Commit Graph

507 Commits

Author SHA1 Message Date
can1357 9628c2e2e6 Merge PR #7754: feat(omp): load only explicitly trusted extensions (@oleksoleksoleks) 2026-08-06 13:24:29 +02:00
Alexander Kirilin 9154c56a69 feat(omp): load only explicitly trusted extensions
Co-authored-by: Eric Singer <singer.ericm@gmail.com>
2026-08-05 16:32:45 -04:00
can1357 e9888367d1 refactor: migrated packages to internal utility modules and removed external dependencies
- Implemented in-house, zero-dependency utility modules in `pi-utils` covering DOM manipulation, markdown parsing, templating, browser automation helpers, and terminal buffers.
- Migrated packages across the repository to consume the new internal utilities and `omptype` schema validators instead of external dependencies.
- Removed multiple external runtime and development dependencies including Zod, Marked, LRU cache, Turndown, and Puppeteer browser packages.
2026-08-05 13:39:09 +02:00
can1357 a66805bd78 Merge PR #7634: fix(stats): restrict dashboard to loopback (@roboomp) 2026-08-05 01:11:58 +02:00
metaphorics 726698e2b0 fix(release): validate explicit versions and drop duplicate comparators
Review findings on #7586:
- validate an explicit release version before comparing; the shared
  comparator never throws, so 999.bad previously reached every manifest
- ci-release-notes imports the comparator by relative path: the
  release_github job runs without bun install
- route Bun cache pruning through compareVersions and delete
  compareSemverLikeVersions
- regression test for the release-version guard
2026-08-05 02:48:59 +09:00
metaphorics 954894f1d4 refactor: centralize version comparison in pi-utils 2026-08-05 02:48:59 +09:00
roboomp 951051086d fix(stats): opened dashboard on bound hostname
Threaded the loopback hostname returned by startServer through the omp stats CLI and /stats slash command so the browser and logged URL target the actual listener instead of localhost.

Fixes #7633
2026-08-04 15:34:09 +00:00
can1357 c53a47f97d Merge PR #7287: fix(coding-agent): prune archived session stats (@alphastorm)
# Conflicts:
#	packages/coding-agent/src/session/session-manager.ts
2026-08-03 15:15:36 +02:00
can1357 10625d2e9a Merge PR #7376: feat(coding-agent): add OpenAI service tier override (@paralin)
# Conflicts:
#	packages/coding-agent/src/commands/launch.ts
2026-08-02 21:22:41 +02:00
can1357 f1c7eda7de Merge PR #7205: perf(cli): keep root help off runtime graph (@eggpeat)
# Conflicts:
#	packages/coding-agent/src/cli-commands.ts
#	packages/coding-agent/src/cli/args.ts
2026-08-02 20:59:12 +02:00
can1357 912807cdbe Merge PR #7394: fix(update): detect active Linux libc (@BrianHotopp) 2026-08-02 20:53:35 +02:00
can1357 46c66ac03a fix(setup): always resolve interpreter during setup probe 2026-08-02 20:53:34 +02:00
can1357 46f780fedd Merge PR #7390: fix(setup): align Python setup probe with eval (@paolofraz) 2026-08-02 20:53:34 +02:00
can1357 ca2385b0ec Merge PR #7382: fix(cli): restore piped custom session persistence (@roboomp) 2026-08-02 20:53:21 +02:00
Brian Hotopp 2f9a8dcf61 fix(update): detect active Linux libc 2026-08-02 13:20:02 -04:00
can1357 4a946e2cfc fix(coding-agent/tools): serialized tab grouping operations in the relay bridge
- Serialized group and ungroup operations to prevent duplicate tab group creation races.
- Queued and serially drained tab grouping requests in the relay bridge to prevent overlapping RPCs.
- Mirrored tab group titles to session storage and healed duplicate groups during background service worker recovery.
- Renamed run-cancellation utility to run-scope and updated corresponding module and test references.
2026-08-02 18:07:07 +02:00
Paolo Frazzetto 24ecd0269c fix(setup): align Python setup probe with eval 2026-08-02 14:55:52 +02:00
Christian Stewart 9d69db481a feat(coding-agent): add OpenAI service tier override
The OpenAI service tier could only be chosen through the `tier.openai`
setting, or for a resumed session through whatever tier that session
recorded. Wanting flex or priority for a single run meant editing
settings and putting them back afterwards, while `bench` already took a
`--service-tier` flag that the session CLI did not offer.

Add `--service-tier` to the root command. The flag wins over the
configured setting and over a resumed session's recorded tier, leaves
the Anthropic and Google entries untouched, and records the resulting
map so a later resume keeps it. `none` removes the OpenAI entry, which
omits `service_tier` from the request.

Signed-off-by: Christian Stewart <christian@aperture.us>
2026-08-02 05:07:33 -07:00
roboomp 72d8d4eaca fix(cli): restored piped session persistence
- Treated undefined stdin TTY state as redirected input.

- Honored PI_CODING_AGENT_SESSION_DIR with CLI precedence.

Fixes #7378
2026-08-02 11:33:58 +00:00
can1357 92c79d80c7 feat: introduced OMP Browser Relay extension with CDP RPC execution
- Implement the OMP Browser Relay extension with WebSocket communication and CDP RPC execution.
- Add browser relay server, daemon management, and bridge multiplexing in the coding agent.
- Introduce CLI commands and settings schema options for configuring and installing the relay.
- Add utility functions and test suites supporting environment parsing and relay lifecycle handling.
2026-08-02 05:33:07 +02:00
Sunil Srivatsa 980ab4fd0a fix(coding-agent): harden archived stats cleanup 2026-08-01 17:17:46 -04:00
Sunil Srivatsa f3a555ac78 fix(coding-agent): reconcile archived session stats 2026-08-01 14:43:59 -04:00
Sunil Srivatsa 5f35e40a5f fix(coding-agent): preserve retained session stats 2026-08-01 13:21:36 -04:00
Sunil Srivatsa 1550ae5a98 fix(coding-agent): prune archived session stats 2026-08-01 12:38:01 -04:00
Sunil Srivatsa 8a7edb3f3d fix(coding-agent): preserve explicit extensions in isolation 2026-08-01 12:32:19 -04:00
Brent dc4d15e59d fix(cli): centralize command help metadata 2026-08-01 00:29:57 +00:00
Brent c8871419e2 fix(cli): statically link help environment setup 2026-07-31 22:49:04 +00:00
Brent a572fcb9be fix(cli): preserve help metadata contracts 2026-07-31 22:01:19 +00:00
Brent 9df3067930 perf(cli): keep root help off runtime graph 2026-07-31 21:28:41 +00:00
can1357 f11641d5a8 feat(coding-agent): enabled importing foreign sessions from claude and codex
- Implemented session stores and metadata converters to import Claude and Codex sessions into OMP.
- Added `--from-claude` and `--from-codex` CLI flags and `/resume` command arguments for foreign session resolution.
- Updated session selector components and controllers to support listing and picking external agent sessions.
- Added comprehensive unit tests and documentation covering foreign session import functionality.
2026-07-30 00:28:40 +02:00
can1357 756e872f64 Merge PR #6946: fix(tui): nest usage metrics in grouped reads (@joshrzemien) 2026-07-29 23:08:42 +02:00
joshrzemien a3e90b3d95 fix(tui): nest usage metrics in read groups
(cherry picked from commit 101268adc632e80bb3f8304b95497ac7bd884131)
2026-07-29 23:08:41 +02:00
can1357 ab48f43783 Merge PR #6888: fix(ttsr): flag text-source inference for unlisted file extensions (@roboomp) 2026-07-29 23:08:24 +02:00
roboomp 43534b25bc fix(ttsr): flag text-source inference for unlisted file extensions
`omp ttsr test <file>` inferred the match source from the path extension
against a hardcoded allowlist (`SOURCE_FILE_EXT`); a supplied source file
whose extension was absent silently fell through to the text (prose)
context, where tool-scoped rules can never match. The result was a false
negative indistinguishable from a non-matching regex, contradicting the
documented "a positional that resolves to a file defaults to tool/edit
context" contract.

- Emit an explanatory note when a resolvable file path is supplied and the
  source is inferred as `text`, pointing at `--source tool --tool edit`.
  Surfaced in both text and `--json` output via `TestReport.inferenceNote`.
- Extend the allowlist with the .NET family and other common source
  languages (cs, razor, cshtml, fs, fsx, vb, sh, bash, sql, zig, dart,
  scala, ex, exs, proto, tf).

Left the fall-through default itself unchanged (inverting the test is a
behaviour change and a maintainer call).

Fixes #6887
2026-07-28 10:35:31 +00:00
can1357 a10fe079ce fix(coding-agent): suppressed credential disable tombstones for active accounts
- Update isActionableDisable in usage-cli.ts to accept active accounts and check identity matches.
- Suppress credential disable tombstones when an active account exists for the same provider and identity.
- Add test coverage for suppressing tombstones when active accounts share the same identity.
2026-07-28 11:47:08 +02:00
can1357 c7b10c3340 Merge PR #6763: fix(cli): preserve live task-isolation sandboxes on worktree clear (@roboomp) 2026-07-28 10:59:37 +02:00
roboomp 7f4f322c73 fix(cli): wrap streaming-phase download timeout with friendly message
downloadVerifiedBinary only wrapped isTimeoutError around the fetch()
catch, so a 15-minute timeout firing while pipeline() streamed the
response body re-threw the raw "TimeoutError: The operation timed out."
Mirror the wrap into the pipeline catch after cleaning up the partial
file, matching the connection-phase message.

Fixes #6822
2026-07-27 18:19:54 +00:00
can1357 d16a251777 chore: reorg tests 2026-07-27 16:43:53 +02:00
can1357 41ce810cff fix(mcp): preserved native resource URIs and opaque scheme routing
- Native (non-mcp://) resource URIs now pass through byte-for-byte via
  rawHref; slash elision applies only to the legacy mcp:// wrapper, so
  catalog://root/ style URIs match exact-equality server lookups.
- resources/templates/list failure no longer discards a successful
  resources/list (Promise.allSettled; templates retried later).
- Opaque RFC 3986 URIs (urn:doc, custom:item) are recognized by both
  the router and read-cli discovery gates, with drive-path and
  read-selector false positives guarded.
- Review follow-up for PR #6790.
2026-07-27 16:15:02 +02:00
Dongmen Laohu 2c77c8535a fix(mcp): resolve native resource URIs 2026-07-27 18:59:12 +08:00
roboomp 91c0feaa87 fix(cli): recognize isolation marker before mount exists
The setup window between writeIsolationOwner and isoStart left the base
dir holding only the marker file and no `m` mount, so classifyDir
returned null and scanWorktrees classified it as a stray — which a
non-`--all` clear removes, defeating the ownership guard mid-setup.

classifyDir now treats the presence of the ownership marker as a
task-isolation signal (in addition to the mount dir), so an in-progress
sandbox with a live owner is preserved throughout backend setup.

Fixes #6761
2026-07-27 03:47:20 +00:00
roboomp eeca809193 fix(cli): preserve live task-isolation sandboxes on worktree clear
`omp worktree clear` (without `--all`) removed every task-isolation dir
under the worktree base, including sandboxes owned by subagents running
right now, and the "no live task owns it" reason was asserted from the
mere presence of the `m` mount dir with no ownership check.

`ensureIsolation` now stamps each sandbox base dir with a pid-bearing
ownership marker before the backend materialises `m`, and the worktree
scanner classifies a sandbox as live while its owning process is alive,
so `clear` reclaims only crashed leftovers.

Fixes #6761
2026-07-27 03:42:33 +00:00
Ant39140 20d96304f2 fix(coding-agent): prevented invalid configs from being overwritten
- Treated missing files separately from malformed or unreadable configs.
- Backed up malformed YAML and wrote settings atomically without dropping pending changes.
- Reported success only after saving, with regression tests for global and project configs.
2026-07-27 03:26:40 +08:00
can1357 713856c9e0 Merge PR #6557: fix(update): verify GitHub release asset and digest (@rvagg) 2026-07-26 15:45:31 +02:00
can1357 4892f48493 Merge PR #6618: fix(coding-agent): source auth-gateway catalog from ModelRegistry (@roboomp) 2026-07-26 15:41:31 +02:00
can1357 97ea63920b fix(coding-agent): keep bun/npm routing for regular-file entries on Windows
Bun's global bin entry on Windows is a regular-file .exe shim, not a
symlink, so the standalone-binary override would have rerouted a
legitimate bun-managed install to in-place binary replacement and
clobbered the shim. Gate the override on POSIX, where package-manager
bin entries are always symlinks; add a regression test.
2026-07-26 15:41:30 +02:00
can1357 e0c26cc262 Merge PR #6527: fix(coding-agent): self-update binary install when its dir overlaps npm/bun bin dir (@am423) 2026-07-26 15:41:29 +02:00
can1357 5aa599f9ac fix(cli): treat cleared (empty-string) credentials as unset in config list
The settings panel persists "" when a credential is cleared and renders
that as unset; config list now uses the same semantics instead of
masking the empty string as a configured credential.
2026-07-26 15:41:29 +02:00
Wolfgang Schoenberger 3e1679f584 fix(cli): keep the Hindsight URL readable and redact only set credentials
The credential pass marked `hindsight.apiUrl` secret instead of
`hindsight.apiToken`: both share `condition: "hindsightActive"` and the flag
landed on the wrong one, so the settings panel masked an ordinary endpoint. The
token keeps its masking through the `credential` marker.

`config list` also redacted on classification alone, so a fresh configuration
reported every unset credential as though one were stored. Redaction now
depends on a value being present.

The suite asserted classification and panel metadata only, so both output
branches could be deleted while every test passed, which is how the wrong flag
shipped. It now drives `runConfigCommand` and reads the real human and JSON
output.
2026-07-26 02:58:38 -07:00
Wolfgang Schoenberger 914afc0d6c fix(cli): redact credential settings in config list
omp config list printed every configured value, including auth.broker.token,
searxng.token, searxng.basicPassword and dev.autoqaPush.token, in both the
human and --json output. Nobody asked for those specific credentials; the
command dumps everything.

Credentials are marked with a top-level credential flag rather than ui.secret,
because four of them have no settings-panel entry and so have nowhere to put a
UI-level flag. isCredential is the single accessor both the CLI and the panel
consult, so the two spellings cannot produce different behaviour on different
surfaces.

Human output shows dots. JSON omits value and marks the entry redacted instead
of substituting a placeholder, which a consumer could not distinguish from a
real value and might write back.

config get <path> is deliberately unchanged: that is an explicit request for a
single value, and masking it would break a retrieval API with no way to read
your own token back.
2026-07-26 02:58:38 -07:00