Commit Graph

14738 Commits

Author SHA1 Message Date
can1357 2da45f9f9a chore: aligned blocked-todo test, added robomp sandbox scaffolding
- Aligned the blocked-todo reconciliation test with the debounced
  subagent-lifecycle observer on main (fake timers + 100ms advance).
- Carries in-progress robomp queue/sandbox/config scaffolding from the
  shared worktree (.env.example, config.py, queue.py, sandbox.py).
2026-07-23 17:35:35 +02:00
can1357 08be77c483 fix: repaired mis-applied conflict resolutions from title-state merge 2026-07-23 17:34:13 +02:00
can1357 154d4ace9f Merge PR #4448: feat(todo): add blocked status with block/unblock ops (@mattwilkinsonn)
# Conflicts:
#	packages/coding-agent/src/modes/interactive-mode.ts
#	packages/coding-agent/src/prompts/tools/todo.md
2026-07-23 17:32:43 +02:00
can1357 1d2779cf7c docs(coding-agent): added changelog entry for run-state terminal title 2026-07-23 17:31:30 +02:00
can1357 8490654df3 refactor(coding-agent): expressed run state via the title separator instead of prefix glyphs
Kept the bare 'π' brand per owner direction: the separator between the
brand and the session label now carries the state — '>' when it's the
user's turn (idle), animated spinner frames while working, '!' when the
agent is blocked on the user. Disabled ('tui.titleState' off) renders the
pre-state 'π: label' layout. Updated the state/runtime tests to the new
contract.
2026-07-23 17:31:30 +02:00
can1357 e1e5e0b530 fix(coding-agent): kept attention title until the last approval prompt resolved 2026-07-23 17:31:30 +02:00
can1357 0dac3d45b5 Merge PR #4451: feat(coding-agent): reflect agent run state in terminal title (@mattwilkinsonn)
# Conflicts:
#	packages/coding-agent/src/modes/controllers/event-controller.ts
#	packages/coding-agent/src/modes/interactive-mode.ts
2026-07-23 17:31:30 +02:00
can1357 bcd23ee7c1 fix: kept seeded workspace roots lazy until the session file is durable
Seeding additionalDirectories at launch (via --add-dir or the
workspace.additionalDirectories setting) called #rewriteAtomically on a
brand-new session manager, which materialized a header-only JSONL and a
fresh breadcrumb before any assistant output. Launching and exiting with
configured roots therefore created an empty resumable session that
--continue picked over the previous conversation.

Gated all three workspace-directory mutators behind the existing
#shouldHaveSessionFile() lazy-persistence gate (one shared helper), and
made setAdditionalDirectories a no-op when the normalized list is
unchanged so resuming large sessions no longer rewrites the whole JSONL
on every startup. Roots set before the gate is crossed land in the
header with the first durable write; added a regression test.
2026-07-23 17:30:34 +02:00
can1357 26726fdcb9 Merge PR #6255: add dynamic multi-root workspace context (@maatheusgois-dd) 2026-07-23 17:30:33 +02:00
can1357 9d5f158e23 fix(coding-agent): preserved default markdown rendering for internal-URL reads
Gated the read.renderMarkdown opt-in at read time (details tagging) instead
of inside the renderer. The renderer gate silently flipped every
protocol-supplied text/markdown read (skill://, pr://, issue://, history://,
rule://, omp://, agent://, vault://, local://, memory://, ssh://) from the
formatted markdown cell to the raw code cell when the setting was off, which
regressed default TUI behavior. Local file tagging now happens only when the
setting is enabled, so the default render path is byte-identical to the
pre-setting behavior while opt-in previews still work end-to-end.

Also inlined the tautological isMarkdownContentPath wrapper, pinned the
widened prose-summary bypass (.mdx stays verbatim when prose summaries are
off) with a test, and documented it under Changed in the changelog.
2026-07-23 17:30:33 +02:00
can1357 42a3da21de Merge PR #4001: feat(coding-agent): opt-in Markdown read previews (@oldschoola) 2026-07-23 17:30:33 +02:00
can1357 1435f8dbce perf: restored lazy export-module loading by splitting /export arg parsing into export/html/args.ts 2026-07-23 17:30:33 +02:00
can1357 f898e258c5 fix: kept dark export links bright and made light links AA-legible; removed duplicate changelog entry from released 16.5.2 2026-07-23 17:30:33 +02:00
can1357 c76221095f Merge PR #6349: support light, dark, and system themes in HTML exports (@anatoli-tsinovoy) 2026-07-23 17:30:32 +02:00
pr-eval 66f132a6e2 docs(changelog): recorded jj-aware statusline git segment under unreleased 2026-07-23 17:30:32 +02:00
can1357 ed67dfa5e8 Merge PR #4450: feat(statusline): make git segment jj-aware (@mattwilkinsonn) 2026-07-23 17:30:32 +02:00
can1357 09d02c641f fix(coding-agent): closed bash approval rule bypasses
Tested the shell-control guard against the raw command: whitespace
normalization collapsed newlines/CR before the guard ran, so
'git status\nrm file.txt' rode a 'git *' allow rule while bash executed
both lines. Honored tool-owned allow/prompt policies in yolo mode so
per-command prompt rules were no longer silently discarded under the
default approvalMode. Added precision regression tests through the real
matcher (separators, subshells, redirects, env prefixes, path/quoting
variants) that fail on the unfixed head.
2026-07-23 17:30:32 +02:00
can1357 794515fd1a Merge PR #6363: feat(coding-agent): support per-command bash approval rules (@WahidinAji) 2026-07-23 17:30:32 +02:00
can1357 4e78d12428 fixed live queue trim to compact consumed prefix and resync parser 2026-07-23 17:30:15 +02:00
can1357 ebf2b86790 Merge PR #4269: fix(bash): bound interactive bash live display write queue (@metaphorics) 2026-07-23 17:30:15 +02:00
can1357 73b3a2ad53 fix(hindsight): bypassed retention cache on forced retains
Forced retains returned early with an empty incremental slice when no new
messages arrived since the last successful auto-retain, so a user-visible
/memory enqueue rebuild sent nothing and could not recover a deleted or
unmaterialized upstream document. Also removed the public modifier from the
test fake per the root AGENTS.md class-privacy rule and added a forced-retain
resend test.
2026-07-23 17:30:15 +02:00
can1357 0829fc6143 Merge PR #4275: perf(hindsight): cache full-session retention transcript incrementally (@metaphorics) 2026-07-23 17:30:15 +02:00
can1357 2c42715263 fix(compaction): charged pre-archive kept region in rescue budget
Also stamped dead-end warnings before the auto_compaction_end event so the result-driven TUI rebuild shows the badge (Codex round 6 on #6362).
2026-07-23 17:30:15 +02:00
can1357 15f1fb2c7c Merge PR #6362: fix(compaction): rescue snapcompact archives stuck past the maintenance threshold (@HugoLopes45) 2026-07-23 17:30:14 +02:00
can1357 c1451fc05f Merge PR #6380: fix(ai): strip foreign thinking signatures on the latest assistant turn (@LunarECL) 2026-07-23 17:30:14 +02:00
can1357 30a0d67567 removed stray watermark comment markers from usage provider 2026-07-23 17:30:14 +02:00
can1357 0b1e4831f6 Merge PR #6388: fix(ai): SuperGrok usage for unified billing accounts (@musingfox) 2026-07-23 17:30:14 +02:00
can1357 130578aced chore: bump models 2026-07-23 16:42:40 +02:00
can1357 b05cffd0a9 Merge PR #6385: feat(providers): browser OAuth sign-in for Z.AI (GLM Coding Plan) (@cefege) 2026-07-23 16:39:22 +02:00
can1357 a8e81e8427 Merge PR #6386: feat(catalog): add native Meta Model API provider (@eggpeat) 2026-07-23 16:39:21 +02:00
can1357 ffd0ea727f chore: promoted merged changelog entries to unreleased 2026-07-23 16:36:01 +02:00
can1357 b2eedd944f Merge PR #6383: fix: preserve oauth links across wrapped rows (@ondrejsojka) 2026-07-23 16:35:47 +02:00
can1357 da5da41169 Merge PR #6382: feat(ai): report Anthropic extra usage in omp usage (@LunarECL) 2026-07-23 16:35:47 +02:00
musingfox 63535c44c8 fix(ai): show SuperGrok usage for unified billing accounts
#4874 only parsed weekly ?format=credits (creditUsagePercent). Unified
accounts often omit those fields or mark isUnifiedBillingUser while the
default /v1/billing payload still exposes monthlyLimit/used, so omp usage
reported "no usage data". Fall back to and merge the monthly shape.
2026-07-23 22:34:32 +08:00
can1357 fadcd1a650 fix(ai): made credential-pattern redaction opt-in
- Credential-shaped token redaction now requires explicit opt-in via `configureCredentialRedaction` and is disabled by default, so user-supplied credential-like strings reach providers unmodified unless the host enables redaction.
- Wired the `secrets.enabled` ("Hide Secrets") setting to `configureCredentialRedaction` in the coding-agent so the pattern redaction follows the existing secret-obfuscation toggle.
2026-07-23 16:23:08 +02:00
Brent 3b1ba087fe feat: add native Meta Model API provider 2026-07-23 14:15:40 +00:00
LunarECL 4a9ad17298 fix(ai): stop header ingests from sliding the usage-report deadline 2026-07-23 22:26:51 +09:00
LunarECL 2e138ee45d fix(ai): keep header ingests from clearing usage-fetch cooldowns 2026-07-23 22:08:54 +09:00
LunarECL 7f4c3bfba3 fix(ai): keep header-only usage from suppressing full fetch 2026-07-23 21:47:25 +09:00
Ondřej Sojka 5b3cfb4b5f docs: keep wrapped oauth link note under Unreleased 2026-07-23 14:46:44 +02:00
Ondřej Sojka 9bde7217b1 Merge remote-tracking branch 'origin/main' into fix/wrapped-oauth-links 2026-07-23 14:45:59 +02:00
Ondřej Sojka 03686ba32f docs: place wrapped oauth link changelog under Unreleased Fixed 2026-07-23 14:44:03 +02:00
can1357 639bac596d chore: bump version to 17.0.9 2026-07-23 14:40:52 +02:00
can1357 0babb55fbd ci: retried test chunks when bun crashes due to GC bugs
- Detect bun crash exits (signals 132-139) and retry up to MAX_CHUNK_ATTEMPTS in a fresh heap.
- Add `retries` field to ChunkOutcome and surface crash retries in progress output.
- Fix test assertion expecting `stopReason: "aborted"` to use `toolUse` (aborted turns are dropped from context).
2026-07-23 14:40:28 +02:00
black lodge resident a04488abff Merge remote-tracking branch 'origin/main' into pr-6383 2026-07-23 14:30:30 +02:00
LunarECL e7fdc99afd feat(ai): report Anthropic extra usage 2026-07-23 21:25:15 +09:00
Hugo Lopes d8554c92d0 fix(compaction): charge the kept tail in the rescue budget and badge the active entry
Review follow-ups (Codex on #6362, round 5):
- #computeSnapcompactRescueMaxFrames now subtracts the kept tail AFTER the
  archive (plus the existing fixed-context reserves) so the budget mirrors
  what #compactionCreatedHeadroom will measure, and returns 0 when not even
  one frame fits — the rescue bails instead of appending a rebuild that can
  never create headroom (and would wedge prepareCompaction behind its
  last-entry guard once elide fixes the real tail).
- Dead-end warnings now stamp the branch's LATEST compaction entry: the
  post-pass path no longer badges the entry the rescue just superseded, and
  the no-preparation path badges the rebuilt entry when the rescue appended
  without creating headroom.

Claude-Session: https://claude.ai/code/session_014rh4JyWFkxgMhgFaEf8VBY
2026-07-23 14:03:12 +02:00
Mihai f1e70be886 feat(providers): browser OAuth sign-in for Z.AI (GLM Coding Plan)
Adds a login-only `zai-coding-plan` provider that runs the ZCode
"Individual Plan" browser sign-in (authorize on chat.z.ai -> token
exchange -> business login -> mint a durable `id.secret` key) and
stores the minted key under the existing `zai` provider via
`storeCredentialsAs`, so `zai`'s models and `zaiUsageProvider` apply
with no model or catalog changes. Mirrors the existing
`openai-codex-device => openai-codex` pattern.

The flow is built on `OAuthCallbackFlow` (loopback callback on port
54548, plus a paste-redirect fallback via `pasteCodeFlow`) and returns
`OAuthCredentials` with the minted key in `access`; `getOAuthApiKey`
returns it verbatim as the request bearer for `zai`. `zaiUsageProvider`
is widened to accept both `api_key` (paste) and `oauth` (sign-in)
credentials so `/usage` renders Z.AI quota for both login paths.

Strictly additive: the existing paste-key `zai` and `zhipu-coding-plan`
logins are unchanged.

Tests: full authorize -> token -> biz-login -> key-mint walk (find +
create), and `zaiUsageProvider` covering both credential types.
2026-07-23 14:42:15 +03:00
LunarECL 5795515af2 fix(ai): strip foreign thinking signatures on the latest assistant turn
Switching models into a signing Anthropic endpoint while the latest
surviving assistant turn came from a different anthropic-messages
provider (e.g. kimi-code/k3) replayed that turn's foreign thinking
signature verbatim: the cross-model signature strip in
transformMessages was gated on !isLatestSurvivingAssistant and the
latest-abandoned byte-for-byte exemption was unconditional, so every
request 400'd with `Invalid signature in thinking block` and the
session wedged onto its fallback model until a fallback turn completed
and the poisoned turn stopped being latest.

The latest turn now strips signatures whose issuing provider differs
from the target provider — Anthropic's byte-for-byte rule only covers
the target provider's own latest response — while same-provider
cross-model-id switches keep their byte-for-byte latest turn (pinned
by anthropic-prefill). Foreign redacted_thinking siblings are dropped
alongside instead of riding the wire unverifiable.

Fixes #6379
2026-07-23 20:41:43 +09:00
can1357 0f54c0df70 fix(tools): autoqa consent handling from default off to opt-in 2026-07-23 13:24:45 +02:00