Commit Graph

17025 Commits

Author SHA1 Message Date
Andrew Fischer 5da9525afd ci(release): add SHA256SUMS.txt to GitHub releases
Generate a sha256sum-compatible checksums file covering every release
binary and the browser-relay zip, and upload it as a release asset so
downloads can be verified offline without hitting the GitHub API.
2026-08-04 15:38:18 -07:00
Can Bölük 36830e3d05 Merge pull request #7645 from psamwel77/fix/bedrock-govcloud-us-gov-catalog
fix(catalog): emit AWS GovCloud us-gov Bedrock Claude inference profiles
2026-08-04 23:16:46 +02:00
Can Bölük 02ae28aecb Merge pull request #7651 from lederniermagicien/fix/copilot-fleet-skew-400
fix(ai): retry GitHub Copilot fleet-skew model 400s
2026-08-04 23:15:49 +02:00
Can Bölük 1fbb1c9e72 Merge pull request #7656 from can1357/farm/95e5830c/revert-7397
revert(session): restore legacy project directory names
2026-08-04 23:13:55 +02:00
roboomp 172ce9bf6c revert(session): restored legacy project directory names
Reverted PR #7397 session directory hashing and automatic migration.

Restored existing script compatibility with the legacy cwd-derived naming scheme.

Fixes #7646
2026-08-04 21:10:54 +00:00
Magicien f3ad5ede6b fix(ai): scope the Copilot 8-attempt retry budget to model flaps
The 3 -> 8 bump in callWithCopilotModelRetry was shared by the generic
retryable branch, so a persistent status-less transport blip on Copilot
would ramp across 8 attempts (~11.2s of dead time) instead of the 3 it
took before, and a repeated Retry-After 429 could stretch the same way
on top of the transport's own fetchWithRetry budget.

Derive the budget from the failure kind: model-availability 400s keep the
8-attempt reroll, everything else caps at the previous 3.

Also read COPILOT_TRANSIENT_MODEL_CODES with Object.hasOwn — `code` is
provider-controlled, so a 400 body whose code was `__proto__` or
`toString` classified as transient through the prototype chain.
2026-08-04 21:51:35 +01:00
Magicien d33f2a1658 fix(ai): retry GitHub Copilot fleet-skew model 400s
Any Copilot model in the middle of a rollout (claude-sonnet-4.6,
claude-opus-4.6, gpt-5.4, gpt-5.3-codex, ...) returned a raw HTTP 400 on
roughly half of all turns. GET /models on api.githubcopilot.com returns
two different catalogs across repeated calls: part of the fleet serves
those ids, part rejects them with

  400 {"error":{"message":"The requested model is not available for
  integrator \"copilot-language-server\". ...",
  "code":"model_not_available_for_integrator", ...}}

The absorb machinery already existed and was correct
(isCopilotTransientModelError -> isProviderRetryableError -> the
Anthropic transport's PROVIDER_MAX_RETRIES). Only the classifier missed:
it matched the older model_not_supported code and probed err.code /
err.error.code, while the real code is model_not_available_for_integrator
sitting at err.error.error.code (the SDK stores the parsed body on
.error, and Copilot's body is itself {error:{code}}). So
isProviderRetryableError fell through to "4xx => terminal".

Fix the classifier: providerErrorCode() walks the error envelope up to
depth 3 instead of hardcoding a shape, both Copilot model-availability
codes are accepted, and a wire-body text match backs it up because SDK
envelope shapes drift between provider families while the stringified
message does not. This alone restores the retry path, because
isProviderRetryableError consults the provider hook before its
4xx short-circuit.

Retry shape, since a rejection is a per-request replica reroll rather
than upstream backpressure:

- both transports wait a flat delay between model-flap attempts instead
  of the growing backoff; generic retryable failures (429/5xx/transport)
  keep their linear ramp and Retry-After handling
- the OpenAI-transport budget goes 3 -> 8 attempts, because a measured
  ~70% flap window produced a turn that needed 6 wire attempts and
  exhausting the budget escalates to the agent-level retry, which
  restarts the whole turn

Absorbed attempts cost no tokens: rejections are gateway-side, carry no
usage block, and return in ~208ms median versus ~1884ms for a served
request.

Also refresh the exhausted-retry guidance text, which cited a
nonexistent model id and described the cause as a per-client rollout gap
rather than fleet skew.
2026-08-04 21:45:44 +01:00
Pete Samwel fce059930e fix(catalog): emit AWS GovCloud us-gov Bedrock Claude inference profiles
Bare anthropic.claude-* Bedrock rows already derived eu.* selectors; also
emit us-gov.* so GovCloud accounts can resolve system inference profiles
without requiring a full partition ARN.
2026-08-04 13:13:18 -05:00
can1357 5af71dc9cf docs(coding-agent): added 17.2.8 changelog entry 2026-08-04 18:25:07 +02:00
can1357 fc7cd30bd1 fix(omptype): restored required-first wire ordering and defaulted optional keys
- Restored required-before-optional property ordering in JSON Schema emission; downstream wire consumers (pi-ai toolWireSchema) rely on that stable ordering.
- Mapped Type.Optional with a default to a plain defaulted key in the TypeBox shim, since omptype (like ArkType) rejects optional keys that specify defaults.
2026-08-04 18:25:07 +02:00
can1357 003bb5548c chore: bump version to 17.2.8 2026-08-04 05:53:35 +02:00
can1357 90b5d8e707 feat(omptype): implemented advanced schema operators and type features
- Added support for bigint, RegExp literals, and regex execution in the string DSL alongside intersection and pipe operators.
- Enhanced error aggregation, cycle detection, and alternative branch rendering for union and collection validations.
- Updated object compilation and evaluation to support symbol and pattern indexes.
- Extended type methods with subtyping, type intersection, and scope building features.
2026-08-04 05:52:57 +02:00
can1357 f7b9170f2d test(omptype/ark): refactored test suites and validation assertions
- Cleaned up test suites by removing redundant JSON property and schema assertions.
- Updated validation error messages and assertions to adopt bracket and string formats.
- Replaced internal structure inspections with runtime evaluation and allows checks.
- Standardized type equality checks using Eq type assertion helpers.
2026-08-04 03:23:29 +02:00
can1357 0eae38c0e3 test(omptype/ark): added arktype test suites and configuration
- Add extensive test suites covering arrays, objects, keywords, and core type operations.
- Introduce ArkType development dependencies and project configuration updates.
- Configure tsconfig to exclude the new ArkType test directory from compilation.
2026-08-04 02:49:17 +02:00
can1357 b7adf21415 feat(omptype): added input and output io options for JSON schema generation
- Support `io: 'input'` and `io: 'output'` in `toJsonSchema` to control morph and default representation.
- Track `.to(target)` step output IR to drive output-side JSON schemas for piped types.
- Update string DSL inference to correctly handle input-side union members and morph sources.
2026-08-04 02:26:35 +02:00
can1357 ee335ce9c2 feat(snapcompact): implemented squad context compression benchmark
- Added a new SQuAD-based context-compression benchmark script for evaluating recall conditions.
- Added model and shape command-line arguments along with pricing and shape configurations.
- Updated default model variants and added an unknown billing family to shape resolution.
- Updated shape resolution and model resolution tests to verify the new defaults.
2026-08-04 02:20:03 +02:00
can1357 e8f890fb16 feat(omptype): implemented standard schema interop and json schema parsing
- Added Standard Schema V1 interop via `~standard` property to enable synchronous validation across tools like tRPC and @t3-oss/env.
- Added `fromJsonSchema()` function to rebuild callable schemas from JSON Schema documents with recursive reference support.
- Added comprehensive unit test suites covering Standard Schema validation and JSON Schema round-tripping.
2026-08-04 02:12:35 +02:00
can1357 a5090f1f81 chore: bump version to 17.2.7 2026-08-04 01:19:36 +02:00
can1357 60acbee44a docs(changelog): normalized and regenerated unreleased changelogs 2026-08-04 01:19:08 +02:00
can1357 9b52d592a4 fix(omptype): bound toJsonSchema before wrapping in typebox adapter
- withJsonSchemaKeywords extracted toJsonSchema unbound, breaking this.description access added by the definition-inference fix.
2026-08-04 01:08:32 +02:00
can1357 d81fe8089b Merge PR #7561: fix(catalog): honor disabled DeepSeek thinking (@roboomp) 2026-08-04 01:03:07 +02:00
can1357 ad37de9663 Merge PR #7553: fix(coding-agent): allow quoted metacharacters in bash patterns (@roboomp) 2026-08-04 01:03:01 +02:00
can1357 fbfae3b4ad Merge PR #7540: fix(discovery): honor disabled codex mcp servers (@roboomp) 2026-08-04 01:02:56 +02:00
can1357 c662a861ba Merge PR #7518: fix(cursor): degrade K3 same-model history missing thinking (@roboomp) 2026-08-04 01:02:53 +02:00
roboomp 58ced35dc0 fix(catalog): honored disabled DeepSeek thinking
Moved the direct DeepSeek enabled toggle into the thinking-only compat variant and normalized stale cached compat metadata before request encoding.

Fixes #7559
2026-08-03 21:48:40 +00:00
can1357 e2412f68b2 Merge PR #7546: fix(setup): verify musl binary starts before reporting install success (@roboomp) 2026-08-03 23:41:21 +02:00
can1357 1cf919099e style(pi-shell): wrapped long command string in test
- Split a long command string across multiple lines in shell test.
2026-08-03 23:41:07 +02:00
can1357 b515024edc fix(omptype): resolved TS2589 instantiation cycles in definition inference
- Added an any-cutoff guard to InferDef/InferDefIn so permissive instantiation
  terminates instead of recursing through spread/index members without bound.
- Boxed spread and index-signature recursion behind an interface member and
  flattened primitive keyword lookup plus member-inference fallback chains.
- Gave BaseType (type.raw results) the fluent composition surface so .array()
  and friends type-check.
2026-08-03 23:36:29 +02:00
roboomp 98a65ffbdf fix(coding-agent): blocked escaped reinterpreted payloads
- Preserved escaped control characters for the downstream reinterpretation safety decision.
- Covered the backslash-escaped git inline shell-alias bypass.

Fixes #7552
2026-08-03 21:18:35 +00:00
roboomp b621a9a637 fix(coding-agent): flagged double-quoted reinterpreted payloads
- Treated double-quoted shell-control chars like single-quoted ones so a -c/-e reinterpretation option still gates them.
- Covered the double-quoted git inline shell-alias bypass.

Fixes #7552
2026-08-03 21:13:13 +00:00
roboomp 9bcd31fcd2 fix(coding-agent): blocked reinterpreted quoted shell payloads
- Kept quoted shell controls prompt-gated when code-evaluation options can reinterpret the argument.
- Covered the reported git inline shell-alias bypass while retaining Cargo regex approval.

Fixes #7552
2026-08-03 21:08:52 +00:00
can1357 f559e7e9dc feat(omptype): introduced boolean validation caching and parser helpers
- Added `compileAllows` and specialized `.allows()` caching for boolean validation.
- Optimized parser performance with helper methods for whitespace scans and object definitions.
- Cloned path arrays in error handling to prevent internal mutation bugs.
- Updated benchmarks and added unit tests covering nested and optional property validation.
2026-08-03 23:02:52 +02:00
roboomp 54b2e38564 fix(coding-agent): allowed quoted bash pattern metacharacters
- Replaced the raw character guard with quote-aware scanning while retaining command substitution and unquoted shell-control protections.
- Added regression coverage for the reported Cargo benchmark filter.

Fixes #7552
2026-08-03 20:54:41 +00:00
can1357 bc39ffa265 feat: introduced omptype validation package and migrated workspace dependencies
- Introduce `@oh-my-pi/omptype` as a new ArkType-compatible schema validation package featuring a lazy JIT runtime, JSON Schema emission, and compatibility adapters.
- Replace `arktype` across workspace packages and test utilities with `@oh-my-pi/omptype`.
- Add benchmark suites, tests, and documentation for the new validation engine and adapters.
- Update workspace build, test runner, and release configurations to include the new package.
2026-08-03 21:56:48 +02:00
roboomp 5046438f3b fix(setup): verify musl binary starts before reporting install success
install_binary downloaded the release binary, chmod'd it, and printed
"✓ Installed omp" with exit 0 without ever running it. Bun's musl-target
binaries link libstdc++/libgcc dynamically, which stock Alpine/musl systems
lack, so the binary exits 127 with relocation errors while the installer
still claimed success.

Smoke-run `omp --version` after install; on failure print the captured
error, add the `apk add libstdc++ libgcc` remediation for musl targets,
and exit non-zero. Document the Alpine/musl runtime requirement in the
README install section.

Fixes #7545
2026-08-03 18:55:10 +00:00
can1357 b48aeacf25 fix(coding-agent/eval): made cells own every bridge call they start
- Split the Python bridge signal: the raw abort reaches tools (so
  subagents die with the turn) while a shielded signal governs how long
  the host waits, so a cancel can no longer settle a cell on top of a
  still-running isolation merge.
- Mirrored the contract in the JS runtime: abort in-flight tool calls
  immediately, then drain any deferExternalAbort phase before killing
  the worker, and refuse new bridge calls once cancelled.
- Held a finished worker result until the run's tool calls drain. A
  floated agent() previously settled the cell at once, dropping the
  run's abort listener and leaving the subagent running with nothing
  able to cancel it.
- Added regression coverage for all three, each verified to fail
  without its fix.
2026-08-03 19:55:20 +02:00
can1357 dce12984f2 fix(pi-shell): parsed state format specifier correctly in ps builtin
- Corrected the mapping of the "state" specifier to PsField::State in the ps format parser.
- Added a test to verify that the ps builtin successfully accepts tpgid and other job control columns.
2026-08-03 19:01:09 +02:00
can1357 c7a3010d7c fix(coding-agent/eval): ensured tool bridge receives unshielded abort signal
- Prevent eval agent bridge calls from inheriting the kernel abort shield.
- Unset maxRuntimeMs in runEvalAgent to properly inherit task.maxRuntimeMs.
2026-08-03 18:57:22 +02:00
can1357 451eb9842c fix: mapped tail builtin broken pipe to silent exit 141
- Handled broken pipe errors across tail output and follow paths by translating them to a silent SIGPIPE exit code.
- Prevented stderr noise when downstream pipeline readers exit early, matching native tail behavior.
2026-08-03 18:53:14 +02:00
roboomp 6f7600cd89 fix(discovery): prioritized project codex mcp entries
Load project Codex MCP entries before user entries so a disabled project server claims its dedupe key before a same-named user server can survive.

Added regression coverage for project-over-user disable precedence.

Fixes #7538
2026-08-03 16:52:54 +00:00
can1357 cdd1d13079 feat(pi-shell): extended ps builtin format specifiers and process metrics
- Added support for extended ps format specifiers including tpgid, ruid, rgid, egid, pri, flags, min_flt, maj_flt, times, sz, s, ruser, rgroup, and tgid.
- Implemented group name resolution via `getgrgid_r` on Unix platforms.
- Suppressed broken pipe diagnostic output in the tail builtin to match standard tail behavior on downstream closure.
2026-08-03 18:51:23 +02:00
can1357 fe1da34008 Merge remote-tracking branch 'origin/farm/2da60ddc/codex-omit-auto-service-tier' 2026-08-03 18:47:58 +02:00
roboomp 012836d99e fix(discovery): tag disabled codex mcp servers instead of dropping
Carry enabled = false through discovery so loadAllMCPConfigs' suppress
path can claim the dedupe key (keeping a same-named lower-priority
source disabled) and honor the user force-enable allowlist. Dropping the
entry outright defeated both.

Fixes #7538
2026-08-03 16:45:31 +00:00
roboomp 8b854598f1 fix(discovery): honored disabled codex mcp servers
- Skipped Codex config.toml MCP entries explicitly marked enabled = false.
- Added discovery regression coverage for disabled and enabled entries.

Fixes #7538
2026-08-03 16:38:20 +00:00
can1357 1a8caad23e chore: update docs + rename reset to clear 2026-08-03 18:37:23 +02:00
roboomp 5f1f9a1b48 fix(cursor): surfaced K3 missing-thinking turns
- Warned when a K3 turn completed without thinking blocks so the source turn is visible before degraded replay.
- Reported one-based assistant-turn positions on first degraded replay and deduplicated subsequent warnings for the same messages.
- Covered completion and replay warning behavior.

Fixes #7516
2026-08-03 15:26:12 +00:00
roboomp 7b1923b099 fix(ai): stop forwarding auto service tier to codex
shouldSendServiceTier/applyOpenAIServiceTier began forwarding every tier —
including `auto` — for openai/openai-codex after PR #7376. Legacy/default
sessions resolve to {openai:"auto"}, so Codex (ChatGPT OAuth) requests now
carry service_tier:"auto", which that endpoint rejects with a 400, breaking
every turn at default settings.

Never send `auto`: it is OpenAI's implicit default, so omitting service_tier
is identical where accepted and required where the tier is rejected. Explicit
default/flex/scale/priority are unchanged.

Fixes #7517
2026-08-03 15:23:35 +00:00
roboomp 467437a47e fix(cursor): degrade K3 same-model history missing thinking
assertCursorKimiK3HistoryReplayable threw for any assistant turn lacking a
non-empty thinking block, including same-model kimi-k3 turns whose stream
carried no thinkingDelta events. Such a turn is persisted with only
text/toolCall blocks, so every subsequent turn failed locally before any
request, permanently bricking the session.

Split the two failure modes: foreign history still hard-errors (another
model's turns cannot replay K3 reasoning), but a same-model turn missing
thinking now degrades to a one-time warning and replays without the
reasoning part via buildCursorAssistantContent, which already omits it.

Fixes #7516
2026-08-03 15:20:09 +00:00
can1357 01c1f91ff5 chore: bump version to 17.2.6 2026-08-03 16:44:19 +02:00
can1357 74c346623b chore: clippy 2026-08-03 16:43:59 +02:00