Commit Graph
1210 Commits
Author SHA1 Message Date
Can BölükandGitHub 26931fe8ce Merge pull request #1055 from jiwangyihao/fix/browser-worker-startup-errors
fix(browser): surface tab worker startup errors
2026-05-14 04:47:31 +02:00
Can BölükandGitHub 3d2bbe5e8f Merge branch 'main' into fix/browser-stealth-target-setup 2026-05-14 04:46:30 +02:00
Can BölükandGitHub 3ad9255b18 Merge branch 'main' into dmarsh/acp-thinking-level-push 2026-05-14 04:43:55 +02:00
Can BölükandGitHub 9530f94a36 Merge pull request #1061 from ldx/fix/mcp-oauth-persist-dynamic-client
fix(coding-agent): persist dynamically registered MCP OAuth client_id
2026-05-14 04:43:08 +02:00
Can BölükandGitHub 38255a4e6e Merge pull request #1062 from enieuwy/fix/copy-handoff-context
Fix /copy fallback for handoff context
2026-05-14 04:42:53 +02:00
can1357 f1f6516056 refactor: reorganized exports and removed obsolete helper branches
- Removed export leakage by demoting many helper and const symbols to module-local scope.
- Renamed underscore-prefixed internals and cache fields, then updated related references and `satisfies never` checks.
- Deleted obsolete logic branches and helpers, including harmony-stream interruption flow and unused benchmark runtime helpers.
- Updated Biome config and manifests by broadening lint coverage and removing an unused `@napi-rs/cli` dev dependency.
- Adjusted tests and utilities to use renamed test helpers and remove redundant private test-only helpers/locals.
2026-05-14 04:36:19 +02:00
enieuwy fa1d83e527 Fix copy fallback for handoff context 2026-05-14 09:41:06 +08:00
can1357 6b6cc417f2 test(coding-agent/acp): bumped ACP stdout-hygiene timeout to 60s for slow CI runners 2026-05-14 03:26:25 +02:00
Vilmos Nebehaj a7f73ee645 fix(coding-agent): persist dynamically registered MCP OAuth client_id
When an MCP server uses OAuth Dynamic Client Registration (RFC 7591) and
no client_id is pre-configured, MCPOAuthFlow registers a fresh public
PKCE client on each authorize, captures the issued client_id into a
private field, then discards it once the flow object goes out of scope.
At refresh time, MCPManager#resolveAuthConfig calls refreshMCPOAuthToken
with auth.clientId from mcp.json — which is empty for these servers —
so providers that require client_id on the refresh grant (e.g. Linear at
mcp.linear.app/token) reject with HTTP 401 invalid_client. The user is
forced to /mcp reauth manually every time the access token expires.

This change threads the resolved/registered client credentials back out
of the OAuth flow and persists them into mcp.json so refresh has what
it needs indefinitely:

- MCPOAuthFlow exposes resolvedClientId / registeredClientSecret getters.
- MCPCommandController#handleOAuthFlow returns OAuthFlowResult with
  credentialId + clientId + clientSecret, populated from the flow's
  post-login state.
- The initial-connect non-wizard path and /mcp reauth path persist the
  returned client credentials into both auth.{clientId,clientSecret}
  (used at refresh) and oauth.{clientId,clientSecret} (used by future
  /mcp reauth to skip re-registration).
- The wizard's onOAuth callback signature now returns the same shape;
  #launchOAuthFlow folds the registered credentials into wizard state so
  the final mcp.json entry built by #buildServerConfigWithAuth includes
  them under auth.{clientId,clientSecret}.

Servers that configure a static oauth.clientId in mcp.json (Notion,
Slack, Datadog) are unaffected: #tryRegisterClient short-circuits, the
returned clientId equals the configured one, and the write-back is a
no-op.

Adds two MCPOAuthFlow unit tests covering both paths.
2026-05-13 15:39:04 -07:00
David Marshallandomp b626609314 refactor(coding-agent/acp): extracted ACP_BOOTSTRAP_RACE_GUARD_MS and consolidated race notes
/simplify pass on 4882d1e38. Three small cleanups, no behavior change.

* Extracted the inline 50ms bootstrap-race guard into an exported
  ACP_BOOTSTRAP_RACE_GUARD_MS constant at the top of acp-agent.ts.
  Source uses it in the #scheduleBootstrapUpdates setTimeout. Tests import
  it and call a new waitForBootstrapGuard() helper (constant + 30ms slack
  for setTimeout drift) instead of three hardcoded Bun.sleep(80) sites —
  tests now bind to the source-of-truth instead of dueling magic numbers.
* Consolidated four block comments that all narrated the same race story
  into one canonical explanation at the install site (#scheduleBootstrapUpdates).
  Field declaration, #registerPreparedSession, and the setSessionConfigOption
  handler keep brief one/two-line pointers. Net change is roughly 30 lines
  of comments removed without losing the diagnosis.
* Trimmed the handler-site thinkingHandledBySubscription comment from six
  lines to three; the local-variable name carries the intent.

Verified:
* bun test test/acp-agent.test.ts: 11/11 pass
* biome check on touched files: clean
* No behavior change (no test had to be updated)

Co-Authored-By: omp <noreply@oh-my-pi.dev>
2026-05-13 16:43:45 -05:00
David Marshallandomp 4882d1e386 fix(coding-agent/acp): deferred thinking-level lifetime subscription until after bootstrap-guard
Addresses codex review on #1060: an extension session_start handler that
calls setThinkingLevel via the exposed extension action (line 1541) would
have run BEFORE #registerPreparedSession set the record into #sessions and
BEFORE the session/new response was delivered to the client, causing
config_option_update to be pushed for a session id the client did not yet
know about. This is the exact race that #scheduleBootstrapUpdates already
documents and guards for available_commands_update / session_info_update
(Zed's 'Received session notification for unknown session' drop).

Moved the session.subscribe(...) installation out of #registerPreparedSession
and into #scheduleBootstrapUpdates's 50ms timer callback so the lifetime
subscription shares the same response-delivery guard as the existing
bootstrap notifications. The pre-bootstrap thinking level is still
communicated to the client through the response payload's configOptions
(newSession / loadSession / resumeSession / unstable_forkSession all return
it), so no state is lost; it is only the notification that is deferred.

For client-driven setSessionConfigOption({thinking}) the handler now only
skips its own push when the lifetime subscription is already installed.
Pre-bootstrap the handler keeps pushing (the client knows the session id
because they passed it in), post-bootstrap the subscription pushes
exactly once. No double-push, no missing pre-bootstrap notification.

Tests:
- updated existing pushes-config-option-update test to await past the 50ms
  bootstrap timer before driving the internal setThinkingLevel
- updated the single-config_option_update-per-setSessionConfigOption test
  the same way
- added 'suppresses lifetime config_option_update during the bootstrap
  window' regression that drives setThinkingLevel synchronously after
  newSession and asserts zero notifications, then asserts notifications
  resume after the bootstrap timer fires
- bun test test/acp-agent.test.ts: 11/11 pass

Co-Authored-By: omp <noreply@oh-my-pi.dev>
2026-05-13 16:34:54 -05:00
David Marshallandomp c7722838b7 fix(coding-agent/acp): pushed config_option_update on every thinking-level change
ACP clients (Zed, etc.) only received `config_option_update` notifications
when they themselves drove the change via `session/set_session_config_option`.
Internal thinking-level updates (slash commands, automatic model-driven
adjustments, extension UI) bypassed the notification path, so client config
panels went stale until the next user-initiated change.

AgentSession now emits a `thinking_level_changed` event from
`setThinkingLevel`, and AcpAgent installs a session-lifetime subscription on
each managed session that pushes a fresh `config_option_update` whenever the
event fires — independent of prompt-turn lifecycle. The
`session/set_session_config_option` handler no longer pushes its own
notification for the `thinking` config (lifetime subscription covers it);
the response still returns fresh `configOptions` so callers see the new
state synchronously. Subscriptions are released in `#disposeSessionRecord`.

Also consolidated four duplicate `config_option_update` send sites into a
new `#pushConfigOptionUpdate(record)` helper.

Tests: added two cases to `test/acp-agent.test.ts` — one verifying internal
`setThinkingLevel` calls produce a `config_option_update` and a no-op
re-set produces none, and one verifying client-driven
`setSessionConfigOption(thinking, …)` produces exactly one notification.

Co-Authored-By: omp <noreply@oh-my-pi.dev>
2026-05-13 16:14:18 -05:00
can1357 453071d34d fix(coding-agent): restored coordinate-mapping dimension note and made bash SGR test color-mode agnostic
- Restored formatDimensionNote bracket form '[Image: original WxH, displayed at WxH. Multiply coordinates by S to map to original image.]' that tests assert. The Bun 1.3.14 refactor regressed it to a less informative 'Image resized from …' line.
- Broadened bash-sixel-render multi-line styling assertion to accept both truecolor (38;2;) and 256-color (38;5;) SGR runs so CI runners with TERM=dumb don't fail. The contract being tested — every line carries its own SGR — is independent of color depth.
2026-05-13 20:43:03 +02:00
can1357 c7d04f3a13 fix(coding-agent): constrained bash cwd auto-detect regex to single-line cd commands
- Updated BashTool's leading `cd` regex to stop matching newline characters so cwd extraction only applies to a single-line `cd ... &&` prefix.
- Added a regression test for multiline commands with a later-line `&&` to ensure each line of the script executes normally.
2026-05-13 19:19:50 +02:00
jiwangyihao 11a19eb8d4 fix(browser): bound stealth target setup during tab open
Keep the active page stealth setup synchronous, but make the broader CDP target UA override sweep selective and best-effort. Non-page or ephemeral Chrome targets can otherwise block worker initialization long enough for browser.open to hit the tool timeout before the tab worker sends ready.

Fixes #1053
2026-05-14 01:19:01 +08:00
jiwangyihao 8830b2e367 fix(browser): surface tab worker startup errors
Forward worker error and messageerror events while acquireTab waits for the initial ready/init-failed response. This prevents async worker module-load or early startup failures from being reported only as a generic tab worker init timeout.
2026-05-14 00:34:55 +08:00
can1357 7fd2a7b309 fix(coding-agent/tools): highlighted multi-line bash commands in result rendering
- Added a new formatBashCommandLines helper that syntax-highlighted each command line and applied the dim prefix only to the first line.
- Updated the shell renderer to emit command output as line-based entries instead of a single dimmed string.
- Extended the bash renderer test to verify multi-line commands keep ANSI styling on every rendered line.
2026-05-13 18:15:57 +02:00
can1357 af07faec11 feat: Bun 1.3.14
- Raised the Bun minimum version to >=1.3.14 across package metadata, install scripts, and changelog notes.
- Removed the Photon native image pipeline and added SIXEL-based `sixel` support in pi-natives.
- Migrated coding-agent image handling and resizing to `Bun.Image`, including updated tests and a JPEG quality bump to 80.
- Added HTTP/2 fetch bootstrap with HTTPS-only fallback and updated Bun build flags for autoload suppression/`--keep-names`.
2026-05-13 13:21:59 +02:00
Can BölükandGitHub 1087e7cdb9 Merge pull request #1047 from jiwangyihao/fix/openai-processing-retry
fix(coding-agent): retry OpenAI retry-suggested errors
2026-05-13 13:21:32 +02:00
jiwangyihao 02df3a1534 fix(coding-agent): 重试 OpenAI 建议重试错误 2026-05-13 18:53:10 +08:00
can1357 0756f2b36a test(coding-agent/bash-executor): update outputBytes bound for middle-elision
The OutputSink now keeps a head budget (tools.artifactHeadBytes, default
20 KB) in addition to the tail spill window, so outputBytes can legally
reach head + tail + marker overhead. The multi-million line test still
asserted the pre-elision tail-only bound and started failing on CI.
2026-05-13 11:51:34 +02:00
can1357 9828764cb4 feat(scripts-session-stats): added session-stats search relevance plotting
- Changed multi-file search paging to skip whole files and page results in file windows.
- Added per-file match caps, round-robin file selection, and new file-limit truncation reporting.
- Replaced match/result limit metadata with fileLimitReached and perFileLimitReached.
- Lowered read.defaultLimit default to 300 with 1 lead and 3 trailing context lines.
- Replaced the search skip test with file-pagination coverage and added per-file cap tests.
- Added session-stats analytics tooling to classify searches, detect repeats, and render relevance plots.
2026-05-13 11:38:09 +02:00
can1357 a541a63547 feat: added read-selector analyzers and coverage plotting tools
- Updated read range expansion to use 1 leading and 3 trailing context lines.
- Changed read.defaultLimit from 500 to 300 in settings defaults.
- Updated read docs and tests to reflect the asymmetric context line behavior.
- Added read-selector analyzers and replay simulators to evaluate coverage and savings.
- Added plotting tools that output new session-stats PNG dashboards from local usage data.
2026-05-13 11:33:42 +02:00
can1357 28b9ce7a0c feat(coding-agent): added middle-elision caps to OutputSink truncation
- Added `tools.artifactHeadBytes` and `tools.outputMaxColumns` settings with defaults in `SETTINGS_SCHEMA`.
- Expanded `OutputSink` with `headBytes`/`maxColumns` and middle truncate logic with elision markers and tracking.
- Updated output-meta to resolve sink settings, emit truncation metrics, and use `truncateMiddle` for spills.
- Integrated head and column limits into JS/Python/Bash/SSH/read output flows, with `:raw` skipping read truncation.
- Documented new output middle-elision and column-cap behavior in `CHANGELOG.md`.
- Added truncation tests for `OutputSink`, `truncateMiddle`, and read-tool line handling.
2026-05-13 11:19:11 +02:00
Ogrodevandcan1357 4e4e74be49 fix(coding-agent/acp): tighten ACP conformance per review feedback
Addresses the codex review comments on #1015 plus a sweep of adjacent
ACP conformance gaps surfaced while wiring them up.

Tool call + diff metadata
- acp-event-mapper: thread session cwd through and resolve every
  `ToolCallLocation` (initial args, in-flight updates, result details)
  to absolute paths against it; ACP requires absolute paths for
  client-side file mapping.
- edit/modes/patch: emit the destination path for moves in the diff
  result so post-edit "open file" actions land on the new file.

Permissions
- agent-session: pass cwd into `extractPermissionLocations` and resolve
  raw `path`/`file`/etc. fields against it before sending
  `session/request_permission`.
- agent-session: gate the permission wrapper on
  `bridge.capabilities.requestPermission && bridge.requestPermission`,
  matching the read/write/bash capability+method pattern.

acp-agent
- `authenticate`: validate `methodId` against the methods advertised by
  `initialize` and reject anything else, so malformed clients fail fast.
- `setSessionConfigOption(MODE_CONFIG_ID)`: also emit
  `current_mode_update` so clients tracking `modes.currentModeId` see
  the same transition `session/set_mode` would produce.
- Pass `runtime.notifyConfigChanged` to builtins; emit
  `available_commands_update` from a shared `reloadPlugins` helper
  reused by `/reload-plugins`, `/marketplace`, and `/plugins`.
- prompt resource handling: route `resource` content with `image/*`
  MIME into the `images` array instead of dropping it as an opaque
  blob; non-image blobs still fall back to the URI placeholder.
- pass session cwd to the event mapper.

Builtins
- model: call `runtime.notifyConfigChanged()` after a successful
  `setModel` so the ACP config selector reflects the new model
  immediately.
- mcp: redact query strings and userinfo from MCP server URLs before
  emitting them in `/mcp list` (prevents leaking `?exaApiKey=…` style
  secrets); wire `manager.setAuthStorage(...)` before `prepareConfig`
  in `/mcp test|resources|prompts` so OAuth servers can refresh tokens.
- ssh: reject non-integer `--port` values via a `^\d+$` guard instead
  of silently coercing through `Number.parseInt`; list project hosts
  first and dedupe user-scope duplicates to match capability-loader
  precedence.
- export: reject clipboard aliases (`--copy`, `clipboard`, `copy`)
  before passing them to `exportToHtml` as a filename.
- compact / force / move / browser: surface underlying failures via
  `usage(errorMessage(...))` instead of letting them crash the command.
- session save|delete: route through the active SessionManager so the
  persist writer is consulted and stale storage references are removed.
- marketplace / plugins / reload-plugins: call `runtime.reloadPlugins()`
  on install/uninstall/upgrade and enable/disable so slash command
  registries and command lists refresh consistently.
- shared.usage: make async and `await runtime.output(...)` so
  `sessionUpdate` text is never dropped or reordered.
- types: document the new `reloadPlugins` and `notifyConfigChanged`
  runtime hooks.

bash tool
- Use a shared `fireKill()` from the abort listener so `session/cancel`
  terminates the remote command immediately instead of waiting for the
  next `currentOutput()` round trip.
- Race `currentOutput()` against the abort signal so a stuck
  `terminal/output` RPC cannot delay cancellation.
- Kill the terminal before reading final output on timeout so a slow
  output read cannot let a timed-out command keep running past the
  enforced timeout.

Tests
- acp-agent.test: extend the existing config-option assertions to
  verify both `model` and `thinking_level` changes emit
  `config_option_update` notifications scoped to the right session.
- acp-builtins.test: cover `/model` emitting both
  `notifyTitleChanged` and `notifyConfigChanged`; lock in the parsed
  `mcp add` / `ssh add` call shapes so future arg-parser regressions
  fail the test instead of silently writing different configs; add a
  `reloadPlugins` stub plus a typed `notifyConfigChanged` slot to the
  shared test runtime factory.
- acp-stdout-hygiene.test: drain stderr in parallel and assert no
  JSON-RPC frame leaks onto it; terminate the spawned process so the
  stderr pump resolves deterministically.

CHANGELOG: itemize the above under `[Unreleased] > Fixed`.

CI
- bun run check: clean (TS + Rust)
- bun run test: 4128 pass / 689 skip / 0 fail (TS); 252 pass / 0 fail
  (Rust nextest)
- bun run ci:test:smoke: --version / --help / `stats --help` all OK
2026-05-13 06:00:45 +02:00
Ogrodevandcan1357 1a44cd2e36 Fix ACP review follow-ups 2026-05-13 06:00:45 +02:00
Ogrodevandcan1357 9ae60cd793 Fix assistant image fixture path 2026-05-13 06:00:45 +02:00
Ogrodevandcan1357 be36c7c24f Fix ACP review comments 2026-05-13 06:00:45 +02:00
Ogrodevandcan1357 d8e38bcc62 test(acp): add comprehensive ACP and edit tool test suites
- AcpAgent integration tests: initialize→run→notify cycle, notification structure, message-ID continuity
- ACP built-in slash command unit tests across all command handlers via fake runtime
- ACP event mapper unit tests: text chunks, thinking, tool calls/results, errors → SessionNotification
- ACP initialize conformance: terminal auth capability negotiation, agentInfo/agentCapabilities contract
- stdout hygiene smoke test: first bytes on omp acp stdout must be a valid JSON-RPC frame
- AgentSession permission gate: allow-once, reject-once, allow-always, abort-during-pending, non-gated tools
- BashTool ACP terminal routing: bridge dispatch vs local PTY fallback
- EditTool diff content propagation: patch, replace, and multi-file aggregation paths
- ReadTool and WriteTool ACP filesystem permission tests
- Shared ACP schema test helper
2026-05-13 06:00:45 +02:00
can1357 5a37fd4516 fix(ai): resolved ai auth credential_disabled queueMicrotask flushing
- Deferred initialize to flush queued credential_disabled events via queueMicrotask and event splicing.
- Added tests for pre-initialize credential_disabled emissions and onError propagation of handler failures.
- Replaced auth credential disable flow with CAS checks in #tryDisableAuthCredentialIfMatches and matching SQL statement.
- Retried OAuth getApiKey after disable failures; added peer-rotation race test for fresh token and active credential retention.
- Updated CHANGELOG for deferred microtask flushing plus eval import renames and diff URL/quoted-path parsing fixes.
2026-05-13 05:33:03 +02:00
can1357 db1a3fd7b1 fix(packages/coding-agent): corrected js import rewriting empty AST body
- Added guard for ASTs with no body and trimmed trailing EmptyStatement nodes before final-expression capture.
- Exposed wrapCode via context-manager export for external JS import-rewrite callers.
- Added regression test asserting final-expression wrapping when trailing semicolons follow await.
2026-05-13 05:24:33 +02:00
can1357 218fe8b892 fix(packages/coding-agent): resolved JS display fallback for noncloneable values
- Handled structured-clone failures in JsRuntime.display by falling back to text output.
- Added regression coverage for non-structured-cloneable JS display output.
2026-05-13 05:24:33 +02:00
can1357 fc1ff60294 fix(packages/coding-agent): corrected interactive submit shutdown handling in coding-agent
- Updated submitInteractiveInput to await checkShutdownRequested after submission, avoiding premature teardown (#1020).
- Mapped extension UI shutdown hook to set ctx.shutdownRequested for deferred teardown handling (#1020).
- Added regression coverage for interactive shutdown propagation and issue #1020 teardown behavior.
2026-05-13 05:24:33 +02:00
can1357 a14a2c402c fix(packages/coding-agent): resolved compaction queue plan ordering
- Pinned final plan path before handleCompactCommand so queued messages use approved plan, not draft.
- Added regression coverage for setPlanReferencePath timing before compaction queue flush.
2026-05-13 05:24:33 +02:00
can1357 087124d559 fix(packages/coding-agent): corrected github-cache hard-TTL purge on open
- Removed one-shot eviction in openDb(), preventing cache rows from being purged before settings load.
- Moved hard-TTL enforcement to getOrFetchView() sweepIfDue() so configured retention applies per lookup.
- Extended github-cache tests to verify row persistence across reopen and expiry under stricter hardTtl.
2026-05-13 05:24:33 +02:00
can1357 ecc6d23bed test(packages/coding-agent): updated system-prompt template assertion
- Updated system-prompt test assertion to match revised surgical edit wording.
2026-05-13 05:24:33 +02:00
can1357 724ef3784a chore: fix mentions of read tool in backticks causing confusing against bash read 2026-05-13 05:22:41 +02:00
can1357 c53c63e96d fix(coding-agent/internal-urls): patched numeric host diff path parsing
- Extended short-form diff URL parsing to treat `<scheme>://N/diff` as a diff path across schemes, so `issue://N/diff` now follows the issue no-diff rejection path.
- Kept repository listing behavior unchanged for `<scheme>://owner/diff` by limiting diff short-form disambiguation to numeric hosts.
- Added regression coverage asserting `issue://9/diff`, `issue://9/diff/all`, and `issue://9/diff/3` now reject with the issue no-diff error.
2026-05-13 04:52:27 +02:00
can1357 1ccc56aca6 fix(coding-agent/eval): routed JS import calls through session-aware import helper
- Updated JS import rewriting to route top-level `import` declarations through `__omp_import__` with support for import attributes.
- Added AST traversal to replace `import(...)` call callee nodes with `__omp_import__` so dynamic imports resolve via session-aware helper.
- Updated runtime `__omp_import__` to accept an optional options object and pass it through to `import(target, options)`.
2026-05-13 04:47:49 +02:00
can1357 e70084976b fix(coding-agent): corrected issue-pr diff URL parsing to list outputs
- Fixed `issue://owner/diff` and `pr://owner/diff` parsing so they resolve to issue and PR list outputs.
- Fixed `pr` short-form parsing by requiring `scheme==='pr'` and a numeric host before `diff` matching.
- Fixed PR unified-diff parsing to decode quoted header paths and count `----`/`++++` hunk lines as one deletion/addition.
- Fixed `read` error rendering to emit status blocks with cleaned, range-aware, tab-normalized lines.
- Stopped `github-cache` from chmod-ing existing parent directories, preserving pre-existing permission modes.
2026-05-13 04:39:16 +02:00
can1357 64b4aa1ae0 feat(coding-agent): implemented PR diff URL parsing for pr://<N>/diff
- Replaced `op: pr_diff` with `pr://<N>/diff` URL variants and routed PR diffs through URL parsing.
- Added `readArgsHaveTarget` checks to gate read-call tracking on `path`/`file_path` targets.
- Added auth-key-aware GitHub caching with scoped rows, default auth resolution, and hard-TTL invalidation.
- Added markdown output rendering for read with markdown-cell layout, ANSI-aware truncation, and expand-width cache reuse.
- Updated PR diff and cache tests, replacing deprecated `pr_diff` cases with `/diff` and auth/TLL coverage.
2026-05-13 04:32:16 +02:00
can1357 d483531b6b fix(coding-agent): decoupled internal URL read calls from read tool grouping
- Added readArgsTargetInternalUrl in the read tool group component to detect targets handled by InternalUrlRouter from path or file_path arguments.
- Updated event-controller and UI helper read rendering paths to skip grouping read tool calls when those arguments target internal URLs.
- Passed session cwd and settings into internal URL resolution in read.ts and added tests for internal versus non-internal target detection.
2026-05-13 04:05:23 +02:00
can1357 a733390462 feat: added issue:// and pr:// handlers with sqlite cache ttl refresh
- Added issue:// and pr:// URL handlers for single lookups and list queries with query filters.
- Added a SQLite-backed GitHub cache with soft/hard TTLs, stale hits, and background stale refresh.
- Removed issue_view and pr_view tool operations, inputs, and docs, requiring reads via issue:// and pr:// URLs.
- Added github-cache and issue-pr-protocol tests with temporary cache DB setup and OMP_GITHUB_CACHE_DB teardown.
2026-05-13 04:04:45 +02:00
can1357 569438fdc5 test: drop stale inspect_image guidance assertion 2026-05-13 03:26:05 +02:00
can1357 c27d007828 feat(docs): added NEVER/AVOID guidance to agent/tool/system prompts
- Standardized prompt templates across agents, tools, system, memory, and compaction to NEVER/AVOID wording.
- Reinforced policy language to ban edits/builds, state changes, and unsolicited JSON/code or filler output.
- Renamed stripRfc2119Bold to normalizeRfc2119, mapped NEVER/AVOID aliases, and skipped inline-code replacements.
- Updated the unreleased changelog to document the prompt-terminology migration.
2026-05-13 03:10:39 +02:00
can1357 1d4ea04769 fix(coding-agent): honor path-scoped enabledModels in default fallback
The SDK default-model fallback used `modelRegistry.getAll()` and only
filtered by stored credentials, ignoring the path-scoped `enabledModels`
allow-list. When the configured `modelRoles.default` was filtered out by
`disabledProviders`, the fallback could pick a model from a provider that
`enabledModels` did not permit for the current path.

Add `resolveAllowedModels(modelRegistry, settings, prefs)` which returns
`getAvailable()` intersected with the path-scoped `enabledModels`
patterns (or just `getAvailable()` when no patterns are configured), and
use it for both the default-role resolution and the fallback scan. When
`enabledModels` is set but no allowed model has usable credentials, the
fallback now surfaces a message instead of silently picking a disallowed
provider.

Fixes #1022.
2026-05-13 03:06:22 +02:00
can1357 2654859712 fix(coding-agent): wire ctx.shutdown() to InteractiveMode.shutdownRequested
The extension shutdown context action installed by
ExtensionUiController.initializeHookRunner was an empty stub, so
ctx.shutdown() in interactive mode silently did nothing while extensions
fell back to process.exit(0), bypassing session flush and terminal
restore. Flip InteractiveModeContext.shutdownRequested so the main
loop's existing checkShutdownRequested() drives the graceful path.

Fixes #1020.
2026-05-13 02:58:02 +02:00
can1357 a376cf8205 fix(tools): corrected github tool search parsing for /search/issues responses
- Switched issue and PR search handlers to `gh api /search/issues` with `is:issue`/`is:pr` queries.
- Added REST search response models and mapped issue/code/commit/repo payloads to normalized results.
- Updated code, commit, and repo search parsing to read `{items}` envelopes and convert snake_case fields.
- Fixed merged-PR output state by deriving it from `pull_request.merged_at` in test fixtures.
2026-05-13 02:55:30 +02:00
Can BölükandGitHub f72e7ddbea Merge branch 'main' into feat/plan-mode-approve-compact-context 2026-05-13 02:46:59 +02:00
can1357 3fc8cfc444 Merge PR #998: feat(ai,coding-agent): credential_disabled extension event via multi-subscriber AuthStorage
Converts AuthStorage from a single-subscriber to multi-subscriber model
so the SDK and extensions can both observe credential changes without
clobbering each other, and emits a new credential_disabled event when
storage permanently rejects a credential. Lets extensions prompt
re-auth instead of silently failing the next call.

Reconciliation + mismatch rejection covered for both the SDK and
runSubprocess paths.

Closes #998
2026-05-13 02:29:03 +02:00