Commit Graph

4378 Commits

Author SHA1 Message Date
can1357 3b60edd276 refactor(coding-agent/tools): removed output schema evaluator and simplified validator handling
- Deleted the `ValidationVerdict` type and `evaluateOutputAgainstSchema` API from the output schema validator.
- Updated `yield.ts` to bind `buildOutputValidator`'s error directly to `schemaError` during validator setup.
- Removed the obsolete evaluator tests and adjusted validation success fixture to match the raw summary input shape.
2026-05-26 07:28:42 +02:00
can1357 e0eae43fde feat(tools): added shared output schema validator for YieldTool
- Unified output schema construction and validation by adding buildOutputValidator and using it in YieldTool and task executor.
- Added MAX_SCHEMA_RETRIES so YieldTool now retries schema failures three times with hints before overriding.
- Updated failure handling to use shared summarizeValidationFailure and formatters for required-field reporting.
- Added tests for output-schema-validator and YieldTool covering malformed schemas and nested-array retry edge cases.
2026-05-26 06:34:30 +02:00
can1357 27cc5a077b fix(ai,coding-agent): close OAuth lifecycle gaps from the AuthStorage rework
Centralizing OAuth refresh in AuthStorage (e6893515) introduced five
follow-on bugs surfaced by an audit of the commit; this fixes all of
them and updates the tests that relied on the old refresh seam.

1. packages/ai/src/auth-storage.ts (#tryOAuthCredential):
   For built-in providers the path went directly to `getOAuthApiKey`
   with the (possibly still-expired) selection.credential when the
   pre-refresh at line 2587 caught a transient error. `getOAuthApiKey`
   then threw the "expired … must be refreshed via AuthStorage"
   precondition error, which the disable classifier matched against
   `/expired.*refresh/` and soft-disabled the row. A single network
   blip during refresh could permanently kill a still-valid Anthropic /
   OpenAI / Gemini-CLI / Copilot credential. Built-in providers now
   route through the broker-aware single-flighted
   `#refreshOAuthCredential` first, so transient failures surface as
   network errors (5-min temp block) instead of definitive auth
   failures.

2. packages/ai/src/auth-storage.ts (#fetchUsageUncached):
   The usage refresh check only fired once `Date.now() >= expiresAt`,
   missing the 60-second skew that `getApiKey` honors. A token
   expiring inside the skew window was posted to the usage endpoint
   and 401'd mid-flight, briefly hiding quota in the UI. Aligned with
   `OAUTH_REFRESH_SKEW_MS`.

3. packages/coding-agent/src/web/search/index.ts (webSearchCustomTool):
   The CustomTool counterpart of WebSearchTool dropped sessionId so
   SDK callers that opted into `web_search` via toolNames lost
   per-session credential stickiness — multi-account users saw the
   provider round-robin between searches in the same session. Threads
   `ctx.sessionManager.getSessionId()` through to `executeSearch`.

4. packages/coding-agent/src/web/search/providers/perplexity.ts
   (findOAuthToken):
   `authStorage.getApiKey("perplexity")` returns runtime/config
   overrides, stored api_key credentials, OAuth bearers, and env keys.
   Filtering only env keys meant a config-pinned `pplx-…` API key was
   POSTed to `www.perplexity.ai/rest/sse/perplexity_ask` (the OAuth
   endpoint) instead of falling through to
   `api.perplexity.ai/chat/completions`, producing 401s. Switched to
   `getOAuthAccess` so only true OAuth bearers reach the OAuth
   branch; api_key credentials/overrides correctly fall through.

5. packages/ai/scripts/generate-models.ts:
   `getOAuthApiKey` was being called directly with possibly-expired
   credentials. The new contract throws on expired, the broad catch
   swallowed it, and the build silently fell back to bundled models
   instead of refreshing. Both helpers now route through
   AuthStorage's `getApiKey` / `getOAuthAccess`, which trigger the
   full broker-aware refresh pipeline.

Test updates:
- auth-storage-credential-disabled-event.test.ts,
  sdk-credential-disabled-bridge.test.ts: the `failOAuthRefresh`
  helper used to spy on `getOAuthApiKey` to inject invalid_grant.
  With refresh now happening before that helper, the spy never fired.
  Switched to spying on `refreshOAuthToken` so the simulated failure
  reaches the disable classifier.
- auth-storage-rotation.test.ts: stub `refreshOAuthToken` so the test
  doesn't hit a real OAuth endpoint when the seeded credential lands
  inside the 60s skew window.
2026-05-26 05:32:47 +02:00
roboomp 0a3a48b92d fix(task): respected parent lsp disable for subagents
Combined task.enableLsp with the parent session enableLsp gate before spawning subagents, so --no-lsp remains authoritative even when subagent LSP is enabled in settings.

Fixes #1385
2026-05-26 03:13:28 +00:00
roboomp 28a0dc3ae4 feat(task): gated subagent LSP behind task.enableLsp setting
Added task.enableLsp (boolean, default false) and routed both regular and isolated subagent dispatch through it. Keeps subagents cheap by default while letting users opt in to LSP-aware delegation. Updated regression tests to cover the default-off, opt-in, plan-mode, and isolated paths.

Fixes #1385
2026-05-26 03:09:09 +00:00
roboomp 8948101e2b fix(task): forwarded parent enableLsp flag to subagents
Subagents now inherit the parent session's enableLsp value, so a top-level --no-lsp invocation propagates into spawned tasks instead of falling back to the executor's default of true.

Fixes #1385
2026-05-26 03:06:14 +00:00
roboomp 5ff1c747ce fix(task): inherited lsp for subagents
Removed the hardcoded subagent LSP disable flag so executor defaults and user settings control LSP availability. Passed the effective plan-mode agent definition into both regular and isolated subagent dispatch so plan-mode tool restrictions apply consistently.

Fixes #1385
2026-05-26 03:01:57 +00:00
can1357 d56c7fcfa8 fix(test): rewrite Kimi issue #957 test for new AuthStorage refresh flow
- packages/ai/test/issue-957-repro.test.ts now tests:
  - refreshKimiToken applies the 5-minute server-side skew (Kimi-specific)
  - AuthStorage refreshes kimi-code credentials inside its 60s skew window
- packages/ai/test/anthropic-stream-timeout.test.ts: raise the
  streamFirstEventTimeoutMs from 10ms to 5000ms so slow CI scheduling
  cannot fire the first-event watchdog before the mocked events arrive.
  The test still exercises the (1ms) idle path it was written for.

fix(web): allow Parallel extract via PARALLEL_API_KEY env var without storage

The fetch tool and YouTube scraper previously gated the Parallel extract
branch behind `storage && findParallelApiKey(storage)`. With no
AgentStorage the env key was never consulted, so callers that ran
without a per-session storage (e.g. ReadTool sessions in unit tests, and
in practice any caller that has only an env API key) silently fell back
to raw-html / no-ytdlp paths.

- findCredential/findParallelApiKey now accept null or undefined storage
  and rely solely on the env-first path when no storage is supplied.
- searchWithParallel/extractWithParallel mirror the same nullable shape.
- Drop the redundant `storage && ` guards in fetch.ts and youtube.ts;
  the inner findParallelApiKey call already returns null when no
  credential is available.
2026-05-26 04:50:01 +02:00
can1357 8f6e1fa0dc Merge remote-tracking branch 'origin/farm/9ad9de48/fix-explore-agent-ref-jtd-keyword' 2026-05-26 04:36:34 +02:00
can1357 e689351597 fix(coding-agent): resolved OAuth token expiry flow in AuthStorage
- Centralized OAuth access lifecycle in `AuthStorage`, returning identity metadata and new access-result types.
- Added 60-second skew and strict expiry checks, returning undefined/throws for stale or expired OAuth credentials.
- Removed provider-local token refresh flows from Gemini, Gemini CLI, Antigravity, Kimi, and related OAuth helpers.
- Migrated web-search providers from `AgentStorage` to `AuthStorage` session-aware lookup with `authStorage`/`sessionId`/`signal` flow.
- Replaced `findAnthropicAuth`/DB auth lookup with `buildAnthropicAuthConfig` and explicit base-url override/env fallback ordering.
2026-05-26 03:59:13 +02:00
roboomp aa6dbc9c83 fix(coding-agent/prompts): renamed explore agent output ref field to path
`ref` is a JTD-reserved keyword (RFC 8927) used by the schema-reference
form, so the JTD-to-JSON-Schema converter on releases prior to 15.3.2
silently dropped it from the generated JSON Schema and required it at
the same time. Every explore-agent invocation then failed validation
with `schema_violation: files.0.ref: must not be present`.

The converter side was hardened in #1345 (shipped in 15.3.2). This
rename is defense-in-depth at the prompt level: the explore agent's
output contract no longer relies on the converter recognising a
user-named property that collides with a JTD keyword, and the field
name now matches what it actually carries.

Fixes #1379
2026-05-25 22:58:16 +00:00
can1357 cfabeeb17c feat(web): added Codex and Gemini web search providers with shared AgentStorage flow
- Added OpenAI Codex and Gemini web search provider options with updated setup/auth descriptions.
- Updated Codex OAuth flow to refresh near-expiry tokens during web_search and persist the refreshed credentials.
- Plumbed AgentStorage through search orchestrator, scrapers, and fetch paths so providers share session credentials.
- Refactored web provider and credential helpers to accept caller-provided AgentStorage and resolve keys synchronously.
2026-05-25 21:21:13 +02:00
Can Bölük d201442a16 Merge pull request #1372 from can1357/farm/e4c67c73/fix-subagent-session-start-busy
fix(agent): prevent subagent session_start busy race
2026-05-25 21:59:38 +03:00
Can Bölük 8b4525e869 Merge branch 'main' into farm/70c1e455/bash 2026-05-25 21:56:06 +03:00
roboomp 23300d0348 fix(bash): quarantined stalled shell sessions
Quarantined persistent session keys only while the native cancellation promise remains unsettled, so healthy cleanup restores persistent mode and stalled cleanup cannot accumulate live shell instances.

Added coverage for both stalled and settled native cleanup paths.

Fixes #1347
2026-05-25 18:48:20 +00:00
roboomp 1217091557 fix(agent): prevented subagent session_start busy race
Queued extension-delivered user messages when deliverAs is set and waited for session_start extension message sends before prompting subagents.

Fixes #1343
2026-05-25 18:48:06 +00:00
Can Bölük 47dab57559 Merge branch 'main' into farm/5c2ff3c3/report-finding-tool-agent-output-schema- 2026-05-25 21:42:35 +03:00
roboomp 8e5c7c9bf1 fix(bash): kept persistent shells after cancel
Stopped marking persistent bash sessions as permanently broken when the JavaScript abort or timeout race wins.

Stopped the Rust descendant kill-wave helper once no cancellation targets remain so later commands are not swept into old cancels.

Fixes #1347
2026-05-25 18:40:22 +00:00
can1357 7acc631ce9 chore: bump version to 15.3.2 2026-05-25 20:30:37 +02:00
can1357 a7af3900bd feat(coding-agent/task): added parent-aware labels to nested live task snapshots
- Updated nested task-rendering tests to use parent-qualified IDs for completed child task results.
- Updated in-flight nested snapshot expectations to verify parent-aware `Parent>Subtask` labeling.
- Documented the live nested task rendering behavior in the package changelog.
2026-05-25 20:27:22 +02:00
can1357 b464719208 Revert "fix(coding-agent): drop hash anchor when a displayed line was truncated"
This reverts commit 0d80a01280.
2026-05-25 20:26:56 +02:00
can1357 a5275b17ce feat(coding-agent): added hashline inline |TEXT matching for BOF/EOF
- Added inline `|TEXT` payload parsing for `"/"` before/after inserts, including BOF/EOF usage.
- Fixed inline anchor handling by resolving matching `|TEXT` bodies and handling whitespace-containing payloads.
- Added parser tests for `applyDiff` and `parseHashline` covering whitespace, matching, and non-matching inline `|TEXT`.
- Added nested live task fixtures and snapshot tests for ordered in-flight and completed child rendering.
- Documented hashline inline `|TEXT` behavior updates in CHANGELOG.
2026-05-25 20:24:44 +02:00
can1357 3105870c86 feat(coding-agent/task): added live nested-subagent progress rendering
- Captured `tool_execution_update` snapshots for `task` calls into in-flight progress state for live nested rendering.
- Cleared in-flight task snapshots at task start and completion to prevent stale nested progress from persisting.
- Updated progress rendering to combine completed and in-flight task details through a dedicated nested task tree view.
2026-05-25 20:21:24 +02:00
roboomp 14c7ddf7d0 fix(bash): returned on stalled cancellation
Raced bash execution against the JavaScript abort signal and timeout so the tool returns even when native shell cleanup does not settle.

Added regression coverage for native cleanup stalls on ESC abort and timeout.

Fixes #1347
2026-05-25 18:03:09 +00:00
roboomp 6e9cf81544 style: bun run fix 2026-05-25 18:01:45 +00:00
roboomp 6b14cf1f55 fix(coding-agent): coerced report_finding string priority to number for reviewer schema
The report_finding tool's priority is exposed as a string enum
("P0"-"P3") for ergonomics, but the reviewer agent and every
custom review agent declare priority as `type: number` in their
JTD output schema. The cast at executor.ts:1473 lied about the
runtime shape, so the auto-injected `findings[].priority` flowed
through as strings and every yield with at least one finding was
rejected with `findings.0.priority: expected number, received string`,
forcing the run into the schema_violation exit path.

Added `toReviewFinding(details)` in tools/review.ts that maps the
priority enum to its numeric ordinal via the existing PRIORITY_INFO
table and use it at the boundary in executor.ts. Render paths still
see the original `ReportFindingDetails` shape (string priority)
through normalizeReportFindings, so display formatting is unaffected.

Fixes #1350
2026-05-25 18:01:38 +00:00
can1357 53c1494d42 fix(ai): added session-aware OAuth credential invalidation
- Extended `invalidateCredentialMatching` to accept session-scoped options and clear cached session credentials before blocking the matched credential.
- Updated the OAuth auth-error retry flow to pass `agent.sessionId` through credential invalidation.
- Added a regression test ensuring invalidating a session-sticky OAuth key rotates to the next active credential.
2026-05-25 19:59:11 +02:00
can1357 2ad7124e25 feat(ai): added tri-state credential checks in auth-gateway check flow
- Added `checkCredentials()` with result types/options for per-credential tri-state health checks.
- Added `/v1/credentials/check` endpoint via `handleCredentialsCheck` returning `{ generatedAt, credentials }`.
- Added `omp auth-gateway check` flow with provider grouping, `--json` output, and exit status 1 on failures.
- Added command examples, changelog updates, and tests for expired OAuth refresh, null/missing config, and ordering edge cases.
2026-05-25 19:53:58 +02:00
Can Bölük a40864c5b2 Merge branch 'main' into farm/ccf5d9fd/csharp-lsp-plugin-doesn-t-work-with-omp- 2026-05-25 20:37:30 +03:00
roboomp 24b249219e fix(lsp): supported config-only marketplace servers
Loaded marketplace lspServers metadata from Claude plugin caches and embedded it for OMP marketplace installs so config-only plugins register without package code.

Fixes #1352
2026-05-25 17:34:32 +00:00
Can Bölük 29d0e3a470 Merge branch 'main' into farm/b4be9197/task-explore-agent-fails-with-schema-vio 2026-05-25 20:27:22 +03:00
roboomp ef68db17f5 fix(coding-agent/tools): stopped re-walking JTD-converted JSON Schema for nested JTD detection
The JTD-to-JSON-Schema converter post-processed convertSchema's
output with normalizeMixedSchemaNode, which walked back into the
emitted JSON Schema looking for nested JTD forms. Inside a
properties block, user-defined property names whose keys happened
to collide with JTD keywords ('ref', 'elements', 'values',
'optionalProperties', 'discriminator') were misclassified as JTD
forms and re-rewritten - corrupting properties like { ref: { type:
'string' } } into { $ref: '#/$defs/[object Object]' } and breaking
the built-in explore agent's output validator with
schema_violation: files.0.ref: must not be present.

convertSchema is already fully recursive and emits pure JSON Schema,
so the post-walk is both unnecessary and unsafe. Drop it.

Fixes #1345
2026-05-25 17:21:53 +00:00
can1357 e2b86b8a41 chore: bump version to 15.3.1 2026-05-25 14:07:16 +02:00
can1357 80186e341c feat(agent): threaded intentTracing option through append-only context
- Exported `normalizeTools` so `AppendOnlyContext` uses the same tool normalization as the agent loop.
- Added `BuildOptions.intentTracing` to `build()`/`reset()`/`takeSnapshot()` so intent injection is consistent and included in the prefix fingerprint.
- Improved `#computeDigest` to cover tool_calls, tool_call_id, name, and id fields to catch in-place mutations.
- Fixed `#unsubscribeAppendOnly` leak and added no-op guard in `#syncAppendOnlyContext`.
2026-05-25 14:06:44 +02:00
can1357 079d18a82b fix(model-registry): fixed tp- token-plan baseUrl lost during discovery merge
- Extracted `mergeDiscoveredModel` so discovered baseUrl takes priority over bundled entry, fixing 401s on Xiaomi tp- token-plan streams.
- User providerOverride.baseUrl still wins over both discovered and bundled values.
- Added regression tests covering all merge priority paths.
2026-05-25 14:06:13 +02:00
can1357 d6acef8b76 perf(status-line): replaced index-based token cache with message sidecar cache
- Added Symbol-keyed sidecar on each AgentMessage to memoize estimateTokens, with a cheap content fingerprint to detect in-place mutations.
- Fixed stale cache on same-length replaceMessages, post-hoc error attachment, and branch rebuild edge cases.
- Fixed usage fetch error backoff: stamped fetchedAt on failure so the 5-min TTL also gates retries during outages.
- Extracted computeNonMessageBreakdown as shared helper to prevent drift between status-line and context panel token counts.
2026-05-25 14:06:05 +02:00
can1357 8e3e4fd5f0 fix(slash-commands): captured mode state before handler call for history
- Fixed /plan and /goal history preservation by snapshotting enabled state before handlePlanModeCommand/handleGoalModeCommand executes.
- Previous check read state after the call, missing cases where the handler itself toggled the mode off (e.g., confirmed exit).
- Added tests covering confirm-exit, cancel-exit, and first-activation paths.
2026-05-25 14:05:55 +02:00
can1357 81cec1c38b fix(clipboard): hardened WSL PowerShell fallback for headless environments
- Raised PowerShell timeout to 8s and swallowed reap errors to prevent unhandled throws on WSL interop.
- Fixed fallback logic so arboard is skipped when no display server is present on headless WSL.
- Added test coverage for the headless WSL short-circuit path.
2026-05-25 14:05:48 +02:00
can1357 79f6bf4f76 fix(session-manager): added orphaned backup recovery after EPERM rename
- Added `recoverOrphanedBackups` to promote `.jsonl..bak` files back to their primary path when the primary is missing, preventing data loss after a mid-rename crash.
- Changed backup filename from dot-prefixed to plain `..bak` so the shared `*.bak` glob can find it on both real and in-memory storage backends.
- Surfaced the original EPERM as the error `cause` and included both original and retry messages when rollback also fails.
2026-05-25 14:05:41 +02:00
can1357 975c836015 fix(image-resize): deferred OMP_NO_WEBP evaluation to call time
- Replaced baked module-load value with per-call `isWebPExcluded()` so runtime env changes take effect.
- Only `"1"` and `"true"` (case-insensitive) enable exclusion; empty string and `"0"` are treated as disabled.
- Fast path now bypassed for WebP sources when exclusion is active.
- Explicit error surfaced when decode fails and WebP exclusion cannot be honored.
2026-05-25 14:05:31 +02:00
can1357 e5bc511392 edit(hashline): leniently parse anchors with trailing |TEXT body and read/search decoration
Anchors are formatted by read/search as LINE+HASH|TEXT, and lines may be
prefixed with marker decoration (*, >, +, -). The parser previously required
a bare LINE+HASH and rejected verbatim copy-pasted anchors with:

  line N: expected a full anchor such as "119sr", ...; got "364sp|".

Loosen LID_CAPTURE_RE to allow optional leading decoration and an optional
trailing |... body on each anchor (including each side of a range).
2026-05-25 13:36:44 +02:00
can1357 45345f43b0 chore: bump version to 15.3.0 2026-05-25 12:56:19 +02:00
can1357 1b58e484ab chore(coding-agent): remove unused status-line segment editor 2026-05-25 12:55:48 +02:00
can1357 5eec35367f chore: fix types 2026-05-25 12:42:26 +02:00
can1357 3801b4ee32 fix(coding-agent): added configurable retry delay cap and surfaced rate-limit failure state
- Added `retry.maxDelayMs` to the settings schema and interfaces, with a default cap for provider backoff delays.
- Updated session auto-retry logic to fail fast when a requested wait exceeds the cap without fallback, emitting terminal auto-retry failure state.
- Propagated retry state and failure data into task progress and rendering so children show retry/wait details and reminder prompts stop after terminal errors.
2026-05-25 12:37:32 +02:00
roboomp 294f0067d0 fix(tui): refreshed model tabs by provider id
Separated model selector provider tab labels from provider ids so human-readable labels like Ollama Cloud refresh and filter the underlying ollama-cloud models.

Fixes #1153
2026-05-25 12:25:12 +02:00
roboomp a2032850e5 fix(legacy-pi-compat): fall back to peer deps when resolveSync fails in binary mode
In a compiled binary, Bun.resolveSync(spec, import.meta.dir) throws
'Cannot find module' because import.meta.dir is inside /$bunfs/root
and the virtual FS exposes no node_modules tree at runtime.

Previously this throw propagated through rewriteLegacyPiImports ->
rewriteLegacyPiImportsForRuntime -> mirrorLegacyPiFile ->
loadLegacyPiModule -> loadExtension, which swallowed it as 'Failed to
load extension' and silently dropped any plugin whose files imported
@mariozechner/pi-ai (or any @mariozechner/pi-* whose bundled
counterpart isn't reachable via resolveSync in the binary).

Fix: wrap the resolution call in rewriteLegacyPiImports in a try/catch
and return the original match on failure. rewriteBareImportsForLegacyExtension
runs immediately afterwards in every call path and already resolves bare
specifiers against the importer's real filesystem directory, so it picks
up @mariozechner/pi-ai from the plugin's installed peer deps instead.

Apply the same fallback to resolveLegacyPiSpecifier (the Bun plugin
shim's onResolve handler) for tool/hook files loaded directly via Bun's
import system rather than through loadLegacyPiModule.

Fixes #1215
2026-05-25 12:22:57 +02:00
can1357 8e74996513 chore: adjust tests 2026-05-25 12:22:43 +02:00
Can Bölük 1084a854f8 Merge pull request #1296 from can1357/farm/93902d04/goal-set-rejects-active-goals-but-clears
fix(cli): allow /goal set to replace active goals
2026-05-25 13:20:46 +03:00
Can Bölük e4165a41e6 Merge branch 'main' into farm/bfe680ee/ctx-ui-notify-during-session-start-is-cl 2026-05-25 13:20:04 +03:00