Commit Graph
201 Commits
Author SHA1 Message Date
can1357 bce01ce0db refactor(jj): restructured exports into namespaced repo and diff objects
- Grouped `isRepository`, `workspaceRoot`, and `clearWorkspaceRootCache` under a `repo` namespace (`repo.is`, `repo.root`, `repo.clearRootCache`).
- Promoted `diff` to a named export with a `changedFiles` sub-method via `Object.assign`.
- Added `ensureAvailable` check and `nameOnly` support to `diff`.
- Updated callers and tests to use the new API surface.
2026-06-03 00:13:05 +02:00
Patrik Sundberg f5114a4ba9 Support JJ workspaces in review 2026-06-02 10:45:58 +01:00
can1357 b2fa0ad0f9 Merge remote-tracking branch 'fork-jacobzyy/fix/marketplace-plugin-skills-loading' 2026-06-02 10:33:38 +02:00
JacobZyy 8790736173 fix: remove plugin: prefix from marketplace skill names
The plugin:name prefix (e.g. hyperpiemia:whistle-rules) broke skill://
URL parsing because colons are ambiguous with port separators. Skills
from marketplace plugins are now registered under their plain names.
Name collisions are handled by the existing capability-layer dedup
based on provider priority ordering.
2026-06-02 15:36:22 +08:00
can1357 ab935e992c fix(legacy-pi-compat): scope rewrite hook to the import graph, not a dir
Address review of the in-place loader: the directory-subtree filter had two
regressions vs the old mirror.

- It only rewrote files under the entry's package root, so a `dist/`
  entry importing `../../shared/helper.ts` (or a symlink-escaping sibling)
  left that module's legacy `@(scope)/pi-*` / `@sinclair/typebox` imports
  un-rewritten.
- `findExtensionRoot` walked up to the nearest package.json, which for an
  ad-hoc extension under a project (e.g. `/repo/.omp/extensions/foo.ts`)
  resolved to the project root — so the permanent onLoad hook would then
  rewrite unrelated project/host source imported later.

Replace the directory filter with a precise scope: pre-walk the entry's
relative-import graph (static + dynamic `./`/`../` specifiers), collect each
module's realpath, and build the onLoad filter as an exact-path alternation
of just those modules. This matches exactly the set the old mirror tracked
(minus the copy): it covers `../src`/symlinked siblings and never touches
the host, other extensions, node_modules deps, or unrelated project files.

Adds a regression test that a non-imported sibling stays outside the rewrite
scope, and renames the ../src test to reflect graph-following.
2026-06-02 09:15:44 +02:00
can1357 c5e3698f45 fix(legacy-pi-compat): load extensions in place instead of mirroring
Legacy Pi extensions were mirrored module-by-module into a flat temp dir
(`omp-legacy-pi-file/entry-<hash>/`) with imports rewritten to absolute
URLs. Running from that temp root made `import.meta.url`/`__dirname`
resolve to the mirror, so `readFileSync(join(__dirname, "ui.html"))`-style
asset loads ENOENT'd — e.g. @plannotator/pi-extension's HTML never loaded
and it auto-approved plans (#1674). The standing remedy (#1675) copied
~30MB of .html/.css per startup with a fragile extension whitelist.

Bun's runtime plugins don't fire onResolve for transitive imports, which
is why the mirror pre-resolved everything. But onLoad does fire
transitively for file-namespace modules matching its filter, and a real
file import keeps import.meta.url pointing at the source. So:

- Load the extension entry in place via `import(pathToFileURL(real))`;
  realpath first so the path matches what Bun hands onLoad (macOS
  /var->/private/var, bun link/pnpm symlinks).
- Register one Bun.plugin() onLoad per extension *package root* (nearest
  package.json), filtered to that root's .js/.ts but excluding any
  node_modules segment, that rewrites only `@(scope)/pi-*` and the bare
  `@sinclair/typebox` specifier to absolute bundled/shim URLs.
- Everything else — relative siblings (incl. ../src), the extension's own
  node_modules deps (CJS/ESM), and bundled assets — resolves natively.

Removes the flat mirror, the temp-dir writes, the asset-copy problem, and
the now-dead `omp-legacy-pi-file:` namespace machinery. import.meta.url is
the real source file, so assets resolve exactly as under the original Pi
runtime. Adds an in-place load regression test covering asset reads,
submodule .css siblings, node_modules-excluded native deps, and
package-root-scoped ../src rewrites.

Fixes #1674.
2026-06-02 09:15:44 +02:00
Can BölükandGitHub 52a29e5df5 Merge branch 'main' into feat/assistant-thinking-renderer 2026-06-01 18:16:42 +03:00
rimless-casualty 3c7d50d292 Improve ask option rendering 2026-06-01 17:37:26 +08:00
shoucandanghehe fbb24fb7dc fix(coding-agent): tighten thinking renderer semantics 2026-05-31 20:59:15 +08:00
shoucandanghehe 569cc3442b feat(coding-agent): add assistant thinking renderers 2026-05-31 20:44:02 +08:00
can1357 14bd572f49 refactor(shake): removed shake-summary mode and local-model compressor
- Dropped `summarizeShakeRegions`, the shake-summary prompt, and related types.
- Removed `shake-summary` compaction strategy and `providers.shakeSummaryModel` setting.
- Migrated existing `shake-summary` configs to plain `shake` on load.
- Simplified `/shake` to `elide` and `images` modes only.
2026-05-31 14:14:37 +02:00
can1357 19be67921d feat(coding-agent): added shake configuration and type modeling
Introduce shake-related configuration and types: strategy options, action enums, and shake result types.
2026-05-31 07:39:51 +02:00
Can BölükandGitHub 7ad52b25ff Merge pull request #1503 from erik-sv/upstream-pr/extension-flag-initial-message
fix(coding-agent): strip extension flags from the initial prompt
2026-05-31 07:25:03 +03:00
can1357 b48b825344 fix(coding-agent): process @file before session creation; drop built-in flag-name list
Two review fixes for the extension-flag/initial-prompt work:

1. @file ordering — `processFileArguments` runs `process.exit(1)` on a
   missing/unreadable file. It had been moved after `createSession`, which
   writes the terminal breadcrumb eagerly (SessionManager.create →
   #newSessionSync), so `omp @missing.md "x"` left a junk session/breadcrumb
   behind before exiting.

   Resolve extension-registered CLI flags BEFORE creating the session: load the
   session's extensions up front (new `loadSessionExtensions` helper, the single
   source of createAgentSession's discovery-branch logic), build an
   ExtensionFlagSink straight from the loaded extensions + runtime, re-parse
   argv, then process @file args — all before any session exists. The loaded
   result is handed back to createAgentSession via `preloadedExtensions` (now
   checked before `disableExtensionDiscovery`, so it can't double-load) and the
   same EventBus is shared, so no extra work. This keeps the P1#1 fix
   (`--flag @value` is the flag's value, not a file) while failing fast with no
   session side effects.

2. "Can we avoid the big list of names?" — removed the hand-maintained
   `BUILTIN_FLAG_NAMES` set (and its stale "rejected at registration" doc).
   `applyExtensionFlags` now always falls back to recovering a flag's value from
   argv when parseArgs didn't surface it; the recovery scan mirrors parseArgs's
   consumption rules (flag-looking space-form values stay their own flag) and is
   a no-op for flags that were absent or already surfaced, so no list of
   built-in names is needed.

Adds `ExtensionRunner.aggregateFlags` (static) so getFlags and the CLI's
pre-session sink share one implementation.

Tests: pre-session flag resolution via the exact main.ts sink pattern;
list-free recovery of an arbitrary colliding built-in (`--model`); and the
flag-looking-value rule. Verified typecheck + extension/runner/acp suites.
2026-05-31 06:23:15 +02:00
can1357 9f547d8e4f refactor(mnemosyne/core): typed embedding provider outputs and tightened normalization
- Defined `EmbeddingRow` and `EmbeddingOutput` in runtime options and exported them from core embeddings.
- Updated `EmbeddingProvider`, `MnemosyneEmbeddingProvider`, and `provider` runtime option types to return `EmbeddingOutput` instead of `unknown`.
- Refactored embedding result normalization to accept typed rows and sync/async batches and coerce them into validated `Float32Array` vectors.
2026-05-31 05:32:28 +02:00
can1357 495c570ed4 fix(coding-agent): normalize hosted plugin git shorthands
Addresses review feedback on #1527.
2026-05-31 04:47:39 +02:00
oldschoolaandcan1357 84a50e8921 fix(coding-agent): classify git+ and unprefixed scp specs as git
Codex review on #1527 flagged that the documented forms
`git+https://github.com/user/repo` and `git@github.com:user/repo` still
fell through to the npm install path. `git+https` was rejected by the
package-name validator; scp-style `git@…` passed the validator but then
resolved `actualName` via `extractPackageName` to `git` (everything before
the `@`), causing the post-install package.json lookup to fail at
`node_modules/git/package.json`.

- `parseGitUrl`: strip leading `git+` (forwarded to bun/git as-is) and
  extend the protocol gate to also accept scp-like `git@host:user/repo`.
  The scp form is unambiguous — no local path starts with `git@` — and
  matches what `git clone` itself takes.
- `isGitSpec` now returns true for both forms, routing them through the
  snapshot/diff path in `PluginManager.install` so the real package name
  is discovered correctly.
- Tests: flip the two cases that asserted rejection, add ref and
  `git+ssh` coverage. Verified end-to-end:
  `PluginManager.install('git+https://github.com/oldschoola/omp-insights')`
  installs `@oldschoola/omp-insights@1.2.3`.
2026-05-31 04:46:08 +02:00
oldschoolaandcan1357 22e564a85d feat(coding-agent): accept GitHub/git URLs in plugin install
Extends `omp plugin install` to accept git sources alongside npm specs and
marketplace refs. Bun's installer already understands git URLs; the blocker
was `PluginManager.install`'s strict npm-name validator and the assumption
that the actual package name could be derived from the spec.

- `git-url.ts`: `parseGitUrl` now recognizes npm-style namespaced shorthand
  (`github:user/repo`, `gitlab:`, `bitbucket:`, `codeberg:`, `sourcehut:` /
  `srht:`), with optional `#ref` and `.git` suffix. Exposes `isGitSpec` as
  `parseGitUrl(s) !== null`. Existing protocol-URL and `git:` shorthand paths
  are untouched.
- `manager.ts`: `install()` branches on `isGitSpec`. Git specs go through a
  separate `validateGitSpec` (shell-metachar rejection only — `/`, `:`, `@`,
  `#`, `+` are legal) and the real package name is discovered by snapshotting
  `plugins/package.json` deps before `bun install` and diffing afterwards.
  Falls back to value-match on force-reinstall where the key already exists.
- Help text in `plugin-cli` documents the new sources and adds a github:
  example.

Smoke tested end-to-end on Windows with both forms against the test repo:
  PluginManager.install('github:oldschoola/omp-insights')
  PluginManager.install('https://github.com/oldschoola/omp-insights')
both resolve `@oldschoola/omp-insights@1.2.3` and write a correct lock entry.
Shell-injection probe (`github:foo/bar; rm -rf /`) is rejected.
2026-05-31 04:46:08 +02:00
Erik Svilichandcan1357 38d2341300 fix(coding-agent): preserve built-in-colliding extension flags instead of rejecting
The previous collision guard threw in registerFlag, which broke loading the
bundled plan-mode example extension (it registers `--plan`, also a built-in)
even when `--plan` was never passed — making a documented extension unusable.

Registering a built-in-named flag is a supported pattern: `--plan` is both the
built-in plan-model selector and plan-mode's boolean mode toggle, and the value
must reach both. So instead of rejecting, preserve delivery: remove the guard,
and in applyExtensionFlags recover a colliding flag's value from argv
(resolveCollidingFlag) when parseArgs routed it to the built-in branch and it
never reached unknownFlags. Non-colliding flags are unchanged (peer-* etc.).

Verified the real bundled plan-mode.ts loads with --plan registered and
delivered; replaced the reject-test with a loads-without-throwing regression
plus colliding-flag delivery coverage.
2026-05-31 04:45:51 +02:00
Erik Svilichandcan1357 d6f887d152 fix(coding-agent): close remaining extension-flag edge cases (GPT-5.5 review)
Three issues from an adversarial review, all rooted in the startup argv parse
running before extensions load:

1. Flag-looking string values (`--name --print`): the extension-aware reparse
   consumed the following token as the value, disagreeing with the startup
   parse that treated `--print` as the built-in flag — so the reparse could
   silently flip command shape. Extension string flags now consume a following
   token only in `--flag=value` form or when it is not flag-looking; pass a
   flag-looking value as `--flag=value`. Keeps both parses consistent.

2. `@file` string values (`--target @notes.md`): file args were processed from
   the startup parse, which misreads the value as a file and reads it into the
   prompt. processFileArguments now runs on the extension-aware parse
   (initialArgs.fileArgs); pipedInput stays early for mode detection.

3. Built-in collisions: an extension flag named like a built-in (e.g. `model`)
   was consumed by the built-in branch and never delivered to the runner.
   registerFlag now rejects names in BUILTIN_FLAG_NAMES with a clear error
   (isolated per-extension by loadExtension's try/catch).

Adds tests for all three plus the documented startup-parse misclassification.
2026-05-31 04:45:51 +02:00
roboomp 2780f5dec6 fix(coding-agent): kept legacy-pi paths under compiled bunfs root
Bun 1.3 compiled modules report the bunfs mount root from import.meta.dir, not their source-layout module directory. The prior helper walked four directories above that value and escaped the embedded root.

Append packages to the compiled bunfs root, while keeping a guarded suffix path for future module-specific import.meta.dir semantics. Update regression tests to pin the compiled-root behavior observed by a bun build --compile probe.

Fixes #1514
2026-05-29 19:44:36 +00:00
roboomp 9e35b784d8 fix(coding-agent): derived legacy-pi compat bunfs root from import.meta.dir for windows
External extensions importing @oh-my-pi/pi-* values (e.g. AssistantMessageEventStream from @oh-my-pi/pi-ai) failed on Windows compiled binaries with "Cannot find package $bunfs\\root\\packages\\...". Shim paths in LEGACY_PI_PACKAGE_ROOT_OVERRIDES were built from a hardcoded POSIX literal "/$bunfs/root/packages"; Win32 normalised the leading slash to a backslash and the path never resolved against the real bunfs mount (<drive>:\\~BUN\\root\\...).

Derive the bunfs package root by walking four directories up from import.meta.dir (which oven-sh/bun#15766 confirms returns the platform-native bunfs path inside the binary). All override targets now go through path.join, so separators stay native on Windows, Linux, and macOS.

Fixes #1514
2026-05-29 19:39:50 +00:00
roboomp 4d108c1951 fix(plugins): enumerate linked plugins for sub-discovery
PluginManager.link symlinks the package into <plugins>/node_modules
and records it in omp-plugins.lock.json, but never writes to
<plugins>/package.json#dependencies. getEnabledPlugins iterated only
the dependency map, so the documented `omp install ./local-extension`
workflow (delegated to plugin link) succeeded but its sibling skills/,
hooks/, tools/, etc. stayed invisible after install.

Iterate the union of package.json#dependencies and
omp-plugins.lock.json#plugins so symlinked-only packages surface
alongside npm/marketplace installs. Lockfile entries whose
node_modules tree has since been deleted (stale link) are skipped
silently. Linked-only setups with no <plugins>/package.json at all
now work too.

Per-PR review feedback: https://github.com/can1357/oh-my-pi/pull/1498
2026-05-29 06:34:10 +00:00
roboomp bdce9cf068 feat(discovery): scan installed plugin packages for sub-discovery
Marketplace and `omp plugin link` installs write to
`<plugins>/node_modules/` rather than to `extensions:` in settings,
so the original PR still missed their sibling skills/, hooks/,
tools/, commands/, rules/, prompts/, .mcp.json sub-trees. Wire
listOmpExtensionRoots to enumerate getEnabledPlugins(cwd, { home })
in addition to CLI-injected and settings-driven roots.

Adds an optional { home } parameter to getEnabledPlugins so the
discovery loader can pass through LoadContext.home for tempdir-rooted
tests. The getPluginsNodeModules/getPluginsPackageJson/
getPluginsLockfile helpers gain the same optional home overload so
they mirror getPluginsDir.

Per-PR review feedback: https://github.com/can1357/oh-my-pi/pull/1498
2026-05-29 06:28:33 +00:00
can1357 625c8b1992 test(ai): updated tests for model metadata and auth token fallback
- Mocked the Vertex stream E2E test to override the home directory and clear GOOGLE_APPLICATION_CREDENTIALS so token resolution uses metadata credentials instead of local ADC files.
- Updated wafer and model-registry test expectations to match current model metadata values (Qwen3.7 Max and claude-opus-4-8).
2026-05-29 06:56:29 +02:00
roboompandcan1357 437b6524cd fix(cli): restored package resolver for non-compiled pi root remaps
Limited bunfs package-root overrides to compiled-binary mode so non-compiled installs (monorepo, source-link, node_modules) keep resolving legacy pi roots through Bun's package resolver instead of a hardcoded source-tree path.

Refs #1474
2026-05-29 06:42:47 +02:00
roboompandcan1357 349fb51ddb fix(cli): preserved legacy peer fallback for subpaths
Retried original legacy specifiers after canonical peer fallback fails so direct plugin imports with only legacy-scoped peer dependencies continue to load.
2026-05-29 06:42:46 +02:00
roboompandcan1357 564b6d0f22 fix(cli): routed legacy pi-coding-agent imports through a sibling shim
Listing the coding-agent's own ./src/index.ts as a bun --compile extra entrypoint silently breaks the CLI binary startup. Added a dedicated legacy-pi-coding-agent-shim.ts that re-exports the canonical barrel, registered the shim instead of the package index, and updated the compat resolver to point pi-coding-agent at the shim path.
2026-05-29 06:42:46 +02:00
roboompandcan1357 82008e4f38 fix(cli): restored legacy pi package root remaps
Added bundled root overrides for legacy pi package imports in compiled binaries and corrected fallback resolution to use canonical @oh-my-pi specifiers.

Fixes #1474
2026-05-29 06:42:46 +02:00
can1357 5053a6a4d3 fix(coding-agent): corrected coding-agent incomplete stop recovery logic
- Handled "incomplete" stop reasons in session recovery and auto-compaction workflows.
- Dropped the prior assistant turn before attempting recovery on incomplete-length stops.
- Expanded auto-compaction reason types and triggers to include "incomplete".
- Updated internal URLs parsing internals, export order, tests, and Obsidian URI prompt docs.
2026-05-28 10:10:34 +02:00
roboomp 802e3f3e63 fix(extensibility): resolved compat shims to bunfs entry paths in compiled binaries
Reviewer caught that the new `legacy-pi-ai-shim.ts` is only referenced
via a computed string path, so Bun's `--compile` static analyzer cannot
trace it into bunfs. The same gap existed for the pre-existing
`typebox.ts` shim — `path.resolve(import.meta.dir, "../typebox.ts")`
collapses to `/$bunfs/typebox.ts` in compiled mode (where
`import.meta.dir` is `/$bunfs/root`), which does not exist in bunfs.
Legacy plugins importing bare `@sinclair/typebox` or `@(scope)/pi-ai`
therefore hit "Cannot find module" in release builds.

- Branch `TYPEBOX_SHIM_PATH` and `LEGACY_PI_AI_SHIM_PATH` on
  `isCompiledBinary()`: in compiled mode they point at the
  `--root`-relative bunfs entry path with a `.js` extension
  (`/$bunfs/root/packages/coding-agent/src/extensibility/<file>.js`);
  in dev they keep the `path.resolve(import.meta.dir, "../<file>.ts")`
  source path so tests still resolve against the workspace tree.
- List both shims as additional `--compile` entrypoints in
  `scripts/build-binary.ts` so Bun actually emits them into bunfs at the
  paths the runtime expects.

Verified with a focused `bun build --compile` probe: `Bun.resolveSync`
returns the expected bunfs path for both shims when they are listed as
entries, and fails when they are not. Dev-mode test suite unchanged
(17 pass / 0 fail across the four legacy-pi compat test files).
2026-05-27 12:34:27 +00:00
roboomp 6f7da0769b fix(extensibility): redirected legacy pi-ai root imports through Type-compat shim
Plannotator-class legacy extensions still import `Type` from
`@(scope)/pi-ai` (e.g. `@earendil-works/pi-ai` rewritten to
`@oh-my-pi/pi-ai`). pi-ai 15.1.0 removed the root `Type` runtime
export, so extension load crashed with `Export named 'Type' not found`
even though the `@sinclair/typebox` Zod-backed shim still ships in the
coding agent.

Routed bare `@oh-my-pi/pi-ai` root specifiers — used by both the
mirrored-source rewriter and the Bun.plugin onResolve hook — through a
new sibling shim that re-exports the canonical pi-ai surface plus the
`Type` runtime from the existing TypeBox shim. Subpath imports such as
`@oh-my-pi/pi-ai/utils/oauth` continue to resolve directly against the
bundled pi-ai package.

Fixes #1437
2026-05-27 12:14:57 +00:00
can1357 535f7cfa89 fix(coding-agent/tools): reworked yolo approval resolution to honor user tool policies
- In `resolveApproval`, yolo mode now returns the user policy directly (`allow`/`prompt`/`deny`) and ignores tool `override` prompts.
- Updated approval-mode and approval unit tests to match the new behavior for critical bash patterns under yolo and auto-approve.
- Updated docs and settings metadata to describe yolo as user-policy-driven rather than override-driven.
2026-05-27 00:21:33 +02:00
can1357 e4a16451ec feat(coding-agent): added coding-agent approval types and mode options
- Added `ToolTier`, `ToolApproval`, and `ToolApprovalDecision` types and exported approval APIs.
- Updated approval-mode options from `auto|prompt|custom` to `always-ask|write|yolo` and defaulted mode to `yolo`.
- Changed approval resolution to apply per-tool decisions first, then mode-tier limits, with legacy-mode migration.
- Assigned read/write/exec `approval` and approval-detail prompts across built-in, custom, extension, and MCP tools.
2026-05-26 21:52:16 +02:00
can1357 be5837406b ux(coding-agent): implemented coding-agent tool approval selector
- Replaced tool-approval confirmations with an explicit Approve/Deny selector interface.
- Passed approval reason text as selector help and denied actions unless "Approve" was chosen.
- Removed formatApprovalPrompt, truncation helpers, and tool-specific prompt assembly logic.
- Deleted obsolete formatApprovalPrompt tests tied to removed approval prompt formatting.
2026-05-26 21:07:24 +02:00
oldschoolaandcan1357 3893e68fd8 docs(wrapper): clarify approvalMode resolution comment
Stale comment said 'layers user config on top' which sounded like custom
mode merged defaults with config. The actual behaviour (and what the user
asked for): in custom mode user config wins; built-in defaults only fill
gaps for tools the user hasn't configured. auto and prompt modes ignore
tools.approval entirely.
2026-05-26 20:53:34 +02:00
oldschoolaandcan1357 107acc39de feat(coding-agent): add tools.approvalMode setting (auto/prompt/custom)
New global setting under /settings -> Interaction that controls the tool
approval flow:

  auto   (default) Skip every approval prompt — yolo. Matches --auto-approve.
  prompt           Built-in per-tool defaults only. Destructive tools (bash,
                   edit, write, eval, ssh) require confirmation; read-only
                   tools auto-allow; tools.approval.<tool> overrides ignored.
  custom           tools.approval.<tool> config wins. Built-in defaults only
                   fall back for tools the user hasn't configured. Critical
                   safety patterns (rm -rf /, fork bombs, curl|bash) still
                   prompt even when the tool is user-allowed.

The CLI --auto-approve / --yolo flag always wins regardless of the setting,
preserving the automation/CI path.

Wires through ExtensionToolWrapper.execute(): the wrapper reads
tools.approvalMode from settings, derives userPolicies only for custom mode,
and feeds the existing requiresApproval() resolver. Resolution order inside
requiresApproval already places user config above built-in defaults, so
'config wins' falls out naturally in custom mode.

Adds test/tools/approval-mode.test.ts covering all three modes, the CLI
override, the built-in fallback in custom mode, and the critical-pattern
override that fires even when bash is user-allowed.
2026-05-26 20:53:34 +02:00
oldschoolaandcan1357 4d26453a0b feat(coding-agent): restore per-tool approval policies with safer defaults
Re-introduces the per-tool approval system from luzidd's commit 39124f3 (which
is no longer reachable from main) and improves it before re-landing.

What's restored:
- ApprovalPolicy (allow/deny/prompt) plus DEFAULT_APPROVAL_POLICIES.
- ACTION_EXCEPTIONS registry (LSP read-only, bash critical patterns).
- getApprovalPolicy() six-level resolution order.
- ExtensionToolWrapper.execute() gate before extension handlers.
- --auto-approve / --yolo CLI flag and tools.approval.<tool> user config.
- docs/approval-mode.md user guide.

What's improved over the original:
- Replaced unchecked 'as any' casts with typed unknown narrowing helpers.
- Validate userConfig values: invalid strings, numbers, etc. fall through to
  the built-in default instead of being silently honoured (typo no longer
  locks a tool out or grants implicit approval).
- Expanded CRITICAL_BASH_PATTERNS: chmod -R /, chown -R /, bash <(curl ...),
  writes to /etc/passwd|shadow|sudoers, shutdown/reboot/halt/init 0,
  kill -9 1, nc -e / nc -c reverse shells. Pattern shapes require a
  command-position boundary so 'npm run reboot-tests' and 'echo "shutdown the
  queue"' don't false-positive.
- Added DEBUG_READONLY_ACTIONS exception so DAP inspection actions (threads,
  stack_trace, variables, scopes, read_memory, …) auto-allow while
  execution-side actions (launch, attach, continue, evaluate, write_memory,
  set_breakpoint, …) still prompt.
- formatApprovalPrompt: labels mcp__<server>__<tool> calls as MCP server
  tools, surfaces ssh host + command, recognises the modern § hashline header
  for edit, and truncates >240-char fields so a heredoc-sized body cannot
  blow out the confirmation dialog.
- Test suite grown from 40 to 57 cases — new coverage for invalid user
  config, the extended critical-bash patterns, benign-keyword negatives,
  debug exceptions, MCP/ssh prompt formatting, and command truncation.

Verification:
- bun test packages/coding-agent/test/tools/approval.test.ts -> 57 pass
- bun x biome check . -> clean
- bun run check:ts across all 9 workspaces -> clean
2026-05-26 20:53:33 +02:00
Can BölükandGitHub 8448a67602 Merge pull request #1374 from superhedge22/fix-review-enter-submit
Fix /review custom instructions submission
2026-05-26 21:40:15 +03:00
can1357 5364a9bfd0 refactor(tool-discovery): simplified tool discovery API by removing MCP-specific shims
- Removed deprecated MCP-specific type aliases and functions from tool-discovery module, consolidating to unified generic tool discovery API.
- Migrated session and SDK code to use generic filterBySource() and collectDiscoverableTools() instead of MCP-specific variants.
- Removed deprecated interface members including hasQueuedMessages(), FocusPane, AcpBuiltinCommandRuntime, and legacy settings methods.
- Updated test suites to use renamed generic discovery methods and removed back-compat test coverage for legacy MCP shapes.
2026-05-26 15:27:05 +02:00
Can BölükandGitHub d201442a16 Merge pull request #1372 from can1357/farm/e4c67c73/fix-subagent-session-start-busy
fix(agent): prevent subagent session_start busy race
2026-05-25 21:59:38 +03:00
SuperHedge 70e873aa8d Fix review custom instructions submission 2026-05-25 20:48:46 +02:00
roboomp 1217091557 fix(agent): prevented subagent session_start busy race
Queued extension-delivered user messages when deliverAs is set and waited for session_start extension message sends before prompting subagents.

Fixes #1343
2026-05-25 18:48:06 +00:00
Can BölükandGitHub a40864c5b2 Merge branch 'main' into farm/ccf5d9fd/csharp-lsp-plugin-doesn-t-work-with-omp- 2026-05-25 20:37:30 +03:00
roboomp 24b249219e fix(lsp): supported config-only marketplace servers
Loaded marketplace lspServers metadata from Claude plugin caches and embedded it for OMP marketplace installs so config-only plugins register without package code.

Fixes #1352
2026-05-25 17:34:32 +00:00
roboompandcan1357 a2032850e5 fix(legacy-pi-compat): fall back to peer deps when resolveSync fails in binary mode
In a compiled binary, Bun.resolveSync(spec, import.meta.dir) throws
'Cannot find module' because import.meta.dir is inside /$bunfs/root
and the virtual FS exposes no node_modules tree at runtime.

Previously this throw propagated through rewriteLegacyPiImports ->
rewriteLegacyPiImportsForRuntime -> mirrorLegacyPiFile ->
loadLegacyPiModule -> loadExtension, which swallowed it as 'Failed to
load extension' and silently dropped any plugin whose files imported
@mariozechner/pi-ai (or any @mariozechner/pi-* whose bundled
counterpart isn't reachable via resolveSync in the binary).

Fix: wrap the resolution call in rewriteLegacyPiImports in a try/catch
and return the original match on failure. rewriteBareImportsForLegacyExtension
runs immediately afterwards in every call path and already resolves bare
specifiers against the importer's real filesystem directory, so it picks
up @mariozechner/pi-ai from the plugin's installed peer deps instead.

Apply the same fallback to resolveLegacyPiSpecifier (the Bun plugin
shim's onResolve handler) for tool/hook files loaded directly via Bun's
import system rather than through loadLegacyPiModule.

Fixes #1215
2026-05-25 12:22:57 +02:00
can1357andCan Bölük 8dc9125b0b fix(coding-agent): stabilize extension and hyperlink tests 2026-05-21 17:35:04 +09:00
Can Bölük 4024fbe7e2 fix(ai): decontaminate leaked Zod schema instances to valid JSON Schema
Rewrites JSON-roundtripped Zod 4 schema objects that leak Zod internals as
JSON Schema keywords (e.g., `type:"enum"`, `enum:{...}`) into valid
JSON Schema 2020-12. This prevents validation failures when such schemas
are used as tool input schemas (e.g., from MCP servers).

Updates `isZodSchema` to reject deserialized Zod impostors that retain
`_zod` but lose their prototype.

Wires `toJSON` methods onto TypeBox shim schemas to ensure `JSON.stringify`
produces clean JSON Schema, preventing future leaks.

Fixes #1101
2026-05-19 10:16:40 +09:00
can1357 5c7c5eccb8 fix(ai): corrected AI schema normalization to draft-2020-12 prefixItems
- Adopted draft-2020-12 tuple validation with `prefixItems`, rejecting array-valued `items`.
- Expanded strict-mode handling to recurse `prefixItems` entries and infer `array` when tuple prefixes exist.
- Normalized Anthropic schemas through `prefixItems`, keeping supported tuple constraints and dropping unsupported fields.
- Updated coding-agent schema metadata and tests to draft-2020-12 `$schema` targets, including MCP/theme fixtures.
- Added `trimTrailingWhitespace()` to strip trailing spaces/tabs and keep the original line when none exist.
2026-05-15 23:46:23 +02:00
can1357 e1aaf78874 refactor(compaction): moved compaction APIs to @oh-my-pi/pi-agent-core
- Relocated compaction, branch-summarization, pruning, and utils from coding-agent to packages/agent/src/compaction.
- Moved OpenAI remote compaction helpers from packages/ai to the new compaction module.
- Added handoff.ts with extractHandoffDocument, createHandoffContext, and renderHandoffPrompt helpers.
- Exposed new entries.ts with standalone SessionEntry types so coding-agent no longer owns them.
2026-05-15 18:31:12 +02:00