Commit Graph

473 Commits

Author SHA1 Message Date
can1357 a10fe079ce fix(coding-agent): suppressed credential disable tombstones for active accounts
- Update isActionableDisable in usage-cli.ts to accept active accounts and check identity matches.
- Suppress credential disable tombstones when an active account exists for the same provider and identity.
- Add test coverage for suppressing tombstones when active accounts share the same identity.
2026-07-28 11:47:08 +02:00
can1357 c7b10c3340 Merge PR #6763: fix(cli): preserve live task-isolation sandboxes on worktree clear (@roboomp) 2026-07-28 10:59:37 +02:00
roboomp 7f4f322c73 fix(cli): wrap streaming-phase download timeout with friendly message
downloadVerifiedBinary only wrapped isTimeoutError around the fetch()
catch, so a 15-minute timeout firing while pipeline() streamed the
response body re-threw the raw "TimeoutError: The operation timed out."
Mirror the wrap into the pipeline catch after cleaning up the partial
file, matching the connection-phase message.

Fixes #6822
2026-07-27 18:19:54 +00:00
can1357 d16a251777 chore: reorg tests 2026-07-27 16:43:53 +02:00
can1357 41ce810cff fix(mcp): preserved native resource URIs and opaque scheme routing
- Native (non-mcp://) resource URIs now pass through byte-for-byte via
  rawHref; slash elision applies only to the legacy mcp:// wrapper, so
  catalog://root/ style URIs match exact-equality server lookups.
- resources/templates/list failure no longer discards a successful
  resources/list (Promise.allSettled; templates retried later).
- Opaque RFC 3986 URIs (urn:doc, custom:item) are recognized by both
  the router and read-cli discovery gates, with drive-path and
  read-selector false positives guarded.
- Review follow-up for PR #6790.
2026-07-27 16:15:02 +02:00
Dongmen Laohu 2c77c8535a fix(mcp): resolve native resource URIs 2026-07-27 18:59:12 +08:00
roboomp 91c0feaa87 fix(cli): recognize isolation marker before mount exists
The setup window between writeIsolationOwner and isoStart left the base
dir holding only the marker file and no `m` mount, so classifyDir
returned null and scanWorktrees classified it as a stray — which a
non-`--all` clear removes, defeating the ownership guard mid-setup.

classifyDir now treats the presence of the ownership marker as a
task-isolation signal (in addition to the mount dir), so an in-progress
sandbox with a live owner is preserved throughout backend setup.

Fixes #6761
2026-07-27 03:47:20 +00:00
roboomp eeca809193 fix(cli): preserve live task-isolation sandboxes on worktree clear
`omp worktree clear` (without `--all`) removed every task-isolation dir
under the worktree base, including sandboxes owned by subagents running
right now, and the "no live task owns it" reason was asserted from the
mere presence of the `m` mount dir with no ownership check.

`ensureIsolation` now stamps each sandbox base dir with a pid-bearing
ownership marker before the backend materialises `m`, and the worktree
scanner classifies a sandbox as live while its owning process is alive,
so `clear` reclaims only crashed leftovers.

Fixes #6761
2026-07-27 03:42:33 +00:00
Ant39140 20d96304f2 fix(coding-agent): prevented invalid configs from being overwritten
- Treated missing files separately from malformed or unreadable configs.
- Backed up malformed YAML and wrote settings atomically without dropping pending changes.
- Reported success only after saving, with regression tests for global and project configs.
2026-07-27 03:26:40 +08:00
can1357 713856c9e0 Merge PR #6557: fix(update): verify GitHub release asset and digest (@rvagg) 2026-07-26 15:45:31 +02:00
can1357 4892f48493 Merge PR #6618: fix(coding-agent): source auth-gateway catalog from ModelRegistry (@roboomp) 2026-07-26 15:41:31 +02:00
can1357 97ea63920b fix(coding-agent): keep bun/npm routing for regular-file entries on Windows
Bun's global bin entry on Windows is a regular-file .exe shim, not a
symlink, so the standalone-binary override would have rerouted a
legitimate bun-managed install to in-place binary replacement and
clobbered the shim. Gate the override on POSIX, where package-manager
bin entries are always symlinks; add a regression test.
2026-07-26 15:41:30 +02:00
can1357 e0c26cc262 Merge PR #6527: fix(coding-agent): self-update binary install when its dir overlaps npm/bun bin dir (@am423) 2026-07-26 15:41:29 +02:00
can1357 5aa599f9ac fix(cli): treat cleared (empty-string) credentials as unset in config list
The settings panel persists "" when a credential is cleared and renders
that as unset; config list now uses the same semantics instead of
masking the empty string as a configured credential.
2026-07-26 15:41:29 +02:00
Wolfgang Schoenberger 3e1679f584 fix(cli): keep the Hindsight URL readable and redact only set credentials
The credential pass marked `hindsight.apiUrl` secret instead of
`hindsight.apiToken`: both share `condition: "hindsightActive"` and the flag
landed on the wrong one, so the settings panel masked an ordinary endpoint. The
token keeps its masking through the `credential` marker.

`config list` also redacted on classification alone, so a fresh configuration
reported every unset credential as though one were stored. Redaction now
depends on a value being present.

The suite asserted classification and panel metadata only, so both output
branches could be deleted while every test passed, which is how the wrong flag
shipped. It now drives `runConfigCommand` and reads the real human and JSON
output.
2026-07-26 02:58:38 -07:00
Wolfgang Schoenberger 914afc0d6c fix(cli): redact credential settings in config list
omp config list printed every configured value, including auth.broker.token,
searxng.token, searxng.basicPassword and dev.autoqaPush.token, in both the
human and --json output. Nobody asked for those specific credentials; the
command dumps everything.

Credentials are marked with a top-level credential flag rather than ui.secret,
because four of them have no settings-panel entry and so have nowhere to put a
UI-level flag. isCredential is the single accessor both the CLI and the panel
consult, so the two spellings cannot produce different behaviour on different
surfaces.

Human output shows dots. JSON omits value and marks the entry redacted instead
of substituting a placeholder, which a consumer could not distinguish from a
real value and might write back.

config get <path> is deliberately unchanged: that is an explicit request for a
single value, and masking it would break a retrieval API with no way to read
your own token back.
2026-07-26 02:58:38 -07:00
can1357 667111575e feat: implemented credential lifecycle tracking and management APIs
- Added `listDisabledCredentials` and `refreshSnapshot` methods to credential stores along with API endpoints and wire schemas.
- Added `authorizedAt` timestamps and Anthropic OAuth grant TTL constants to track credential lifecycles.
- Updated the usage CLI to render auto-disabled credential tombstones and grant expiration warnings.
- Added comprehensive unit and broker integration tests covering the new credential management features.
2026-07-25 18:02:43 +02:00
roboomp 576bb548a0 fix(coding-agent): isolated gateway catalog from local model config
The pi-native-only filter still let any non-pi-native models.yml provider override (baseUrl/apiKey/headers) reach the broker-backed gateway: config keys shadowed broker credentials (bypassing account pooling, refresh, and accounting) and a custom baseUrl redirected the broker bearer to a configured endpoint. Generalized the flag to ignoreLocalModelConfig, which short-circuits loadCustomModels so the gateway serves bundled plus broker-discovered catalog metadata only, applying no local overrides, config API keys, custom models, or custom discovery.

Fixes #6615
2026-07-25 13:42:41 +00:00
roboomp 4362598cf8 fix(coding-agent): prevented auth-gateway self-routing
Gateway catalog construction now ignores models.yml provider entries whose transport is pi-native. This keeps the registry's bundled, cached, and upstream-discovered models while preventing client-side gateway base URLs and bearer keys from being applied to server-side dispatch.

Added a regression test proving a normal client registry retains pi-native routing while the gateway registry restores the bundled provider route before indexing the model.

Fixes #6615
2026-07-25 13:33:45 +00:00
roboomp df3018e89b fix(coding-agent): source auth-gateway catalog from ModelRegistry
runServe built /v1/models and the resolveModel behind /v1/chat/completions from getBundledModels only, freezing the gateway catalog on the compiled-in snapshot. Every discovery-only model omp itself reaches (ids released after the build date) was unroutable through the gateway while the same broker credential answered it in the TUI.

Source the catalog from ModelRegistry (bundled + cached + discovered) like every other omp surface, via a shared indexModelsByRequestId helper that preserves the credential scoping and qualified/bare-id registration. Rebuild it every 15m so a long-lived serve tracks newly discovered models without a restart; a failed refresh keeps serving the previous catalog.

Fixes #6615
2026-07-25 13:22:32 +00:00
Rod Vagg e20af5b49d fix(update): optionally use GITHUB_TOKEN | GH_TOKEN when calling GH 2026-07-25 10:41:15 +10:00
Rod Vagg 17a62618ad fix(update): verify release binary digests 2026-07-25 10:12:30 +10:00
mr-r0b0t 82e2a9fd63 fix(coding-agent): self-update binary install when its dir overlaps npm/bun bin dir
resolveUpdateMethod classified the install purely by directory containment,
so a standalone binary placed where `npm prefix -g` / `bun pm bin -g` also
points (e.g. ~/.local/bin) was misrouted to `npm install -g`, which then
aborted with EEXIST refusing to overwrite the existing regular file. Now a
plain executable (not a symlink) inside a package-manager bin dir is treated
as the standalone binary and self-updated in place.
2026-07-24 10:43:55 -05:00
can1357 e0509d5d62 fix(coding-agent): preserve bench catalog-first resolution 2026-07-24 16:26:59 +02:00
can1357 457d735475 Merge PR #6509: fix(coding-agent): honor modelRoles.default over cursor/default catalog id (@roboomp) 2026-07-24 16:26:48 +02:00
can1357 5acdefc7b3 feat(coding-agent/web): introduced structured web-search query parsing module
- Implemented a structured web-search query parsing module supporting directives, tokenization, date parsing, and syntax serialization.
- Updated search providers to map query directives and date bounds to native provider parameters and filters.
- Added lenient result constraint post-filtering and configuration settings for enhanced engine routing.
- Added comprehensive unit and integration tests covering query parsing, constraint filtering, and provider-specific request mapping.
2026-07-24 16:05:14 +02:00
roboomp 8191cf41d3 fix(coding-agent): used authenticated registry models by default
Required CLI model registries to expose getAvailable() and used that authenticated
set whenever callers omit availableModels. Deferred SDK and bench/dry-balance
resolution now lets configured roles beat unauthenticated catalog id collisions.

Updated resolver test registries and made the #6508 regression omit the explicit
availableModels option, covering the deferred-caller path from the review.

Fixes #6508
2026-07-24 11:41:58 +00:00
can1357 c9c0882724 feat(audio): replaced Chromium browser audio with native audio stack
- Switched from `miniaudio` to `maudio` Rust crate and added `AudioCapture` and `AudioPlayback` native classes.
- Removed browser-side audio infrastructure including Web Audio API, audio worklet processor, and WebRTC runtime.
- Migrated STT recorder and transcriber modules to use native `AudioCapture` with callback-based streaming.
- Replaced streaming audio player with native `AudioPlayback` that writes PCM directly without TypeScript intermediaries.
- Removed ffmpeg, wav, and platform-specific playback commands from the audio toolchain.
2026-07-24 08:54:16 +02:00
usr-bin-roygbiv b9504f65e7 feat: add native Codex computer use 2026-07-24 01:40:04 +00:00
can1357 5ded27b0b1 fix(cli): stopped $-pattern expansion when injecting cache prefix 2026-07-24 02:25:25 +02:00
can1357 3f2ef2cea1 Merge PR #6413: feat(cli): benchmark prompt cache reuse (@riverpilot)
# Conflicts:
#	packages/ai/src/providers/pi-native-server.ts
#	packages/ai/src/stream.ts
#	packages/ai/src/types.ts
2026-07-24 02:25:24 +02:00
Alex TYRODE 60920e1c00 Merge upstream main into feat/auth-broker-account-pools 2026-07-23 21:37:51 +00:00
Alex TYRODE e6ab870d37 fix(ai): close auth broker account pool gaps 2026-07-23 21:28:17 +00:00
Alexander Kirilin 4274100bbe fix(cli): preserve cache prefix whitespace 2026-07-23 16:52:20 -04:00
Alexander Kirilin f25cc6cf09 fix(cli): harden prompt cache benchmark diagnostics 2026-07-23 16:37:39 -04:00
roboomp 5f47afba16 fix(session): validate blob refs before path join
parseBlobRef sliced the blob:sha256: suffix and returned it unvalidated;
get/getSync then fed it into path.join(this.dir, hash), so a crafted ref
like blob:sha256:../../../etc/passwd escaped the blob directory and read
arbitrary files into resolved image history (base64, raw UTF-8, and the ACP
sync path).

Reject any suffix that is not a canonical 64-char lowercase hex hash in
parseBlobRef, the single choke point for every resolution entry point. Reuse
the shared BLOB_HASH_RE in gc-cli instead of its duplicate HASH_RE.

Fixes #4088
2026-07-23 19:51:53 +00:00
Alexander Kirilin 88296f9c55 fix(cli): preserve cache benchmark affinity diagnostics 2026-07-23 15:40:07 -04:00
Alexander Kirilin 9c471a5088 feat(cli): benchmark prompt cache reuse 2026-07-23 15:18:37 -04:00
can1357 26726fdcb9 Merge PR #6255: add dynamic multi-root workspace context (@maatheusgois-dd) 2026-07-23 17:30:33 +02:00
can1357 da5da41169 Merge PR #6382: feat(ai): report Anthropic extra usage in omp usage (@LunarECL) 2026-07-23 16:35:47 +02:00
LunarECL e7fdc99afd feat(ai): report Anthropic extra usage 2026-07-23 21:25:15 +09:00
can1357 0f54c0df70 fix(tools): autoqa consent handling from default off to opt-in 2026-07-23 13:24:45 +02:00
Gareth-Rouse e2839d1288 feat(ai): added Synthetic usage provider
/usage and omp usage now report Synthetic (synthetic.new) quota state
via GET /v2/quotas (free, does not consume quota): the rolling 5-hour
request limit with per-tick regeneration rate, and the weekly credit
quota in USD. Applies to API-key credentials for the synthetic
provider; every payload section is parsed defensively since only
subscription is documented.
2026-07-23 08:46:18 +01:00
can1357 59877a01bd fix(update): fetch musl release asset on musl hosts and align musl release test
- omp update's getBinaryName now detects a musl Linux host (Alpine release file or /lib/ld-musl-* loader, mirroring scripts/install.sh) and downloads omp-linux-musl-<arch>, so self-update no longer replaces a musl install with the glibc build.
- Updated musl-release dry-run assertions to the Bun.build output format the binaries script now emits; promoted the musl changelog entry to [Unreleased].
2026-07-22 23:12:24 +02:00
roboomp 29f773ece2 fix(cli): disposed model-listing extensions
Emitted session_shutdown after model rendering and centralized managed timer cleanup across one-shot listings and agent sessions.

Added regression coverage for the extension shutdown lifecycle.

Fixes #6297
2026-07-22 15:51:47 +00:00
maatheusgois-dd 32d8b84e26 Add dynamic multi-root workspace context (#2569)
A session now carries an ordered list of workspace directories beyond cwd,
managed live from the terminal. New /add-dir, /remove-dir, and /dirs slash
commands let you add and remove folders mid-session; the repeatable --add-dir
CLI flag seeds them at launch, and the workspace.additionalDirectories
setting persists defaults per project. Additional roots are persisted in the
session header, survive reopen/fork/move, and are surfaced to the agent in the
system prompt so it knows they exist and can read/grep/glob them by absolute
path. Design aligns with the endorsed community implementation on
feature/session-workspace.

Co-authored-by: oh-my-pi <https://omp.sh>
2026-07-21 23:38:32 -03:00
Christian Stewart 670304eafa fix(coding-agent): resolve bare model role aliases
Signed-off-by: Christian Stewart <christian@aperture.us>
2026-07-18 03:51:09 -07:00
roboomp 22a8524058 fix(tools): recognized zip-family archives and pruned unconvertible extensions
- Treated ZIP-based .jar/.war/.ear/.apk as zip archives in archiveFormatFromPath and parseArchivePathCandidates so read/write member access works.
- Shared one archive-extension alternation between format detection and path splitting to stop them drifting.
- Derived the markit convertible-extension set from a single source of truth (utils/markit) matching the registered converters (pdf/docx/pptx/xlsx/epub), dropping legacy .doc/.ppt/.xls/.rtf that had no converter and only produced Unsupported format errors.
- Updated read/write tool prompts to document the zip-family extensions.

Fixes #5808
2026-07-17 08:04:10 +00:00
can1357 93cc1fed1c merged PR #5417: fix(openai): render native response images
# Conflicts:
#	packages/coding-agent/src/modes/components/chat-transcript-builder.ts
#	packages/coding-agent/test/agent-session-skill-keywords.test.ts
2026-07-16 03:48:21 +02:00
roboomp e291d77cb0 fix(tool): routed omp grep CLI path through expandPath
The `omp grep` subcommand resolved its path argument with a bare
`path.resolve` in `runGrepCommand`, bypassing `expandPath`. The
leading-colon strip from #5529 never fired, so `:/abs/path` was
mangled into `<cwd>/:/abs/path` and failed to resolve.

Route the path arg through `expandPath` so it inherits the leading-`:`
strip plus `@`-prefix, tilde, and unicode-space normalizations, matching
`read`/`edit`/in-agent `grep`.

Fixes #5624
2026-07-15 22:17:35 +00:00