Commit Graph
674 Commits
Author SHA1 Message Date
can1357 319909c0ee chore: reformat 2026-05-21 15:52:55 +09:00
Can Bölük 68dc6e3ace Merge remote-tracking branch 'origin/farm/ebb932bf/emit-osc-8-hyperlinks-around-file-paths-' 2026-05-21 15:50:56 +09:00
roboomp eb314025f7 fix(tui): hyperlinks for fs-backed internal URLs and root-level grouped files 2026-05-21 06:44:58 +00:00
can1357andCan Bölük a00d3f5c9f revert(coding-agent): remove leaked search.ts redaction wiring
Cleanup tail of 2817c582a — the search archive commit (78841798f) had
inadvertently included the redaction.ts import and wiring in
search.ts. That ad-hoc redactor was already reverted; this drops the
matching call sites so the file no longer references the deleted
module. SecretObfuscator (gated on `secrets.enabled`) is the supported
path for redaction.
2026-05-21 15:22:46 +09:00
can1357andCan Bölük 8fa46f0182 Revert "feat(coding-agent): redact secret-shaped values in tool output"
This reverts commit 3d1f2f877359f374d43e1590580be6ec8e99ea60.
2026-05-21 15:22:46 +09:00
can1357andCan Bölük 66d954ed7a feat(coding-agent): redact secret-shaped values in tool output
Adds a focused redaction utility that targets well-known token shapes
(AWS, GitHub PATs/tokens, Slack, OpenAI-style sk-, JWT) plus a
key/value heuristic for env-style lines whose key contains SECRET /
TOKEN / PASSWORD / API_KEY / PRIVATE_KEY, plus Bearer/Basic Authorization
header values. Replacements are tagged `#REDACTED:<hint>#` so callers
can tell why each value was scrubbed.

Wired into read, search and ssh tool outputs. Each call site appends a
`[redacted N secret-like values]` footer when at least one value was
scrubbed so the model knows the output was modified.

Gated behind a new `tools.redactSecrets` boolean setting (default true).
Sandboxed tests that intentionally surface secret-shaped fixtures can
disable it via Settings.isolated({ "tools.redactSecrets": false }).
2026-05-21 15:22:46 +09:00
can1357andCan Bölük 0d57ad586d fix(coding-agent): support searching inside zip/tar archive members
`read` accepts `archive.zip:member` selectors but `search` previously
ignored them, returning zero matches even when the member's text
contained the query. resolveArchiveSearchPaths now detects archive
selectors, opens the archive via the shared archive-reader, decodes
UTF-8 members into a scratch tmpdir, and rewrites match paths back to
the original selector before returning. Binary, non-UTF-8, missing
members and unreadable archives surface as a structured error or a
per-archive footer note. Scratch dir is cleaned up in finally.
2026-05-21 15:22:46 +09:00
can1357andCan Bölük 0d80a01280 fix(coding-agent): drop hash anchor when a displayed line was truncated
The read renderer was emitting `LINE+HASH|content` for lines whose
content had been column-truncated for display, but `computeLineHash`
is content-only and recomputes against the disk line. The model copied
the displayed anchor, edit rejected it as mismatched, even though the
underlying file had not changed.

formatTextWithMode now accepts an optional truncatedLines set; in
hashLines mode those lines emit as `LINE|content` (no hash) so the
verifier never tries to recompute against truncated text. Multi-range
and single-range read paths both populate the set when truncateLine
flips wasTruncated.
2026-05-21 15:22:46 +09:00
roboomp fb0fcdfa7c feat(tui): added OSC 8 hyperlink support for file paths in tool output 2026-05-21 05:01:23 +00:00
can1357 1f1e6e3eb1 revert(coding-agent): restore opaque extra record in resolve schema
The narrowed object-with-title schema added in e26a17f3f is no longer
necessary: the upstream constrained-sampling fix lets models emit
arbitrary props on a record now, so the opaque shape no longer hides
title from discovery. Plan-approval callers still pass extra.title and
the renderer/handler logic accept it unchanged.

The companion changes from e26a17f3f (resolve.md context enumeration,
runResolveInvocation apply-throw requeue) stay intact.
2026-05-19 19:29:44 +09:00
can1357andCan Bölük e26a17f3fc fix(coding-agent): expose extra.title in resolve schema, requeue on apply throw
- The plan-approval gate required extra.title but the wire schema only
  declared an opaque additionalProperties record so codex/gpt-5.x could
  not discover the field. Schema now declares title with a description
  while still allowing passthrough for future per-context keys.
- resolve.md replaces the truncated "Schema depends on context:" line
  with the actual enumeration.
- runResolveInvocation wraps apply() in try/catch; a thrown apply (e.g.
  ast_edit overlap) requeues the resolve directive so the model can
  discard or fix-and-retry instead of losing the preview.
2026-05-19 19:24:16 +09:00
can1357andCan Bölük b191e6c5ff fix(coding-agent): reject task-N ID confusion, error on partial todo apply
- todo-write.md adds an explicit note that tasks are referenced by
  verbatim content text; the tool never emits task-N IDs.
- resolveTaskOrError rejects ^task-\d+$ inputs with a clarifying error.
- execute sets isError:true when any op failed.
- appendItems short-circuits on the first "already exists" error so the
  call no longer applies the prefix of a doomed batch.
2026-05-19 19:24:16 +09:00
can1357andCan Bölük ef505142bf fix(coding-agent): fall back to inline worker when tab worker startup errors
Worker emits BuildMessage errors via the async error event, after the
surrounding try/catch in spawnTabWorker has already resolved, so the
documented spawnInlineWorker fallback was unreachable for the very case
it was added to cover. initializeTabWorker now terminates the broken
worker and retries once via spawnInlineWorker, with the original error
attached as cause if the inline fallback also fails.
2026-05-19 19:24:16 +09:00
can1357andCan Bölük 93e74819cb fix(coding-agent): raise browser tool timeout cap from 30s to 300s
clampTimeout silently floored the caller-supplied timeout to 30s, so a
requested 120s for a slow waitForResponse came back as a 30s failure
indistinguishable from the default. Raise the cap and document the new
max in the schema field description.
2026-05-19 19:24:16 +09:00
can1357andCan Bölük d700004489 fix(coding-agent): default browser waitUntil to "load"
networkidle2 requires <=2 in-flight requests for 500ms which never
resolves on dev servers (HMR, websockets, telemetry beacons), so
browser.open and tab.goto timed out before user code ran. "load" matches
Puppeteer's documented default and works on real-world pages.
2026-05-19 19:24:16 +09:00
can1357andCan Bölük a1fe78e092 fix(coding-agent): correct grep regex doc, hard-error on mis-shaped paths
- search.md no longer claims "full regex syntax". Engine is rust-regex
  (RE2) so lookaround and backreferences are unsupported; the doc now
  says so and points at the post-filter alternative.
- search.ts rejects array entries containing a top-level comma with an
  actionable ToolError, instead of silently demoting to a footer note
  and returning zero matches.
- Add a paths-as-array example to search.md.
2026-05-19 19:24:16 +09:00
can1357 9a335ece68 fix(coding-agent): timeout knob, partial matches on timeout, gitignore toggle
- Expose optional timeoutMs (clamped 0.5..60s) and pipe through to the
  native walker. Default stays at 5s.
- On timeout, drain accumulated matches and return them with
  truncated:true plus a notice line instead of throwing.
- Add gitignore boolean to the schema so callers can opt out of the
  default exclude when looking for .env/.jsonl/build artifacts.
- Reject comma-in-paths array entries with an actionable ToolError.
- Update find.md with the knobs and the array-shape example.
2026-05-19 19:15:58 +09:00
can1357 f48af07d3a fix(coding-agent): honor caller-supplied read selector limit
The ignoreResultLimits flag now gates only the byte-budget tail-truncate,
never the explicit line window. Reads of internal URLs (skill, local,
memory) with a line range previously returned the tail of the file
instead of the requested window for files larger than the byte budget.
2026-05-19 19:15:49 +09:00
roboomp cb34503ba5 fix(debug): preserved dap launch failures
- Preserved launch and attach request failures when configurationDone also fails.
- Handled initial stop-outcome watcher rejections for failed launch and attach attempts.
- Rejected directory-valued debug launch programs before adapter selection and documented the debugpy launch shape.

Fixes #1187
2026-05-19 07:18:33 +00:00
can1357 2e40fb250b fix(coding-agent/tools): fixed internal URL selector splitting in read path resolution
- Added splitInternalUrlSel to iteratively peel internal-URL selector chunks while preserving unsupported schemes like mcp://.
- Updated ReadTool to use the internal splitter before routing so selector parsing is handled via parseSel.
- Added unit tests covering malformed selectors, namespaced skill hosts, and unchanged behavior for non-URLs or unsupported schemes.
2026-05-19 07:12:56 +02:00
can1357 aa8fa00c4e fix(coding-agent/tools): capped AST parse errors and preserved total counts
- Added capParseErrors in shared render utilities and updated ast_grep and ast_edit to return capped parseErrors plus parseErrorsTotal.
- Threaded the preserved totals into parse-error formatting and renderer output so labels and overflow counts report the full number of issues.
- Added an ast_grep test asserting parse errors are capped at PARSE_ERRORS_LIMIT while parseErrorsTotal retains the original count.
2026-05-19 05:30:59 +02:00
can1357 9155df2bf0 fix(coding-agent): scoped report_tool_issue enum to active built-in tools
- Built a dynamic enum from constructed built-in/hidden tools so MCP and extension tools are excluded from QA reports.
- Added allowlist guard to silently drop reports targeting non-built-in tools at runtime.
- Stripped `proxy_` prefix before allowlist check so passthrough-wrapped tools resolve correctly.
2026-05-17 05:45:25 +02:00
can1357 69aeb94621 fix(grievances): replaced hostname with platform/arch 2026-05-17 02:16:23 +02:00
can1357 0bb385f8ab feat(grievances): added consent gate & push
- Added `dev.autoqa.consent` setting and single-flight popup handler wired through `InteractiveMode`.
- Added `flushGrievances` to batch-POST unpushed rows to `dev.autoqaPush.endpoint` with cooldown and single-flight deduplication.
- Added `omp grievances push` subcommand with TTY progress bar for manual draining.
- Migrated shared DB logic to `openAutoQaDb` (with `pushed` column migration) exported from `report-tool-issue`.
2026-05-17 01:47:24 +02:00
can1357 39f34ada70 feat: added pure-JS sanitizeText
- Migrated sanitizeText from pi-natives to pi-utils as a pure-JS implementation, removing the native dependency across all call sites.
2026-05-16 20:12:26 +02:00
can1357 84ec8fba49 feat(coding-agent/eval): implemented JSON cell-based eval tool inputs
- Removed the legacy `parseEvalInput` parser module and `eval.lark`, eliminating `*** Cell` stream parsing.
- Replaced eval tool arguments from single `input` strings to ordered `cells` arrays in tool calls and schema.
- Updated execution to resolve language explicitly, map `py` to `python`, and apply timeout/reset defaults.
- Removed backend sniffing and `ABORT_WARNING` suffix handling, then updated docs and tests to the new JSON cells format.
2026-05-16 19:33:44 +02:00
can1357 64fcdc308f refactor(coding-agent)!: removed StringEnum helper and shortened tool schema descriptions
- Replaced all StringEnum(...) usages with z.enum([...]) across tools, examples, and tests.
- Removed StringEnum re-export from @oh-my-pi/pi-coding-agent public API.
- Condensed verbose tool parameter descriptions to minimal lowercase phrases.
- Renamed AuthCredentialStore to SqliteAuthCredentialStore at usage sites.
2026-05-16 19:26:32 +02:00
Can BölükandGitHub 58505b8423 Merge pull request #1109 from itzrnvr/fix/windows-pty-hang-root-cause
fix: PTY hangs on Windows — ConPTY deadlocks waiting for cursor position
2026-05-16 18:09:28 +02:00
can1357 32453aaff0 feat(agent): added AgentTelemetry across compaction and branch-summary
- Added optional AgentTelemetry to summary, handoff, branch-summary, and compact option types.
- Replaced one-shot `completeSimple` usage with `instrumentedCompleteSimple` across compaction, summary, and branch-summary calls and passed `oneshotKind`.
- Added `PiGenAIAttr.OneshotKind`, `InstrumentedChatSpanOptions`, and response-header forwarding in telemetry span lifecycle.
- Added `resolveTelemetry` propagation in coding-agent session and inspect-image paths to pass request-scoped telemetry.
- Added compaction telemetry test harness and span assertions for success, no-telemetry, and error cases.
2026-05-16 18:03:07 +02:00
Sanskar Singh 158b00266b fix: pass configured shell to PTY instead of hardcoding sh
The PTY runner hardcoded CommandBuilder::new("sh"), but on Windows the
user's shell might be a Git Bash absolute path that isn't on PATH. The
non-PTY path already uses the resolved shell from getShellConfig(). Now
the PTY path does the same, passing it through PtyStartOptions.shell.
2026-05-16 10:10:59 +05:30
Sanskar Singh cffc94a978 fix: prevent ClosePseudoConsole deadlock hanging PTY on Windows
ConPTY's ClosePseudoConsole can deadlock when it tries to flush output
to a pipe that nobody is reading (microsoft/terminal#1810). This caused
the PTY Promise to never resolve on Windows, making bash commands with
pty:true hang indefinitely.

Root cause: portable-pty's drop(master) calls ClosePseudoConsole
synchronously. If ConPTY's internal render thread is blocked writing to
a full/undrained output pipe, ClosePseudoConsole waits forever.

Fix (three parts):

1. Rust (pty.rs): Reordered teardown to follow Microsoft's recommended
   shutdown sequence:
   - Drop writer first (close ConPTY input pipe)
   - Drain reader thread with 500ms timeout (consume output pipe)
   - Drop master in a background thread with recv_timeout(2s):
     * Clean case: ClosePseudoConsole completes, thread reclaimed
     * Hung case: timeout expires, main thread returns anyway
   - Replace child.wait() with try_wait() polling on Windows
     (WaitForSingleObject can also hang in ConPTY)

2. TypeScript (bash-pty-selection.ts): Remove the Windows blanket
   disable that prevented PTY from ever being used on Windows.

3. Tests: Updated to verify PTY works on Windows with UI context.
2026-05-16 07:02:24 +05:30
Sanskar Singh 5d1a14e72a fix(coding-agent,pi-natives): Windows PTY hang root-cause fix with opt-out
Replaces the blanket PTY disable on Windows (PR #1105) with a targeted fix:

- TypeScript: PI_FORCE_PTY env var allows explicit Windows PTY opt-in.
  PTY is still disabled by default on Windows to prevent hangs, but power
  users who need interactive workflows can override.

- Rust: Adds ct.heartbeat() checks during PTY setup (openpty, spawn, reader
  creation) so the existing timeout mechanism works even during setup.

- Rust (Windows): Wraps openpty() in a 5-second startup timeout thread.
  If ConPTY hangs during pseudo-console creation, the Promise rejects with
  a clear error instead of hanging forever.

Fixes #1103 #1106
2026-05-16 05:03:23 +05:30
can1357 ece3c9d165 fix(ai): resolved tool strictness for loose additionalProperties schemas
- Preserved object schemas with explicit `additionalProperties` settings by avoiding strict coercion to false.
- Probed schema strictness before sanitization and set `tool.strict` false for non-strict schemas.
- Set `tool.strict` false for `null`, `true`, and unconstrained `outputSchema` fallbacks.
- Documented the fix in Unreleased changelog entries for both `ai` and `coding-agent` packages.
- Added regression tests covering loose `additionalProperties` and yield strictness behavior across tools.
2026-05-16 00:12:47 +02:00
can1357 85515f35a6 fix(coding-agent): added gap separators between noncontiguous search matches
- SearchTool now tracked the last emitted line and inserted ellipsis markers when noncontiguous match blocks were output.
- Display output gap markers were padded to align with code-frame gutters.
- Added a regression test that verified a no-context search emits an ellipsis between separated matches in the same file.
2026-05-15 23:46:23 +02:00
can1357 7282d92bf4 fix: normalized line-ending handling for text and TUI output flows
- Unified line-ending normalization to `replace(/\r\n?/g, "\\n")` in editor, scraper, benchmark, and utils modules.
- Added terminal-aware line sanitization in code-cell rendering to collapse inline carriage returns and avoid overwrite corruption.
- Tightened editor and paste sanitizers to trim control characters consistently after CR normalization.
2026-05-15 23:46:23 +02:00
can1357 2e6d96d3bc feat(coding-agent/tools): added open-ended line range shorthand for read selectors
- Updated read-line selector parsing to accept line-range selectors ending with a trailing dash.
- Mapped selectors with a trailing dash to open-ended ranges that read from the start line onward without requiring an explicit end.
- Updated read tool documentation to document `:50-` as the shorthand for reading from line 50 onward.
2026-05-15 23:46:23 +02:00
roboomp 13d77ad6ee fix(coding-agent): disable interactive pty on windows
Fixes #1103
2026-05-15 21:41:11 +00:00
can1357 2f2e72c5ac fix: updated metadata URLs and Bun WebSocket types
- Added homepage metadata entries to the Rust and Python package manifests.
- Replaced OpenRouter HTTP-Referer values with https://omp.sh/ in completion and image requests.
- Updated Codex WebSocket typing and construction to use Bun.WebSocket for handshake header capture.
Fixes #1102
2026-05-15 21:22:03 +02:00
can1357 03f09e7ee9 fix(coding-agent/tools): ignore literal refs when scanning yield schemas
YieldTool's unresolved-ref fallback now skips literal-value positions such as const, enum, default, and examples when looking for unresolved schema refs. Valid schemas containing data literals like { "": "literal" } no longer degrade to the loose schema and still reject invalid yield payloads.
2026-05-15 18:31:12 +02:00
can1357 46cff37ce4 fix(coding-agent/tools): yield falls back to loose schema on unresolved $ref
dereferenceJsonSchema leaves $ref strings in place when references are unresolvable (external URLs, missing definitions, certain cycles). The new yield-parameters builder now walks the resolved schema for any remaining $ref strings before installing validation; if any are found, it throws so the existing catch branch swaps in looseRecordSchema and disables strict validation. Previously YieldTool installed a validator that rejected every success payload with an unresolved-reference error.
2026-05-15 17:49:23 +02:00
can1357 45fe4df39e fix(ai): corrected AI tool handling via JSON-schema validation flow
- Replaced fromTypeBox conversion with a JSON-schema validator flow in ai tool handling and execution paths.
- Added recursive schema validation and expanded TypeBox checks for refs, enums, uniqueItems, and constraint keywords.
- Sanitized Azure/CCA tool schemas by dropping unsupported fields and rewriting oneOf tool branches as anyOf.
- Tightened argument and model-config validation, preserving unknown tool fields and adding apiKey plus compatibility flags.
2026-05-15 15:16:50 +02:00
can1357 2867e1f4e3 feat(deps): added pi.zod exports and removed TypeBox package exports
- Added canonical `pi.zod` schema API exports and removed TypeBox package exports/imports.
- Migrated Tool schema typing from TypeBox to shared `TSchema`/Zod flow with legacy TypeBox compatibility.
- Updated AI provider adapters and MCP/agent builders to convert tool params through `toolWireSchema()`.
- Reworked schema validation from AJV to Zod-safe parsing with `fromTypeBox`, `toolWireSchema`, and meta schema checks.
2026-05-15 14:46:54 +02:00
can1357 b642607ea9 feat(coding-agent/task): added telemetry propagation for subagent task handoffs
- Task tool sessions now expose and forward parent OpenTelemetry config when creating subagent tasks.
- Subprocess execution now derives child telemetry from the parent config with the subagent identity and child session conversation handling.
- Subagent creation now records a handoff span using the resolved parent telemetry handle before running the child loop.
2026-05-15 14:46:54 +02:00
can1357 995ba8e51e fix(coding-agent/tools): suppressed repeated bash fixup notices per session
- Tracked emission state so the bash fixup notice is shown at most once per BashTool instance.
2026-05-15 04:55:51 +02:00
can1357 4c494aaa3a feat(coding-agent/tools): defaulted GitHub search repo scope to the current checkout
- Added a `resolveSearchRepoScope` helper that uses an explicit `repo` when provided, skips defaulting when a query already contains a repo/org/user/owner scope qualifier, and otherwise resolves the current checkout via `resolveDefaultRepoMemoized`.
- Updated `search_issues`, `search_prs`, `search_code`, and `search_commits` to use the resolver before composing API queries, defaulting `repo` when omitted but silently falling back to an unscoped search on resolution failure.
- Documented the new search-repo defaulting rules in tool prompts, user docs, and the package changelog.
2026-05-15 04:38:58 +02:00
can1357 f0ff398607 fix(coding-agent/tools): stripped duplicate output notices from TUI tool renderers
- Added stripOutputNotice to output-meta to remove appended truncation notices when output metadata is available.
- Updated bash, eval, browser, read, and ssh renderers to strip the notice before display so the styled warning line is not duplicated.
- Left fallback behavior unchanged so outputs without a notice continue through unchanged.
2026-05-15 03:16:16 +02:00
can1357 7754607561 fix(coding-agent/tools): wrapped bash fixup notice in system-warning tags
- Updated `formatBashFixupNotice` to wrap the stripped-pattern warning in a `<system-warning>` wrapper.
- Reworded the notice to clarify output is already truncated and stderr is merged into stdout.
- Extended the Bash interceptor test to verify the warning tag appears for head/tail stripping.
2026-05-15 02:23:35 +02:00
can1357 92c42f44f7 fix(coding-agent/tools): resolved bash fixup parsing for head/tail chunks
- Added top-level parsing and segment splitting to apply bash fixups only on safe command chunks.
- Replaced `stripTrailingHeadTail` usage with `applyBashFixups` and array-based notice formatting.
- Fixed terminal `| head`/`| tail` and redundant `2>&1` stripping while preserving command semantics.
- Updated fixup tests for cross-command cases and removed superseded head-tail-only test coverage.
2026-05-15 02:12:28 +02:00
can1357 bddf9989b5 feat: added host-uri frame and rpc bridge for read/write/cancel routing
- Added `set_host_uri_schemes` and host-uri frame/type definitions; documented read/write/cancel behavior.
- Added `RpcHostUriBridge` in rpc mode to register schemes, dispatch read/write/cancel ops, and clear pending requests.
- Added internal URL write support with lowercased scheme matching, handler routing, and hashline-prefixed success output.
- Added Python host-uri APIs/exports, cancellable client request handling, and host-uri read/write test coverage.
2026-05-15 00:54:09 +02:00
can1357 9bbc7465ba feat(coding-agent): strip trailing | head/tail from single-line bash commands
Drop trailing `| head [args]` / `| tail [args]` pipes that exist purely
to limit output — the harness already truncates bash output and exposes
the full result via the bash-original artifact, so these pipes only
hide content from the agent.

Conservative gates (any failing leaves the command verbatim):

  - single-line only; multi-line scripts may legitimately end pipelines
    with head/tail to bound a generator or loop body
  - whitelisted limit-only args (-nN, -n N, -cN, -N, -q, -v, --lines[=N],
    --bytes[=N], --quiet, --verbose); rejects -f/-F/+N/filenames so
    `tail -f`, `tail -n +2` etc. stay intact
  - regex anchored at end of command; any downstream operator (`&&`,
    `||`, `;`, `&`, `>`, `|`, `` ` ``, `$(…)`, `)`) blocks the match, so
    `just build 2>&1 | tail -3 && just up && …` is untouched
  - refuses to reduce the command to an empty string
  - pipe boundary uses `[ \t]*`, not `\s*`, so a `|` on a continuation
    line cannot be swallowed

Consolidates the existing `timeoutClampNotice` and the new strip notice
into a single `pendingNotices: string[]` array threaded through every
execute branch (async, auto-background, ACP terminal, local exec).

New setting `bash.stripTrailingHeadTail` (default `true`).
2026-05-15 00:50:00 +02:00