Commit Graph

16166 Commits

Author SHA1 Message Date
can1357 6fb922e5ca style: format codex zstd test 2026-07-29 23:10:58 +02:00
can1357 f2251b7d59 chore: normalize changelogs and formatting after merging open fixes 2026-07-29 23:09:40 +02:00
can1357 6527671c3a fix(lsp): sanitize expanded generic output
(cherry picked from commit 1260d0633a5fb533c492f272ee500fec60c46e22)
2026-07-29 23:09:14 +02:00
can1357 2adf484ef1 Merge PR #7042: fix(lsp): handle quick exits before reader teardown (@roboomp) 2026-07-29 23:09:13 +02:00
can1357 a459878b1e test(ai): cover bare-string Devin system prompt
(cherry picked from commit aa2087a480995e89cc1586e30542131a26db0ff8)
2026-07-29 23:09:13 +02:00
roboomp dca8f44b73 fix(lsp): handled quick exits before reader teardown
Waited briefly for process exit publication after clean stdout EOF so the process handler preserves the real exit code and stderr, while genuine reader errors still tear down immediately.

Cleared only the matching initialization failure for explicit reloads and added regressions for quick exits, reader errors, ordinary backoff, and immediate reload retries.

Fixes #7041

(cherry picked from commit a76522b759f14421202d4cc437ec611b78be20d1)
2026-07-29 23:09:13 +02:00
can1357 3e379410b4 Merge PR #7038: fix(ai): normalize bare-string systemPrompt in bedrock and devin (@roboomp) 2026-07-29 23:09:12 +02:00
can1357 abf4f3eda8 Merge PR #7033: fix(ai): classify bare resource_exhausted as MODEL_CAPACITY (@roboomp) 2026-07-29 23:09:12 +02:00
roboomp 5578a2203b fix(ai): normalize bare-string systemPrompt in bedrock and devin
buildSystemPrompt hand-rolled systemPrompt?.map(...) and devin's request
builder called (context.systemPrompt ?? []).join(...); both crash when
Context.systemPrompt is a bare string, as legacy @earendil-works/pi-ai
extensions remapped onto the fork pass it. The failure surfaced as
stopReason "error" with "systemPrompt?.map is not a function".

Route both through the existing normalizeSystemPrompts() helper, which
already accepts readonly string[] | string, matching the other providers.

Fixes #7037

(cherry picked from commit d681de5daa7e3316f118e6fb4cf8805ec5318c32)
2026-07-29 23:09:12 +02:00
roboomp ca8fcb25b8 fix(ai): strip every bare resource-exhausted token
parseConnectEndStream repeats the default status phrase in the message
body, so the trailer reads "resource_exhausted: resource exhausted".
Using a global strip removes both occurrences, so the leftover
"exhausted" no longer trips the generic quota branch and reintroduces
the 30-minute credential block for an otherwise bare status.

Fixes #7032

(cherry picked from commit 3d46a042c649e3892d9c68abbc3789a7719f0667)
2026-07-29 23:09:11 +02:00
roboomp f144f5db36 fix(ai): preserved quota details on resource exhaustion
Stripped the resource_exhausted status token before classifying the
remaining provider message. Bare or opaque status errors still use the
short model-capacity backoff, while explicit quota, rate-limit, capacity,
or server details remain authoritative.

Added regression coverage for a Connect resource_exhausted trailer with
an explicit quota-exceeded body.

Fixes #7032

(cherry picked from commit ee04c065692e34ccabe1a07b45b5f5987297ff84)
2026-07-29 23:09:11 +02:00
roboomp 3c7ffa3e08 fix(ai): classify bare resource_exhausted as MODEL_CAPACITY
Connect/gRPC end-streams carry the status name `resource_exhausted`
(underscore), but parseRateLimitReason only matched the space phrase
"resource exhausted" in its MODEL_CAPACITY branch. The underscore form
fell through to the generic includes("exhausted") catch-all and was
classified QUOTA_EXHAUSTED, producing a 30-min credential block and the
retry.maxDelayMs fail-fast at the session layer.

Match both forms via /resource.?exhausted/i, consistent with the
existing resource.?exhausted clause in USAGE_LIMIT_PATTERN, which is left
untouched so stream/session credential rotation is preserved.

Fixes #7032

(cherry picked from commit bc18cbb5b9bcf5c2bf41dc494581ae31061fcfcb)
2026-07-29 23:09:11 +02:00
can1357 672857d238 Merge PR #7025: fix(coding-agent): coalesce models config resource probe (@paralin) 2026-07-29 23:09:10 +02:00
Christian Stewart a43c7a4d36 fix(coding-agent): coalesce models config resource probe
The models config resource regression started two cold child processes inside one five-second test. Under parallel CI chunk load, the second child could still be waiting for pipe drain or process exit after the validator had completed.

Keep the process boundary as the owner of the lifecycle measurement and run the missing and custom phases in one child. The missing phase closes its storage and registry before the baseline snapshot, while the custom phase proves schema identity and retention without changing config loading or validator cleanup semantics.

Signed-off-by: Christian Stewart <christian@aperture.us>
(cherry picked from commit 81fa98491544c7fbcbf075922889e0a9e1a0a3b4)
2026-07-29 23:09:10 +02:00
can1357 5711b763e0 docs(auth): align remaining credential ladders
(cherry picked from commit c606fe3a106611be413f140310ee47a88324cded)
2026-07-29 23:09:09 +02:00
can1357 5c79f5bc4a Merge PR #7023: docs(auth): correct credential precedence (@wolfiesch) 2026-07-29 23:09:09 +02:00
Wolfgang Schoenberger 031beb1751 docs(auth): correct credential precedence
(cherry picked from commit 33ede5efbc52cedc9819cb65c642cfeab82c337c)
2026-07-29 23:09:09 +02:00
can1357 3efc354749 Merge PR #7022: fix(ai): preserve API-key validation HTTP errors (@wolfiesch) 2026-07-29 23:09:08 +02:00
can1357 1b3f01d197 Merge PR #7019: test(ai,catalog): give spawn-based lazy tests explicit timeouts (@roboomp) 2026-07-29 23:09:07 +02:00
Wolfgang Schoenberger cf3e601ec0 fix(ai): preserve API-key validation HTTP errors
(cherry picked from commit a4f8efb58327d3d8cbe5c18019ec42643b888e28)
2026-07-29 23:09:07 +02:00
roboomp cc04600a64 test(ai,catalog): give spawn-based lazy tests explicit timeouts
Spawn-based lazy-loading tests assert exitCode===0 on a child process but
set no per-test timeout, so bun's 5s default kills the child under CPU
contention and the assertion reports a dead child rather than a regression.

Give each spawn test an explicit 60s per-test timeout, matching the
existing precedent in auth-gateway-anthropic-caching.test.ts.

Fixes #7018

(cherry picked from commit 00e5ec8855eb8ba31c1bdf571bd7c16f2405d679)
2026-07-29 23:09:06 +02:00
can1357 1b4c9d7d1a Merge PR #7015: perf(prompts): streamline tool guidance (@usr-bin-roygbiv) 2026-07-29 23:09:05 +02:00
usr-bin-roygbiv 066a3239f8 fix(prompts): preserve supported tool routes
(cherry picked from commit 0b02fb9219f07e212d7a0f67dacd7747b622ee45)
2026-07-29 23:09:05 +02:00
usr-bin-roygbiv 1e0d352a72 perf(tools): streamline shell guidance
(cherry picked from commit 9039728d89f07852904962685581c752ffebcdc6)
2026-07-29 23:09:05 +02:00
can1357 83294afc0a Merge PR #7013: fix(tui): prevent UUID prefixes rendering color swatches (@roboomp) 2026-07-29 23:09:04 +02:00
can1357 def7c5fadd test(task): exercise bundled budget through subprocess
(cherry picked from commit 6e023cfcebebc429cc020f0f823604eb64eb9c18)
2026-07-29 23:09:03 +02:00
roboomp 4e06b7f1f5 fix(tui): prevented UUID prefixes rendering color swatches
Excluded canonical hash-prefixed UUIDs from prose hex-color matching while preserving standalone 8-digit CSS colors.

Fixes #7002

(cherry picked from commit b423fe6e51bb1d45b88916f885f1b81e1ce54ff0)
2026-07-29 23:09:03 +02:00
can1357 d2d9c81c84 Merge PR #7012: fix(task): let task.softRequestBudget lower bundled subagent budgets (@terrxo) 2026-07-29 23:09:03 +02:00
can1357 adad262ba9 fix(xdev): include truncation marker in summary byte cap
(cherry picked from commit aa2067bf7952191beab85b71002aafe812f544bc)
2026-07-29 23:09:01 +02:00
Nik Divjak c3011fff3c fix(task): let task.softRequestBudget lower bundled subagent budgets
The soft request budget resolved to `SOFT_REQUEST_BUDGET[agent.name] ??
configured`, so the bundled entries for scout and sonic replaced the
configured value outright. Lowering `task.softRequestBudget` to tighten
the guard therefore did nothing for exactly the two agents that spawn
most often: a scout kept its 100-request budget no matter how small the
user set the knob. Only 0 (disable) and raising the value for
non-bundled agents had any effect.

Treat both numbers as upper bounds and take the smaller one. The bundled
entries stay ceilings, so a runaway scout is still stopped at 100 by
default and existing behavior is unchanged for anyone who has not
lowered the setting; a configured 0 still disables the guard entirely.
Resolution moves into `resolveSoftRequestBudget`, which also normalizes
negative and fractional inputs, so the rule is testable without standing
up a subprocess run.

This composes with `task.maxEffort` on a separate axis: effort caps how
hard each request thinks, this caps how many requests a run may spend.

(cherry picked from commit f0db29f8f725f11390b64ca9342300c482ff5c5d)
2026-07-29 23:09:01 +02:00
can1357 4666b1ae41 Merge PR #7010: fix(xdev): bound device summaries in UTF-8 bytes and flag untrusted metadata (@terrxo) 2026-07-29 23:09:01 +02:00
Nik Divjak 630f9e5324 fix(xdev): bound device summaries in UTF-8 bytes and flag untrusted metadata
Catalog summaries of mounted xd:// devices are inlined verbatim into the
system prompt. External devices (MCP servers, plugins) supply that text, and
it was bounded only by character count: a summary of multi-byte script passed
roughly three times the intended budget, and control characters survived into
the prompt where they can forge structure.

Summaries now go through a single sanitize-and-bound step that strips C0/C1
control characters and bounds the result in UTF-8 bytes via the central
truncateHeadBytes helper, so a cut lands on a code point boundary and never
renders a partial code point. The built-in/external distinction is derived
once per entry, and that same boolean both selects the description cap and is
exposed as `dynamic`, so the cap and the flag cannot disagree. The prompt uses
the flag to state that dynamic summaries are untrusted metadata, and the mount
notice says the same for newly appeared devices.

(cherry picked from commit 5989da6235d820bc687779a791e655e6f1b2df0f)
2026-07-29 23:09:00 +02:00
can1357 f62526f111 fix(coding-agent): preserve VCS cache refresh semantics
(cherry picked from commit 3f3e475109deb7b9e7690720827876fc982b5b8d)
2026-07-29 23:08:59 +02:00
can1357 1d41b269f7 Merge PR #6997: perf(coding-agent): keep reftable branch resolution off the render path (@metaphorics) 2026-07-29 23:08:59 +02:00
robomp-bot 65707c7f4c fix(coding-agent): close VCS cache lifecycle gaps
(cherry picked from commit b88851334b07eb1da6743b51b542ea5d3222ccca)
2026-07-29 23:08:58 +02:00
robomp-bot c5b0348150 fix(coding-agent): harden async reftable resolution
(cherry picked from commit e451f1d6f3537d4b58dfe479a6daf8919d169397)
2026-07-29 23:08:58 +02:00
robomp-bot d966b3f8a0 perf(coding-agent): keep reftable branch resolution off the render path
(cherry picked from commit 5724c30ff66e2036ed03a2ce3514a9237a72a657)
2026-07-29 23:08:58 +02:00
can1357 650a8f0faf fix(collab): detach reconciled loader on idle
(cherry picked from commit d675de815644a5b02358fa90d83e5cd5c78141d2)
2026-07-29 23:08:57 +02:00
can1357 872a931795 Merge PR #6996: fix(collab): start the guest loader when the host reports streaming (@metaphorics) 2026-07-29 23:08:57 +02:00
robomp-bot 4557a4bb3d fix(collab): preserve maintenance loaders during state reconciliation
(cherry picked from commit ad611afa4885a71bbf8e8ad6c00328fb0be37d35)
2026-07-29 23:08:56 +02:00
robomp-bot d6dc8f5d14 fix(collab): start the guest loader when the host reports streaming
(cherry picked from commit 0bc0e38d865815b70c848bd00be3dc1fcd228ba4)
2026-07-29 23:08:56 +02:00
can1357 eb8f3e6c2c Merge PR #6993: fix(coding-agent): require web_search_call in codex search (@roboomp) 2026-07-29 23:08:55 +02:00
can1357 94eafa37de Merge PR #6992: fix(collab-web): surface terminal auto_retry_end failures (@metaphorics) 2026-07-29 23:08:54 +02:00
roboomp e5ea31b22c fix(coding-agent): require web_search_call in codex search
GPT-5.6 Responses-Lite models receive tool_choice "auto" (the forced
hosted choice is invalid under the lite shape, #5771/#5772), so the model
may answer without invoking the hosted web_search tool. The codex search
parser accepted any non-empty answer, returning a stale completion with
zero sources as a successful search.

callCodexSearch now tracks response.web_search_call.* events (and
web_search_call output items) and throws CodexNoWebSearchError when none
occurred. The candidate chain treats that error as retryable, advancing
default lite models to a non-lite model that forces web_search, and
surfaces a clear failure when the model was explicitly configured.

Fixes #6988

(cherry picked from commit a276cd0b3df1d0d041faf0a63fabcbb884e36a91)
2026-07-29 23:08:54 +02:00
can1357 68192c8d8e Merge PR #6989: fix(providers): fixed novita key validation for restricted accounts (@quantverse) 2026-07-29 23:08:53 +02:00
robomp-bot 9db6fb770e docs(collab-web): add PR attribution
(cherry picked from commit c059d6fe0f3dc96ef6719cd83e084db75ad82f19)
2026-07-29 23:08:53 +02:00
robomp-bot a54b11f4c3 fix(collab-web): surface terminal auto_retry_end failures
(cherry picked from commit 6a6c4014158d9636ed0e030837633ad313c1aa5a)
2026-07-29 23:08:53 +02:00
can1357 9f80d24e20 fix(ai): preserve pre-stream provider error provenance
(cherry picked from commit d3c66195866de8886d05fc8002533160fa8f2767)
2026-07-29 23:08:52 +02:00
Karel Vávra 2aca6e5082 fix(providers): fixed novita key validation for restricted accounts
(cherry picked from commit cccd8b7c6b0f36e06de088be062b2f48bd7ffda2)
2026-07-29 23:08:52 +02:00
can1357 832d4f1506 Merge PR #6987: fix(coding-agent): treat streamed visible text as replay-unsafe in turn recovery (@metaphorics) 2026-07-29 23:08:51 +02:00