Commit Graph
168 Commits
Author SHA1 Message Date
can1357 9fb082bf14 refactor(utils): consolidated file locking into pi-utils file-lock
- Moved the coding-agent lock-directory primitive to @oh-my-pi/pi-utils/file-lock
  and migrated settings, MCP config-writer, and security store imports.
- Replaced the stats aggregator's parallel ~200-line token/breaker lock protocol
  with the shared primitive: dead owners reclaimed immediately, live-but-wedged
  owners after STATS_SYNC_LOCK_STALE_MS, unstamped acquisitions after the new
  acquireStaleMs grace (10s).
- Shared primitive now treats EPERM kill probes as live owners.
- Rewrote the stats lock-reclamation regressions against the shared protocol
  and moved the file-lock contract test into pi-utils.
2026-08-03 15:25:03 +02:00
can1357 5039b33a11 test(utils): skipped torn log lines in logger poll loop
- waitForLogEntry raced winston's async flush and JSON.parsed a
  partially written line, failing the error-serialization tests on
  loaded CI runners; unparseable lines now wait for the next poll.
2026-08-03 06:52:11 +02:00
can1357 f1c7eda7de Merge PR #7205: perf(cli): keep root help off runtime graph (@eggpeat)
# Conflicts:
#	packages/coding-agent/src/cli-commands.ts
#	packages/coding-agent/src/cli/args.ts
2026-08-02 20:59:12 +02:00
roboomp a6521f07ed fix(auth): guarded config-value resolvers against case-insensitive env hijack
On Windows process.env/Bun.env lookups are case-insensitive, so the
"env var name, else literal" resolvers turned a literal /login key like
`public` (OpenCode Zen's free key) into the built-in PUBLIC=C:\Users\Public,
sending `Authorization: Bearer C:\Users\Public` and 401ing every request.

Added `$envExact` in pi-utils, which trusts an env lookup only when an
exact-case key is enumerated (the only case-preserving signal on Windows;
the getter and hasOwnProperty/getOwnPropertyDescriptor traps are all
case-insensitive there). Wired it into all three resolvers:
resolve-config-value.ts, model-registry.ts, and auth-storage.ts.

Fixes #7361
2026-08-02 06:53:18 +00:00
can1357 dda859b60f fix(ci): hardened logger probe timeouts and silenced async trait lint
- Raised probe-spawning logger tests to 30s timeouts; bun's 5s default
  SIGTERMed probe children (exit 143) on shared-core CI runners, matching
  the precedent documented in logger-contract.test.ts.
- Allowed clippy::unused_async_trait_impl on KillCommand::execute with an
  unknown_lints guard for the pinned CI nightly that predates the lint.
2026-08-01 22:34:39 +02:00
can1357 72c66c87c1 fix(xdg): adopted legacy secret-placeholder.key and marketplaces.json at XDG paths 2026-08-01 20:46:25 +02:00
can1357 f13f9b1228 fix(utils): recognize underscore Bun test entrypoints 2026-08-01 20:14:39 +02:00
can1357 5b2aefe584 Merge PR #7263: fix(tui): prevent test env from suppressing interactive launch (@roboomp)
# Conflicts:
#	packages/utils/test/env.test.ts
2026-08-01 20:14:08 +02:00
roboomp 9f9c9758a1 fix(tui): prevented test env from suppressing interactive launch
Scoped test-runtime detection to explicit runner markers and Bun test entrypoints, so application NODE_ENV/BUN_ENV values no longer make ProcessTerminal headless.

Added subprocess regression coverage and propagated the private marker to test children.

Fixes #7261
2026-08-01 11:39:57 +00:00
pi3123 96a206440c Add unit tests for getDbBusyTimeoutMs 2026-07-31 20:04:30 -07:00
Brent a572fcb9be fix(cli): preserve help metadata contracts 2026-07-31 22:01:19 +00:00
Brent 9df3067930 perf(cli): keep root help off runtime graph 2026-07-31 21:28:41 +00:00
can1357 8db0228f4d fix(ci): unblocked release run on formatting and chunk watchdog
- Reformatted the logger burst test per biome (the type-check job gates on
  check:tools, which failed on the previous hotfix's formatting).
- Raised the native/unit bucket's chunk watchdog to 1200 s: the mupdf PDF
  extraction chunk runs ~7 min per attempt on burstable runners under a
  full fan-out and the 600 s default SIGKILLed both tries in release run
  30519992654; the watchdog targets wedged children, not slow chunks.
2026-07-30 08:59:03 +02:00
can1357 053dbfa605 fix(ci): stopped mtime prune from gutting extracted bazel repos
- The hosted disk-cache prune swept ~/.cache/omp-bazel-repo file-by-file;
  extracted repository contents keep upstream-archive mtimes (months old),
  so a restored archive lost most of rules_rust while bazel still trusted
  the entry's recorded_inputs — both darwin release legs failed with
  'BUILD file not found' in release run 30519253683. Prune only the
  action disk cache, whose files carry bazel-written mtimes.
- Gave the logger burst-order contract an explicit 30 s budget: two probe
  children measure ~4.4 s unloaded and bun's 5 s default test timeout
  SIGTERMed them (exit 143) on shared-core runners.
2026-07-30 08:33:27 +02:00
can1357 a4773c0baa refactor(typescript-edit-benchmark): updated mutation plans
- Update benchmark fixtures archive file.
- Adjust mutation plan block sizes and counts in generator script.
- Remove postmortem quit test.
2026-07-30 07:57:55 +02:00
can1357 38ebd30337 chore: update stale tests 2026-07-30 07:49:43 +02:00
can1357 f925f9f38a test(utils): cover quit without stdout drain
(cherry picked from commit 59a8002411726d8686c187a6d031a1f54577093b)
2026-07-29 23:08:32 +02:00
usr-bin-roygbivandcan1357 574f400b0f fix(utils): pin logger rotation entrypoint
(cherry picked from commit 6dc31019848a20053e66df947c48e087cce8566a)
2026-07-29 23:08:28 +02:00
usr-bin-roygbivandcan1357 08b280d550 perf(utils): avoid Winston runtime dispatch
(cherry picked from commit e5aeff8153551c8c4a5cb6a47c7ed00cba32000f)
2026-07-29 23:08:27 +02:00
usr-bin-roygbivandcan1357 54e3a9f156 test(utils): define lean logger contract
(cherry picked from commit 4ded69a293827e0dfbc3333f3da2944c97d71016)
2026-07-29 23:08:27 +02:00
can1357 532e4c318c fix(utils): filter NODE_ENV dotenv files and keep escaped quotes in dotenv values
- filterChildShellEnv now also filters Bun-autoloaded .env.{NODE_ENV||development}
  entries, closing the .env.production/.env.development leak into child shells.
- parseEnvLine skips backslash-escaped quotes when locating the closing
  delimiter, restoring baseline/Bun-literal handling of values like JSON="{\"a\":1}"
  that the new parser truncated.
- Adds a parseEnvFile regression test for escaped quotes.
2026-07-28 10:58:59 +02:00
can1357 0a5727670f Merge PR #6814: fix(cli): stop forwarding project dotenv to shells (@roboomp) 2026-07-28 10:58:59 +02:00
can1357 315fb784e5 Merge PR #6818: fix(cli): set kernel process name via prctl on linux (@roboomp) 2026-07-28 10:58:58 +02:00
can1357 be98b64529 fix(utils): raised postmortem probe watchdog to tolerate slow ci spawns
- The 2s deadline returned the -999 kill sentinel when a cold bun spawn
  transpiling the pi-utils module graph exceeded it on loaded parallel CI
  runners; green runs still resolve on child exit, so the bound only
  guards genuine hangs.
2026-07-27 23:31:24 +02:00
roboomp b9f1c32f69 fix(utils): parsed dotenv with bun-compatible syntax
Handled export prefixes and quote-aware inline comments when parsing dotenv files, and filtered child shells by launcher provenance so injected values are dropped regardless of value formatting.

Covered export and inline-comment forms in unit and shell-filter tests.

Fixes #6813
2026-07-27 15:37:13 +00:00
roboomp 2860abadaf fix(cli): set kernel process name via prctl on linux
Bun's `process.title` setter is a JS-level no-op: it stores the value
internally but never calls `prctl(PR_SET_NAME)`, so `omp` appeared as
`bun` in ps/pgrep/killall/top and `pkill bun` became a footgun killing
every Bun process. Add `setProcessName` in pi-utils that also drives
prctl via bun:ffi on Linux, and use it at CLI startup and in the daemon
broker.

Fixes #6815
2026-07-27 15:28:59 +00:00
can1357 f8dbb3669f feat(utils): implemented windows shell resolution for bash execution
- Added resolveWindowsShell to locate Git Bash, scoop installs, and path binaries with a fallback to cmd.exe.
- Updated bash-executor to prevent wrapping user commands in cmd.exe when using fallback shell paths.
- Updated installation script to report optional shell status rather than failing when bash is absent.
2026-07-26 20:27:16 +02:00
can1357 a6dfc78c73 Merge PR #6644: fix(utils): contain ptree timeout rejections (@roboomp) 2026-07-26 15:45:10 +02:00
can1357 fb38343a89 Merge PR #6581: fix(utils): correct shell path config guidance (@roboomp) 2026-07-26 15:45:09 +02:00
can1357 9b8715ee78 Merge PR #6493: fix(coding-agent): bypass extension guards during shutdown (@roboomp) 2026-07-26 15:41:31 +02:00
roboomp 8376555099 fix(utils): contained ptree timeout rejections
- Observed timed-out child lifecycle failures without altering awaited rejection semantics.
- Added coverage for callers that settle without observing the lifecycle promise.

Fixes #6635
2026-07-25 20:17:08 +00:00
usr-bin-roygbiv 9ceebb2a4d fix(workers): isolate compiled host selectors 2026-07-25 08:31:54 +00:00
roboomp ca0d3e3e5b fix(config): resolved shell setting source paths
Tracked the effective global, project, overlay, or runtime source of shellPath so resolution errors identify the configuration users must edit.

Covered custom agent directories and higher-precedence settings layers with focused regressions.

Fixes #6579
2026-07-25 05:32:40 +00:00
roboomp b363d2a93d fix(utils): corrected shell path config guidance
Updated Windows shell resolution errors to point at the canonical config.yml file instead of the migration-only settings.json path.

Added a regression test for the invalid custom shell path error.

Fixes #6579
2026-07-25 05:21:40 +00:00
roboomp e09eda00cd fix(coding-agent): bypassed extension guard for shutdown
- Captured the native hard-exit function for postmortem signal, fatal, and manual exits.
- Added bounded child-process coverage for SIGINT and fatal cleanup during pending guarded loads.
- Preserved extension and hook exit isolation and made the EPIPE race assertion observe the real exit event.

Fixes #6488
2026-07-24 07:26:22 +00:00
can1357 fc6256372d test: fix local-midnight logger flake and stale kimi k3 thinking format pin
- logger-multiprocess asserted the UTC day (toISOString) while DailyRotateFile names files with the LOCAL date, failing nightly between 00:00 and 02:00 local (UTC+2); the per-pid rotation-file invariant now matches any dated name.
- kimi-code k3 bundled compat moved to thinkingFormat 'kimi' with the catalog regen; the K3 named-tool-choice downgrade gate keys on provider/id/baseUrl, so only the stale precondition needed updating.
2026-07-23 00:13:14 +02:00
can1357 ac8e9e05bb fix(utils): made runtime module resolver uninstallable
installRuntimeModuleResolver patched Module._resolveFilename process-wide
with no way back. In the shared bun test process the leaked patch broke
createRequire relative requires for every later test file (Bun 1.3.14 calls
a JS _resolveFilename override with parent === undefined, so './x' resolves
'from ""'), failing legacy-pi-inplace-load only in full-suite runs.

The installer now returns an uninstaller that drops the registration and
restores the pristine resolver when no runtime roots remain; the known Bun
limitation is documented so the patch stays scoped to worker runtimes.
2026-07-18 22:17:04 +02:00
can1357 f92d8feeec merge PR #5761 via eval/pr-5761: fix(utils): bounded default ptree stderr retention 2026-07-17 04:42:10 +02:00
roboomp edba577e7a fix(utils): bounded default ptree stderr retention
Default ChildProcess unconditionally pushed every raw stderr chunk into
`#stderrChunks`, so long-lived noisy subprocesses (LSP/DAP/RPC) grew OMP
memory linearly despite the 32 KiB visible tail cap.

- Allocate `#stderrChunks` only when full capture is requested at spawn.
- Decouple retention from stream exposure via `spawnInternal`, so
  `exec({ stderr: "full" })` retains without an unused live tee.
- Reject retroactive `wait({ stderr: "full" })` on a default child with a
  clear error instead of returning truncated data.

Fixes #5759
2026-07-16 21:41:44 +00:00
roboomp 7b5d936f95 fix(utils): pruned stale pid log namespaces
Kept live process logs isolated while globally retaining only the five newest files from completed processes.

Removed one-use audit files after their owning process exits and covered short-lived invocation cleanup.

Fixes #5716
2026-07-16 14:56:28 +00:00
roboomp 7550bd887c fix(utils): isolated fatal logging teardown
Made fatal reporting bypass revoked stderr streams and armed a referenced forced-exit watchdog around bounded cleanup.

Separated rotating log and audit namespaces by PID and disabled compression pipelines so concurrent TUI processes cannot race shared rotation state.

Fixes #5716
2026-07-16 14:46:40 +00:00
can1357 2c355102ce chore: applied biome formatting to merged sources 2026-07-16 03:52:48 +02:00
can1357 f7ed718302 fix(utils): share active postmortem cleanup 2026-07-16 03:50:06 +02:00
can1357 fd54f897f4 merged PR #5419: fix(acp): await teardown on stdio disconnect
# Conflicts:
#	packages/coding-agent/src/modes/acp/acp-mode.ts
2026-07-16 03:50:06 +02:00
can1357 362f89a2ec Merge remote-tracking branch 'origin/farm/fe301a84/reduce-stream-decoding-cpu' 2026-07-15 09:54:59 +02:00
can1357 404ebb0fb0 Merge remote-tracking branch 'origin/farm/ae7a5593/ttsr-inline-regex-flags-and-scope-quoting' 2026-07-15 09:54:46 +02:00
roboomp 22fa8f6623 perf(stream): batched response decoding
- Batched complete SSE lines into one UTF-8 decode per source chunk.

- Parsed Ollama NDJSON bytes directly without TextDecoder buffering.

Fixes #5542
2026-07-15 02:55:02 +00:00
can1357 984a97fa51 style: formatted evaluator test additions 2026-07-14 23:11:49 +02:00
can1357 0418d8622a fix(cli): handle native parser usage errors 2026-07-14 23:11:11 +02:00
can1357 33f61cc511 Merge PR #5496: fix(cli): print concise usage error instead of source dump (@roboomp) 2026-07-14 23:11:11 +02:00