Commit Graph

80 Commits

Author SHA1 Message Date
Larry Gordon 6ad935d093 fix(extensions): resolved brokered file paths and named their session
Review on #8052 found three problems in the write/delete fallback seam.

A symlink guard that only `lstat`'d the final component let the same
escape through a symlinked ancestor: `ws/link/file` under a
`ws/link -> /outside` link reached a handler as a lexically innocent
path, so a helper's prefix allowlist passed while the bytes landed
outside. Refusing every symlinked component is not available, since
`/var` and `/tmp` are links on macOS and every path under `os.tmpdir()`
traverses one. So `req.dst` is now the path the failed syscall itself
acted on, via `resolveSyscallTarget` beside `confineToWorkspace`: fully
resolved for a write, resolved up to the last component for a delete,
because `unlink` removes a link rather than following it. Resolving also
closes the TOCTOU window a refusal left open. A path that cannot be
canonicalized — a dangling final link, or an ancestor whose own
resolution is denied — is not brokered at all.

Per-handler throw isolation lived outside the per-extension trampoline,
so a throw from one extension's first handler advanced the registry to
the next extension and skipped every later handler that one had
registered. Each handler call is now wrapped individually.

The registry stays process-wide. A subagent spawned with restricted
tools gets `preloadedExtensionPaths: []` and loads no extensions of its
own, so scoping resolution to the originating session would turn its
brokered writes into hard failures, and a host that registers once in
its top-level session expects its subagents covered. The request names
its origin instead: `req.sessionId` against the handler's own
`ctx.sessionManager.getSessionId()`, entered by `ExtensionToolWrapper`,
which `sdk.ts` already puts around the whole tool registry whenever a
runner exists. Both registries are also walked over a snapshot, so a
concurrent session shutdown cannot make another session's walk skip
whichever handler shifted into the hole.

Unit tests go 30 -> 35 and integration 6 -> 7, covering the resolved
target, a symlinked ancestor on both seams, a dangling link, a target
whose own metadata is behind the boundary, same-extension handler
ordering after a throw, and `req.sessionId` matching the handler's own
session end to end.
2026-08-14 08:55:44 -07:00
can1357 c01d18eb57 Merge PR #7657: fix(read): split semicolon-delimited internal URLs (@revofusion) 2026-08-05 21:50:25 +02:00
Revofusion 84c4c58063 fix(read): preserve literal routed URL semicolons 2026-08-04 15:53:58 -06:00
Revofusion 3d6ecf9237 fix(read): split semicolon-delimited internal URLs 2026-08-04 15:41:45 -06:00
roboomp 262ce960fc fix(coding-agent): split semicolon path lists that trip ENAMETOOLONG
The grep/glob multipath detector probed the raw joined string with lstat
and only split when the probe reported "missing" (ENOENT/ENOTDIR).
ENAMETOOLONG was classified as "unknown", which suppressed the split, so
a semicolon-delimited path list long enough to exceed NAME_MAX or
PATH_MAX collapsed to one literal path and failed with
"Path not found: <whole list>" even though every entry existed.

Classify ENAMETOOLONG as "missing" in probeLiteralPathExists and
delimitedPathPartResolves (a too-long string can never name a real
single entry), and broaden glob's stat catch so the raw errno never
reaches the caller.

Fixes #7597
2026-08-04 06:07:42 +00:00
Kyle McCleary dba303e2e0 Merge remote-tracking branch 'origin/main' into feat/security-native 2026-07-29 20:31:08 -07:00
Kyle McCleary 089a9963f8 feat(security): OMP-native security subsystem (planner handoff) 2026-07-29 18:47:51 -07:00
Diogo Soares Rodrigues 821fe75f5d fix(cursor): close download hardlink escape, MCP mime and read range
Hard link escape: a hardlink inside the workspace is a regular file
that passes containment AND `O_NOFOLLOW` while sharing its inode with
a file anywhere else, so truncating it clobbers that file. Proven
before the fix. The open now drops `O_TRUNC`, checks `nlink`/regular
on the OPEN handle, and truncates only after - the pattern
`autolearn/managed-skills.ts` already uses. `O_NOFOLLOW` covers the
final component only; the parent-swap window is documented, not
claimed shut.

MCP resource discovery: `getServerResources` is async and awaits
`ensureServerResources`, so a frame arriving while a server's catalog
still loads no longer reads the empty cache and reports "advertises
nothing" - a lie the model cannot distinguish from the truth.

Mixed-content reads: the mime type came from `contents[0]` while the
payload came from whichever item supplied it, so an image blob
followed by a text note sent the text as `image/png`.

Ranged `pi_read`: a plain `:N+K` selector pads one leading and three
trailing context lines, so offset 5/limit 20 handed Cursor lines 4-27.
Ranged reads compose `:raw:N+K`, verified against a real `ReadTool`.
The wire result is an opaque string, so the gutter `raw` drops is not
part of the contract.

(cherry picked from commit 679785aa6b3243ea39b26abf4dda9435960019b1)
2026-07-30 01:42:30 +02:00
Diogo Soares Rodrigues 91b703b6af fix(cursor): resolve symlinks when confining resource downloads
A lexical containment check is not containment. `out/config` is
relative and `..`-free, so it passed - while a `ws/out -> /elsewhere`
link inside the workspace sent the write straight out. Proven before
the fix: the download landed in the link's target.

Containment now realpaths three things: the target when it exists, the
immediate link destination when it is a dangling symlink (a write still
follows it), and otherwise the deepest existing ancestor with the
not-yet-created segments re-applied. Each branch has a regression, and
all three fail the suite when individually reverted.

Also moves this branch's ai/catalog changelog entries back under
[Unreleased]; two commits had re-landed them inside the released
[17.1.5] section, which left `packages/ai/CHANGELOG.md` with two.
All three released sections are now byte-identical to upstream/main.

(cherry picked from commit e3ed4035ab8a1781c49a68c1fbe92c88bec3aa25)
2026-07-30 01:42:29 +02:00
Diogo Soares Rodrigues 7a944f1baa fix(cursor): confine MCP resource downloads to the workspace
`download_path` is workspace-relative by contract, but it arrives from
the server and `resolveToCwd` deliberately honors absolute paths, `~`,
and `..` - correct for a path a user typed, a write-anywhere primitive
for one a remote peer supplied. `/etc/cron.d/x` or `../../escape` would
have been written wherever the process can reach.

`confineToWorkspace` accepts only a non-empty relative path resolving
under the live cwd, and the download refuses anything else. The refusal
throws inside the dispatch's existing try, so it reaches the model as a
`ReadMcpResourceError` rather than a silent success or a crash.

(cherry picked from commit 963cfee21a56576033ec115db745bb18ab0a8d06)
2026-07-30 01:42:29 +02:00
roboomp 662e4392da fix(edit): aligned relative path resolution
- Shared unique workspace suffix resolution between read and direct edit modes.

- Preserved create destinations and ambiguous-path failures while resolving existing update targets.

- Added direct replace, patch, and apply_patch regression coverage.

Fixes #6359
2026-07-23 19:14:09 +00:00
roboomp dc7238f5a4 fix(read): supported history URL selectors
Added history to selector-aware internal URL schemes so read paging resolves the agent id before applying transcript ranges.

Fixes #5806
2026-07-17 07:46:37 +00:00
roboomp f512d99614 fix(tool): strip leading colon before Windows path shapes
expandPath's leading-colon strip only fired before POSIX prefixes
(`/`, `~/`, `./`, `../`), so Windows-mangled inputs like `:C:\repo\file`
or `:.\src` slipped through and path.resolve treated them as relative
children of cwd. The omp grep subcommand is the Windows grep path, so it
hit the common Windows form of the same bug.

Broaden the lookahead to admit `\` separators, `.\`/`..\` relatives, and
drive-letter absolutes (`[A-Za-z]:`). Add expandPath regression tests
for the Windows forms and the bare-token non-strip cases.

Fixes #5624
2026-07-15 22:25:44 +00:00
roboomp e0e24efaf6 fix(tools): strip stray leading colon from tool paths
Some models intermittently prefix an otherwise-valid path with a leading
`:` (e.g. `:/abs/path`, `:../rel`). read/edit/grep hard-failed because
resolveToCwd left the colon intact and resolution missed the real file.
The #4618 literal-preferring probe cannot recover it: the literal
`:/abs/path` does not exist on disk, so the peel proceeds to an empty
path.

Strip the mangled prefix in expandPath — the shared resolution funnel for
read (resolveReadPath), grep (resolveToolSearchScope), and edit
(resolvePlanPath) — mirroring the existing @-prefix normalization. The
lookahead only fires before `/`, `~/`, `./`, or `../`, so selector-shaped
tokens like `:raw` are untouched.

Fixes #5508
2026-07-14 20:41:45 +00:00
roboomp a2e055fa9c fix(tools): closed two open literal-wins gaps flagged by codex
Two Codex bot findings from earlier PR reviews were still open.

1. local:// URL selector shadow (read.ts): the local:// branch resolved
   `local://foo:1-2` and rewrote readPath to `${localFile.path}:${sel}`,
   then let splitPathAndSelPreferringLiteral run on the synthesized
   string. A sibling literal `${localFile.path}:${sel}` file would win
   over the intended URL selector semantics. The branch now promotes the
   URL selector into the explicit-selector state and sets
   readPath = localFile.path, so downstream literal-preferring routing
   never re-splits the concatenation.

2. Delimited expansion before literal probe (path-utils.ts): grep called
   expandDelimitedPathEntries before parsePathSpecs, and
   splitDelimitedPathEntry only checked whether the peeled base of the
   entry resolved. A real POSIX file whose name contained a delimiter
   plus a selector-shaped tail (a;b:1-2) got split into ["a", "b:1-2"]
   and never reached the literal-preferring probe. splitDelimitedPathEntry
   now short-circuits on probeLiteralPathExists — "missing" is the only
   outcome that lets delimiter expansion run.

Added regressions: `read local://notes.md:1-2` still slices the base file
when a sibling `notes.md:1-2` literal exists, and grep searches a real
`a;b:1-2` file without semicolon-splitting.
2026-07-05 19:24:21 +00:00
roboomp 6c8e7625a2 fix(tools): tightened literal-path probe against stat ambiguity
resolveExistingReadPath treated any stat failure other than ENOENT/ENOTDIR as
"exists" and any other resolved path was considered a hit. That silently
reinterpreted a real literal path such as test:1-2 as test plus selector 1-2
whenever the raw path was a dangling symlink, sat under an unreadable parent,
or hit a transient I/O error.

The new probeLiteralPathExists returns "exists" / "missing" / "unknown" from
an lstat probe. splitPathAndSelPreferringLiteral now falls back to the strict
selector split only on "missing"; both "exists" and "unknown" keep the raw
path, so an unreachable literal is never reinterpreted. Grep and read use
the same probe: the explicit selector branch keeps the literal path when
existence is uncertain, and only a definitive ENOENT/ENOTDIR lets structured
archive/sqlite/pdf dispatch take over.

Added regressions covering probeLiteralPathExists exists/missing/dangling-
symlink cases and splitPathAndSelPreferringLiteral over a dangling symlink.
2026-07-05 18:17:59 +00:00
roboomp ff3b0c795c fix(tools): added explicit selector fields for read and grep
The literal-path stat fallback made selector-shaped filenames accessible, but it did not give callers a deterministic way to read or grep a range from a literal filename such as test:1-2. Encoding that as test:1-2:1-2 remained recursively ambiguous if a longer literal file later appeared.

Read now accepts an optional selector field that is parsed independently from path. When selector is present, path is treated as the exact path first, so { path: "test:1-2", selector: "1-2" } always means lines 1-2 from the literal file test:1-2. Inline :<sel> remains supported for compatibility.

Grep now accepts an optional line-range selector field with the same literal-path behavior. Explicit selectors bypass path suffix peeling, while archive/internal/URL routing still handles non-literal structured paths.

Updated read/grep tool prompts and added deterministic regressions proving that a longer literal file like test:1-2:5-6 or test:1-2:2-2 does not change the meaning of { path: "test:1-2", selector: ... }.
2026-07-05 18:09:29 +00:00
roboomp c493d12f95 fix(tools): preserved escaped literal selector-shaped paths
splitPathAndSelPreferringLiteral only statted resolveToCwd(rawPath), so shell-escaped paths such as dir/a\ b:1-2 missed the existing dir/a b:1-2 file and fell back to the strict selector peel. That let read target dir/a\ b with a range instead of the literal filename.

The helper now probes resolveReadPath(rawPath, cwd), reusing the read path resolver's existing escaped-space and filesystem variant normalization before deciding whether the literal file exists.

Grep also stores the resolved filesystem path for literal matches so the later search-scope parser does not reinterpret backslashes as path separators. Regression coverage now includes helper, read, and grep cases for dir/a\ b:1-2.
2026-07-05 17:47:06 +00:00
roboomp c8df93ca31 fix(tools): preferred literal filesystem match over trailing :selector peel for read and grep
splitPathAndSel unconditionally peels a trailing :<sel> chunk whenever it
matches the read-tool selector grammar (raw, conflicts, N-M, N+K, ...). On
POSIX, filenames may legitimately contain colons, so a real file named
test:1-2 or log:raw was shredded to test/log before either read.ts or
grep.parsePathSpecs stated anything and both surfaced "Path not found".

Added splitPathAndSelPreferringLiteral(rawPath, cwd) alongside the strict
splitter: it only overrides the peel when fs.stat succeeds against the raw
path. Read (execute) and grep (parsePathSpecs) call the async variant for
non-URL paths; internal-URL splitting stays unchanged. Regression covers
splitter fallbacks, read/grep behavior on literal-colon files, and that
:1-2 selectors still work when the base file is the only real match.

Fixes #4618
2026-07-05 17:23:12 +00:00
roboomp 2b8c8cadfb fix(read): kept raw artifact chunks verbatim and broadened path-only resolution
Skipped the workflow notice on raw selectors so bounded raw reads stay byte-for-byte, and taught resolveToolSearchScope to request pathOnly resolution so ast_grep/ast_edit scope-only calls no longer trip the inline-content cap on large artifacts.

Fixes #4482
2026-07-03 23:36:57 +00:00
can1357 e73a25489c feat(coding-agent/tools): migrated path input from array to semicolon-delimited string
- Changed the `path` property from an array of strings to a single semicolon-delimited string across tool definitions and tests.
- Updated validation error messages to reflect the new `path` input format.
- Adjusted all relevant test cases to provide path targets as semicolon-separated strings.
2026-07-02 17:48:46 +02:00
can1357 95b91c7f73 feat(coding-agent/tools)!: replaced paths arrays with path strings
- Replaced `grep`, `glob`, and `ast_grep` `paths` inputs with optional single `path` strings while preserving default workspace-root behavior.
- Added shared `toPathList` normalization for legacy arrays and JSON-encoded arrays across tool execution and TUI renderers.
- Updated prompts, fixtures, shims, transcript summaries, and tests to send and display the new `path` argument.
- Updated collab-web search tool cards to read `path` while falling back to legacy `paths` for historical transcripts.
- Recorded the contiguous coding-agent changelog run for the tool-path breaking change and adjacent TTS entries.
2026-07-02 08:30:33 +02:00
can1357 978b950804 fix(coding-agent): resolved path resolution and fetch errors for fuzzy urls
- Fixed grep and ast-grep tools rejecting fuzzy url-shaped paths like schemeless www. or collapsed-scheme spellings.
- Applied the extra-CA wrapper to the model registry default fetch to respect the NODE_EXTRA_CA_CERTS environment variable.
- Moved isReadableUrlPath utility to path-utils to share recognition logic between reading and searching pipelines.
- Implemented a fallback that checks if a directory matching a fuzzy URL path exists locally before resolving it as an external URL.
- Added explicit errors for unsupported URL schemes to replace misleading local-path errors.
2026-07-02 01:51:09 +02:00
can1357 6066814d3e Merge PR #3650: fix(tools): materialize URL paths for search scopes (@roboomp) 2026-07-01 21:42:23 +02:00
roboomp 777b609e63 fix(cli): preserved windows extension paths
Rejoined split Windows extension module paths before launch parsing finishes and stripped extended-length Win32 prefixes before Bun import and worker spawn APIs see them.

Fixes #3804
2026-06-29 11:50:36 +00:00
roboomp b6274a6109 fix(tools): materialized external read urls
- Materialized readable URL bodies through the read cache before resolving search, ast_grep, and ast_edit filesystem scopes.
- Preserved URL source extensions for AST language detection and added regression coverage for URL search paths.

Fixes #3649
2026-06-27 11:35:24 +00:00
Tommaso Fontana 73c1b33fd9 fix(omp): address #3553 review feedback
- reject explicit ssh:// port 0 before connecting (Codex P2)
- keep a path-less ssh://host:port authority port out of selector peeling
- restore ResolveContext on ProtocolHandler.complete (symmetry with resolve/write)
- clarify search/read selector-parity docs + add read-side regression
2026-06-26 20:41:35 +02:00
Tommaso Fontana f9ece90853 fix(omp): harden ssh:// URL handler per PR review
- buildSshTarget rejects destinations beginning with "-" (SSH argument-injection / local RCE guard)
- gate ssh:// read/search/write at the exec approval tier; substring scan covers search's pre-expansion delimited paths and write's hashline-wrapped paths
- validate the entire materialized buffer as UTF-8 instead of only the first 8 KiB prefix
- write peels read selectors (raw/conflicts) so it targets the same file read does, and rejects line-range/malformed selectors instead of silently stripping them
- write to a uniquely named remote temp; document symlink-replacement on write as a v1 limit
2026-06-26 20:41:35 +02:00
Tommaso Fontana c63171b909 feat(omp): add ssh:// URL support to read, search, and write 2026-06-26 20:41:35 +02:00
roboomp 3ce34621c0 fix(agent): preserved skill url session context
Threaded the caller's loaded skills through internal URL resolution so skill:// handlers do not depend on process-global skill state during tool execution.

Fixes #3436
2026-06-25 03:54:15 +00:00
can1357 360c70fd1f fix: semicolon priority over comma 2026-06-15 14:56:16 +02:00
roboomp 0533240ada fix(tool): preserved rooted windows paths
Restricted MSYS and WSL drive alias normalization to forward-slash roots so native Windows root-relative paths like \d\logs stay on the current drive.

Fixes #2634
2026-06-15 13:44:44 +02:00
roboomp 2f8e523173 fix(tool): normalized windows drive aliases
Mapped MSYS and WSL drive aliases before bash cwd validation and brush filesystem resolution so cd, stat-style tests, and tool cwd handling agree on Windows.

Fixes #2634
2026-06-15 13:44:44 +02:00
can1357 97445ebb9b fix(coding-agent/tools): fanned out explicit file targets for multi-path searches
- Added `fanOutFileItems` plumbing through `resolveSearchPathItems`/`resolveExplicitSearchPaths` and `ToolScopeOptions` so plain-file entries can be scanned as explicit targets instead of being folded into an unrequested ancestor walk.
- Search tool now enabled `fanOutFileTargets` and deduplicated overlapping results by tracking a `path\0line` key before merging matches.
- Expanded multi-path tests for shared non-root ancestors, explicit `.git/config` targets, and overlap deduplication behavior.
2026-06-11 21:24:30 +02:00
danzaio ac1107a1f3 fix(tools): preserve escaped path delimiters 2026-06-10 14:34:25 -03:00
danzaio 701fff5fd0 fix(tools): normalize Windows search paths 2026-06-10 14:16:01 -03:00
can1357 7e72d364ce fix(coding-agent/tools): fixed multi-path find target processing and duplicate result emission
- Processed explicit multi-path `find` targets independently and merged scoped results.
- Ignored missing or invalid extra targets in multi-path `find` queries instead of failing the whole run.
- Deduplicated overlapping matches when combining per-target `find` results.
- Tracked streamed match paths to prevent repeated update rows during long-running scans.
2026-06-08 06:18:54 +02:00
can1357 ee4df538f0 fix(tools): resolved search-path parsing and local sandbox checks
- Set `FindTool` to disable recursive glob traversal so `dir/*` stays shallow.
- Added `parseSearchPathPreferringLiteral` to prefer literal paths like `apps/[id]/page.tsx` when they exist.
- Updated `resolveToolSearchScope` to reject external URLs with a clear `read` usage error.
- Expanded plan-mode sandbox checks to allow absolute paths inside the local artifact root.
2026-06-08 02:04:59 +02:00
can1357 1002ba0242 feat(search): accepted internal URL selectors as line filters
- Added selectorLineRanges to extract ranges from raw/conflicts selectors.
- Routed internal URLs through URL-aware splitter in content search.
- Treated display-mode selectors as whole-resource searches instead of rejecting.
2026-06-05 16:29:58 +02:00
can1357 b1b4b0c0ed feat(coding-agent/tools): allowed .. aliases for line range selectors
- Extended line selector parsing in path-utils to accept `..` as a forgiving alias for `-`, with `..` normalized during chunk parsing.
- Updated selector-matching regexes for file selectors and internal URL selectors to recognize alias-style ranges in single chunks and comma-separated lists.
- Added tests covering `N..M`, `N..`, mixed separators, inverted-range errors, and path-splitting behavior with `:N..M` selectors and `foo:../bar.ts` paths.
2026-06-04 01:35:39 +02:00
can1357 fbed7d1787 fix: expanded tool argument parsing to accept delimiter-separated paths
- Expanded path parsing to split top-level comma, semicolon, and whitespace entries.
- Updated find/search and scope resolution to apply delimiter expansion before path-spec validation.
- Updated read tool fallback to try split path parts before raising missing-path errors.
- Coerced bare string arguments into singleton arrays for array-typed schemas.
2026-06-02 11:14:02 +02:00
roboomp 73102d20df fix(coding-agent): routed local:// reads through the calling session
- Extended ResolveContext / WriteContext with localProtocolOptions so the
  internal-URL router can thread the calling session's local-root mapping
  through to handlers.
- LocalProtocolHandler.resolveOptions now prefers context.localProtocolOptions
  before consulting the process-global override or the first main-kind session
  in AgentRegistry, fixing multi-session ACP hosts (cmux) where reads of
  local://PLAN.md were routing to a sibling session's artifacts dir even
  though plan-mode writes succeeded against the calling session.
- read, find, ast_grep, ast_edit, and search now thread
  this.session.localProtocolOptions into the router so local://, memory://,
  agent://, and other handlers see the right caller.
- Added regression tests covering the override-vs-context priority and the
  ENOENT-against-caller-root path.

Fixes #1608
2026-06-01 11:27:14 +00:00
can1357 1709172bfe feat(coding-agent): added obsidian integration
- Added vault:// URL parsing, typed variants, and path resolution with vault-root validation.
- Added VaultProtocolHandler with fs and Obsidian CLI-backed resolve/read/write/list support plus caching.
- Added vault scheme integration in router, path utils, and plan-mode guard using resolveVaultUrlToPath.
- Documented vault:// read/edit and `?op`-scoped URI formats in system prompts when Obsidian is available.
- Secured vault:// operations by rejecting traversal, absolute, and symlink-escape path cases.
- Fixed response.incomplete recovery by dropping truncated turns and promoting context.
- Added internal tests for vault protocol parsing, caching, CLI behavior, and invalid-path defenses.
2026-05-28 10:10:34 +02:00
can1357 56c34a0d13 feat(summary): added BFS unfold and file-scoped line ranges to search
- Added `unfoldUntilLines`/`unfoldLimitLines` options to progressively reveal nested elidable spans breadth-first instead of collapsing everything behind the outermost elision.
- Added `minTotalLines` setting to skip summarization for short files, returning verbatim content instead.
- Added `:` selector support to `search` paths for constraining matches to specific line ranges.
- Extracted `parseLineRanges`/`parseLineRangeChunk`/`isLineInRanges` from `read.ts` into shared `path-utils.ts`.
2026-05-27 03:55:04 +02:00
oldschoola 96aad47eb6 fix(coding-agent): address PR #1388 review feedback
Refactor:
- session.ts: extract mapDebugpyMissingModule helper; replace the duplicated
  inline check in launch/attach catch blocks. Add jsdoc on DapStartRequestFailure.settled
  documenting per-call ownership and how throwPreferredDapStartError consumes it.
- path-utils.ts: replace the no-op keepOpaqueResourceUri branch with an
  OPAQUE_RESOURCE_SCHEMES Set so the structure carries the intent. Functionally
  equivalent; new opaque schemes become a one-line Set change.

Tests:
- dap-launch-failures: cover the debugpy stderr -> 'pip install debugpy'
  rewrite for launch and attach, plus a negative case (non-debugpy adapter
  with the substring in stderr is left untouched).
- dap-launch-failures: model the delayed-launch-failure case the new
  settled-race in throwPreferredDapStartError defends against. FakeDapClient
  gains optional launchErrorDelayMs/attachErrorDelayMs.
- dap-launch-failures (DebugTool): assert adapter:'debugpy' early-throw
  surfaces 'python not found in PATH' on both launch and attach when
  selectLaunchAdapter/selectAttachAdapter return null, and the unspecified-adapter
  path still falls back to the generic 'No debugger adapter' error.
- find.ts: export validateFindPathInputs and pin the new backslash-escape
  semantics (\, no longer trips the comma-joined heuristic) plus the
  existing brace-expansion and rejection paths.
- patch.ts: cover the post-write verification error message. The user-facing
  ToolError must contain the caller-supplied relative path and not the
  absolute resolvedPath (which still lives in the structured context for
  log correlation).
- split-internal-url-sel: reword two mcp:// test comments that described a
  'peeler refuses' guard that doesn't exist; rename the tests to reflect the
  actual opaque-scheme rule.
2026-05-26 01:54:09 -07:00
oldschoola 2171ae4dd1 fix(coding-agent): browser default, patch error path, mcp:// selectors, find timeout/sort, DAP launch races, debugpy diagnostics
- browser tool's existing-tab re-nav defaults to waitUntil: 'load' (matching
  new-tab path); identical acquireTab() calls no longer hang on dev servers
- patch tool error path uses caller-supplied relative path; absolute
  resolvedPath stays in structured context only ($HOME no longer leaks to TUI)
- splitInternalUrlSel keeps mcp:// resource URIs opaque even when they end in
  ':raw' or '/:1-50' (McpProtocolHandler matches by verbatim URI)
- find tool: timeout signal honored by onMatch; partial results sorted by
  mtime desc; backslash-escaped commas skipped in path-list validation
- DAP throwPreferredDapStartError waits up to 50ms for the underlying
  launch/attach error instead of one microtask
- debug tool surfaces 'python missing' and 'pip install debugpy' diagnostics
  separately when adapter: 'debugpy' is requested
2026-05-26 01:54:09 -07:00
can1357 2e40fb250b fix(coding-agent/tools): fixed internal URL selector splitting in read path resolution
- Added splitInternalUrlSel to iteratively peel internal-URL selector chunks while preserving unsupported schemes like mcp://.
- Updated ReadTool to use the internal splitter before routing so selector parsing is handled via parseSel.
- Added unit tests covering malformed selectors, namespaced skill hosts, and unchanged behavior for non-URLs or unsupported schemes.
2026-05-19 07:12:56 +02:00
can1357 2e6d96d3bc feat(coding-agent/tools): added open-ended line range shorthand for read selectors
- Updated read-line selector parsing to accept line-range selectors ending with a trailing dash.
- Mapped selectors with a trailing dash to open-ended ranges that read from the start line onward without requiring an explicit end.
- Updated read tool documentation to document `:50-` as the shorthand for reading from line 50 onward.
2026-05-15 23:46:23 +02:00
can1357 8fc5b78f30 feat(read): added comma-separated scatter gather line selector support
- Extended selector regex and parser to accept ranges like `:5-16,960-973`.
- Ranges are sorted and merged automatically before reading.
- Out-of-bounds ranges surface as inline notices instead of errors.
- Added `#readLocalFileMultiRange` and `#buildInMemoryMultiRangeResult` for file, archive, notebook, and internal URL targets.
2026-05-14 05:58:25 +02:00
can1357 f1f6516056 refactor: reorganized exports and removed obsolete helper branches
- Removed export leakage by demoting many helper and const symbols to module-local scope.
- Renamed underscore-prefixed internals and cache fields, then updated related references and `satisfies never` checks.
- Deleted obsolete logic branches and helpers, including harmony-stream interruption flow and unused benchmark runtime helpers.
- Updated Biome config and manifests by broadening lint coverage and removing an unused `@napi-rs/cli` dev dependency.
- Adjusted tests and utilities to use renamed test helpers and remove redundant private test-only helpers/locals.
2026-05-14 04:36:19 +02:00