Commit Graph

18622 Commits

Author SHA1 Message Date
roboomp 9cc881ce5b fix(mcp): refresh broker-backed MCP OAuth credentials
Remote OAuth MCP servers dropped out of /mcp under `omp auth-broker
serve` once their access token expired: neither the client nor the
broker could complete the refresh.

- Client: the MCP manager threw on the broker-redacted refresh sentinel
  (REMOTE_REFRESH_SENTINEL) instead of asking the broker to refresh. It
  now routes redacted MCP refreshes through
  AuthStorage.forceRefreshCredentialById, which calls back to the broker
  (the real refresh token never leaves the broker host).
- Broker: the serve process had no mcp_oauth:* refresh path, so
  POST /v1/credential/:id/refresh answered "Unknown OAuth provider". Its
  AuthStorage is now built with a refreshOAuthCredential override that
  refreshes MCP credentials with a generic refresh_token grant from the
  credential's embedded token endpoint and client id. The background
  refresher keeps MCP tokens live through the same path.

Extract shared refreshManagedMcpOAuthCredential and
mcpOAuthServerUrlFromCredentialId helpers so both paths use identical
refresh material selection and RFC 8707 fallback-resource logic.

Fixes #8933
2026-08-19 09:34:51 +00:00
roboomp 8ae547091f fix(ai): serve ipv4-only oauth callback when ipv6 is disabled
The `::1` companion listener added in #8081 cannot bind on hosts with
IPv6 disabled at the kernel (ipv6.disable=1). Bun reports that failure
with its generic "Is port X in use?" message (oven-sh/bun#7187), which
isAddressInUse misread as a real collision, tearing down the healthy
IPv4 listener and throwing a bogus "port 1455 is in use"
ConfigurationError that blocked Codex login.

#createServer now probes os.networkInterfaces() for an internal IPv6
loopback up front and serves IPv4 alone when none exists, instead of
relying on Bun error classification the message ambiguity defeats.

Fixes #8814
2026-08-19 09:33:46 +00:00
roboomp 565d09b13a fix(catalog): route copilot grok-4.6 through responses api
GitHub Copilot serves grok-4.6 / grok-4.6-1m only via /responses, but
isCopilotResponsesModelId matched grok-4.5 exactly, so both the static
generator and dynamic discovery classified grok-4.6 as openai-completions
and requests 400d with unsupported_api_for_model.

- match grok-4.6 in isCopilotResponsesModelId
- add grok-4.6 / grok-4.6-1m to COPILOT_CACHE_INVALIDATED_MODEL_IDS so
  stale cached completion routes drop on refresh
- regenerate github-copilot/grok-4.6 to api openai-responses (compat
  block dropped, xhigh effort added by the responses policy)
- cover discovery routing and cache migration in tests

Fixes #8807
2026-08-19 09:27:16 +00:00
roboomp 1b65e471fb fix(catalog): route opencode-go muse-spark to responses api
The OpenCode Go gateway serves muse-spark-1.2 and
muse-spark-1.2-contributor only at /zen/go/v1/responses, but the
/zen/go/v1/models discovery omits the provider.npm hint, so the
resolver fell through to openai-completions. The completions parser
then closed the stream without a finish_reason on every tool-call turn.

Pin both ids to openai-responses in OPENCODE_GO_API_RESOLUTION, mirroring
the existing deepseek-v4-flash override, and add a resolver regression.

Fixes #8957
2026-08-19 09:24:54 +00:00
roboomp 0808226ca3 fix(coding-agent): paint optimistic row for idle /skill submits
InputController.#invokeSkillCommand cleared the draft and awaited the full
promptCustomMessage dispatch with no transcript render. AgentSession.#promptWithMessage
runs awaited preflight (memory recall, before_agent_start hooks, auto-thinking
classification, pre-prompt compaction) before the message reaches the agent, so a slow
step such as a Hindsight auto-recall timeout left the composer cleared with no pending
row, unlike a normal prompt's optimistic row from startPendingSubmission.

Idle skill submissions now paint an optimistic skill row before the awaited dispatch;
the canonical message_start reconciles it in place via EventController instead of
appending a duplicate. Streaming submissions still queue and show their chip.

Fixes #8895
2026-08-19 09:19:47 +00:00
roboomp e6c0cf90a4 fix(compaction): reject stale pre-compaction anchor in context breakdown
getContextBreakdown used message position (anchorIndex >= pending.cutoffCount) as a proxy for usage freshness. After a mid-run compaction rebased the in-flight snapshot, an in-flight provider response whose request predated the compaction landed past the rebase cutoff carrying pre-compaction usage, so it out-ranked the rebased estimate and reported the pre-compaction token count (~2.6x the real one). That phantom overflow tripped the "freed too little context to make progress" guard and drove the frame-rescue path on a byte-identical tokensBefore.

Assistant context snapshots now carry a monotonic compaction epoch, bumped in rebaseAfterCompaction and stamped at message-record time. A post-cutoff anchor whose epoch predates the pending snapshot's epoch is no longer trusted over the rebased estimate.

Fixes #8887
2026-08-19 09:13:33 +00:00
roboomp caace28295 fix(tui): honor tui.input.submit remap onto ctrl+enter
The multiline editor's key dispatch checked a hardcoded Ctrl/Shift+Enter
-> newline branch before the config-driven tui.input.submit branch, so a
user remap of submit onto Ctrl+Enter was swallowed as a newline and never
submitted. Gate the hardcoded newline fallbacks behind an explicit submit
binding; the bare-LF (iTerm2 Shift+Enter) case stays exempt because its
canonical form is indistinguishable from plain Enter.

Fixes #8906
2026-08-19 09:10:10 +00:00
roboomp 6996b36f4a fix(commit): fail loudly when staged binary truncates split-commit diff
Split-commit captured the staged diff with `git diff --cached --binary`,
whose stdout is hard-capped at GIT_COMMAND_OUTPUT_LIMIT_BYTES (8 MiB) by
readCappedText. A single large binary (base85-encoded inline) crossed the
cap; the capture was truncated silently, so files sorting after the binary
were absent from the parsed diff and stage.hunks threw a misleading
`No diff found for <path>` naming an innocent file.

Surface truncation as GitCommandResult.truncated, add a requireComplete
diff option that throws the new GitOutputTruncatedError instead of
returning a silently truncated diff, and have runSplitCommit request a
complete diff and abort with a clear message pointing at the real cause.

Fixes #8897
2026-08-19 09:07:29 +00:00
roboomp 289cc19325 fix(catalog): self-heal a corrupt models.db model cache
The shared SQLite model cache wrapped every read/write in a blanket catch that swallowed unrecoverable SQLITE_CORRUPT*/SQLITE_NOTADB failures as best-effort misses, and getSharedDb cached the broken handle. A physically corrupt models.db therefore permanently disabled cached catalogs across processes: a successful live discovery could never overwrite the corrupt cache, so a runtime extension with no bundled catalog was stuck with only its bootstrap model.

On those unrecoverable codes the cache now self-heals: close the handle, quarantine models.db(+-wal/-shm) to models.db.corrupt-<ts>, recreate a fresh database, and retry the operation once. SQLITE_BUSY, permission, and unrelated errors keep their existing best-effort paths. The SQLITE_BUSY/corruption classifiers moved to @oh-my-pi/pi-utils so the credential store and model cache share one implementation.

Fixes #8867
2026-08-19 09:00:07 +00:00
roboomp 3d844bf3b2 fix(ai): surface litellm concurrency-admission 429 immediately
The OpenAI-wire transport called fetchWithRetry with maxAttempts: 6 and
the default 60s maxDelayMs cap, so a LiteLLM max_parallel_requests
rejection (HTTP 429, Retry-After: 60) was slept-and-retried up to six
times before TurnRecovery ever saw it. A 60s hint equals the cap, so
fetchWithRetry never bailed early and one turn could stall ~300s,
bypassing the user's retry.maxDelayMs/maxRetries and the session-level
CONCURRENT_LIMIT backoff + model fallback.

postOpenAIStream now opts out of transport-level retry for this
concurrency-admission response class via fetchWithRetry's shouldRetryResponse
gate, detecting the rate_limit_type=max_parallel_requests marker in the
response header or structured body. The 429 surfaces on the first attempt
so session recovery owns retry/fallback. Genuine RPM/quota 429s carry no
such marker and keep honoring Retry-After.

Fixes #8854
2026-08-19 08:55:17 +00:00
roboomp 7cff20cfd0 fix(tui): pin anchored regions under an unpinned streaming seam
TUI.render merged live-region seams with a topmost-seam-wins rule that
adopted only that seam's pin policy for the whole frame. While the primary
turn streams, the transcript reports the topmost, unpinned seam, so the
frame-wide pin flag becomes false and a pinned AnchoredLiveContainer below
it (the /btw panel, the working HUD) loses its pinning: once its content
grows past the viewport, the emit path commits the scrolled-off rows as
frozen snapshots on every growth frame, piling duplicates into native
scrollback.

Track a pinnedBoundary (start row of the topmost pinned region)
independently of which seam wins the topmost merge, and cap every commit
ceiling at it. Equivalent to the prior behavior for a fully-pinned frame
and for a frame with no pinned region; only the mixed case changes.

Fixes #8793
2026-08-19 08:51:13 +00:00
roboomp 4b07f409f6 fix(ai): hoist assistant message interleaved in responses tool batch
opencode-go's Console Go gateway rejects Responses input where an assistant message sits between a function_call batch and its function_call_output items, 400ing with "No tool output found for tool call ..." and permanently poisoning the session in history. This happens whenever a model streams a trailing text/demoted-thinking block after its tool calls: the block-encode path preserves stream order, emitting the message between the calls and the outputs appended afterward.

buildResponsesInput and buildOpenAiNativeHistory now hoist such interleaved assistant messages ahead of their call batch (canonical message(s) -> calls -> outputs); content is unchanged. OpenAI's Responses API is order-tolerant so this is a no-op there.

Fixes #8789
2026-08-19 08:46:28 +00:00
roboomp a0b7ca6708 docs: clarify bash.patterns gates bash tool only, not eval
bash.patterns only feeds the bash tool's approval decision. The eval
tool declares the exec tier and can spawn a shell via subprocess, so a
deny rule there does nothing for the same command run through eval;
under yolo the exec call resolves to allow. Note the scope and point at
tools.approval.eval as the lever that closes the path in
bash-tool-runtime.md, approval-mode.md, and settings.md.

Fixes #8838
2026-08-19 08:46:21 +00:00
roboomp 3acc57de8c fix(task): initialize extension runtime on subagent revival
Both subagent revivers rebuilt the session but never wired the extension
runtime, leaving it pre-init where every action method throws
ExtensionRuntimeNotInitializedError. An extension with a tool_call handler
touching a runtime action then tripped the fail-closed gate in emitToolCall
and blocked every tool, including the hidden yield, so the revived agent
could neither finish nor exit and looped until killed.

Both the warm lifecycle reviver (executor.ts) and the cold persisted
reviver (persisted-revive.ts) now call the shared initializeExtensions
helper on the rebuilt session, restoring runtime actions, onError, and the
session_start event.

Fixes #8824
2026-08-19 08:44:55 +00:00
can1357 c5642a5da1 config(python/robomp): corrected agent filename mount path in docker compose
- Updated the agent configuration mount to correctly map AGENTS.md instead of AGENT.md.
2026-08-19 10:24:35 +02:00
can1357 d94bdfa1bb test: hardened new spinner and title-latch suites against full-suite pollution
- Exported stopSharedSpinnerTicker() and wired it into InteractiveMode.stop(): a live block missed by per-component stopAnimation kept the shared 80ms interval alive as a lingering event-loop handle; the spinner suite uses it to observe a freshly armed ticker instead of one leaked by earlier files
- Title-disposal tests now save/clear/restore PI_NO_TITLE (main() in ACP/RPC mode sets it process-wide), matching the prewarm and orphan-submit precedent
2026-08-19 03:20:50 +02:00
can1357 aa98ea9ed5 test: settled in-flight auto-title request between orphan-submit iterations
The title latch from PR #8911 dedupes a second title start while one is in flight; the orphan-submit loop implicitly relied on the first mocked request having settled. Drain its promise chain at a macrotask boundary before the next submit.
2026-08-19 02:04:51 +02:00
can1357 9bc810b36c style: cargo fmt for snapcompact zero-glyph regression assert 2026-08-19 01:48:19 +02:00
can1357 3566bd9b41 fix(ai): unified Cursor interaction-query handling after merging #8889 and #8830
- Kept the shared cursor/interaction-query module as the single handler and deleted the duplicate local implementation in cursor.ts
- Added the named webFetchRequestQuery approval case (field 9 is named under the regenerated proto)
- Preserved the deliberate no-fake-VM-success semantics for setupVmEnvironmentArgs (review of #8047)
- Updated the field-9 regression test to assert the named decode of the raw same-field reply, which also pins the LEN-prefix wire framing
2026-08-19 01:47:20 +02:00
can1357 20bd4ab97b chore(changelog): normalized [Unreleased] sections after merges and added missing entries
- Repaired union-merge artifacts in packages/coding-agent/CHANGELOG.md (duplicated 17.3.6/17.3.7 blocks; promoted the new entries back to [Unreleased])
- Added missing [Unreleased] entries for PRs #8833, #8866, #8879, #8903, #8905, #8915, #8916, #8917, #8920, #8923, #8928, #8929, #8937
2026-08-19 01:42:50 +02:00
can1357 e61775a470 fix(coding-agent): mention oauth exemption in apiKey validation error; add validation tests 2026-08-19 01:39:18 +02:00
can1357 539d841b10 Merge PR #8937: fix(coding-agent): allow auth oauth without apiKey in models.yml (@usr-bin-roygbiv) 2026-08-19 01:39:18 +02:00
can1357 2d8837695c Merge PR #8936: fix(robomp): validate review comment anchors before submitting (@djdembeck) 2026-08-19 01:39:18 +02:00
can1357 8ade6888e6 Merge PR #8929: fix(catalog): register plain Codex route for worker -wm SKUs (@STRML) 2026-08-19 01:39:18 +02:00
can1357 9200fb3426 Merge PR #8928: fix: skip non-UTF-8 host env entries instead of panicking at startup (@STRML) 2026-08-19 01:39:17 +02:00
can1357 78254059b7 Merge PR #8923: fix(catalog): mark coreweave discovery authoritative (@dmontague-crwv) 2026-08-19 01:39:17 +02:00
can1357 75179e1dc0 fix(compaction): scale summary window floor to the model's context
The absolute 16,384-token floor plus the carried summary and output
reserves exceeds windows below ~58k outright, and overflow recovery then
bailed at the very floor that caused the rejection, leaving compaction
unusable on small-context models. Scale the floor to window/8 (min 1k)
and use the same floor in overflow recovery.
2026-08-19 01:39:17 +02:00
can1357 17e47b3eb7 Merge PR #8920: fix(compaction): bound summarization input and stop retrying overflow (@PaleRoses)
# Conflicts:
#	packages/agent/src/compaction/compaction.ts
2026-08-19 01:39:07 +02:00
can1357 fa8faaf2de Merge PR #8917: fix(sdk): accept flattened array argument paths from providers (@re2zero) 2026-08-19 01:38:35 +02:00
can1357 130cc9c0a3 fix(tui): also accept legacy CSI ~ Shift+Enter form in /tree selector
Mirrors the composer's raw-sequence fallback (editor.ts:1466) so
\x1b[13;2~ triggers summarize-and-switch instead of being dropped as
shift+f3, completing the parity requested in issue #8821.
2026-08-19 01:38:35 +02:00
can1357 f60e32f9b8 Merge PR #8916: fix(tui): treat bare LF as Shift+Enter in the /tree selector (@re2zero) 2026-08-19 01:38:35 +02:00
can1357 fc24a491fb Merge PR #8915: fix(session): only advertise --resume when the session is on disk (@re2zero) 2026-08-19 01:38:35 +02:00
can1357 74366ee996 Merge PR #8911: fix(session): generate titles from /skill invocation args (@qiyi71w) 2026-08-19 01:38:34 +02:00
can1357 195033a432 Merge PR #8909: fix(coding-agent): condition think prelude guidance for subagents (@olegpulatov) 2026-08-19 01:38:34 +02:00
can1357 c57d710a67 Merge PR #8905: Advisor blocker advisories wake a new turn instead of parking in the immune window (@STRML) 2026-08-19 01:38:34 +02:00
can1357 12cfaceef1 Merge PR #8903: fix(discovery): expand extension-package MCP env placeholders (@drycode) 2026-08-19 01:38:34 +02:00
can1357 22439b6be2 Merge PR #8896: fix(settings): hide excluded search providers from summary (@poorpaper) 2026-08-19 01:38:34 +02:00
can1357 0ac4e01b7b fix(ai): length-prefix the unknown interaction-query approval payload
Unknown LEN fields in protobuf-es carry raw wire bytes including the
length varint (BinaryReader.skip captures it; BinaryWriter.raw replays
verbatim after the tag). The fallback for unnamed permission-query
variants wrote 'approved {}' as bare 0a 00, producing a frame the
server cannot decode (the 0a is read as a length of 16). Prefix the
payload with its length and lock the wire shape with a round-trip test.
2026-08-19 01:38:25 +02:00
can1357 82257d3ab1 Merge PR #8830: fix(ai): answer Cursor hosted WebFetch permission queries (@Unravl)
# Conflicts:
#	packages/ai/src/providers/cursor.ts
#	packages/ai/test/cursor-interaction-query.test.ts
2026-08-19 01:38:07 +02:00
can1357 0e8c451f66 Merge PR #8889: fix(cursor): answer interactionQuery and resume idle-stall MCP turns (@bnivanov) 2026-08-19 01:37:01 +02:00
can1357 9975e5c70e docs(coding-agent): fix stale worker-cwd comment in js eval process entry
resolveWorkerSpawnCmd no longer pins the host-entry worker cwd to the
install dir; the subprocess inherits the agent cwd (or the package root
under the bun-test fallback). Update the chdir rationale accordingly.
2026-08-19 01:37:01 +02:00
can1357 cad0cdad48 Merge PR #8883: fix(coding-agent): stop pinning worker subprocess cwd to the install dir (@chuzui) 2026-08-19 01:37:01 +02:00
can1357 0128b2e9fc Merge PR #8879: fix(web-search): abort-protect browser fallback setup and teardown (@kimono381) 2026-08-19 01:37:01 +02:00
can1357 cc5068bd17 Merge PR #8872: fix(tui): render xdev tool images inline (@daandden) 2026-08-19 01:37:01 +02:00
evaluator c3fc3d6191 fix(catalog): restore function declaration dropped by doc-comment reformat 2026-08-19 01:37:00 +02:00
can1357 8a4e0afdbe Merge PR #8871: fix(catalog): map aliased Gemini Flash minimal to LOW on Cloud Code Assist (@audreyt) 2026-08-19 01:37:00 +02:00
can1357 52cc0f43b3 Merge PR #8866: Preserve MCP tools across PlanYolo handoff (@nick-maderight) 2026-08-19 01:37:00 +02:00
can1357 8a74892c3b Merge PR #8864: fix(task): refresh model roles before agent discovery (@z80dev) 2026-08-19 01:37:00 +02:00
can1357 e972bdb4d1 Merge PR #8857: fix(discovery): honor Claude Code enabledPlugins for marketplace plugins (@drycode) 2026-08-19 01:37:00 +02:00
can1357 381ed55d5b Merge PR #8852: fix(catalog): add deepseek-v4-pro-0813 discovery limits (@tommyldev) 2026-08-19 01:37:00 +02:00