Commit Graph

215 Commits

Author SHA1 Message Date
roboomp 0b7f4865a7 fix(tui): handled invalid path render args
Validated path-like renderer inputs before calling path helpers so provider-supplied arrays or objects cannot crash TUI rendering before schema validation reports the bad tool call.

Added renderer regression coverage for read, write, and edit call/result components with array and object path arguments.

Fixes #4525
2026-07-04 15:47:52 +00:00
can1357 6e2bba871e feat(agent): implemented automated retry recovery and transcript compaction
- Introduced an automated retry recovery system to track, manage, and persist recovered error states within agent sessions.
- Enabled compact transcript rendering for recovered auto-retry errors by removing heuristic commit machinery.
- Improved raw read tracking and provenance in the ReadTool to support refined file snapshot recording and hashline editing.
- Excluded recovered assistant messages from default model context and updated event controllers to handle retry recovery life cycles.
2026-07-04 11:22:04 +02:00
roboomp 2b8c8cadfb fix(read): kept raw artifact chunks verbatim and broadened path-only resolution
Skipped the workflow notice on raw selectors so bounded raw reads stay byte-for-byte, and taught resolveToolSearchScope to request pathOnly resolution so ast_grep/ast_edit scope-only calls no longer trip the inline-content cap on large artifacts.

Fixes #4482
2026-07-03 23:36:57 +00:00
roboomp 7497e68189 fix(read): shortened artifact paths in user-visible notices
shortenPath() the artifact.path leaked into the read-tool 'Artifact storage' and 'Unbounded raw read blocked' notices so $HOME never appears verbatim; details.resolvedPath keeps the absolute path for tooling.

Fixes #4482
2026-07-03 23:20:20 +00:00
roboomp a9bb4c7d59 fix(read): guarded large artifact raw reads
Resolved artifact:// reads to backing files before selector handling, streamed bounded reads, and blocked unbounded raw reads for large artifacts with recovery guidance.

Fixes #4482
2026-07-03 23:08:18 +00:00
can1357 1301d5b07a Merge remote-tracking branch 'origin/farm/f5b6b32e/fix-edit-anchor-fresh-read' 2026-07-02 23:43:10 +02:00
roboomp b38eba2be7 fix(coding-agent): exclude column-clipped lines from seen-line provenance
Codex reviewer flagged that the ranged-read fallback recommended by
the patcher's over-cap reveal path (`path:N-M`) itself applies the
512-column cap and still records the displayed line numbers via
`recordSeenLinesFromBody`. On a minified wide anchor line, `read
file:N` shows only the clipped prefix but the line lands in the
tag's seenLines — a subsequent edit anchored at N then slips past
the seen-line guard.

- `packages/coding-agent/src/edit/file-snapshot-store.ts`:
  `recordSeenLinesFromBody` grows an optional `excludedLines` set;
  parsed line numbers matching it are filtered before recording.
- `packages/coding-agent/src/tools/read.ts`:
  `#readLocalFileMultiRange` and the single-range disk path build a
  `clippedLines` set alongside `columnTruncated` for both direct-range
  lines and `buildLineEntriesWithBlockContext` context lines, then
  pass it into `recordSeenLinesFromBody`.
- `packages/coding-agent/src/tools/grep.ts`:
  same wiring for the match line via `match.truncated`, plus a
  conservative length+`...`-marker heuristic for context lines
  (native `crates/pi-natives/src/grep.rs` `truncate_line` doesn't
  propagate a per-line flag on `contextBefore`/`contextAfter`; a
  proper native-side flag is a follow-up).
- `packages/coding-agent/test/edit/seen-line-guard.test.ts`:
  new case reads a 4KB single line and asserts the clipped line
  number stays out of `seenLines` and the edit against it still
  rejects with the seen-line guard.
2026-07-02 08:53:18 +00:00
can1357 3830ad353e merge PR #3843 (surviving delta): perf: streaming-reveal/render throughput + core hot-path optimizations (@oldschoola)
# Conflicts:
#	packages/coding-agent/src/config/model-resolver.ts
2026-07-02 10:31:45 +02:00
can1357 978b950804 fix(coding-agent): resolved path resolution and fetch errors for fuzzy urls
- Fixed grep and ast-grep tools rejecting fuzzy url-shaped paths like schemeless www. or collapsed-scheme spellings.
- Applied the extra-CA wrapper to the model registry default fetch to respect the NODE_EXTRA_CA_CERTS environment variable.
- Moved isReadableUrlPath utility to path-utils to share recognition logic between reading and searching pipelines.
- Implemented a fallback that checks if a directory matching a fuzzy URL path exists locally before resolving it as an external URL.
- Added explicit errors for unsupported URL schemes to replace misleading local-path errors.
2026-07-02 01:51:09 +02:00
oldschoola 5abde300a1 Merge remote-tracking branch 'origin/main' into perf/streaming-reveal-throughput 2026-06-29 22:08:03 -07:00
oldschoola a1972d6345 perf: cut hot-path quadratic/allocation costs across 5 subsystems
Five hot-path performance fixes + two low-risk allocation reductions.
No behavior change; all derived counts/orderings are identical.

- session-manager pathTo: leaf->root walk used branch.unshift() per node
  (O(n^2) over branch length); now push + single reverse. Backs
  getBranch(), hit at ~17 sites per turn.

- edit/modes/patch: collapseConsecutiveSharedLines / collapseRepeatedBlocks
  / trimCommonContext built shared-line sets via
  new Set(oldLines.filter(l => newLines.includes(l))) -> O(old*new) per
  hunk. Precompute new Set(newLines) and use .has() -> O(old+new).

- task/executor appendRecentOutputTail: re-split + filter + slice + reverse
  of the full (up to 8KB) recentOutputTail on every text_delta token. Fast
  path extends the current last line in place; full recompute only when a
  newline boundary or truncation changes the window. tailLastLineRepresentable
  flag guards the trailing-whitespace-only-line edge case.

- task/render renderResult: header booleans (3x .some) + footer counts
  (3x .filter) + request total (.reduce) re-scanned details.results ~30x/sec
  via the spinner. Single pass derives aborted/failed/mergeFailed/success
  counts + requestTotal; booleans derived from counts.

- task/render extractIncrementalReviewResult: re-called normalizeYieldData
  internally though both callers had already normalized the same yield data.
  Signature now takes pre-normalized RenderYieldItem[].

Honorable mentions (allocation reduction, no algorithmic change):
- config/model-resolver: hoist case-folded pattern out of matchModel filter
  passes; build the O(n) preference context once per role in
  resolveModelRoleValue and reuse across fallback patterns.
- tools/read countTextLines: count newlines directly instead of allocating
  via split("\n"); hashline formatter reuses the line count instead of
  recomputing.
2026-06-29 22:05:09 -07:00
can1357 e8090bb48a feat: introduced binary file detection to prevent encoding corruption
- Introduced `isProbablyBinary` utility to sniff file headers for NUL bytes or invalid UTF-8 sequences.
- Updated `ReadTool` to use the binary sniffer, preventing mojibake corruption in output when reading non-text files.
- Refined `file-mentions` auto-reads to skip binary files and mark them as `binary` in the message transcript.
- Added comprehensive unit tests for binary detection logic, covering NUL bytes, truncated multibyte characters, and path-based file sniffing.
2026-06-30 02:59:41 +02:00
can1357 5d7b208a3e fix(coding-agent): enabled workspace-external file access using absolute paths
- Adjusted hashline header formatting to preserve absolute file paths instead of truncating them to basenames.
- Ensured absolute paths are passed through shortenPath to allow resolution while keeping home directory references concise.
- Prevented edit failures when reading files outside the workspace by ensuring tags remain resolvable.
2026-06-28 22:50:31 +02:00
can1357 577d2a8eb8 style: biome format/organize-imports across integrated PRs 2026-06-27 02:06:38 +02:00
can1357 274dd55708 Fix ssh URL integration regressions 2026-06-27 02:04:50 +02:00
can1357 cca4c4a026 Merge PR #3553: feat(omp): ssh:// URL support for read/search/write (@zommiommy) 2026-06-27 02:04:49 +02:00
can1357 0ef82d8518 refactor(coding-agent): changed file headers to display only filenames
- Updated `formatReadHashlineHeader` to use `path.basename` instead of the full path.
- Applied the new formatter across record and display functions in the read tool.
- Added and updated tests to verify that hashline headers now contain only the filename for nested files.
2026-06-27 01:10:30 +02:00
Tommaso Fontana f9ece90853 fix(omp): harden ssh:// URL handler per PR review
- buildSshTarget rejects destinations beginning with "-" (SSH argument-injection / local RCE guard)
- gate ssh:// read/search/write at the exec approval tier; substring scan covers search's pre-expansion delimited paths and write's hashline-wrapped paths
- validate the entire materialized buffer as UTF-8 instead of only the first 8 KiB prefix
- write peels read selectors (raw/conflicts) so it targets the same file read does, and rejects line-range/malformed selectors instead of silently stripping them
- write to a uniquely named remote temp; document symlink-replacement on write as a v1 limit
2026-06-26 20:41:35 +02:00
roboomp 93f1019ead fix(coding-agent): extended binary refusal to cover newline-less blobs
The streaming reader's NUL check only walked completed lines collected
from streamLinesFromFile, so a binary blob whose first newline lay past
the byte budget (videos, archives, packed JSON) left collectedLines
empty and slipped through to the firstLineExceedsLimit branch — which
emitted the decoded preview as text instead of the intended refusal.

Sniff firstLinePreview alongside collectedLines so the existing refusal
fires uniformly. Also added a regression test that uses a 256 KiB blob
with no 0x0A bytes to actually exercise the firstLineExceedsLimit
path — the previous 6-byte test fit in one collected line and never
covered the bug.

Fixes #3448
2026-06-25 07:58:20 +00:00
roboomp 83c392482a style: bun run fix 2026-06-25 07:37:51 +00:00
roboomp 4331217af8 fix(coding-agent): refused local binary attachment text reads
Routed file-backed '/data/workspaces/can1357__oh-my-pi__3448/.omp-session/2026-06-25T07-25-13-303Z_019efdab-28d7-7000-a7a4-e20282508056/local' reads through the normal filesystem reader so binary detection, document/image handling, and streaming safeguards apply before content is materialized.

Hardened the local protocol handler to return metadata-only refusals for binary/container resources instead of decoding them with Bun.file().text().

Fixes #3448
2026-06-25 07:37:30 +00:00
roboomp 3ce34621c0 fix(agent): preserved skill url session context
Threaded the caller's loaded skills through internal URL resolution so skill:// handlers do not depend on process-global skill state during tool execution.

Fixes #3436
2026-06-25 03:54:15 +00:00
can1357 c311c30cad fix(coding-agent): resolved local image protocol and process handling
- Standardized `local://` image processing to prevent file corruption during decoding.
- Refactored local path resolution logic to enforce safety constraints and path containment.
- Implemented an image fast-path in `ReadTool` to correctly render local images before text decoding.
- Added comprehensive test coverage for image rendering, text compatibility, and path security.
- Resolved an event loop hang associated with `omp --resume` operations.
2026-06-23 05:16:25 +02:00
can1357 c224ef4df5 feat: standardized elision markers and improve transcript viewer robustness
- Standardized elision markers across all tool outputs and filters to use cohesive `[...N [type] elided...]`, `[...Nln elided...]`, and `[...xB elided...]` syntax.
- Updated documentation, prompts, and test expectations to reflect the unified elision format.
- Improved transcript viewer robustness by preventing content aliasing through path-inclusive signature hashing.
- Added logic to clear stale transcript content when associated session files are deleted, accompanied by verifying test cases.
2026-06-19 04:35:18 +02:00
can1357 021d82ac1f feat(coding-agent): consolidated and optimize archive handling
- Centralized archive operations into a new `utils/zip.ts` module with unified support for ZIP, tar, and tar.gz formats.
- Optimized ZIP reading using lazy, ranged central-directory access and implemented ZIP64 support for large files.
- Hardened archive extraction with directory traversal protection and configured memory limits for loading and extraction.
- Refactored tool-specific logic to utilize the new centralized utility and deleted the redundant `archive-reader.ts`.
2026-06-18 19:21:37 +02:00
can1357 265f271197 feat(coding-agent): added pdf image extraction, caching, and markdown rewriting to the read tool
- Added support for extracting and caching images from PDF documents during Markit conversion.
- Implemented a rewriting step to replace PDF markdown image placeholders with clickable reference commands.
- Introduced specific sub-path routing (`file.pdf:image.png`) allowing direct reading of extracted PDF images.
- Implemented caching for extracted PDF images utilizing unique keys and a `.extracted` marker file.
2026-06-18 01:57:23 +02:00
can1357 e92db73ec6 feat(coding-agent/tools): added explicit ArkType schema descriptions to agent tools
- Added explicit ArkType schema descriptions across all coding agent tool definitions.
- Updated schema definitions in autoresearch and commit tools with descriptive wrappers.
- Documented tool schema enhancements in the packages/coding-agent CHANGELOG.
2026-06-18 00:59:55 +02:00
can1357 a050474af7 feat: migrated validation schemas and tool definitions from Zod to ArkType
- Migrated all wire protocol, schema definitions, and tools validation from Zod to ArkType across multiple packages.
- Updated extension runtimes, custom tools loader, and TypeBox compatibility shim to expose and use ArkType instances.
- Added a comprehensive ArkType migration guide, validation parity tests, and helper utilities.
- Removed redundant PDF asset routing and parsing implementations from the read tool.
2026-06-18 00:59:53 +02:00
can1357 020dd5f821 feat(coding-agent/tools): added PDF embedded-image read support to the read tool
- Added PDF member read syntax (`doc.pdf:<member>`) and trailing-colon listing.
- Added asset-read handling to serve extracted PDF images as inline image content.
- Added PDF image extraction caching keyed by size and mtime with marker files for retries.
- Added basename validation that rejects unknown/traversal-like PDF members and shows available names.
2026-06-17 17:20:09 +02:00
can1357 3f32971944 feat(ai): align OpenRouter max_tokens with caller intent
OpenRouter previously omitted `max_tokens` entirely (except for specific models) to prevent unintended provider filtering when a model's catalog default `maxTokens` exceeded an upstream's actual capacity. This could lead to incorrect routing if a model had a high catalog cap but individual providers under OpenRouter did not.
2026-06-17 12:24:19 +02:00
can1357 be734240ce ux(coding-agent): added line-number gutters to read tool code cells
- Read tool result details now include optional per-line number arrays so displayed content can retain original line mappings.
- Read tool group and renderer now forward code start-line and line-number metadata into code-cell rendering.
- Code cell rendering now draws aligned line-number gutters and pads hidden-line hints to keep gutter alignment.
2026-06-17 12:24:19 +02:00
roboomp e42353a79b fix(hashline): recorded acp read lines
Merge displayed bridge-backed range and multi-range read lines into the existing hashline snapshot provenance so INS.POST anchors pass visible-line validation after ACP reads.

Fixes #2773
2026-06-17 02:54:26 +00:00
can1357 a655953e7a fix(hashline): hardened hashline editing with seen-line and block-anchor validation
- Tracked seen-line provenance in snapshots and propagated it from read/search/ast-grep rows.
- Rejected hashline edits on unseen lines before patching, throwing unseen-line errors.
- Rejected single-line block anchors in strict mode and dropped them in unresolved lenient mode.
- Trimmed one-sided keeper-echo duplicates during multi-line replacements with warning output.
2026-06-15 04:25:33 +02:00
can1357 92fba8d486 fix: addressed model-aware image handling for tool image WebP filtering
- Added model-aware session image normalization by passing active model.
- Propagated model-derived WebP exclusion into browser snapshot capture and resizing.
- Applied model-derived WebP exclusion to eval, fetch, read, and inspect image paths.
2026-06-13 16:17:56 +02:00
can1357 64aa558e62 chore: consistency 2026-06-13 00:03:27 +02:00
can1357 d214e2f022 Merge branch 'pr-2182'
# Conflicts:
#	packages/coding-agent/package.json
#	packages/coding-agent/src/config/model-registry.ts
#	packages/coding-agent/src/main.ts
#	packages/coding-agent/src/modes/components/assistant-message.ts
#	packages/coding-agent/src/sdk.ts
#	packages/tui/src/components/markdown.ts
2026-06-12 11:24:26 +02:00
can1357 12bada4ce0 fix: hardened deferred MCP discovery and streaming render fast paths
- Recomputed `tools.discoveryMode: "auto"` in the deferred MCP closure in `sdk.ts` once the real tool count is known: a toolset crossing the threshold now flips discovery on, registers and activates `search_tool_bm25`, and skips `activateAll` instead of force-activating every MCP tool.
- Guarded the deferred MCP task against disposed sessions: added `AgentSession.isDisposed` and `enableMCPDiscovery()`, and the late connect now calls `disconnectAll()` instead of refreshing tools onto a dead session.
- Cleared `#fastPathKey`/`#fastPathItems` in `AssistantMessageComponent.invalidate()` so theme/symbol changes rebuild reused Markdown children instead of keeping stale captured themes.
- Memoized unusable read summaries as a `false` sentinel in `read.ts` so the per-session LRU no longer retains full sources of unsummarizable files.
- Broadened `HAS_REF_DEF` in `markdown.ts` to match backslash-escaped reference labels (`[a\]b]: x`) and cleared frozen stream-lex state on blank `setText()`.
- Added regression tests: deferred auto-discovery flip and mid-connect dispose (`sdk-mcp-auto-discovery.test.ts` + `many-tools-mcp.ts` fixture), fast-path child rebuild on invalidate, and escaped-ref-def incremental-lex equivalence.
2026-06-12 11:14:39 +02:00
can1357 b69a2024d3 fix: revert read-repeat
This reverts commit 9613076e96.
2026-06-12 03:27:50 +02:00
can1357 9613076e96 feat(coding-agent): added repeat-read notice to the read tool
Tracks successful file reads per resolved base path (selector stripped) for the session; once a path has been whole-file-read three times, every subsequent read for that path appends a one-line nudge suggesting narrower line-range re-reads or the context echoed in edit results. Non-file sources (URLs, internal resources, directories, archives, SQLite, images) are never counted.
2026-06-10 17:53:46 +02:00
roboomp 16a2c03852 fix(coding-agent): documented read uri targets
Updated the read tool's provider-visible path schema, prompt docs, CLI help, and internal URL docs so URL and internal URI targets are advertised consistently. Added schema coverage for the read path description.\n\nFixes #2215
2026-06-10 00:21:12 +00:00
can1357 c3054d5cea fix(coding-agent): capped read-stack resource use and fixed selector routing
tar/tgz stat-gated at 256MB, zip entries reject oversized declared sizes; raw ?q= sqlite capped at 1000 rows; giant-file reads stop scanning to EOF; multi-range reads slice one pass; malformed URL selectors error instead of dumping; archive-root selectors, member tag immutability, case-insensitive selector tokens, session-pinned artifact lookups, shared+escaped suffix globs; archive dir listings honor offsets; binary files get a NUL-sniff notice.
2026-06-10 01:27:17 +02:00
metaphorics a3e3a905ac perf(coding-agent): defer boot work and cut streaming/read CPU
- Defer MCP server discovery off the first-paint critical path for UI
  sessions; tools and slash commands stream in through the existing
  live-refresh channel once each server connects (non-UI modes keep the
  blocking path). ~290ms off first paint with MCP servers configured.
- Build the model catalog's canonical-equivalence index lazily on first
  read instead of eagerly in the ModelRegistry constructor. A default
  interactive launch never reads it pre-paint, moving the ~210ms build
  (over ~3,200 models) off the critical path: ~244ms (~16%) off cold boot.
- Memoize per-session read summaries (tree-sitter parse) on the content
  hash of the freshly-read bytes; the file is still read fresh each call
  so results stay correct. Repeat same-file summary read 17ms -> 2.4ms.
- Reuse the Markdown subtree across streaming reveal ticks, memoize
  grapheme counting, and stop re-highlighting finalized thinking blocks.
- Attribute the previously-unlabeled synchronous boot region in the
  PI_TIMING table and add a bench:guard boot-regression target.
2026-06-09 18:58:22 +09:00
can1357 1e5017bf7d feat: enabled block-boundary context support across read and diff previews
- Added tree-sitter `enclosing_block_boundaries` API with line range models.
- Added N-API `enclosingBlockBoundaries` bridge and exported JS declarations.
- Replaced matching-bracket context resolution with source-aware block context in read and diff flows.
- Passed source path through diff/read generators to surface native block boundary previews.
2026-06-08 14:29:59 +02:00
can1357 b8eecfffde feat(coding-agent): added matching bracket context lines to read and edit previews
- Added matching-bracket utilities to locate partner lines for visible spans.
- Added read tool output to use displayContent text and startLine for bracket-aware previews.
- Added matching-bracket context rows to generateDiffString and generateUnifiedDiffString.
- Adjusted diff row insertion to deduplicate and keep contiguous changed groups together.
2026-06-08 14:00:54 +02:00
can1357 f11cbed185 feat: enabled clickable read links and made deterministic reads non-abortable
- Enabled clickable read-path output for result rows, summaries, and previews.
- Resolved read links from result paths, source metadata, internal URLs, and absolutes.
- Preserved selector suffixes while rendering line-anchor hyperlinks.
- Ignored aborted signals for plain-file and directory reads while keeping conflicts-cancel behavior.
- Added tests for non-abortable read behavior and link-label rendering regression coverage.
2026-06-08 05:40:04 +02:00
can1357 31309d6212 fix(agent): removed tool-level abort-signal bypasses for read/write/edit tool execution
- Updated `executeToolCalls` to always pass the active `toolSignal` into `tool.execute` rather than bypassing it for non-abortable tools.
- Removed the `nonAbortable` option from `AgentTool` and from the read, write, and edit tools so they can no longer opt out of abort handling.
- Documented the cancellation behavior change in the affected tool docs and package changelogs.
2026-06-08 05:27:00 +02:00
can1357 97ae0fd34d fix(coding-agent): fixed grouped read output by splitting and merging selector rows
- Split top-level and delimited read selectors into separate rows before grouping.
- Merged duplicate same-file read selectors into one summarized row with ellipsis truncation.
- Computed grouped-read status and totals from aggregated rows for accurate summaries.
- Updated changelog entries and fixtures to document/read expectations.
2026-06-08 04:51:25 +02:00
can1357 68c454c0fc feat(edit/read): enabled canonical snapshot keys across read/write paths
- Canonicalized snapshot key resolution with realpath, parent fallback, and raw fallback.
- Updated snapshot, hashline, read, and write flows to use canonical snapshot keys consistently.
- Fixed converted-content line-range reads to apply selectors via in-memory range/text builders.
- Updated read tool docs to clarify one-line and multi-range selector context bounds.
2026-06-08 02:04:59 +02:00
can1357 cbd7c20105 feat(coding-agent/tools): added binary routing for notebook, sqlite, and archive payloads
- Added archive format sniffing to identify ZIP, TAR, and TAR.GZ from file bytes.
- Added MIME/extension and header-based routing for notebook, sqlite, and archive payloads.
- Added archive entry rendering with slash-terminated dirs and size suffixes.
- Added tests for archive, sqlite, notebook, and fallback binary dispatch scenarios.
2026-06-07 06:55:52 +02:00
can1357 52f7defeab fix(coding-agent-tools): fixed OSC8 links to use resolved file paths from session context
- Fixed edit/read/search/ast-edit/ast-grep outputs to resolve OSC8 links from session cwd.
- Fixed grouped-file output classification to honor headerBase and fileScope for parent path resolution.
- Fixed read and write renderers to use resolved source/resolved paths as hyperlink targets.
2026-06-07 05:37:10 +02:00