanup hooks from test harness instances.
2026-08-12 03:25:31 +02:00
can1357 21a7693dd7 fix(hashline): prevented exposing terminal newline as an addressable row
- Added `splitAddressableFileLines` to strip terminal newlines from line addressability without removing genuine blank lines.
- Updated coding-agent read tool context parsing to use addressable file lines.
2026-08-12 03:22:01 +02:00
can1357 63b39b7040 feat(coding-agent/utils): expanded tar extraction and validation logic
- Added archive and member size assertion limits along with path byte-length checks for PAX and GNU metadata targets.
- Added support for global PAX attributes, old-GNU name records, and signed GNU base-256 numeric header fields.
- Updated archive reading in WriteTool to accept a filesystem path instead of buffered bytes.
- Added test coverage for signed GNU base-256 values, PAX extensions, overlong path rejections, and oversized archives.
2026-08-12 03:04:17 +02:00
can1357 94a76a8f27 feat: hardened tar parser and optimize prompt handling
- Bound PAX sparse record memory overhead by caching sparse markers and specific keys.
- Update system prompt phrasing and tests for tool inventory and date displays.
2026-08-12 03:04:07 +02:00
can1357 a4d8860a6c feat: added google reasoning controls mcp stream resumption and tar support
- Added Google provider thinking configuration parameters and force-reasoning-off controls.
- Implemented MCP SSE stream resumption using Last-Event-ID and `SSEResumeError`.
- Added support for TAR old-GNU sparse extension blocks, path length checks, and archive entry overrides.
- Restricted external thinking support to specific models and added semver fallback parsing.
2026-08-12 02:32:45 +02:00
can1357 19c0afcc0d feat: implemented external thinking flags and transport reasoning controls
- Added the `--external-thinking` CLI flag alongside model capability checks to gate external thinking tool availability.
- Updated Anthropic and Google transports to honor `forceReasoningOff` for native thinking-off controls.
- Renamed the `thoughts` property and parameter to `notes` across think fixtures, tools, and tests.
- Updated system prompt instructions and test suites to verify transport-specific thinking and tool activation.
2026-08-12 02:23:17 +02:00
can1357 10fd42289c feat: introduced external thinking support and private scratchpad think tool
- Added support for external thinking and forced reasoning disablement across AI provider options and request transformers.
- Implemented the private scratchpad think tool along with its renderer, system prompt rules, and schema configuration.
- Updated agent session management and SDK tools to support dynamic runtime activation of the think tool via the externalThinking setting.
- Added comprehensive unit tests covering reasoning fallbacks, tool activation, and rendering behavior.
2026-08-11 20:39:57 +02:00
can1357 b524dfe36f refactor: standardized outbound User-Agent headers on shared utility constant
- Define a centralized `USER_AGENT` constant in `@oh-my-pi/pi-utils` formatted as `omp/<version>`.
- Replace hardcoded and platform-specific user agent strings across AI providers, catalog scrapers, tools, and search providers with the unified `USER_AGENT`.
- Add unit tests for update-cli binary release distribution gating.
2026-08-11 15:38:32 +02:00
can1357 8fed93632a refactor(ai): rebranded openrouter identifiers and user agent to omp
- Updated user agent and openrouter titles in packages/ai from Oh-My-Pi to omp.
- Integrated getOpenRouterHeaders into image generation tool requests in packages/coding-agent.
- Updated provider documentation and test assertions to reflect the rebrand.
2026-08-11 15:28:28 +02:00
can1357 64baa7c1bd chore(format): applied biome formatting and removed dead code from merged prs 2026-08-11 15:14:15 +02:00
can1357 19edecaa48 fix: kept out-of-order todo completions visible 2026-08-11 15:06:12 +02:00
can1357 f6d4f1e38b Merge PR #7965: fix(coding-agent): surface todo progress in the collapsed panel (@z80dev) 2026-08-11 15:06:12 +02:00
can1357 8504e4865f Merge PR #7945: fix(coding-agent): resolve xd:// device dispatches against device user policy first (@re2zero) 2026-08-11 15:06:11 +02:00
can1357 baf8a1df7e feat(coding-agent/web): expanded web search and fetching providers
- Expanded web search and fetching providers with robust parsing, authentication storage integration, and response validation.
- Added support for new configurations including SearXNG safesearch, Cloudflare AI Gateway endpoints, and dynamic Firecrawl base URLs.
- Implemented comprehensive test suites covering error handling, content filtering, and provider-specific response behaviors.
2026-08-10 11:06:22 +02:00
lee 9e87d432bd fix(tui,utils): remove O(N^2) hot paths when streaming long tool-call args
Long write/edit streams made the TUI stutter or freeze for seconds at a
time (ui.loop-blocked warnings, keystrokes starving while the single JS
thread rebuilt previews). Two compounding quadratic paths:

1. parseStreamingJsonThrottled re-parsed the entire accumulated args
   buffer on a FIXED 256-byte cadence. The comment claimed this bounded
   mid-stream work to O(N), but a constant growth gate still parses an
   N-byte buffer N/256 times at O(N) each: O(N^2) with a smaller
   constant. The gate now scales geometrically (max(256, len/32)), so
   parse points form a geometric progression: O(log N) parses, O(N log N)
   total, with mid-stream snapshots staying within ~3% of the stream.
   Small buffers keep the exact fixed cadence as before.

2. write.ts formatStreamingContent normalized + split('\n') the WHOLE
   accumulated content on every 30Hz reveal tick (renderCall also ran a
   full-payload normalize first): O(N) per tick, O(N^2) per stream, per
   concurrent writer. The collapsed tail-window path now tracks the
   newline count incrementally (append-only resume keyed on the
   component's persistent render-state object via WeakMap) and extracts
   only the tail window with a backward scan: O(delta + preview lines)
   per tick, byte-identical output to the split-based reference. The
   expanded (Ctrl+O) path is unchanged in output and skips its
   split+join round-trip.

Tests: geometric-gate bounds + freshness + small-buffer cadence in
parse-streaming-json-throttled.test.ts; append-growth/reference-
window/CRLF/trailing-newline/restart battery in
write-streaming-incremental.test.ts. Full write/tool-render battery
(56 tests) and ai streaming-args tests (117 tests) pass.
2026-08-08 22:32:26 +01:00
can1357 7cebe901b7 refactor(coding-agent): narrowed over-exported internal symbols
- 28 symbols across discovery, mcp header policy, agent-hub projection and
  rendering, the agent registry, shell tokenizing and changelog comparison
  were exported but referenced only inside their own module; they are now
  module-private, shrinking the deep-import surface.
- Kept AGENT_PLUGIN_MANIFEST_SCHEMA, AGENT_PLUGIN_MCP_SCHEMA,
  parseAgentPluginManifest, clearAgentPluginRootCache and mergeMCPHeaders
  exported: each is a seam for tests that defend real parsing or header
  precedence behavior.
- Nothing reachable from an explicit exports entry or public barrel changed.
2026-08-08 06:32:01 +02:00
can1357 cafe52cd9f refactor(coding-agent): split github tool into domain modules
- gh.ts held wire types, search, Actions run-watch, PR checkout/push/create,
  PR diff parsing and view fetch/format in 3958 lines.
- Split into gh-types, gh-search, gh-run-watch, gh-pr-checkout, gh-pr-diff,
  gh-view and a gh-common module holding the shared primitives and the single
  process-lifetime default-repo memo pair; gh.ts is now 246 lines.
- All 22 exports stay on gh.ts because tools/index.ts star-exports ./gh, so
  the issue:// and pr:// protocol handlers needed no edits.
2026-08-08 06:32:01 +02:00
can1357 7454b6e78f refactor(coding-agent): split read tool into per-source modules
- ReadTool mixed plain-file reading with archive, sqlite, pdf-image, summary,
  selector, formatting and renderer concerns in one 3763-line module.
- Each now owns a sibling module; read.ts drops to 2020 lines and keeps its
  public exports, including the readToolRenderer re-export required because
  tools/index.ts star-exports ./read through the explicit ./tools entry.
- The pdfImageExtractions map and summaryParseCaches WeakMap stay single
  instances; execute() was deliberately left intact.
2026-08-08 06:32:01 +02:00
z80 40b2d534a0 fix(coding-agent): surface todo progress in the collapsed panel
While the agent worked through a plan, every sub-todo rendered unchecked
no matter how far along the run was: the phase header highlighted, the
task rows below it looked untouched. Three separate causes, all on the
collapsed path that is the default view.

`selectCollapsedTodos` dropped every closed row while a phase held open
work, so finishing a task only ever *removed* a line — the panel never
rendered a checked box until the whole phase settled. That also made the
card's completion animation dead code: `details.completedTasks` drives a
14-frame strike reveal at 65ms with a component render per tick, against
a row the viewport had already discarded. The existing animation test
missed it by asserting on `expanded: true`.

The viewport now keeps the newest closed task as a checked lead row,
additive to the open-task cap so it never evicts open work, and the
strike sweep lands where users actually see it.

Second, the card gave a `done/total` count to every collapsed untouched
phase but not to the active one, so the phase being worked in was the
single phase reporting no progress. Extracted `formatPhaseProgress` and
put it on every phase header.

Third, the todo auto-clear (`tasks.todoClearDelay`, default 60s) armed
on any list holding a closed task and physically deleted those tasks
from the HUD's copy. An in-flight phase at `3/4` silently became `0/1`
sixty seconds later, fully-closed phases vanished, and stage roman
numerals renumbered off the filtered index — until the next `todo` call
restored the real snapshot. It now fires only once the whole list is
settled, which is the case the setting exists for; the walking viewport
already hides closed rows while work remains.

Progress counters also count closed tasks rather than only completed
ones. The viewport hides abandoned tasks too, so counting only
completions left a phase reading permanently stuck.
2026-08-07 19:49:31 -04:00
re2zero 9d0699e070 fix(coding-agent): resolve xd:// device dispatches against device user policy first
When an xd:// device is dispatched through the write tool, the outer
approval gate now consults tools.approval.<deviceName> before falling
back to tools.approval.write. This lets users scope allow/deny/prompt
to a single device mount without changing the blanket write tool policy.

The write tool's approval function returns { tier, policyKey: deviceName }
for xd:// device dispatches. resolveApproval uses the policyKey to look
up the user override on the device name, falling back to the invoking
tool's own policy when the device has none configured.

Adds:
- ToolApprovalDecision.policyKey field (optional, additive)
- policyKey-aware lookup in resolveApproval and requiresApproval
- Updated error messages naming the correct config key
- Unit tests for policyKey resolution and WriteTool integration

Fixes can1357/oh-my-pi#7923
2026-08-08 02:45:19 +08:00
can1357 39477ba39b fix(debug): shortened js-debug install hint to the repo download
- Runtime error now just says to download vscode-js-debug from its GitHub repo;
  tarball recipe, extract path, env var, and Mason detail stay in docs/tools/debug.md.
2026-08-07 14:50:17 +02:00
can1357 37849df3e4 Merge PR #7759: docs(coding-agent): clarify js-debug-adapter install is not an npm package (@fcastillo18) 2026-08-07 13:39:54 +02:00
can1357 8b9579c06a fix(bash): preserve escaped newline semantics 2026-08-07 13:39:54 +02:00
can1357 50741716b8 Merge PR #7888: fix(bash): constrain leading cd extraction to a single path token (@roboomp) 2026-08-07 13:39:54 +02:00
can1357 73b91d89d4 Merge PR #7816: fix(coding-agent/tools): preserve native JSON Schema containers (@kimprap) 2026-08-07 13:39:52 +02:00
can1357 b50b05ee39 Merge PR #7790: fix(read): normalize recovery paths (@roboomp) 2026-08-07 13:39:52 +02:00
roboomp 2597244b00 fix(bash): constrain leading cd extraction to a single path token
The `cd <path> && ...` extractor matched everything up to the first `&&`
with a greedy regex, so a redirect or extra argument before the `&&` was
swallowed into the structured cwd. `cd /tmp 2>/dev/null && echo ok` became
cwd `/tmp 2>/dev/null`, which failed fs.stat and killed the command before
the shell ran.

Replace the regex with `extractLeadingCdTarget`, a quote/escape-aware
scanner in shell-tokenize.ts that captures exactly one path token and
bails (leaving the command for the shell) when anything else — a redirect,
extra argument, shell expansion, or a non-`&&` separator — precedes the
top-level `&&`.

Fixes #7883
2026-08-07 06:43:55 +00:00
can1357 2ad61c7b92 feat(discovery): added Agent Plugins 1.0.0 standard support
- New agent-plugins provider discovers packages with a root plugin.json
  targeting the canonical schema (agent-plugins.org) from marketplace
  installs, --plugin-dir, and configured extension roots; skills/ and
  mcp.json load per spec with closed-schema validation,
  ${PLUGIN_ROOT}/${PLUGIN_DATA} expansion, reserved subprocess
  environment, instance-keyed data dirs, and per-component isolation.
- Package-boundary containment (spec §4.1) is enforced before every
  read via the new contained-path helpers, including skill:// resource
  access from the read tool and bash; plugin skill files must
  realpath-resolve inside the plugin root (skills carry containRoot).
- Legacy claude-plugins/omp-plugins providers yield skills and MCP
  surfaces of standard-targeting roots to the new provider and skip
  fatally invalid packages.
2026-08-07 05:59:52 +02:00
kimp cde7f7f30b chore: merge upstream main into strict schema fix 2026-08-07 00:17:51 +07:00
kimp 7dcfd9422a fix(coding-agent/tools): deduplicate JTD primitive detection 2026-08-07 00:17:38 +07:00
kimp 103791f14b fix(coding-agent/tools): preserve native JSON Schema containers 2026-08-06 15:50:22 +07:00
roboomp bfd1e64bf6 fix(read): normalized recovery paths
Used the resolved cwd-relative path in summary recovery selectors, PDF image handles, and notebook diagnostics.

Fixes #7788
2026-08-06 03:40:10 +00:00
Franklin Castillo 3381b4305a docs(coding-agent): correct js-debug runtime + extraction path per review
Two wording fixes for PR #7759 review:
- debug.md no longer requires `node` on PATH; documents that the adapter
  runs under node if available, else the omp Bun host, matching
  resolveDefaultJsDebugAdapter()'s process.execPath fallback.
- The unavailable message and CHANGELOG now say "extract under
  ~/.local/opt" (not "to ~/.local/opt/js-debug/"), so the archive's
  js-debug/src/dapDebugServer.js lands at the auto-discovered path
  instead of one directory too deep.

Refs #7757.
2026-08-05 18:28:28 -04:00
Franklin Castillo 3afc87926b docs(coding-agent): clarify js-debug-adapter install is not an npm package
The "js-debug-adapter not available" message and the debug doc only
mentioned Mason and JS_DEBUG_DAP_SERVER, leaving users to try
`npm i -g js-debug-adapter`, which 404s: js-debug-adapter is the omp
adapter id, not an installable package. Surface the supported installs
(Mason; the standalone vscode-js-debug release tarball extracted to
~/.local/opt/js-debug/, which resolveJsDebugServerPath already
auto-discovers; or JS_DEBUG_DAP_SERVER) in both the error message and
docs/tools/debug.md.

Refs #7757.
2026-08-05 17:59:59 -04:00
can1357 ae84aff853 Merge PR #7675: fix(memory): hide disabled memory protocol (@roboomp) 2026-08-05 22:16:28 +02:00
can1357 c01d18eb57 Merge PR #7657: fix(read): split semicolon-delimited internal URLs (@revofusion) 2026-08-05 21:50:25 +02:00
can1357 f37b06eb3b Merge PR #7680: fix(coding-agent): stringify Bash preview env values (@GratefulDave) 2026-08-05 21:50:24 +02:00
can1357 e6ebfd4d49 Merge PR #7705: fix(coding-agent): validate Linux browser executables before launch (@metaphorics) 2026-08-05 21:50:24 +02:00
can1357 e9888367d1 refactor: migrated packages to internal utility modules and removed external dependencies
- Implemented in-house, zero-dependency utility modules in `pi-utils` covering DOM manipulation, markdown parsing, templating, browser automation helpers, and terminal buffers.
- Migrated packages across the repository to consume the new internal utilities and `omptype` schema validators instead of external dependencies.
- Removed multiple external runtime and development dependencies including Zod, Marked, LRU cache, Turndown, and Puppeteer browser packages.
2026-08-05 13:39:09 +02:00
metaphorics 30bbfd69e7 fix(coding-agent): avoid racing browser probe output 2026-08-05 11:19:38 +00:00
metaphorics e1a7c17c2b fix(coding-agent): bound browser version probes 2026-08-05 11:10:20 +00:00
metaphorics ecb22957cf fix(coding-agent): validate Linux browser executables 2026-08-05 10:50:31 +00:00
Can Bölük 1e492d6ff9 Merge pull request #7354 from brymko/fix/browser-timeout-crash-recovery
Fix/browser timeout crash recovery
2026-08-05 12:39:14 +02:00