Commit Graph

1565 Commits

Author SHA1 Message Date
can1357 2e3fbbbd2a Merge PR #6432: fix(session): clear session-scoped tool state (@roboomp) 2026-07-24 02:24:15 +02:00
can1357 e2a986c6b6 Merge PR #6429: fix(session): preserve compaction data for rewinds (@roboomp) 2026-07-24 02:24:05 +02:00
can1357 9c0ad16b8a Merge PR #6431: fix(agent): commit plan-reference flag on delivery, not construction (@roboomp) 2026-07-24 02:24:05 +02:00
can1357 9687818228 fix(session): cleared branch-scoped tool state
Applied the session-scoped tool reset after /branch and /btw create their
branched logical sessions, closing the same stale-state leak as /new,
handoff, and cross-session switches.

Added a branch transition to the staged-preview regression matrix.
2026-07-24 02:23:15 +02:00
roboomp 55d18e89a5 fix(session): cleared handoff-scoped tool state
Applied the session-scoped tool reset after handoff creates its replacement session.

Added regression coverage for stale staged preview directives across handoff.

Fixes #4093
2026-07-24 02:23:15 +02:00
roboomp e6cdfd6187 fix(session): cleared session-scoped tool state
Cleared queued tool-choice directives and ACP always decisions after successful logical session transitions.

Added new-session and cross-session regression coverage for staged resolves and both ACP always decisions.

Fixes #4093
2026-07-24 02:23:15 +02:00
can1357 9a2639e507 refactor(session): converted PERMISSION_OPTIONS_BY_ID from object to Map
- Changed lookup from bracket notation to Map.get() to safely fail closed on unknown permission IDs.
2026-07-24 01:42:25 +02:00
can1357 f5a4c5fe2a fix(coding-agent): exported advisor stats types and update move command test
- Export specific advisor stats types instead of re-exporting all session advisors.
- Update move command tests to mock session-level move actions.
2026-07-24 01:37:41 +02:00
can1357 7eeaba0471 refactor(coding-agent/session): restructured monolithic agent session
- Extracted internal handlers and logic from AgentSession into dedicated runner, guard, and coordinator modules.
- Created standalone modules for bash execution, evaluation runners, IRC bridging, and prewalk coordination.
- Established dedicated session components for tracking stats, todos, streams, and retry fallback chains.
- Preserved existing session behavior while significantly reducing monolithic class size and complexity.
2026-07-24 01:24:44 +02:00
can1357 46d2b7d864 Merge PR #6439: fix(compaction): stop feeding reasoning back to Claude summarizer (@roboomp) 2026-07-23 23:05:47 +02:00
can1357 8cab2b7cd5 fix(session): run prompts issued while disposing instead of dropping them
- The memory-backend transition await added in PR #6428 guarded with #isDisposed, which beginDispose() sets immediately; prompts issued in the disposing window were silently dropped instead of running their final turn and settling via the dispose abort.
- Guard now only drops the prompt when disposal began during the transition await.
2026-07-23 22:42:34 +02:00
roboomp 5a70eda7d7 fix(compaction): stop feeding reasoning back to Claude summarizer
Both compaction serializers reproduced prior assistant reasoning as text
bound for a Claude target, tripping Anthropic's reasoning_extraction
refusal and wedging Fable 5 sessions:

- context-full: serializeConversation rendered thinking verbatim inside
  <thinking> tags via the anthropic dialect renderer. Now drops thinking
  blocks when the summary target dialect is anthropic; other dialects
  (e.g. Harmony) keep native reasoning.
- snapcompact: emitted ¶think sections baked into replayed archive
  frames. Added an includeThinking serialize option (default true) and
  wired the agent session to disable it for Anthropic-dialect models.

Fixes #6093
2026-07-23 20:38:27 +00:00
can1357 83e0e4cdac Merge PR #6435: fix(session): resume resolved tool stalls (@roboomp) 2026-07-23 22:38:05 +02:00
roboomp 055a0ce0af fix(session): resumed resolved tool stalls
- Preserved stalled assistant turns when every emitted tool call had a result, including synthetic unexecuted results.

- Kept unresolved and non-stall tool errors replay-safe and covered terminal error agent_end delivery.

Fixes #6414
2026-07-23 20:18:03 +00:00
can1357 29c2bd2595 Merge PR #6415: fix(compaction): judge remote-preserve reuse against the active model (@roboomp)
# Conflicts:
#	packages/coding-agent/src/session/agent-session.ts
2026-07-23 22:16:11 +02:00
can1357 72ff07ff84 Merge PR #6428: fix(memory): synchronize live backend lifecycle (@roboomp) 2026-07-23 22:15:25 +02:00
can1357 a6072d0013 Merge PR #6427: fix(session): validate blob refs before path join (@roboomp) 2026-07-23 22:15:22 +02:00
roboomp 111de5ab71 fix(agent): commit plan-reference flag on delivery, not construction
#buildPlanReferenceMessage set #planReferenceSent = true while building the
message, before it was handed to agent.prompt. Any pre-send setup bail (the
four #promptGeneration generation-bail returns) or throw (@-mention reads,
before_agent_start hooks) between build and delivery left the flag true with
nothing delivered, and the #promptWithMessage finally never cleared it — so the
retry short-circuited at `if (this.#planReferenceSent) return null` and the
approved plan was silently dropped for the rest of the session.

Move the flag commit to the delivery hand-off point in #promptWithMessage: set
it only when a plan-reference message was built AND we are about to call
#promptAgentWithIdleRetry. Every bail/throw now leaves the flag clear so the
next prompt re-injects the plan. The compaction-success resets (issue #1246)
still clear it for re-injection on the next turn.

Fixes #4094
2026-07-23 19:54:52 +00:00
roboomp cb63ebd9f5 fix(session): preserved compaction data for rewinds
Kept superseded summaries and preserveData durable while deriving forward transcript elision from the active compaction.

Added branch and rewind coverage for snapcompact archives and OpenAI remote replacement history.

Fixes #4090
2026-07-23 19:53:05 +00:00
roboomp 5a1f227a6b fix(memory): synchronized live backend lifecycle
- Serialized backend transitions across runtime state, tools, and prompts.
- Rehydrated Mnemopi listeners after clear and enqueue maintenance.
- Made memory.backend the sole post-migration local runtime gate.

Fixes #5638
2026-07-23 19:52:09 +00:00
roboomp 5f47afba16 fix(session): validate blob refs before path join
parseBlobRef sliced the blob:sha256: suffix and returned it unvalidated;
get/getSync then fed it into path.join(this.dir, hash), so a crafted ref
like blob:sha256:../../../etc/passwd escaped the blob directory and read
arbitrary files into resolved image history (base64, raw UTF-8, and the ACP
sync path).

Reject any suffix that is not a canonical 64-char lowercase hex hash in
parseBlobRef, the single choke point for every resolution entry point. Reuse
the shared BLOB_HASH_RE in gc-cli instead of its duplicate HASH_RE.

Fixes #4088
2026-07-23 19:51:53 +00:00
roboomp 34fef55d25 fix(session): serialize ArtifactManager first-use init
#ensureDir checked #initialized then set it across an await
#scanExistingIds() gap, so two concurrent first-use save/allocatePath
callers both re-seeded #nextId=maxId+1 and allocateId() handed both the
same id — silently overwriting the first artifact (same toolType) or
making artifact:// resolution ambiguous (different toolTypes).

Memoize the initial scan as a single in-flight #initPromise so all
concurrent callers share one initialization and receive distinct ids.

Fixes #4091
2026-07-23 19:46:30 +00:00
roboomp 116b8f4597 fix(compaction): judged remote-preserve reuse against the active model
After an OpenAI remote compaction, prepareCompaction decided whether to
keep the provider-native replay boundary or re-expand its originals by
asking whether *any* compaction candidate (every role model plus the
largest-context available model) shared the payload's provider. In a
multi-role setup where a role such as modelRoles.smol stays on OpenAI,
the check passed forever, so a session switched to a non-OpenAI active
model kept a placeholder-only summary and never recovered the compacted
span for the rest of the session.

Judge reusability against the active model — the one that assembles the
request context every turn — instead of the candidate set. When the
active model cannot replay the payload, re-expand the originals into a
portable local summary, matching the self-healing already present for
single-provider migrations.

Fixes #6343
2026-07-23 19:12:50 +00:00
can1357 da1056226e Merge PR #5464 port: persist vibe sessions across restarts (@roboomp) 2026-07-23 18:07:22 +02:00
can1357 5d66eb7f2a Merge PR #5464: fix(coding-agent): persist vibe sessions across restarts (@roboomp) 2026-07-23 18:06:11 +02:00
can1357 2ffb67e3c7 fix: reconciled merged tests and dead code with current main structure
- warp completion test updated to event-taking notification signature
- hindsight test config gained required timeout fields
- dropped orphaned parseBillingConfig and advisor secret-collection dupes
- deduped fixture key; formatter pass on merged files
2026-07-23 18:02:31 +02:00
pr-eval 424458e99d chore(secrets): dropped drive-by changes unrelated to secret placeholders
Reverted branch-side edits to spawn-policy prompts/tests, settings tab
groups, mermaid cache typing, prewalk todo gating, and packages/ai test
churn back to merge-base content; trimmed their changelog entries. These
repaired stale CI against an older main and are stale or conflicting
against current main.
2026-07-23 17:56:29 +02:00
can1357 c0c1622012 Merge PR #4636: feat(secrets): add friendly names to secret placeholders (@Mathews-Tom)
# Conflicts:
#	packages/ai/test/pi-native-client.test.ts
#	packages/coding-agent/src/advisor/runtime.ts
#	packages/coding-agent/src/prompts/tools/eval.md
2026-07-23 17:56:24 +02:00
can1357 4af619433b fix(coding-agent): counted queued-but-uninjected async-result follow-ups as pending async work
A completed delivery hands off from the AsyncJobManager to the session's
yield queue before the follow-up is injected (idle flush runs on a delayed
post-prompt task; mid-turn entries wait for the next step boundary). In
that window hasPendingAsyncWork() read false from manager state alone, so
a terminal yield observed there terminated the run and silently dropped
the delivered result - the stale-success class the quiescence barrier
exists to prevent. The wake predicate now also counts queued async-result
entries on the yield queue; added a session-level contract test that
pinned the window (failed before, passes after).
2026-07-23 17:52:52 +02:00
can1357 c522eceff2 Merge PR #6119: feat: lift subagent async/auto-background limits via owner-routed delivery and quiescence (@korri123)
# Conflicts:
#	packages/coding-agent/src/task/executor.ts
2026-07-23 17:52:52 +02:00
can1357 dee5fa63be fix(coding-agent): pointed retry backstops at renamed persistence helper 2026-07-23 17:50:15 +02:00
can1357 3829bff31a Merge PR #4637: feat(notifications): add error turn notifications (@Mathews-Tom)
# Conflicts:
#	packages/coding-agent/src/modes/controllers/event-controller.ts
#	packages/coding-agent/src/prompts/tools/eval.md
#	packages/coding-agent/src/session/agent-session.ts
#	packages/coding-agent/src/task/index.ts
2026-07-23 17:49:06 +02:00
can1357 154d4ace9f Merge PR #4448: feat(todo): add blocked status with block/unblock ops (@mattwilkinsonn)
# Conflicts:
#	packages/coding-agent/src/modes/interactive-mode.ts
#	packages/coding-agent/src/prompts/tools/todo.md
2026-07-23 17:32:43 +02:00
can1357 bcd23ee7c1 fix: kept seeded workspace roots lazy until the session file is durable
Seeding additionalDirectories at launch (via --add-dir or the
workspace.additionalDirectories setting) called #rewriteAtomically on a
brand-new session manager, which materialized a header-only JSONL and a
fresh breadcrumb before any assistant output. Launching and exiting with
configured roots therefore created an empty resumable session that
--continue picked over the previous conversation.

Gated all three workspace-directory mutators behind the existing
#shouldHaveSessionFile() lazy-persistence gate (one shared helper), and
made setAdditionalDirectories a no-op when the normalized list is
unchanged so resuming large sessions no longer rewrites the whole JSONL
on every startup. Roots set before the gate is crossed land in the
header with the first durable write; added a regression test.
2026-07-23 17:30:34 +02:00
can1357 26726fdcb9 Merge PR #6255: add dynamic multi-root workspace context (@maatheusgois-dd) 2026-07-23 17:30:33 +02:00
can1357 1435f8dbce perf: restored lazy export-module loading by splitting /export arg parsing into export/html/args.ts 2026-07-23 17:30:33 +02:00
can1357 c76221095f Merge PR #6349: support light, dark, and system themes in HTML exports (@anatoli-tsinovoy) 2026-07-23 17:30:32 +02:00
can1357 2c42715263 fix(compaction): charged pre-archive kept region in rescue budget
Also stamped dead-end warnings before the auto_compaction_end event so the result-driven TUI rebuild shows the badge (Codex round 6 on #6362).
2026-07-23 17:30:15 +02:00
can1357 15f1fb2c7c Merge PR #6362: fix(compaction): rescue snapcompact archives stuck past the maintenance threshold (@HugoLopes45) 2026-07-23 17:30:14 +02:00
Hugo Lopes d8554c92d0 fix(compaction): charge the kept tail in the rescue budget and badge the active entry
Review follow-ups (Codex on #6362, round 5):
- #computeSnapcompactRescueMaxFrames now subtracts the kept tail AFTER the
  archive (plus the existing fixed-context reserves) so the budget mirrors
  what #compactionCreatedHeadroom will measure, and returns 0 when not even
  one frame fits — the rescue bails instead of appending a rebuild that can
  never create headroom (and would wedge prepareCompaction behind its
  last-entry guard once elide fixes the real tail).
- Dead-end warnings now stamp the branch's LATEST compaction entry: the
  post-pass path no longer badges the entry the rescue just superseded, and
  the no-preparation path badges the rebuilt entry when the rescue appended
  without creating headroom.

Claude-Session: https://claude.ai/code/session_014rh4JyWFkxgMhgFaEf8VBY
2026-07-23 14:03:12 +02:00
Hugo Lopes f48004a182 fix(compaction): only frame-rescue archives that are the actual overflow source
Review follow-up (Codex on #6362, round 4): rebuilding a non-tail archive
appends the replacement compaction at the leaf, so the branch tail becomes a
compaction entry that prepareCompaction's last-entry guard can never
summarize past — even after elide shrinks the oversized kept tool result
that was the real culprit. The rescue now estimates the kept tail AFTER the
latest archive and bails when it alone exceeds the recovery band, leaving
that shape to the elide/image tiers.

Claude-Session: https://claude.ai/code/session_014rh4JyWFkxgMhgFaEf8VBY
2026-07-23 13:15:23 +02:00
Hugo Lopes d9417927bc fix(compaction): surface the frame rescue as a real compaction to the TUI and extensions
Review follow-ups (Codex on #6362):
- #rescueSnapcompactFrameOverflow now returns the CompactionResult and emits
  session_compact for the rebuilt entry, so extensions see the entry that is
  actually active instead of (only) the one the rescue superseded.
- The no-preparation auto_compaction_end now carries that result instead of
  {result: undefined, skipped: true} when the rescue rewrote history — the
  TUI rebuilds the transcript on result, so a successful rescue is no longer
  presented as a benign no-op.

Claude-Session: https://claude.ai/code/session_014rh4JyWFkxgMhgFaEf8VBY
2026-07-23 12:59:15 +02:00
can1357 8205d3ee31 style: applied biome formatting to merged fix commits 2026-07-23 11:39:15 +02:00
Hugo Lopes ef952c6d88 fix(compaction): mirror post-compaction bookkeeping in the frame rescue
Review follow-up (Codex on #6362): the rescue's replaceMessages() rebuild
drops the transient plan-reference message, so clear #planReferenceSent
(#1246) and reset advisor runtimes / todo phases exactly like the regular
compaction append path.

Claude-Session: https://claude.ai/code/session_014rh4JyWFkxgMhgFaEf8VBY
2026-07-23 11:37:59 +02:00
can1357 db3a6a1407 Merge PR #6318: fix(tui): show fallback models in Agent Hub (@roboomp) 2026-07-23 11:37:13 +02:00
can1357 e488d09751 fix(coding-agent): keep failed tails visible in read-only session history
Route loadSessionMessagesReadOnly through transcript mode (collapsed to the
latest compaction) so history:// transcripts of on-disk sessions retain
failed/aborted assistant tails that the provider-context builder now drops.
2026-07-23 11:37:10 +02:00
can1357 6fe0cc99bc Merge PR #6357: fix(coding-agent): guard session context replay tail (@honsunrise) 2026-07-23 11:37:10 +02:00
Hugo Lopes 42f530f187 fix(compaction): gate frame-rescue success on real headroom and cap rescue frames
Review follow-ups (Codex on #6362):
- The !preparation frame rescue now counts as complete only when the rebuild
  actually created headroom; otherwise the elide/image tiers still run and the
  no-progress warning stays — a frame-count shrink alone must not suppress it
  when the oversized tail is a kept message/tool result the archive rescue
  cannot touch.
- #computeSnapcompactRescueMaxFrames now applies the same MAX_FRAMES_DEFAULT /
  maxFramesForDataBudget caps as #computeSnapcompactMaxFrames, so a
  threshold-derived count can never exceed what the rebuilt prompt can attach.

Claude-Session: https://claude.ai/code/session_014rh4JyWFkxgMhgFaEf8VBY
2026-07-23 11:35:09 +02:00
Hugo Lopes 756fed844c fix(compaction): rescue trailing snapcompact archives past the maintenance threshold
A branch whose last entry is a snapcompact CompactionEntry billed past the
compaction threshold (FRAME_TOKEN_ESTIMATE x frames) dead-ended on every
resume: prepareCompaction returns undefined (nothing after the entry to
summarize), and the #4786 elide/image rescue tiers only inspect
"message"/"custom_message" entries, so a type:"compaction" tail escaped both
and the "Compaction freed too little context" warning re-fired forever.

Add a dedicated first rescue tier that rebuilds the SAME archive locally (no
LLM, no network) by re-running snapcompact.compact() over the entry's
carried-forward source text at a maxFrames derived from the trigger
threshold's recovery band instead of the window-fit budget: planArchive
truncates the oldest chars to fit, so the rebuilt entry genuinely shrinks.
Persisting through appendCompaction lets the write-time
superseded-compaction elision drop the stale frame payload from the JSONL,
and the pass skips the misleading no-progress warning.

Fixes the loop reported in
https://github.com/can1357/oh-my-pi/issues/4786#issuecomment-5056055342

Claude-Session: https://claude.ai/code/session_014rh4JyWFkxgMhgFaEf8VBY
2026-07-23 11:31:00 +02:00
can1357 b4a3abe445 feat: added hasProvider method to detect known model providers
- Implemented ModelRegistry.hasProvider to return true when a provider has live models, is discoverable, or is registered at runtime.
- Replaced AgentSession's internal provider check with #isKnownProvider that delegates to the new hasProvider method, updating related fallback logic.
2026-07-23 11:17:00 +02:00