Commit Graph

1762 Commits

Author SHA1 Message Date
can1357 db2ce42e8e Merge PR #8753: fix(coding-agent): classify destructive rm with long options as critical (@ghosty-11) 2026-08-19 01:36:56 +02:00
can1357 9913c58ec1 Merge branch 'main' into pr-8052 2026-08-17 11:00:58 +03:00
ghosty93 2179f1c987 fix(coding-agent): match interleaved options in the destructive rm pattern
Review noted that the option whitelist still let generic short flags
escape: `rm -rf -v /` and `rm -rf -i /` were not classified critical,
which is the same separator class the change set out to close.

Pin only the recursive/force flag and skip any other options on either
side of it, which also removes the need to enumerate long options. An
absolute target is still required, so `rm -rf -- ./build`,
`rm --recursive --force ./dist` and `rm -v /tmp/scratch` remain benign
and are asserted.
2026-08-16 23:03:01 +03:00
ghosty93 ffb816fe7f fix(coding-agent): classify destructive rm with long options as critical
`CRITICAL_BASH_PATTERNS` required the target to follow one short flag
cluster directly, so anything in between escaped the check:

    rm -rf /                      matched
    rm -rf -- /                   missed
    rm --recursive --force /      missed
    rm -rf --no-preserve-root /   missed
    rm --no-preserve-root -rf /   missed

The last two matter most. GNU coreutils already refuses `rm -rf /` with
"it is dangerous to operate recursively on '/'" and names
`--no-preserve-root` as the override, so the pattern matched the form
that fails safe and missed the form that does not.

Repeat the option separator instead of assuming the path follows one
cluster, and treat `--no-preserve-root` as critical wherever it appears.
Absolute targets are still required for the first pattern, so
`rm -rf -- ./build` and `rm --recursive --force ./dist` stay benign;
both are asserted in the test.

PR #5270 reported the `--` and long-option forms in July and was closed
unmerged by the contributor-vouch bot rather than on merit. This keeps
its cases, credits them in the tests, and adds the `--no-preserve-root`
forms that patch did not cover.
2026-08-16 22:41:44 +03:00
can1357 02cd22dc9b feat: added live tracking and stale status warnings for agent activity snapshots
- Added live tracking and stale status warnings for agent activity snapshots.
- Fixed text wrapping with ANSI escape sequences to defer style open sequences after whitespace.
- Added VirtualRenderScheduler for deterministic virtual-clock rendering tests.
2026-08-16 10:18:56 +03:00
can1357 8fdb6a4197 fix(edit): dropped compact seen-line retry tokens (#8461)
Reverted the retry-token continuation flow (merge 34628528bf and prompt
follow-up 446e745bf4): seen-line rejections resend the full patch again.
2026-08-16 07:58:55 +02:00
can1357 b200f938b7 fix(browser): bypassed proxies for relay probes 2026-08-16 02:43:33 +02:00
can1357 f95e523462 Merge PR #8569: fix(browser): probe CDP endpoints over raw TCP to bypass HTTP_PROXY (@roboomp) 2026-08-16 02:43:33 +02:00
can1357 ca60ca0019 Merge PR #8624: fix(browser): suppress blank shared startup window (@roboomp) 2026-08-16 02:43:32 +02:00
can1357 5272039e33 Merge PR #8636: fix(hub): prevent stale agent refs from blocking wait (@roboomp) 2026-08-16 02:43:31 +02:00
can1357 dba8cfcd13 Merge PR #8677: fix(browser): prefer Chrome for Testing on macOS headless launch (@roboomp) 2026-08-16 02:43:30 +02:00
can1357 a5284fb381 fix(ask): preserved empty multi-select answers 2026-08-16 02:13:40 +02:00
can1357 f83111c8d4 Merge PR #8265: fix(tui): multi-select ask dialog submits on Enter instead of dead-ending (@zhang17-24) 2026-08-16 02:13:40 +02:00
can1357 4a37b7cc09 docs(browser): qualified spawned kill behavior 2026-08-16 02:13:39 +02:00
can1357 92ce5db781 Merge PR #8651: fix(browser): clarify close release semantics (@koopmannleon19977-cmyk) 2026-08-16 02:13:38 +02:00
can1357 34628528bf Merge PR #8461: fix(edit): add compact seen-line retries (@Kigbnajd) 2026-08-16 02:13:38 +02:00
Harsha Vardhan ba5885880e fix(coding-agent): preserved mixed-case plugin tool names on refresh 2026-08-16 02:13:38 +02:00
can1357 958a88b25a Merge PR #8503: fix(agent): optimize checkpoint/rewind prompt rendering (@szavadsky) 2026-08-16 02:03:16 +02:00
roboomp d9eb0586bd fix(browser): prefer Chrome for Testing on macOS headless launch
On macOS the shared headless browser daemon launched from the system Google Chrome app bundle, running as a com.google.Chrome instance. macOS LaunchServices could then deliver the user's open-URL Apple Events to the daemon instead of their own Chrome, silently swallowing link clicks.

ensureChromiumExecutable now prefers the isolated Chrome for Testing binary (com.google.chrome.for.testing) on macOS, falling back to system Chrome only when Chrome for Testing cannot be obtained. Other platforms keep the download-avoiding system Chrome preference.

Fixes #8673
2026-08-15 19:38:25 +00:00
Aleksandr Khaustov 006c5371ea perf(coding-agent): bound completed diff rendering 2026-08-15 20:39:36 +04:00
koopmannleon19977-cmyk 7b6029277a fix(browser): clarify close release semantics 2026-08-15 15:11:49 +02:00
roboomp e8b7024b12 fix(hub): prevented stale agent refs from blocking wait
Mirrored registry status from pre-wire session run-state transitions and required live session corroboration before a peer can sustain bare hub waits.

Fixes #8634
2026-08-15 10:19:05 +00:00
roboomp d6dcfed844 fix(browser): suppressed blank shared startup window
Added Chromium no-startup-window to the broker-owned browser launch so no unowned foreground page survives session tab cleanup.

Covered the resolved Chromium argv and documented the Windows regression.

Fixes #8615
2026-08-15 06:49:30 +00:00
roboomp e287a8c6e2 fix(browser): probe CDP endpoints over raw TCP to bypass HTTP_PROXY
The shared-browser CDP liveness probes (probeEndpoint, waitForCdp, probeCdpAt) used a bare fetch() against the loopback DevTools endpoint. Bun's fetch honors HTTP_PROXY/HTTPS_PROXY and forwards even 127.0.0.1 requests to the proxy unless NO_PROXY covers them, so a local proxy (e.g. Clash) that 502s internal addresses made a healthy daemon look dead and ensureSharedBrowser tore it down.

Replace the three probes with probeCdpStatus(), a raw-TCP HTTP/1.1 GET that never routes through a proxy and resolves to the response status (or null on unreachable/aborted/timeout).

Fixes #8567
2026-08-14 16:29:41 +00:00
Larry Gordon 2c5a9c43aa test(tools): pinned the exclusive-create guard against the fallback seam
Review raised that `apply_patch`'s non-overwrite contract for `create` and
a rename destination is decided with `Bun.file(dst).exists()`, which
reports `false` when the parent hides the target's metadata rather than
distinguishing "absent" from "unknown" — so a privileged handler could
be asked to write over a protected file it was told not to touch.

Reproduced all three shapes: no handler is consulted in any of them. A
hidden-metadata destination is refused by the path resolver, because the
same denied `lstat` that fools the existence check also leaves the final
component unproven, and an unverifiable destination is never brokered. A
destination that is a symlink onto a protected file is caught earlier —
`exists()` follows the link and reports `true`. A plainly visible
existing file is caught by the same check.

So the contract holds, but it holds through two independent guards in two
files. Pinned that with a regression test asserting the premise (the
existence check cannot see the file), that no handler is consulted, and
that the file is intact; deleting the resolver's symlink proof makes it
fail. Recorded the coupling in the module header too, since relaxing the
refusal to broker unverifiable paths would silently break exclusivity
and needs an explicit intent field first.
2026-08-14 08:55:45 -07:00
Larry Gordon 6ad935d093 fix(extensions): resolved brokered file paths and named their session
Review on #8052 found three problems in the write/delete fallback seam.

A symlink guard that only `lstat`'d the final component let the same
escape through a symlinked ancestor: `ws/link/file` under a
`ws/link -> /outside` link reached a handler as a lexically innocent
path, so a helper's prefix allowlist passed while the bytes landed
outside. Refusing every symlinked component is not available, since
`/var` and `/tmp` are links on macOS and every path under `os.tmpdir()`
traverses one. So `req.dst` is now the path the failed syscall itself
acted on, via `resolveSyscallTarget` beside `confineToWorkspace`: fully
resolved for a write, resolved up to the last component for a delete,
because `unlink` removes a link rather than following it. Resolving also
closes the TOCTOU window a refusal left open. A path that cannot be
canonicalized — a dangling final link, or an ancestor whose own
resolution is denied — is not brokered at all.

Per-handler throw isolation lived outside the per-extension trampoline,
so a throw from one extension's first handler advanced the registry to
the next extension and skipped every later handler that one had
registered. Each handler call is now wrapped individually.

The registry stays process-wide. A subagent spawned with restricted
tools gets `preloadedExtensionPaths: []` and loads no extensions of its
own, so scoping resolution to the originating session would turn its
brokered writes into hard failures, and a host that registers once in
its top-level session expects its subagents covered. The request names
its origin instead: `req.sessionId` against the handler's own
`ctx.sessionManager.getSessionId()`, entered by `ExtensionToolWrapper`,
which `sdk.ts` already puts around the whole tool registry whenever a
runner exists. Both registries are also walked over a snapshot, so a
concurrent session shutdown cannot make another session's walk skip
whichever handler shifted into the hole.

Unit tests go 30 -> 35 and integration 6 -> 7, covering the resolved
target, a symlinked ancestor on both seams, a dangling link, a target
whose own metadata is behind the boundary, same-extension handler
ordering after a throw, and `req.sessionId` matching the handler's own
session end to end.
2026-08-14 08:55:44 -07:00
Larry Gordon 6e4334c003 feat(extensions): broker denied file writes and deletes
A host that runs omp inside an OS sandbox can grant a path mid-session but cannot
apply that grant to an in-process write: `write` and `edit` do their I/O in the
agent process, so an out-of-workspace write fails and stays failed until the
process restarts under a wider profile.

Nothing available today closes that. A `tool_call` handler can block and a
`tool_result` handler can rewrite content, but neither can re-run a tool.
`ctx.invokeTool` delegates execution, but the delegated native tool runs in the
same process under the same restrictions. And the failure lands AT the write
syscall - after the tool computed the final content, before it returned - so the
bytes are gone with the throw, and reconstructing them means reimplementing
`edit`'s hashline protocol and the snapshot bookkeeping.

The byte-write that `write`, `edit` and `apply_patch` perform on an ordinary file
path already funnels through one two-line primitive
(`file ? file.write(content) : Bun.write(dst, content)`) at four call sites.
Routing that primitive through `writeFileWithFallback` gives an embedder a single
seam to intercept a permission-denied write: the native tool still records its own
snapshot under the real destination path once a handler reports success, so a
follow-up hashline `edit` on that path keeps working.

Only a permission boundary diverts - `EPERM`/`EACCES`/`EROFS`. Two cases needed
more than that:

- `Bun.write` creates missing parents itself, and when that `mkdir` is the denied
  operation it reports the subsequent `open()`'s `ENOENT` instead of the denial -
  making a sandboxed write into a new out-of-tree directory indistinguishable from
  an ordinary bad path. Redoing the `mkdir` explicitly recovers the real errno, and
  because it runs through the same enforcement path as the write it also sees
  kernel-level denials (Seatbelt, LSM) that a `stat`/`access` probe reports as
  writable. If no handler takes the write, the original `ENOENT` is still what
  propagates, with the recovered denial attached as its `cause`.
- `apply_patch` creates the parent as a separate step before writing, so a denial
  there threw before the seam was ever reached. That `mkdir` now tolerates a
  permission denial when a fallback is registered, letting the write report it.

A denial reached through a SYMLINK is never brokered. The in-process write follows
the link, so the kernel denied the link's TARGET, but a handler receives `dst` and
a privileged helper opening it with ordinary follow semantics would land the bytes
wherever the link points. That also defeats the obvious helper-side defence, since
a prefix allowlist passes when the link sits inside the allowed root while its
target does not. omp cannot vouch for the destination, so it refuses rather than
hand the ambiguity to a privileged writer - the same answer `confineToWorkspace`
already gives an unresolvable link.

Removing a file is a different primitive, so it gets its own seam
(`deleteFileWithFallback`, `registerFileDeleteFallback`) covering `edit`'s `REM`,
a hashline `MV`'s source unlink, and `apply_patch`'s delete op. Two differences
from the write path: `ENOENT` is never diverted, since nothing is created on the
way to an unlink and `REM` needs it to become a not-found error; and the seam
refuses a target it can confirm is a directory, because `unlink` on a directory
reports `EPERM` on Darwin and is otherwise indistinguishable from a sandbox
denial. That check cannot always run - a sandbox denying the unlink usually denies
the target's metadata too - so the request carries `confirmedFile`, and a handler
is required to use a plain unlink rather than resolving or recursing.

The two registries are deliberately separate. A write handler brokers `content` to
`dst`, so a delete request reaching it with no content invites brokering an empty
write and truncating the file it was asked to remove.

With nothing registered both seams are inert: the primitives run exactly as
before, a failure rethrows from the same place, and no extra syscalls are
performed.

Scope is deliberately narrow. Archive-member and SQLite writes are unchanged -
neither is a byte-write to a path, so brokering them needs a different request
shape - along with the ACP bridge's `writeTextFile`, the `lsp` tool's own
workspace-edit and formatter writes, and directory removal.
2026-08-14 08:52:34 -07:00
can1357 a3c15d2dec feat(coding-agent/tools): implemented pdf page screenshot rendering
- Add `renderPdfPageScreenshot` to render PDF pages via headless Chromium.
- Update `ReadTool` to intercept legacy PDF image paths and return page screenshots.
- Ensure daemon clients are closed on read command exit.
2026-08-14 14:37:56 +02:00
can1357 04fab5ecb4 feat: replaced custom mupdf wasm pipeline with native function
- Replaced the custom MuPDF-WASM PDF extraction and rendering pipeline with the new `pdfToMarkdown` native function from `@oh-my-pi/pi-natives`.
- Removed legacy MuPDF extraction modules, WASM embedding scripts, and PDF image extraction tools.
- Added OCR warnings and browser/text redirection for unsupported PDF image reads.
- Updated native package definitions, documentation, and test suites for the new PDF inspection capability.
2026-08-14 14:08:28 +02:00
Slava Zavadsky 24779714e6 fix(agent): optimize checkpoint/rewind prompt rendering
Move the rewind instruction out of the permanent checkpoint tool result into a transient post-checkpoint notice that is branch-cut away on rewind; rewrite the rewind-report prompt forward-looking (no negation); collapse the rewind tool description to one line. Closes #8499.
2026-08-14 01:11:05 -04:00
can1357 0d6a7146a3 feat(coding-agent): supported allSettled and any promise combinators in browser scope
- Added `allSettled` and `any` to tracked promise combinators in run scope.
- Updated browser cancellation tests to cover new promise combinators.
2026-08-14 00:11:04 +02:00
roboomp a02f88994b fix(tools): preserve workspace-relative path in read hashline headers
formatReadHashlineHeader collapsed every relative in-workspace path to its
basename, so reading a nested file (e.g. src/settings.json) emitted
[settings.json#tag]. When a same-basename file existed at the session cwd,
a verbatim follow-up edit resolved against the cwd file; Patcher.prepare only
runs snapshot-tag path recovery when the authored path is missing, so the
valid edit was deterministically rejected with "hash is not from this
session". Keep the workspace-relative path, which names the file uniquely and
stays directly resolvable against cwd. Out-of-workspace absolute paths remain
shortened; root-level files are unchanged.

Fixes #8482
2026-08-14 00:04:59 +02:00
Kigbnajd 5e903cbb79 fix(edit): address seen-line retry review 2026-08-13 22:09:50 +02:00
roboomp cf1ff14f5f fix(coding-agent): confine browser executable probe to linux
The executable version probe added in ecb22957 ("validate Linux browser
executables") replaced the file-only check in resolveSystemChromium with
isChromiumExecutable, which spawns the candidate `--version` for every
platform. On Windows chrome.exe is a GUI-subsystem binary: `--version`
does not print to a detached stdout and can hand off to a running
instance, opening/activating the user's normal browser window, after
which the probe rejects the candidate and falls back to cached Chrome
for Testing.

Gate the spawn probe on process.platform === "linux" (its intended
platform, where non-Chromium PATH wrappers are the real risk) and trust
the executable-file check on Windows and macOS.

Fixes #8445
2026-08-13 16:28:57 +00:00
can1357 4658662c35 fix(write): keep streaming preview append checks bounded 2026-08-13 01:14:46 +02:00
can1357 9c311d7a7b Merge PR #8040: fix(tui,utils): remove O(N²) hot paths when streaming long tool-call args (@AmecoCoding) 2026-08-13 01:14:45 +02:00
left-to-right b245be11c5 fix(ask): address review comments on multi-select Enter submit
- Multi-question dialogs now advance on Enter in multi-select mode
  instead of submitting every question at once (roboomp blocking)
- Ask tool accepts an empty multi-select submission as a "select none"
  answer instead of aborting as a cancellation (codex P2)
- Footer hint reflects advance vs submit for multi-question dialogs
- Move the #8252 changelog entry to Unreleased (codex P2)

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-12 22:58:02 +08:00
can1357 e49f8f4fb2 test(coding-agent): added shared auth storage and model registry to tests
- Added shared auth storage and model registry for concurrent and eager compaction tests.
- Replaced per-test auth storage creation and cleanup routines with shared lifecycle management.
- Removed local auth storage variables and individual cleanup hooks from test harness instances.
2026-08-12 03:25:31 +02:00
can1357 21a7693dd7 fix(hashline): prevented exposing terminal newline as an addressable row
- Added `splitAddressableFileLines` to strip terminal newlines from line addressability without removing genuine blank lines.
- Updated coding-agent read tool context parsing to use addressable file lines.
2026-08-12 03:22:01 +02:00
can1357 63b39b7040 feat(coding-agent/utils): expanded tar extraction and validation logic
- Added archive and member size assertion limits along with path byte-length checks for PAX and GNU metadata targets.
- Added support for global PAX attributes, old-GNU name records, and signed GNU base-256 numeric header fields.
- Updated archive reading in WriteTool to accept a filesystem path instead of buffered bytes.
- Added test coverage for signed GNU base-256 values, PAX extensions, overlong path rejections, and oversized archives.
2026-08-12 03:04:17 +02:00
can1357 94a76a8f27 feat: hardened tar parser and optimize prompt handling
- Bound PAX sparse record memory overhead by caching sparse markers and specific keys.
- Update system prompt phrasing and tests for tool inventory and date displays.
2026-08-12 03:04:07 +02:00
can1357 a4d8860a6c feat: added google reasoning controls mcp stream resumption and tar support
- Added Google provider thinking configuration parameters and force-reasoning-off controls.
- Implemented MCP SSE stream resumption using Last-Event-ID and `SSEResumeError`.
- Added support for TAR old-GNU sparse extension blocks, path length checks, and archive entry overrides.
- Restricted external thinking support to specific models and added semver fallback parsing.
2026-08-12 02:32:45 +02:00
can1357 19c0afcc0d feat: implemented external thinking flags and transport reasoning controls
- Added the `--external-thinking` CLI flag alongside model capability checks to gate external thinking tool availability.
- Updated Anthropic and Google transports to honor `forceReasoningOff` for native thinking-off controls.
- Renamed the `thoughts` property and parameter to `notes` across think fixtures, tools, and tests.
- Updated system prompt instructions and test suites to verify transport-specific thinking and tool activation.
2026-08-12 02:23:17 +02:00
can1357 10fd42289c feat: introduced external thinking support and private scratchpad think tool
- Added support for external thinking and forced reasoning disablement across AI provider options and request transformers.
- Implemented the private scratchpad think tool along with its renderer, system prompt rules, and schema configuration.
- Updated agent session management and SDK tools to support dynamic runtime activation of the think tool via the externalThinking setting.
- Added comprehensive unit tests covering reasoning fallbacks, tool activation, and rendering behavior.
2026-08-11 20:39:57 +02:00
can1357 b524dfe36f refactor: standardized outbound User-Agent headers on shared utility constant
- Define a centralized `USER_AGENT` constant in `@oh-my-pi/pi-utils` formatted as `omp/<version>`.
- Replace hardcoded and platform-specific user agent strings across AI providers, catalog scrapers, tools, and search providers with the unified `USER_AGENT`.
- Add unit tests for update-cli binary release distribution gating.
2026-08-11 15:38:32 +02:00
can1357 8fed93632a refactor(ai): rebranded openrouter identifiers and user agent to omp
- Updated user agent and openrouter titles in packages/ai from Oh-My-Pi to omp.
- Integrated getOpenRouterHeaders into image generation tool requests in packages/coding-agent.
- Updated provider documentation and test assertions to reflect the rebrand.
2026-08-11 15:28:28 +02:00
can1357 64baa7c1bd chore(format): applied biome formatting and removed dead code from merged prs 2026-08-11 15:14:15 +02:00
can1357 19edecaa48 fix: kept out-of-order todo completions visible 2026-08-11 15:06:12 +02:00
can1357 f6d4f1e38b Merge PR #7965: fix(coding-agent): surface todo progress in the collapsed panel (@z80dev) 2026-08-11 15:06:12 +02:00
can1357 8504e4865f Merge PR #7945: fix(coding-agent): resolve xd:// device dispatches against device user policy first (@re2zero) 2026-08-11 15:06:11 +02:00