Publish terminal daemon completions to the session that started the
process so idle agents can resume without polling hub status.
Persist every unacknowledged generation with a stable completion ID and
immutable snapshot. Replay the collection after reconnect or broker
recovery, and clear each event only after the owning client acknowledges
it.
Signed-off-by: Christian Stewart <christian@aperture.us>
- Aborting a caller while it was the sole extraction waiter tore the shared
extraction down and deadlocked against the blocked conversion mock, hanging
the CI chunk until SIGKILL.
- Sequenced owner/joiner starts and added an untilAborted spy barrier that
waits for both waiters to attach before aborting.
inspect_image resolved @vision with resolveModelFromString, which dropped the
:high thinking selector, and passed no reasoning to the oneshot. The
google-gemini-cli mapper then emitted thinkingBudget: 0, which thinking-only
Gemini models reject with HTTP 400. Resolve the role's explicit thinking
selector, clamp it to the model's supported efforts, and forward it as the
oneshot reasoning.
Fixes#7448
- Added shared Python call and literal serialization utilities with multiline verbatim support.
- Standardized tool inventories to format as an OpenAI-Harmony functions namespace using TypeScript declarations.
- Updated tool normalization and rendering functions to accept options objects and default to Python-syntax examples.
- Refactored Gemini dialect rendering to leverage shared serialization functions directly.
- Replaced monolithic desktop native bindings and action batching with a modular cross-platform backend structure supporting Wayland, X11, macOS, and Win32.
- Updated the computer tool schema and supervisor to execute persistent JavaScript script runs with timeout clamping and asynchronous tool calling.
- Integrated accessibility (AX) tree snapshotting, node querying, and bounds-based hit testing across platform desktop layers.
- Added native clipboard bindings and updated coding-agent prompts, renderers, and tests to validate script-based computer workflows.
- Added an LSP multiplexer server, protocol definitions, and daemon lifecycle management to route traffic across sessions.
- Introduced `lsp.shared` settings configuration and SDK session creation support for shared language servers.
- Migrated shared daemon ensure helpers into a central launch module with updated import references.
- Added comprehensive unit tests and fake LSP server fixtures covering muxing, sharing, caching, and restarts.
- Serialized group and ungroup operations to prevent duplicate tab group creation races.
- Queued and serially drained tab grouping requests in the relay bridge to prevent overlapping RPCs.
- Mirrored tab group titles to session storage and healed duplicate groups during background service worker recovery.
- Renamed run-cancellation utility to run-scope and updated corresponding module and test references.
- Added window discovery, targeting, and frame validation for macOS, Windows, and Linux platforms.
- Updated computer tool and protocol definitions to support listing and targeting specific application windows.
- Refactored native computer tool exposure to function-only representation across models.
- Updated documentation and test suites to reflect window-scoped computer control capabilities.
`bun test` fails the coding-agent native/unit job with
ReferenceError: Cannot access 'CHROMIUM_AVAILABLE' before initialization
in test/tools/browser-attach.test.ts and browser-tab-evaluate.test.ts,
taking the job red on every pull request.
chromium-probe.ts initializes its only export with top-level await. When
a test file importing it is the first file the runner loads, the await
settles before that file evaluates and the binding reads fine. When any
other test file was loaded first, the importer's body runs while the
binding is still in its temporal dead zone, and registration throws at
the `skipIf` call. `bun test <one file>` passes and `bun test --parallel=1
<any earlier file> <that file>` fails, which is why the job fails while a
single-file run does not.
Export the memoized probe as a function and let each test file await it
during its own evaluation, which the runner sequences. The probe still
runs once per process and resolves the executable exactly as before.
Signed-off-by: Christian Stewart <christian@aperture.us>
Dropped the single-active-run fallback that claimed unrelated stackless rejections in the shared main-process realm, matching the eval inline-mode invariant. Only guest-file stack frames attribute a rejection now; stackless reasons keep the fatal path. Restored the probe to an Error rejection carrying a guest stack.
Fixes#7365
Attributed unmatched rejection reasons when exactly one cmux guest run is active, covering primitive and library-created failures without guessing between concurrent runs. Updated the process probe to reject with a primitive value.
Fixes#7365
Captured browser-run-attributable promise rejections before the global fatal handler and surfaced active failures as tool errors. Retained finished run filenames so late rejections remain isolated without consuming unrelated process failures.
Fixes#7365
- Implement the OMP Browser Relay extension with WebSocket communication and CDP RPC execution.
- Add browser relay server, daemon management, and bridge multiplexing in the coding agent.
- Introduce CLI commands and settings schema options for configuring and installing the relay.
- Add utility functions and test suites supporting environment parsing and relay lifecycle handling.
- Prevent xdev state allocation and tool mounting in sessions lacking a write tool.
- Expose discoverable tools top-level instead of auto-granting write transports.
The Codex SSE `type:"error"` branch read only top-level `code`/`message`,
so backend rejections emitted under a nested `error` or `response.error`
object collapsed to `Codex error (): Unknown error`, hiding the cause
(e.g. a regional/model-snapshot rejection). `response.failed` similarly
dropped the error code.
Add a shared `extractCodexSseError` that reads top-level, nested `error`,
and `response.error` envelopes, and wire both error paths through it so
the backend code and message survive in `SearchProviderError`. The
existing `web_search_call` requirement is untouched.
Fixes#7200
- Extracted the chromiumCanLaunch probe from browser-tab-evaluate into a
shared test/tools/chromium-probe.ts helper.
- The two attached-navigation tests from PR #7006 launch real headless
Chrome; CI runners without Chrome system libraries (libnspr4 & co.)
cannot exec the downloaded binary, failing the native/unit bucket.
- Gave both tests 30s timeouts to survive CI cold starts.
Match interceptor regexes against conservative, raw shell command segments
in addition to the complete command, so anchored rules can detect commands
after &&, ||, ;, |, &, and newlines without treating quoted or escaped text
as commands.
Add extractFlatShellCommandSegments() to preserve source text for
user-configured regexes, unlike the token-based approval matcher.
Add skipShellWord() and environment-assignment stripping so rules can match
commands prefixed with NAME=value assignments. Preserve the original command
in interception errors after extracting a leading cd command.
- Replaced legacy `SWAP`, `INS`, and `PASTE` commands with unified `PUT` and `CUT` hunks across parser, grammar, tokenizer, and test suites.
- Added support for named registers and span paste operations in clipboard and block execution logic.
- Implemented indentation repair and enhanced gap locator formatting for improved patch resilience.
- Updated documentation, system prompts, and session analysis scripts to reflect the new syntax and header shapes.
DuckDuckGo does not parse after:/before: operators, so the provider relies
on the shared lenient post-filter to enforce them. But parseHtmlResults()
discarded the ISO timestamps DuckDuckGo now emits per result row, so every
source was undated and passed the date filter unconditionally.
Extract the timestamp span into publishedDate/ageSeconds so
applyQueryConstraints can honor the requested window.
Fixes#7115
Followed DuckDuckGo's returned continuation form until the requested result limit is satisfied, preserving deduplication across pages and the existing search deadline.
Added regression coverage for continuation field submission and 20-result collection.
Fixes#7116
launchHeadlessBrowser let puppeteer-core create and delete a temporary
Chrome profile via an unretried rm() from an eager process-exit hook. On
Windows, when an orphaned browser tree still held the profile lock, that
rm threw EBUSY and rejected the eager promise with no handler attached,
crashing OMP with an unhandled rejection during cleanup.
OMP now passes an explicit --user-data-dir, which makes puppeteer treat
the profile as non-temporary (ChromeLauncher.cleanUserDataDir becomes a
no-op), and removes the directory itself on dispose with lock-tolerant
retry, warning and leaving it in place if it stays busy rather than
crashing.
Fixes#7058