Commit Graph

18051 Commits

Author SHA1 Message Date
can1357 58f319912e feat: introduced dynamic version discovery and rate limit parsing for google
- Added dynamic Antigravity version discovery with environment variable overrides and fallback endpoint support.
- Introduced structured Google RPC `ErrorInfo` rate limit reason parsing and backoff classification.
- Added `gemini-3.7-flash` and `deepseek-v4-pro:preview` model configurations alongside updated pricing.
- Removed system instruction injection logic and dropped unsigned thinking blocks for Antigravity requests.
2026-08-13 23:59:37 +02:00
can1357 de99219db0 test(coding-agent): revert fake-timer rewrite of session_shutdown cap test
- The b279db1790 rewrite wrapped runner.emit() in vi.useFakeTimers() and
  hand-advanced the clock, but the runner registers its cap setTimeout after
  more microtask turns than the test advances (emit defers the timeout
  machinery to the first matching handler and hops through Bun.sleep(0)),
  so the cap timer never fires, emit never settles, and fake timers also
  neutralize bun's per-test timeout — the singleton/global-state CI bucket
  hung silently until the 600s watchdog SIGKILL (exit 137).
- Restored the pre-refactor real-time version: it has no sleeps or polling
  loops, runs the hung handlers against a 100ms cap, and asserts bounded
  wall-clock plus the per-extension timeout warnings.
- Verified the full 79-file singleton bucket passes (867 tests) and the
  restored file passes on Linux bun 1.3.14 in Docker.
- Restored the original 17.3.1 status-line changelog bullet (released
  sections stay immutable).
2026-08-13 20:56:15 +02:00
can1357 6563b16424 fix(coding-agent): stat-poll git HEAD instead of fs.watch for branch display
- Bun's inotify-backed fs.watch permanently stops delivering events after
  observing git's atomic HEAD.lock -> HEAD rename in the watched directory
  (oven-sh/bun#24875), so the directory-watch fix for issue #8412 still froze
  the status-line branch on Linux after the first switch; CI caught it as a
  30s timeout in status-line-vcs-refresh.test.ts.
- Added git.head.watch: fs.watchFile stat-poll of the HEAD path (reftable dir
  for reftable repos) with a disposer; path-based polling survives inode swaps
  on every platform.
- Status line and footer now consume the helper; the footer previously bound
  fs.watch to the HEAD file inode and died after one switch on all platforms.
- Dropped the FSWatcher error-listener plumbing (StatWatcher has no error
  mode) and reworked the watcher lifecycle tests to the stat-poll contract;
  verified the atomic-rename regression test passes on Linux bun 1.3.14 in
  Docker where it previously timed out.
2026-08-13 20:20:49 +02:00
can1357 0bc2c342f4 chore: bump version to 17.3.1 2026-08-13 19:39:21 +02:00
can1357 3ce33d436b feat(catalog): added Gemini Flash model definitions and routing
- Added Gemini 3.7 Flash model definitions and reasoning effort routing configurations.
- Implemented geminiLevelFlashFamily in variant-collapse.ts to manage 3.6+ flash thinking levels.
- Added test coverage for Gemini 3.7 Flash variant collapse and discovery routing.
2026-08-13 19:36:51 +02:00
can1357 b279db1790 test: refactored test suites to eliminate time-based sleeps and polling loops
- Replaced time-based sleeps and polling loops with event-driven promise resolvers and fake timers across agent and tool tests.
- Migrated test suites to share in-memory auth storage and fixtures using lifecycle hooks.
- Updated catalog model definitions, metadata, and configurations.
2026-08-13 19:32:22 +02:00
can1357 28997c0d46 refactor(coding-agent): restructured transcript rendering during initialization
- Stage transcript initialization inside a detached TranscriptContainer to keep existing messages visible during incremental rendering.
- Add fallback state restoration in InteractiveMode.renderInitialMessages when chat rendering is aborted or fails.
- Update render-initial-messages tests to assert that old transcripts remain visible until replacements are fully committed.
2026-08-13 18:55:36 +02:00
can1357 778dfaccca test(coding-agent): align browser probes with linux scope 2026-08-13 18:46:18 +02:00
can1357 a32cf5f30a Merge PR #8446: fix(coding-agent): confine browser executable probe to Linux (@roboomp) 2026-08-13 18:46:18 +02:00
can1357 a2aad5408e Merge PR #8443: fix(natives): static-link win32 MSVC CRT so addon needs no VC++ redist (@roboomp) 2026-08-13 18:46:08 +02:00
can1357 2b02b1fbf0 test(tui): clear PI_TUI_RESIZE_IN_PLACE in stress env patch
The deterministic replay oracle only models in-place resize for tmux and
direct HerdR, but an inherited PI_TUI_RESIZE_IN_PLACE=1 makes the runtime
treat every scenario as in-place and desyncs the oracle. Add the key to
the stress env patch so a developer's override cannot leak into replay.
2026-08-13 18:44:18 +02:00
can1357 23aff5ae3f test(tui): model direct HerdR in-place resize in stress oracle
The HerdR flicker fix routed direct HerdR panes onto the in-place
multiplexer resize path, but the randomized render-stress oracle still
modeled them as ED3 replaying direct terminals. The width-epoch ledger
now applies to any in-place-resize scenario (multiplexer + direct HerdR)
via a dedicated resizeRepaintsInPlace trait, keeping HerdR's direct
scrollback semantics intact. Adds a deterministic replay regression
(seed 0xcafed00d, 24 iterations) that fails without the oracle update.
2026-08-13 18:39:29 +02:00
roboomp cf1ff14f5f fix(coding-agent): confine browser executable probe to linux
The executable version probe added in ecb22957 ("validate Linux browser
executables") replaced the file-only check in resolveSystemChromium with
isChromiumExecutable, which spawns the candidate `--version` for every
platform. On Windows chrome.exe is a GUI-subsystem binary: `--version`
does not print to a detached stdout and can hand off to a running
instance, opening/activating the user's normal browser window, after
which the probe rejects the candidate and falls back to cached Chrome
for Testing.

Gate the spawn probe on process.platform === "linux" (its intended
platform, where non-Chromium PATH wrappers are the real risk) and trust
the executable-file check on Windows and macOS.

Fixes #8445
2026-08-13 16:28:57 +00:00
roboomp 2e2bf1f3a5 fix(natives): pin cmake opus build to static MSVC CRT (/MT)
The win32 addon static-CRT switch enabled the static_link_msvcrt cc
feature, but audiopus_sys's bundled opus is built through the generated
CMake toolchain, which pinned CMAKE_MSVC_RUNTIME_LIBRARY=MultiThreadedDLL
(/MD) as authoritative under CMP0091 NEW. The opus objects could then
still emit /MD and pull VCRUNTIME140.dll / conflict with the static CRT
the rest of the addon links, leaving the outcome dependent on compile-
flag ordering.

Pin CMAKE_MSVC_RUNTIME_LIBRARY to MultiThreaded (static release /MT) in
the msvc toolchain.cmake so opus deterministically matches rustc's
+crt-static and the static_link_msvcrt feature.

Verified with a fully cold `bazel build //:natives-win32-x64-baseline`
(opus recompiled): the produced .node imports no VCRUNTIME140.dll and no
api-ms-win-crt-* — only core Windows system DLLs.

Fixes #8439
2026-08-13 16:21:23 +00:00
can1357 0b21036f66 chore: update changelogs 2026-08-13 18:09:56 +02:00
can1357 391502ade0 chore: merge duplicate Unreleased changelog heading 2026-08-13 18:02:31 +02:00
can1357 eadfbcb689 Merge PR #8440: fix(discovery): honor Claude config directory (@roboomp) 2026-08-13 18:01:31 +02:00
roboomp 246dda7f1c fix(natives): static-link win32 MSVC CRT so addon needs no VC++ redist
The shipped win32-x64 pi_natives addon linked the dynamic MSVC CRT (/MD)
and imported VCRUNTIME140.dll from the Visual C++ Redistributable, which
is absent on a clean Windows install. LoadLibrary of the extracted .node
then failed with error 126 ("The specified module could not be found"),
so omp could not start after a fresh `irm install.ps1 | iex`.

Static-link the CRT for the win32 addon: +crt-static for rustc (crate
BUILD select) plus the static_link_msvcrt cc feature enabled for win32 in
the native_addon transition, so its C deps (opus/cmake, tree-sitter,
blake3, ring) compile /MT in lock-step. The rebuilt .node imports only
core Windows system DLLs -- no VCRUNTIME140.dll, no api-ms-win-crt-*.

Fixes #8439
2026-08-13 16:00:33 +00:00
can1357 219123244e fix(update): serialize target swap under a per-target lock
Two overlapping `omp update` runs now share the target only for the
swap + stale-artifact sweep, guarded by withFileLock. This closes the
rollback race the unique-temp fix left open: a concurrent run's sweep
could delete a live run's .bak before its failed verification rolled it
back. The download stays outside the lock (unique temp path, safe to
overlap). Adds a regression covering a failed verification overlapping a
successful update.
2026-08-13 17:57:01 +02:00
roboomp 3e4b59fa94 test(discovery): cleared inherited CLAUDE_CONFIG_DIR in setup
Legacy-path Claude discovery tests now unset an inherited override in beforeEach so they read the fixtures under their temp homes; relocation cases still set it explicitly.
2026-08-13 15:51:06 +00:00
roboomp 406306f972 fix(discovery): isolated plugin root caches by home
Included the resolved OMP plugin registry path in cache identity and covered shared Claude config directories across isolated SDK homes.
2026-08-13 15:44:02 +00:00
roboomp 3629464cf9 fix(discovery): honored claude config directory
Resolved Claude user configuration, plugin, MCP, and session paths through CLAUDE_CONFIG_DIR while retaining the legacy defaults.

Fixes #8436
2026-08-13 15:33:27 +00:00
can1357 98682472e2 test(update): initialize theme in isolated race test 2026-08-13 17:32:50 +02:00
can1357 69862139b3 Merge PR #8435: fix(update): unique temp path for concurrent self-updates (@roboomp) 2026-08-13 17:32:50 +02:00
roboomp 1d6d35bd24 fix(update): unique temp path for concurrent self-updates
Two overlapping `omp update` runs shared the fixed `<binary>.new` temp
path. downloadVerifiedBinary unlinks the target before writing, so the
second run's unlink deleted the first run's still-downloading temp file;
the first kept writing to its open fd (size and digest still passed),
then chmod hit the missing path and aborted with ENOENT.

Give the temp path the same unique per-attempt suffix the backup path
already uses (pid, timestamp, and a new process-local counter that also
covers same-millisecond, same-process collisions). Generalize the stale
backup sweep to also reclaim orphaned `.new` temp files, age-gated by the
download window so a concurrent run's in-progress temp is never deleted.

Fixes #8434
2026-08-13 15:17:41 +00:00
can1357 f4eb28e778 docs(tui): correct HerdR stress-scenario comment to match in-place resize policy
Direct HerdR panes no longer clear/replay via ED3 on resize; the
scenario description still claimed the old behavior. Aligns the comment
with PR #8433.
2026-08-13 17:13:14 +02:00
can1357 76457f82de refactor(tui): drop formatter churn from HerdR flicker fix
Revert the unrelated object-literal reflow bundled into the PR merge,
keeping only the direct-HerdR in-place resize routing, its tests, and
docs. PR #8433 (@roboomp).
2026-08-13 17:08:23 +02:00
can1357 90d4803fdd Merge PR #8433: fix(tui): stop direct HerdR pane flicker (@roboomp) 2026-08-13 17:04:50 +02:00
can1357 fcdaa2162a Merge PR #8425: fix(extensions): lower embedded omptype schemas in Type.Unsafe (@roboomp) 2026-08-13 16:57:20 +02:00
can1357 4ce4874e78 fix(cli): validate ACP tool allowlists after discovery 2026-08-13 16:57:17 +02:00
can1357 bc77dcabb6 Merge PR #8424: fix(cli): allow extension tools in --tools allowlists (@roboomp) 2026-08-13 16:57:14 +02:00
can1357 05eb8beebc Merge PR #8423: fix(extensions): populate runtime mode in context (@roboomp) 2026-08-13 16:57:11 +02:00
can1357 a1baa16531 test(coding-agent): pin stable git watch target 2026-08-13 16:57:08 +02:00
can1357 39d2fd3b3c Merge PR #8415: fix(coding-agent): watch git dir so branch display tracks switches (@roboomp) 2026-08-13 16:57:05 +02:00
roboomp 9b389d6006 fix(tui): preserved direct herdr clears
Scoped direct Herdr multiplexer behavior to resize repaint selection so explicit transcript replacements continue to clear and replay scrollback.

Added coverage for resize stability and resetDisplay ED3 behavior.
2026-08-13 14:45:03 +00:00
roboomp bb0314a5a1 fix(tui): stopped direct herdr pane flicker
Kept direct Herdr panes on the host-safe in-place resize path so streaming redraws no longer clear and replay pane scrollback.

Updated the resize regression, stress scenario, renderer docs, and changelog.

Fixes #8431
2026-08-13 14:34:03 +00:00
roboomp 9286b72b4f fix(omptype): preserved TypeBox constraint keywords
Emit pattern, non-URL format, and multipleOf from the TypeBox adapter alongside the runtime narrows that enforce them. Embedded builders lowered by the legacy compatibility shim now retain identical validation constraints in the raw JSON-Schema validator.

Added adapter-level wire assertions and an end-to-end unsafe embedding regression.
2026-08-13 09:15:34 +00:00
roboomp 3749478239 fix(cli): validated allowlists after tool discovery
Moved strict --tools validation to the completed session registry so extension modules, custom tool directories, and plugin manifest tools are all eligible while unknown names still fail startup.
2026-08-13 09:12:12 +00:00
roboomp a4adf17986 fix(extensions): preserved run properties in unsafe schemas
Require the omptype schema brand before treating a raw document's run key as the self-reference copied by a schema spread. This keeps legitimate JSON Schema properties named run intact while retaining spread-schema recovery.

Added regression coverage for a required boolean run parameter.
2026-08-13 09:06:18 +00:00
roboomp 9d7e13a158 fix(extensions): lowered embedded omptype schemas in Type.Unsafe
Legacy Pi extensions build raw tool-parameter documents against real
TypeBox, whose Type.* builders return plain JSON-Schema objects. omptype's
builders return callable schema values instead, so a legacy document that
embeds them (Type.Unsafe({ anyOf: [Type.Array(...), Other] })) or spreads
them (Type.Unsafe({ ...Schema, description })) carries functions. The shim
then structured-cloned that document during plugin install validation and
threw "The object can not be cloned.", rejecting extensions that load fine
when linked (e.g. pi-subagents, all published versions).

Type.Unsafe now lowers embedded builders to their wire JSON and rebuilds
spread documents from the copied run self-reference before cloning or
serializing, matching the plain-object schemas real TypeBox produces.

Fixes #8420
2026-08-13 08:59:50 +00:00
roboomp 6980275a50 fix(cli): allowed extension tools in allowlists
Deferred --tools validation until extension discovery, then validated against built-in and registered tool names while preserving strict rejection of unknown names.

Fixes #8421
2026-08-13 08:53:59 +00:00
roboomp 7463803c95 fix(extensions): populated runtime mode in context
Expose the Pi-compatible tui, rpc, json, or print host mode to every extension context and cover mode transitions in the runner regression suite.

Fixes #8419
2026-08-13 08:51:05 +00:00
roboomp e62814b4b0 fix(coding-agent): watch git dir so branch display tracks switches
The status-line branch watcher bound fs.watch to the .git/HEAD file.
git updates HEAD via a lock file plus an atomic rename (HEAD.lock ->
HEAD), which unlinks the watched inode, so the watch fired for the
first branch switch and then died on the stale inode. The displayed
branch froze on the previous branch while later switches went unseen.

Watch the git directory instead of the HEAD file (and, for reftable
repos, the reftable dir as before) and filter directory events for the
HEAD entry. The directory inode is stable across renames, so the watch
survives every switch.

Fixes #8412
2026-08-13 07:05:32 +00:00
can1357 326d24bd40 fix(tests): passed explicit apiKey in anthropic cache-refresh tests
- Tests relied on ambient ANTHROPIC_API_KEY from env/.env cascade and
  failed in CI where no key exists; explicit test key removes the
  dependency.
2026-08-13 08:47:35 +02:00
can1357 8b0f400d3c chore: bump version to 17.3.0 2026-08-13 08:28:43 +02:00
can1357 6b4823181b test: cleaned test suites and documented filtering guidelines
- Remove redundant definedness, null, and type checks across test suites in multiple packages.
- Clean up unused assertions, metadata tests, and obsolete test cases.
- Add good versus bad test filter guidelines and requirements to project documentation.
2026-08-13 08:28:42 +02:00
roboomp 04a0b44d6a fix(tests): align test fixtures with low/high/max ladder for deepseek-v4-pro (#8405)
Updates test assertions and fixtures to reflect that V4 Pro now exposes the full [low, high, max] effort ladder, switches the incompatible-fallback test to the openrouter deepseek-v4-pro entry, and adds a shared browser lease in the evaluation suite to avoid relaunching Chromium per test under load.
2026-08-13 08:28:42 +02:00
roboomp dee2196985 fix(catalog): regenerated deepseek-v4-pro metadata
Regenerated the bundled catalog so raw models.json consumers receive the
low/high/max reasoning-effort ladder for DeepSeek V4 Pro entries.

Fixes #8405
2026-08-13 07:18:46 +02:00
roboomp 93795acdd4 fix(catalog): expose low reasoning effort for deepseek-v4-pro
DeepSeek's Chat Completions API now advertises reasoning_effort
low/high/max for both deepseek-v4-flash and deepseek-v4-pro, but the
catalog gated the low tier behind isDeepseekV4FlashModelId, so V4 Pro
(and every non-Flash reasoner) fell through to high/max. Broaden the
DeepSeek effort ladder to give any V4 SKU the low/high/max scale on the
direct API and faithful aggregator routes, keeping OpenRouter's non-Flash
route at high-only and the older V3.x/R1 reasoners at high/max.

Fixes #8405
2026-08-13 07:18:46 +02:00
can1357 ddbf1ffecb feat: fell back to pinned bunx package for bun2nix generation
- Added a fallback to the pinned bunx package when generating Nix bun dependencies without an active Nix environment.
- Updated generator resolution logic and corresponding tests.
2026-08-13 07:18:17 +02:00