Commit Graph
8953 Commits
Author SHA1 Message Date
Mathews-Tom 6efe70876a chore: merge upstream/main into feat/secret-friendly-names 2026-07-06 19:58:29 +05:30
can1357 f75b758c61 test(coding-agent): flushed coalesced observer sync before todo assertion
- Subagent lifecycle reconciliation now runs behind the 100ms observer UI
  coalescing timer; the test advances fake timers instead of asserting
  synchronously after emit.
2026-07-06 09:34:57 +02:00
can1357 d8e568fad1 chore: bump version to 16.3.10 2026-07-06 08:13:30 +02:00
can1357 0006252d6e test(utils): validated tool error handling and cleanup signal propagation
- Added comprehensive test suite for `postmortem` utility error handling, covering cleanup symbol marking, cause chain depth validation, and process exception suppression.
- Added tests for `browser-run-cancellation` ensuring proper `unhandledRejection` suppression and correct `ToolAbortError` propagation during teardown.
- Implemented `collectUnhandledRejections` helper to verify silence of process-level rejections during async race conditions in browser runs.
- Added integration-style probe tests for `postmortem` to verify that marked cleanup errors allow process survival while unmarked ones remain fatal.
2026-07-06 08:07:25 +02:00
can1357 4f172fb27c feat(tui): relocated terminal restore registration to tui init
- Moved emergency terminal restore registration to the TUI terminal initialization logic.
- Ensured terminal restoration triggers correctly on fatal exits by moving registration out of a side-effect-heavy barrel module.
- Added a registration guard to prevent redundant postmortem handler attachments.
2026-07-06 08:07:24 +02:00
can1357 dd5c329bc3 fix(coding-agent): resolved browser teardown crashes by tracking expected abort errors
- Added `markHandled` helper to prevent unhandled promise rejections in fire-and-forget browser tasks.
- Integrated `postmortem.markExpectedCleanupError` to distinguish between expected teardown aborts and actual runtime failures.
- Updated `runCmuxCode` and `WorkerCore` to propagate abort reasons via `ToolAbortError` cause chains.
- Modified `tab-protocol` and supervisor logic to signal expected cleanup states during tab release.
- Added test coverage for `ToolAbortError` wrapping and cause preservation.
2026-07-06 08:07:24 +02:00
can1357 45d95e7bf9 feat(coding-agent): constrained nested task rendering to prevent overflow
- Capped nested subagent trees at the per-level limit to prevent unbounded progress rendering in deep sessions.
- Added elision indicators for collapsed nested subagent rows, prioritizing failed tasks during selection.
- Removed the partial-result spinner repaint loop to reduce CPU usage during high-frequency progress streaming.
2026-07-06 08:07:24 +02:00
can1357 af985eb511 Merge remote-tracking branch 'origin/farm/12bd9282/local-model-vision-detection' 2026-07-06 07:39:11 +02:00
can1357 ccf8789693 Merge remote-tracking branch 'origin/farm/f45f9d5d/get-session-stats-context-usage' 2026-07-06 07:39:07 +02:00
can1357 7adfe9f1a8 Merge remote-tracking branch 'origin/farm/0df0bbf3/fix-skill-card-header-spacing' 2026-07-06 07:38:46 +02:00
can1357 f572841c60 Merge remote-tracking branch 'origin/farm/4a9a5787/fix-irc-between-wait-replies' 2026-07-06 07:38:42 +02:00
can1357 dbc4e9c7c0 Merge remote-tracking branch 'origin/farm/ae58e93f/reset-irc-wake-yield-flag' 2026-07-06 07:38:27 +02:00
can1357 00e96db590 feat(coding-agent): throttled and constrained agent hud updates
- Added throttling and debouncing to HUD data rendering and observer UI synchronization to coalesce update bursts.
- Constrained the subagent HUD display to a maximum of 8 rows with a truncation notice for hidden sessions.
- Enhanced the session observer registry to categorize update types, enabling more granular UI reconciliation.
- Verified render coalescing and display truncation behavior with comprehensive integration tests using fake timers.
2026-07-06 07:38:08 +02:00
Mathews-Tom d975cd630e chore: merge upstream/main to resolve stale mergeability 2026-07-06 10:42:29 +05:30
roboomp 17080bef3c fix(agent): refreshed startup llama.cpp vision metadata
Refresh cached llama.cpp runtime metadata before exposing the initial session model so local vision defaults are not treated as text-only.

Fixes #4670
2026-07-06 04:03:00 +00:00
roboomp 5f44151903 fix(rpc): included context usage in session stats
Added contextUsage to SessionStats so get_session_stats mirrors the existing getContextUsage data used by state responses.

Fixes #4668
2026-07-06 03:16:13 +00:00
roboomp 4a65d2443d fix(tui): corrected skill card header spacing
Fixed skill card headers to render one visible space between the skill tag and skill name.

Fixes #4662
2026-07-06 02:37:50 +00:00
roboomp 06f6762103 fix(agent): surfaced pending irc replies to wait
Drained pending IRC asides before parking irc wait so replies that arrive between wait calls are returned instead of being treated only as queued interrupts.

Added regression coverage for the already-aborted queued-IRC signal path and documented the fix in the coding-agent changelog.

Fixes #4657
2026-07-06 02:36:35 +00:00
roboomp 3a962c54c7 fix(agent): reset IRC wake maintenance state
Reset per-turn maintenance counters before IRC wake prompts so yielded subagents do not carry stale yield termination into later wake turns.

Add regression coverage for empty-stop retry after an IRC wake following a yielded run.

Fixes #4658
2026-07-06 02:34:23 +00:00
can1357 674cf01762 chore: bump version to 16.3.9 2026-07-06 04:19:29 +02:00
can1357 617966c193 chore: update changelogs 2026-07-06 04:17:21 +02:00
can1357 6e95ace3a7 Merge remote-tracking branch 'origin/farm/8b99fd4b/enabled-skill-provider-fallback' 2026-07-06 04:16:54 +02:00
can1357 f75b9514f1 Merge remote-tracking branch 'origin/farm/21632629/fix-split-commit-lock-file-validation' 2026-07-06 04:16:21 +02:00
can1357 9be287516f Merge remote-tracking branch 'origin/farm/91f334f7/detect-local-vision-model' 2026-07-06 04:16:06 +02:00
can1357 79ca069d9c feat(coding-agent): supported streaming TTS for long text inputs
- Implemented streaming synthesis in the `say` command to allow processing of arbitrarily long text without hitting model phoneme limits.
- Added file input support via the `--file` flag and updated the CLI to prevent conflicting arguments.
- Refined `SpeakableStream` segmentation logic to prioritize valid sentence and clause breaks within the maximum segment length when processing large text buffers.
- Added comprehensive tests for stream segmentation behavior under long-form input.
2026-07-06 04:12:39 +02:00
roboomp 306bde3b7e fix(coding-agent): refreshed llama vision input metadata
- Propagated llama.cpp /props input modalities through selected-model runtime refresh.
- Added a regression test for cached text-only local vision models becoming image-capable after refresh.
- Updated the coding-agent changelog for the local vision detection fix.

Fixes #4654
2026-07-06 02:00:20 +00:00
roboomp 914dc9551a fix(coding-agent): kept claude home skills user-scoped
Skipped the home directory during Claude project skill walk-up so disabling Claude user skills cannot reload the same files as project skills.

Added regression coverage for the home-skill duplicate path with an enabled agents fallback.

Fixes #4648
2026-07-06 01:06:48 +00:00
roboomp dd3375981f fix(coding-agent): preserved enabled duplicate skills
Applied source toggles before skill-name dedup so disabled higher-priority providers no longer hide enabled lower-priority authored skills.

Added regression coverage for disabled claude versus enabled agents duplicate names and managed dead-last behavior.

Fixes #4648
2026-07-06 00:51:24 +00:00
Mathews-Tom 534bbc7751 fix(coding-agent): catch a regex friendlyName that normalizes to a discovered value
Codex P2 finding on commit 9632ed5: #friendlyNameCollidesWithSecret tested
a regex-entry friendlyName's RAW spelling directly against the pattern,
which can never match a label that is already normalized (uppercased,
separators stripped) even when that label IS the normalized rendering of
a value the regex actually discovers -- e.g. friendlyName: "TOKABC123"
for content: "tok_[a-z0-9]+" discovering literal tok_abc123. Nothing
compared the label against the actual matched value either. The check
now also compares the sanitized label against the sanitized value of the
secret currently being minted (reusing #prefixIsSecretShaped), catching
this on the secret's first mint before it's recorded as previously
discovered.
2026-07-06 06:21:01 +05:30
Mathews-Tom 9632ed504e fix(coding-agent): compare friendlyName collision against the untruncated label
Codex P2 finding on commit 9b2e14d: #friendlyNameCollidesWithSecret
compared a secret's full sanitized value against the already 32-char-capped
(sanitizeSecretFriendlyName) friendly name, so a secret whose sanitized
form exceeds MAX_FRIENDLY_NAME_LEN could never be fully contained in the
truncated label -- the collision went undetected and the secret's first
32 sanitized characters leaked as an accepted placeholder prefix. The
collision check now runs against the full, untruncated sanitized label
(sanitizeForCollisionCheck(friendlyName)); the 32-char cap is applied
only afterward, to the label actually used for display.
2026-07-06 06:06:06 +05:30
Mathews-Tom 9b2e14d91d fix(coding-agent): normalize plain-secret alias checks, preserve raw friendlyName, guard deobfuscate against forged aliases
Codex P2 findings on commit 029e838:

- secrets/index.ts:189: loadFriendlyName pre-sanitized the friendlyName
  before storing it on the SecretEntry, silently defeating the raw-label
  regex collision check for every secrets.yml-loaded entry. The loader now
  preserves the original, unsanitized string (still validating it sanitizes
  to something non-empty).
- obfuscator.ts:1232: the forged-alias guard (isGeneratedPlaceholder)
  compared the dropped prefix against RAW plain-secret values, so a
  lowercase/punctuated secret's normalized rendering slipped through. Both
  the plain-secret-value and obfuscateMappings loops now normalize the
  compared value the same way the prefix is already constrained to.

Self-discovered while verifying the above: deobfuscate()'s bare-alias
fallback had NO prefix validation at all (unlike obfuscate()'s guard),
so a forged token wrapping any real placeholder's hash suffix in a
secret-shaped prefix would restore to that secret's raw value on the
live provider-output/tool-call-argument path -- strictly worse than the
obfuscate-direction leak. Extracted the shared check into
#prefixIsSecretShaped and reused it in a new #lookupLiveAlias gate for
deobfuscate(), verified a genuine friendly-name rename still round-trips.
2026-07-06 05:52:16 +05:30
Mathews-Tom 029e838bf0 fix(coding-agent): reject forged alias prefixes matching a regex pattern
Codex P2 finding on commit dff2a8d: #isGeneratedPlaceholder's forged-alias
guard only checked a dropped friendly-name prefix against exact previously-
discovered secret strings, recorded in whatever casing they first turned
up in. A case-insensitive (or other flag-variant) regex only ever records
the one casing it actually discovered, so a forged token wrapping a
differently-cased occurrence of that secret-shaped text around a real
bare-alias suffix matched neither exact-string check and sailed through
as an already-redacted placeholder, leaking the secret-shaped text
verbatim. The guard now also tests the dropped prefix directly against
every configured regex pattern.
2026-07-06 05:30:09 +05:30
Mathews-Tom dff2a8dc88 fix(coding-agent): check regex friendlyName collision against raw label
Codex P2 finding on commit 7d3a3a2: #friendlyNameCollidesWithSecret ran a
configured regex entry's pattern against the already-sanitized (uppercased,
separator-stripped) friendly name, so a case-sensitive/punctuated pattern
like tok_[a-z0-9]+ never matched the sanitized label even when the raw
friendlyName was itself a live match for that regex — letting a
secret-shaped label slip through and stamp into every placeholder minted
for it. The regex check now runs against the raw, pre-sanitization label,
matching how the regex would encounter that text verbatim.
2026-07-06 05:16:17 +05:30
Mathews-Tom 7d3a3a23a3 fix(coding-agent): reject unresolvable regex fallback and sanitize friendly-name collision check
Two Codex P2 findings on commit 732f725:

- A default (no custom replacement) mode: "replace" regex that cannot
  escape a 1-2 char match (e.g. ".", "[\\s\\S]", "[\\s\\S]{2}") had its
  key-derived same-length fallback marker returned without checking it
  against the matched value. Since that marker is drawn from an alphabet
  the regex has already proven to match exhaustively, a real 1-2 byte
  secret coinciding with it would ship unredacted. Such entries are now
  rejected: dropped with a warning when loaded from secrets.yml, dropped
  silently as a construction-time backstop otherwise.
- #friendlyNameCollidesWithSecret compared the sanitized (uppercased,
  alnum-only) friendly name against each secret's raw value, so a
  friendlyName that was a lowercase or punctuated variant of its own
  secret slipped through and stamped most of the secret into the
  placeholder. The secret value is now sanitized the same way before
  comparing.
2026-07-06 05:05:26 +05:30
Mathews-Tom 732f72510a fix(coding-agent): address secrets review feedback
- Fix #generateRegexReplacement's pathological (match-everything) fallback
  emitting a 1-2 byte matched value unchanged when it was exactly `Z`/`ZZ`,
  the shared sentinel #generateReplacement uses for such short values.
  Falls back to a same-length, key-derived run instead, which stays a fixed
  point under re-obfuscation without being a public, guessable constant.
- Default getSecretPlaceholderKey()/getExistingSecretPlaceholderKey() to
  getAgentDir() instead of getConfigRootDir(), matching the directory
  createAgentSession() actually passes.
- Isolate the getSecretPlaceholderKey test suite under a fresh $HOME/temp
  agent dir instead of the real homedir, fixing an EACCES failure in
  sandboxed review environments.
- Revert an unrelated gc session-ordering tie-breaker bundled into this
  branch's history; out of scope for the secrets/friendly-name feature.
- Relocate this PR's CHANGELOG.md entries out of already-released sections
  (16.3.0, 16.3.5) into [Unreleased], where a stale merge had left them,
  and drop a duplicate blank line and duplicate serverSideFallback/
  softRequestBudgetNotice entries the same merge introduced.
2026-07-06 04:12:54 +05:30
Mathews-Tom 79d1658703 Merge remote-tracking branch 'upstream/main' into feat/secret-friendly-names 2026-07-06 03:03:55 +05:30
roboomp d5d849f48c fix(commit): capture split-executor staged diff with binary contents
Without --binary, `git diff --cached` writes `Binary files ... differ` stubs
for staged binary files. runSplitCommit reset the index and then fed those
stubs to `git apply --cached --binary`, which cannot reconstruct the content,
so a split plan that included `bun.lockb` (or any other staged binary) would
crash the apply step after the reset had already cleared the index.

Pass `binary: true` when capturing `stagedDiff` so the patch text carries the
real binary payload and the executor can re-stage it per commit group.

Refs #4632, #4634 review
2026-07-05 21:32:40 +00:00
roboomp 7945c1e8eb fix(commit): pair staged lock files with the split-plan commit that owns them
git_overview hides EXCLUDED_LOCK_FILES from the model so lock files never drive
split decisions, but runSplitCommit then re-fetched the raw staged set and
rejected any plan that failed to enumerate them, aborting `omp commit` with
"Split commit plan missing staged files: <lockfile>". Skipping the validator
would have masked a real drop — the executor resets the index and only
re-stages files listed in each commit group.

Introduce packages/coding-agent/src/commit/agentic/lock-files.ts with a
LOCK_FILE_MANIFESTS map and an assignLockFilesToPlan helper that attaches each
orphaned lock file to (1) the commit group touching a sibling manifest in the
same directory, (2) any commit group touching a matching manifest, or (3) the
last commit group. git-overview.ts imports EXCLUDED_LOCK_FILES from the shared
module so the filter and the pairing table stay in sync.

Fixes #4632
2026-07-05 21:21:41 +00:00
can1357 d806ac5e4c chore: bump version to 16.3.8 2026-07-05 19:43:28 +02:00
can1357 58f962b30c feat(patches): upgraded puppeteer and enabled main world execution
- Upgraded puppeteer-core to version 25.3.0 to resolve stealth patch deactivation.
- Enabled main world execution support via the `!world=main` directive for frames and element handles.
- Improved handle management by updating disposal logic to track and clear main world handles.
- Optimized web worker communication by removing redundant Runtime.enable calls.
2026-07-05 19:42:13 +02:00
can1357 b914f552f6 test(coding-agent): pinned plan-reference compaction window to 200k
claude-sonnet-4-5's bundled context window grew to 1M in the catalog regen, so the fixed 191k high-usage turn no longer crossed the ~85% auto-compaction threshold. The auto-continuation never fired and the three re-injection tests hung to their 5s timeout, failing the coding-agent runtime/session CI bucket and blocking the release.

Pin the harness model to a 200k window (mirrors agent-session-eager-compaction / -auto-compaction-queue), keeping the trigger stable across future catalog regenerations.
2026-07-05 17:47:07 +02:00
can1357 0ca345185c chore: bump version to 16.3.7 2026-07-05 16:58:53 +02:00
can1357 3458b037ae chore: update tests 2026-07-05 16:53:07 +02:00
can1357 302f1c3beb test(coding-agent): implemented verification for sdk model selection logic
- Updated event controller fixture to include requestComponentRender mock.
- Added test case for resolving deferred role-alias model patterns.
- Added test case for parsing and falling back comma-delimited model patterns.
2026-07-05 15:57:24 +02:00
can1357 8519286ef7 feat(coding-agent): implemented watchdog and abort logic for lsp notifications
- Implemented a 2-second timeout for `workspace/didChangeWatchedFiles` notifications to prevent agent stalls during server congestion.
- Updated `runLspWritethrough` to gracefully reset notification state when the internal watchdog triggers but the primary operation remains active.
- Added explicit abort signal checks in `acp-bridge` to prevent initiation of file writes after tool cancellation.
- Refactored `notifyWorkspaceWatchedFiles` to use `AbortSignal.any` for unified signaling across timeout and caller-provided triggers.
2026-07-05 15:57:24 +02:00
can1357 da705d76e6 feat(coding-agent): unified resolution logic for deferred model patterns
- Enabled comma-separated string splitting within array-based model patterns.
- Expanded deferred model patterns before registration to align with immediate resolution behavior.
- Unified resolution logic to ensure deferred patterns support the same role aliases and chaining as the standard path.
2026-07-05 15:57:24 +02:00
can1357 34aea528a3 chore: update changelogs 2026-07-05 14:35:17 +02:00
can1357 a89f48188a chore: normalized changelog placement after merges 2026-07-05 13:39:20 +02:00
can1357 34303db1ce test(session): assert persistence-key cache avoids branch walks 2026-07-05 13:39:11 +02:00
can1357 b3c661f164 Merge PR #4272: perf(session): cache persisted-message keys, invalidate on branch change (@metaphorics) 2026-07-05 13:39:11 +02:00