Commit Graph

935 Commits

Author SHA1 Message Date
metaphorics 3802d2dd80 chore(ts): enforce noImplicitOverride 2026-08-05 02:49:01 +09:00
can1357 003bb5548c chore: bump version to 17.2.8 2026-08-04 05:53:35 +02:00
can1357 a5090f1f81 chore: bump version to 17.2.7 2026-08-04 01:19:36 +02:00
can1357 01c1f91ff5 chore: bump version to 17.2.6 2026-08-03 16:44:19 +02:00
can1357 455493dfad feat: introduced native file lock bindings for cross-process advisory locking
- Added native `FileLock` bindings supporting cross-process advisory locking on Linux, Unix, and Windows.
- Replaced directory-based file locking and custom stale-lock reclamation with OS-backed native locks.
- Updated TypeScript declarations, native bindings, and package documentation for the new API.
- Added comprehensive unit tests and fixtures validating single-owner constraints and process death handoff.
2026-08-03 16:09:09 +02:00
can1357 4ddc2d2cd4 chore: rewrite changelogs + fix stale tests 2026-08-03 15:32:19 +02:00
can1357 8f1bb06134 docs(changelog): normalized unreleased entries for the second merge round
- Restored released sections displaced by union changelog merges; [Unreleased]
  now carries the entries for #7377, #7469 (with the OMP_PCRE2_JIT override),
  #7475, #7215, #7287, and the shared pi-utils file-lock module.
2026-08-03 15:25:03 +02:00
can1357 9fb082bf14 refactor(utils): consolidated file locking into pi-utils file-lock
- Moved the coding-agent lock-directory primitive to @oh-my-pi/pi-utils/file-lock
  and migrated settings, MCP config-writer, and security store imports.
- Replaced the stats aggregator's parallel ~200-line token/breaker lock protocol
  with the shared primitive: dead owners reclaimed immediately, live-but-wedged
  owners after STATS_SYNC_LOCK_STALE_MS, unstamped acquisitions after the new
  acquireStaleMs grace (10s).
- Shared primitive now treats EPERM kill probes as live owners.
- Rewrote the stats lock-reclamation regressions against the shared protocol
  and moved the file-lock contract test into pi-utils.
2026-08-03 15:25:03 +02:00
can1357 5039b33a11 test(utils): skipped torn log lines in logger poll loop
- waitForLogEntry raced winston's async flush and JSON.parsed a
  partially written line, failing the error-serialization tests on
  loaded CI runners; unparseable lines now wait for the next poll.
2026-08-03 06:52:11 +02:00
can1357 c53b85aaf4 chore: bump version to 17.2.5 2026-08-03 05:53:12 +02:00
can1357 63b07f8ec0 chore: rewrite changelogs 2026-08-03 05:52:53 +02:00
can1357 a7f3bc2a17 chore: normalized changelog entries after merges 2026-08-02 21:01:11 +02:00
can1357 f1c7eda7de Merge PR #7205: perf(cli): keep root help off runtime graph (@eggpeat)
# Conflicts:
#	packages/coding-agent/src/cli-commands.ts
#	packages/coding-agent/src/cli/args.ts
2026-08-02 20:59:12 +02:00
can1357 980c78538b Merge PR #7395: fix(postmortem): resolve native hard-exit per call (@roboomp) 2026-08-02 20:53:35 +02:00
can1357 3f61117994 Merge PR #7362: fix(auth): guard config-value resolvers against case-insensitive env hijack (@roboomp) 2026-08-02 20:53:20 +02:00
roboomp e27b0e81ec fix(postmortem): resolve native hard-exit per call
The postmortem module bound the native hard-exit once at module init
(process.reallyExit.bind(process)). The shipped bundle defers this
module's evaluation until first access, which can land inside a
withHostGuard window where process.reallyExit is the ExtensionExitError-
throwing stub; .bind() then froze that stub permanently, so every later
host-owned exit (SIGHUP 129, SIGINT 130, fatal 1) threw and re-entered
the unhandled-rejection fatal path in a loop (exit 129 storm).

Resolve the native exit on every call instead of binding at init, and
have withHostGuard stamp its throwing replacement with the native
primitive it shadows so a signal arriving mid-guard still exits (#6488)
without the guard poisoning later exits (#7393).

Fixes #7393
2026-08-02 17:32:12 +00:00
roboomp a6521f07ed fix(auth): guarded config-value resolvers against case-insensitive env hijack
On Windows process.env/Bun.env lookups are case-insensitive, so the
"env var name, else literal" resolvers turned a literal /login key like
`public` (OpenCode Zen's free key) into the built-in PUBLIC=C:\Users\Public,
sending `Authorization: Bearer C:\Users\Public` and 401ing every request.

Added `$envExact` in pi-utils, which trusts an env lookup only when an
exact-case key is enumerated (the only case-preserving signal on Windows;
the getter and hasOwnProperty/getOwnPropertyDescriptor traps are all
case-insensitive there). Wired it into all three resolvers:
resolve-config-value.ts, model-registry.ts, and auth-storage.ts.

Fixes #7361
2026-08-02 06:53:18 +00:00
can1357 92c79d80c7 feat: introduced OMP Browser Relay extension with CDP RPC execution
- Implement the OMP Browser Relay extension with WebSocket communication and CDP RPC execution.
- Add browser relay server, daemon management, and bridge multiplexing in the coding agent.
- Introduce CLI commands and settings schema options for configuring and installing the relay.
- Add utility functions and test suites supporting environment parsing and relay lifecycle handling.
2026-08-02 05:33:07 +02:00
can1357 d595332fc6 chore: bump version to 17.2.4 2026-08-02 00:19:30 +02:00
can1357 dda859b60f fix(ci): hardened logger probe timeouts and silenced async trait lint
- Raised probe-spawning logger tests to 30s timeouts; bun's 5s default
  SIGTERMed probe children (exit 143) on shared-core CI runners, matching
  the precedent documented in logger-contract.test.ts.
- Allowed clippy::unused_async_trait_impl on KillCommand::execute with an
  unknown_lints guard for the pinned CI nightly that predates the lint.
2026-08-01 22:34:39 +02:00
can1357 72c66c87c1 fix(xdg): adopted legacy secret-placeholder.key and marketplaces.json at XDG paths 2026-08-01 20:46:25 +02:00
can1357 03e54555f9 Merge PR #7065: fix(xdg): fix files and folder for xdg-maintained (@Parsifa1) 2026-08-01 20:39:29 +02:00
can1357 44c7421462 chore: normalized changelog entries after merging sweep fixes 2026-08-01 20:14:51 +02:00
can1357 f13f9b1228 fix(utils): recognize underscore Bun test entrypoints 2026-08-01 20:14:39 +02:00
can1357 5b2aefe584 Merge PR #7263: fix(tui): prevent test env from suppressing interactive launch (@roboomp)
# Conflicts:
#	packages/utils/test/env.test.ts
2026-08-01 20:14:08 +02:00
can1357 b6e12240c9 Merge PR #7240: fix(coding-agent): bound synchronous SQLite busy-waits in headless hosts (@pi3123) 2026-08-01 20:13:39 +02:00
roboomp 9f9c9758a1 fix(tui): prevented test env from suppressing interactive launch
Scoped test-runtime detection to explicit runner markers and Bun test entrypoints, so application NODE_ENV/BUN_ENV values no longer make ProcessTerminal headless.

Added subprocess regression coverage and propagated the private marker to test children.

Fixes #7261
2026-08-01 11:39:57 +00:00
Parsifa1 ea437745a3 fix(xdg): move secret-placeholder.key, marketplaces.json, and run/ out of config root
These four paths bypassed DirResolver's XDG-aware rootSubdir/agentSubdir
hooks, resolving directly against getConfigRootDir()/getAgentDir() and
ignoring XDG state/data layout. Add XDG-aware path helpers in dirs.ts
and route all four through them:

- secret-placeholder.key → $XDG_STATE_HOME/omp/ (state, agent flattened)
- marketplaces.json      → $XDG_DATA_HOME/omp/  (data)
- run/daemons/<hash>/    → $XDG_STATE_HOME/omp/run/ (state)
- run/provider-inflight/ → $XDG_STATE_HOME/omp/run/ (state)

omp config init-xdg migrates secret-placeholder.key and marketplaces.json
from their legacy locations; run/ is ephemeral and rebuilds on restart.
2026-08-01 06:40:48 +00:00
can1357 8baa3300bc chore: bump version to 17.2.3 2026-08-01 08:35:39 +02:00
pi3123 4a9350963f Hoist interactive-host flag above settings load; add changelog entries
Settings.init opens agent.db/stats.db before setInteractiveHost ran, so
interactive hosts received the 1000ms headless busy timeout on those
databases (issue #2421 class). Declare the flag before settings load and
add [Unreleased] changelog entries per repo conventions.
2026-07-31 23:27:15 -07:00
pi3123 96a206440c Add unit tests for getDbBusyTimeoutMs 2026-07-31 20:04:30 -07:00
pi3123 edb3feda9b Bound synchronous SQLite busy-waits in headless hosts
Headless hosts (print/RPC/ACP/eval/SDK) run the agent loop on the same
thread as bun:sqlite, so a lock-contention busy-wait of the interactive
5s timeout freezes the protocol loop for seconds at a time with no
liveness signal. Use a 1s busy_timeout for session-critical databases
(agent.db, history.db, stats.db) when the host is not interactive, and
let the existing asynchronous open/retry paths recover from contention.
2026-07-31 19:59:48 -07:00
Brent a572fcb9be fix(cli): preserve help metadata contracts 2026-07-31 22:01:19 +00:00
Brent 9df3067930 perf(cli): keep root help off runtime graph 2026-07-31 21:28:41 +00:00
can1357 d5861c2c66 chore: bump version to 17.2.2 2026-07-31 20:56:49 +02:00
can1357 df9d9c8899 chore: bump version to 17.2.1 2026-07-30 17:27:05 +02:00
can1357 ab572106cd Merge PR #7048: feat(security): add OMP-native security scan subsystem (@kmccleary3301) 2026-07-30 17:11:06 +02:00
can1357 8db0228f4d fix(ci): unblocked release run on formatting and chunk watchdog
- Reformatted the logger burst test per biome (the type-check job gates on
  check:tools, which failed on the previous hotfix's formatting).
- Raised the native/unit bucket's chunk watchdog to 1200 s: the mupdf PDF
  extraction chunk runs ~7 min per attempt on burstable runners under a
  full fan-out and the 600 s default SIGKILLed both tries in release run
  30519992654; the watchdog targets wedged children, not slow chunks.
2026-07-30 08:59:03 +02:00
can1357 053dbfa605 fix(ci): stopped mtime prune from gutting extracted bazel repos
- The hosted disk-cache prune swept ~/.cache/omp-bazel-repo file-by-file;
  extracted repository contents keep upstream-archive mtimes (months old),
  so a restored archive lost most of rules_rust while bazel still trusted
  the entry's recorded_inputs — both darwin release legs failed with
  'BUILD file not found' in release run 30519253683. Prune only the
  action disk cache, whose files carry bazel-written mtimes.
- Gave the logger burst-order contract an explicit 30 s budget: two probe
  children measure ~4.4 s unloaded and bun's 5 s default test timeout
  SIGTERMed them (exit 143) on shared-core runners.
2026-07-30 08:33:27 +02:00
Kyle McCleary 4337797565 Merge remote-tracking branch 'origin/main' into feat/security-native
# Conflicts:
#	packages/coding-agent/src/tools/index.ts
2026-07-29 23:26:22 -07:00
can1357 3d6b5b7ac8 chore: bump version to 17.2.0 2026-07-30 07:58:50 +02:00
can1357 a4773c0baa refactor(typescript-edit-benchmark): updated mutation plans
- Update benchmark fixtures archive file.
- Adjust mutation plan block sizes and counts in generator script.
- Remove postmortem quit test.
2026-07-30 07:57:55 +02:00
can1357 38ebd30337 chore: update stale tests 2026-07-30 07:49:43 +02:00
Kyle McCleary 089a9963f8 feat(security): OMP-native security subsystem (planner handoff) 2026-07-29 18:47:51 -07:00
can1357 93eb95b3b1 chore: rewrite changelogs 2026-07-29 23:34:04 +02:00
can1357 f2251b7d59 chore: normalize changelogs and formatting after merging open fixes 2026-07-29 23:09:40 +02:00
can1357 f925f9f38a test(utils): cover quit without stdout drain
(cherry picked from commit 59a8002411726d8686c187a6d031a1f54577093b)
2026-07-29 23:08:32 +02:00
can1357 897b0c8d6c Merge PR #6920: fix(tui): prevent Windows pane-close deadlock (@roboomp) 2026-07-29 23:08:31 +02:00
roboomp 313f3fa1c4 fix(tui): prevented Windows pane-close deadlock
Skipped stdout draining after ProcessTerminal observes a native Windows terminal disconnect, while preserving normal postmortem cleanup and drain behavior for every other shutdown path.

Fixes #6917

(cherry picked from commit b45fc00ab4b5075ccb9650584947dde061beea20)
2026-07-29 23:08:31 +02:00
usr-bin-roygbiv 574f400b0f fix(utils): pin logger rotation entrypoint
(cherry picked from commit 6dc31019848a20053e66df947c48e087cce8566a)
2026-07-29 23:08:28 +02:00