Commit Graph
4224 Commits
Author SHA1 Message Date
can1357 fccc0ed3ce chore: bump version to 16.2.12 2026-07-01 05:29:19 +02:00
can1357 05c09f6191 chore: update chanelogs 2026-07-01 05:27:25 +02:00
can1357 ccee14586a Merge remote-tracking branch 'origin/farm/d57e0533/openai-models-list-resolve-reference' 2026-07-01 05:26:00 +02:00
can1357 763f950b7f fix: streamlined tool-call cloning and validation in the stream pipeline
- Improved the leaked-thinking stream projector to clone and sync native tool-call blocks directly.
- Eliminated the need for placeholder IDs and complex rekeying logic in the event controller and argument reveal module.
- Simplified native tool-call validation in owned-stream processing by requiring only a non-empty name.
- Added comprehensive unit tests to ensure tool-call IDs and partial JSON parameters remain intact during healing.
2026-07-01 05:25:27 +02:00
can1357 ef7636805b feat(coding-agent): removed canonical model variant selection and tracking
- Removed the canonical model variant indexing, selection, and tracking logic from the model registry and resolver.
- Eliminated the `canonical` sub-command, tab view, search tokens, and equivalence configuration structures from the CLI and model selector components.
- Refined model identification, lookup, and provider fallback resolution to bind exclusively to standard, raw model IDs.
- Relocated the equivalence utility script within the catalog package to support script-only policy generation.
2026-07-01 05:22:42 +02:00
can1357 8e8c3e92ce Merge remote-tracking branch 'origin/farm/e0aafd27/cross-turn-tool-call-loop-guard' 2026-07-01 05:08:41 +02:00
roboomp bf75d80836 fix(coding-agent): resolve bundled reference in discoverOpenAIModelsList
Thin OpenAI-compatible proxies that omit context_length / max_model_len on
/v1/models made every discovered model fall back to
DISCOVERY_DEFAULT_CONTEXT_WINDOW (128K/33K), even when the id matched a
bundled model with a much larger intrinsic window. discoverProxyModels
and discoverLiteLLMModels already resolve ids against the bundled
reference index; discoverOpenAIModelsList (which also backs lm-studio
discovery) now does the same.

Behavior:
- Build the reference index once outside the loop and resolve each item
  via resolveModelReference().
- contextWindow precedence keeps provider-reported values authoritative:
  item.max_model_len ?? item.context_length ?? nativeMetadata?.contextWindow
  ?? reference?.contextWindow ?? DISCOVERY_DEFAULT_CONTEXT_WINDOW.
- maxTokens uses reference?.maxTokens when available, otherwise the
  api-specific discovery default, capped at contextWindow so a bundled
  ref for a larger sibling can never over-request output tokens.
- name / reasoning / thinking / input inherit from the reference; native
  lm-studio metadata still wins for input modality.
- Provider-specific baseUrl, headers, and local-unknown cost stay local.
- OpenAI-compat flags stay conservative (supportsStore / supportsDeveloperRole
  / supportsReasoningEffort all false) to match the proxy sibling.

Also updated two pre-existing regression tests that used
deepseek-v4-pro / deepseek-r1 / DeepSeek-V4-Flash as stand-in "fictional"
ids to exercise the default-fallback branch. Those model names have since
been added to the bundled catalog, so the tests were renamed to
vllm-lab-fork-* ids that unambiguously miss the reference index while
preserving each test's original default-fallback intent.

Fixes #3983
2026-07-01 03:07:14 +00:00
can1357 d6e62591cf chore: update chanelogs 2026-07-01 04:47:55 +02:00
roboomp cf52840c18 fix(agent): detected repeated tool-call turns
Added a cross-turn tool-call loop guard that hashes canonical tool names and arguments, ignores intent metadata, and injects a hidden redirect when identical calls reach the configured threshold.

Fixes #3971
2026-07-01 02:47:08 +00:00
can1357 2ad5a433ea Merge remote-tracking branch 'origin/farm/3fc23c45/linear-session-path-rebuild' 2026-07-01 04:47:04 +02:00
can1357 d562f28c1b Merge remote-tracking branch 'origin/farm/795471ef/cancel-timed-out-browser-run' 2026-07-01 04:46:41 +02:00
can1357 b8a996ac56 Merge branch 'farm/af5c9fdb/fix-eval-spawn-default' 2026-07-01 04:46:23 +02:00
can1357 99346570ba Merge remote-tracking branch 'origin/farm/4b964ee9/mcp-http-body-timeout' 2026-07-01 04:46:20 +02:00
can1357 3c477a6d0c Merge remote-tracking branch 'origin/farm/60bab21a/fix-subagent-yield-schema-wrapping' 2026-07-01 04:46:17 +02:00
can1357 23c81ead9b refactor(coding-agent/config): cached edit model variants and optimize settings parsing
- Introduced an `#editVariantCache` to memoize resolved edit modes for model variants.
- Replaced the generic `shallowStringRecord` helper with specialized, type-safe parsing methods for model variants and roles.
- Invalidated the cached edit variants during settings rebuilds and verified correct cache refreshment across project directories.
2026-07-01 04:45:59 +02:00
roboomp 8614b4c086 fix(task): respected restricted spawn defaults
Resolved eval agent() and task tool defaults from the active spawn policy so restricted agents advertise and execute an allowed default.

Fixes #3973
2026-07-01 02:44:08 +00:00
roboomp 5d2f9ae5a3 fix(mcp): kept http timeouts active through body reads
- Moved Streamable HTTP request and notify timeout cleanup after response body consumption.\n- Added regression coverage for stalled request JSON bodies and stalled notify error bodies.\n\nFixes #3974
2026-07-01 02:43:00 +00:00
can1357 ea36c7256a chore(changelog): normalize merge-sweep entries 2026-07-01 04:41:38 +02:00
can1357 5888bccba0 fix(eval): truncate oversized Python shell output 2026-07-01 04:40:55 +02:00
can1357 2b9d2ca44e merge PR #3968: fix(browser): reap Chromium/Puppeteer on aborted open and session dispose 2026-07-01 04:40:46 +02:00
can1357 68a2c023bc merge PR #3967: fix(lsp): honor tool signal in cold-start initialize and notification writes 2026-07-01 04:40:46 +02:00
can1357 446d5dcba4 merge PR #3965: fix(coding-agent): streamed write progress 2026-07-01 04:40:46 +02:00
can1357 b105782744 merge PR #3957: fix(eval): bound python shell helper output 2026-07-01 04:40:45 +02:00
can1357 7f6b48068c merge PR #3956: fix(mcp): route stdio write/flush failures without parking request() 2026-07-01 04:40:39 +02:00
can1357 8cc7520e47 merge PR #3954: fix(pi-shell): wired fd directory walk to observe scope cancellation 2026-07-01 04:40:39 +02:00
can1357 0e37bd7212 merge PR #3951: fix(extensions): bound tool_call handlers by extensionHandlerTimeoutMs 2026-07-01 04:40:39 +02:00
roboomp 35958a67ed fix(coding-agent): wrapped subagent output schema in result.data for yield prompt
The subagent system prompt rendered `{{jtdToTypeScript outputSchema}}` as a
bare TypeScript interface with the text "Your result MUST match this
TypeScript interface". The yield tool actually nests the user schema under
`result.data`, so the LLM pattern-matched on the visually dominant code
block and put the payload directly in `result.data`, tripping schema
validation repeatedly. In the worst reported case a subagent used all 3
retry attempts, had validation dropped, and lost its audit output entirely.

Add a `renderYieldSchema` Handlebars helper that renders the schema inside
`result: { data: … }` and swap the system-prompt block to use it, so the
model sees the exact envelope the yield tool expects. Multi-line object
schemas, scalars, unions, and array-of-object schemas all round-trip
cleanly with the new helper.

Fixes #3972
2026-07-01 02:33:55 +00:00
roboomp db8560f934 fix(browser): stopped stale timed-out runs
Aborted browser run helpers and recycled timed-out workers so losing JavaScript continuations cannot mutate a live tab after timeout.

Fixes #3964
2026-07-01 02:21:19 +00:00
roboomp 19b85bca70 fix(browser): reap Chromium/Puppeteer on aborted open and session dispose
Two termination boundaries in the browser tool leaked browser-owned OS resources into the long-lived coding-agent process.

1. Aborted 'open' published an orphan. #open wrapped acquisition in untilAborted, which rejects its outer wrapper on abort but lets the inner launch resolve in the background; acquireBrowser then unconditionally stored the resolved handle in the module-global browsers map. releaseAllTabs walks tabs, not browsers, so the refCount:0 handle stayed alive to process exit.

2. Session dispose had no browser teardown. Browser/tab state lives in module-global maps, and AgentSession.dispose() had no hook to walk them, so headless/spawned Chromium the session opened survived it.

acquireBrowser now short-circuits before launch on a pre-aborted signal and disposes the handle when the launch completes after abort. TabSession records the creating session's id (opts.ownerSessionId, threaded through BrowserTool.#open), preserved across reuse so a subagent re-driving an existing tab does not yank teardown responsibility. AgentSession.dispose() invokes releaseTabsForOwner bounded by withTimeout(3s), mirroring the async-job/MCP disposal pattern.

Regression tests exercise both boundaries via spied CmuxSocketClient (no real puppeteer/socket) and cover: pre-aborted open short-circuit, aborted-mid-launch cleanup, releaseTabsForOwner reaping only owned tabs, and reuse preserving original ownership.

Fixes #3963
2026-07-01 02:09:04 +00:00
roboomp 442ee57283 fix(lsp): honor tool signal in cold-start initialize and notification writes
Two client-level paths in the LSP tool bypassed the combined tool-timeout/
caller abort signal built in `LspTool.execute`, so a wedged server hung
past the advertised tool deadline and past user cancellation:

- `getOrCreateClient` took no `AbortSignal` and its `initialize`
  `sendRequest` was invoked with `signal = undefined`. With no signal
  and no explicit `timeoutMs`, `sendRequest` fell back to the hard-coded
  `DEFAULT_REQUEST_TIMEOUT_MS = 30000` internal timer, so a first-use
  `lsp` call against a server that wedged in `initialize` ignored the
  20s tool default (and any user-supplied shorter `timeout`) until the
  30s internal timer fired.
- `writeMessage`/`queueWriteMessage`/`sendNotification` had no timeout
  and no signal, so a `textDocument/didOpen`/`didChange`/`didSave` sent
  to a server that stopped draining stdin awaited `sink.flush()`
  forever. Because writes serialize through `client.writeQueue`, every
  later op on the client stalled behind the stuck flush too.

Thread the caller `AbortSignal` through `getOrCreateClient` (initialize
+ initialized notification) and through `sendNotification` /
`queueWriteMessage` / `writeMessage` so the sink flush is raced against
the signal. On abort, tear the client down: kill the process and evict
it from the active-clients map so the next `getOrCreateClient` call
spawns a fresh server instead of queueing behind the wedged sink.

Update the LSP tool callsites and internal helpers
(`captureDiagnosticVersions`, `captureOpenFileVersions`,
`syncFileContent`, `notifyFileSaved`, `formatContent`,
`getDiagnosticsForFile`, `reloadServer`, and the rename didClose /
didRenameFiles path) to forward their operation signal.

Warmup keeps its short explicit `initTimeoutMs` and passes no caller
signal; `sendRequest`'s existing `timeoutMs ?? (signal ? undefined : DEFAULT)`
policy still uses that fixed timer.

Fixes #3962
2026-07-01 02:06:03 +00:00
roboomp a1a393cdc5 fix(session): linearized session path rebuilds
- Replaced leaf-to-root unshift path assembly with push plus one reverse in buildSessionContext and SessionEntryIndex.pathTo.
- Added regression coverage that keeps deep linear context and branch paths root-to-leaf without Array.unshift work.

Fixes #3961
2026-07-01 01:59:34 +00:00
roboomp 58c84e4c94 fix(coding-agent): streamed write progress
Emitted partial write-tool updates before filesystem, archive, SQLite, internal URL, and conflict writes so the TUI can render execution-phase progress instead of waiting for the final result.

Updated the write renderer to keep partial results pending, show the progress snapshot, and suppress diagnostics until the final result.

Fixes #3960
2026-07-01 01:57:14 +00:00
roboomp e348e8d9b5 fix(eval): bound python shell helper output
Stream Python eval shell helper stdout in fixed-size chunks instead of buffering through subprocess.run or newline-bound text iteration.

Added regression coverage for !cmd and newline-free %%bash streaming.

Fixes #3950
2026-07-01 01:15:38 +00:00
roboomp 379539b3b2 fix(extensions): clear pending timer when a handler wins the timeout race
Bun.sleep(timeoutMs).then(...) leaves an uncancellable timer registered
with the event loop, so every successful handler race in the runner
leaked one — a completed tool_call/tool_result handler could delay
non-interactive CLI exit by up to the 30s default cap. Verified with a
subprocess exit-time probe: buggy pattern exits in ~5000ms for a 5s
timeout, setTimeout+clearTimeout pattern exits in ~17ms.

Extract a raceHandlerWithTimeout helper backed by setTimeout with a
finally-scoped clearTimeout, and route both #runHandlerWithTimeout
(pre-existing latent leak) and emitToolCall (introduced in the same PR)
through it. No behavior change on the timeout branch.

Addresses review on #3951 from chatgpt-codex-connector[bot].
2026-07-01 01:12:30 +00:00
roboomp 0e90d57be6 fix(mcp): route stdio write/flush failures without parking request()
StdioTransport.request() awaited stdin.write() and stdin.flush() before returning the internal deferred promise. When the child stopped draining stdin (wedged process, or full OS pipe buffer with no reader), Bun's FileSink returned a pending Promise that never settled — the async function got stuck above 'return promise', past the timeout timer and the abort handler. cleanup() + reject() still ran on the inner deferred, but the outer async-function promise never adopted it, so the caller's await hung forever and the deferred rejection surfaced as an unhandled promise rejection.

Send the frame without awaiting: sync EPIPE throws (Windows) still reject the request immediately; async EPIPE rejections (POSIX processTicksAndRejections) are wired to the same reject() via a guarded failFromSend handler that no-ops after cleanup(). The returned promise now settles from the response, the timer, the abort signal, or the read loop's transport-close broadcast.

Regression test spawns 'sleep 60' (POSIX only), sends a 1MB tools/call payload past the pipe buffer, and asserts the deferred rejects with the timeout error before the outer window elapses and produces no orphaned unhandled rejections.

Fixes #3945
2026-07-01 01:08:56 +00:00
roboomp 3bb2ade643 fix(pi-shell): wired fd directory walk to observe scope cancellation
The in-process fd builtin passed no-op heartbeats to pi_walker for
both its gitignore-respecting fallback path (`collect_with_heartbeat`
in `search`) and its fast path (`for_each_entry_with_heartbeat` in
`try_search_fast`), so cancellation of a large or slow directory walk
was deferred until traversal completed. The shell wrapper flips the
shared `AtomicBool` cancel flag when the runtime cancellation token
fires and then awaits the blocking task; with no heartbeat hookup the
walker had no way to observe the flag mid-walk and kept collecting the
whole tree before the wrapper could return exit 130.

Introduce `cancel_heartbeat(&AtomicBool)` — the walker-level heartbeat
that returns `io::ErrorKind::Interrupted` when the flag is set — and
plug it into both walker calls. Both call sites recognize the resulting
`WalkError::Interrupted` alongside `cancelled` and break silently
instead of surfacing an `fd:` diagnostic on stderr; the shell wrapper
owns the user-visible exit code.

Regression cover: a walker-level test pre-sets the cancel flag and
asserts `collect_with_heartbeat(cancel_heartbeat(&flag))` surfaces
`WalkError::Interrupted` instead of collecting the tree; two
higher-level `search` tests exercise the silent break for both the
fallback and fast paths; a fourth pins the non-cancelled contract so
the added heartbeat can't stall normal searches. Neuter the helper to
a no-op and the walker-level test fails with the pre-fix `WalkOutcome`
showing every entry scanned — the exact bug the issue reports.

Fixes #3949
2026-07-01 01:08:48 +00:00
can1357 b2a859a7c5 chore: bump version to 16.2.11 2026-07-01 03:06:34 +02:00
roboomp 6c56d39dc5 fix(extensions): bound tool_call handlers by extensionHandlerTimeoutMs
emitToolCall awaited each extension handler directly (runner.ts:704-706),
bypassing the #runHandlerWithTimeout wrapper every other subscribed event
routes through. A tool_call handler that never resolves parked
ExtensionToolWrapper.execute indefinitely, freezing tool dispatch even
though the symmetric emitToolResult path has always been timeout-protected.

Race each tool_call handler against Bun.sleep(extensionHandlerTimeoutMs)
inline (the shared wrapper swallows errors, and this callsite is
fail-closed). On timeout: emit an ExtensionError with event: 'tool_call',
log a warning, and return { block: true, reason: 'Extension <path>
timed out after <ms>ms' } — symmetric with the existing per-handler error
branch. Fail-closed is the correct policy for a pre-execution gate: an
unresponsive extension MUST NOT be silent consent to run the tool.

Fixes #3948
2026-07-01 01:03:37 +00:00
can1357 b92bd7d02c chore: update chanelogs 2026-07-01 02:58:17 +02:00
can1357 ed9c049e15 Merge remote-tracking branch 'origin/farm/4a3419a7/sync-omp-docs-coverage' 2026-07-01 02:57:52 +02:00
can1357 2e8c012eec Merge remote-tracking branch 'origin/farm/3cd77781/bound-ast-search-pages' 2026-07-01 02:57:36 +02:00
can1357 44205d62c4 Merge remote-tracking branch 'origin/farm/cc69ac0e/fix-whisper-stt-download' 2026-07-01 02:57:31 +02:00
can1357 6e9ae7adc7 Merge remote-tracking branch 'origin/farm/a032fc7d/grep-rg-walker-cancel-heartbeat' 2026-07-01 02:57:24 +02:00
can1357 a64749fe1f Merge remote-tracking branch 'origin/farm/d23f8157/bound-async-job-dispose' 2026-07-01 02:57:06 +02:00
can1357 c30526fe39 fix(ai): required non-empty name and id for native streaming tool calls
- Added `hasUsableNativeToolCall` helper to verify that a streaming tool call has non-empty, trimmed name and id values.
- Retain projection initialization and updates on subsequent deltas if the provider emits native tool identifiers late.
- Guard tool call synchronization and late salvage logic to prevent empty or invalid placeholders from corrupting streaming state.
2026-07-01 02:54:42 +02:00
roboomp efcd6cafd6 fix(stt): kept whisper setup downloads alive
Kept the STT subprocess referenced while download and stream requests are pending so setup cannot exit before the worker answers.

Propagated worker download errors to setup callers and verified completed downloads leave the expected cache files.

Fixes #3939
2026-07-01 00:07:14 +00:00
roboomp 92740d3c4f docs(coding-agent): completed full omp docs sync
Added a contributor-facing native crate map (docs/native-crates.md) covering pi-natives, pi-shell, pi-ast, pi-iso, pi-walker, pi_uu_grep, pi-uutils-ctx, and vendored brush crates, and linked it from natives-architecture.md and user-facing-packages.md.

Added a docs-index tool coverage test asserting every BUILTIN_TOOL_NAMES entry and injected custom tool (generate_image, tts) has a docs/tools/<name>.md page served by omp://.

Inlined tiny fail/buildPayloadText/checkDocsIndexFreshness helpers in generate-docs-index.ts per the project rule against single-expression named functions.

Fixes #3934
2026-07-01 00:00:52 +00:00
roboomp 578a2d7626 fix(ast): bounded ast search pagination payloads
Retained only the requested AST search page window in native ast_grep/ast_match and the coding-agent multi-target wrapper while preserving exact totals.

Fixes #3935
2026-06-30 23:54:17 +00:00
roboomp 3c3cb2a76b docs(coding-agent): synced omp docs coverage
Added root omp docs for memory_edit, learn, manage_skill, generate_image, and tts, plus package-level coverage for user-facing README-only CLIs.

Added a docs-index freshness check to package check and made gen:bundle generate and reset the docs embed itself.

Fixes #3934
2026-06-30 23:53:42 +00:00
roboomp dbab0ef84d fix(uutils): wired grep/rg directory walks to observe scope cancellation
The grep and rg in-process builtins passed no-op heartbeats to pi_walker
when recursing into a directory, so the uutils scope's cancel flag was
ignored mid-walk. The shell wrapper sets that flag on abort/timeout and
then awaits the blocking task — with no heartbeat hookup, a cancelled
recursive grep/rg waited for the whole tree to be scanned before the
shell could return exit 130.

Add pi_uutils_ctx::is_cancelled() and have grep's search_dir, rg's
search_dir, and rg's collect_filtered_files supply heartbeats that
return io::ErrorKind::Interrupted when the flag is set. The walker maps
that to WalkError::Interrupted, which the utilities now silently treat
as a harness cancellation (no spurious 'native directory scan
interrupted' on the command's stderr — the shell wrapper owns the
user-visible exit code).

Regression tests pre-set the cancel flag and assert grep -r /
rg / rg --files exit without scanning the matching file in the tree.

Fixes #3933
2026-06-30 23:37:20 +00:00