Commit Graph

5407 Commits

Author SHA1 Message Date
Ogrodev 4e4e74be49 fix(coding-agent/acp): tighten ACP conformance per review feedback
Addresses the codex review comments on #1015 plus a sweep of adjacent
ACP conformance gaps surfaced while wiring them up.

Tool call + diff metadata
- acp-event-mapper: thread session cwd through and resolve every
  `ToolCallLocation` (initial args, in-flight updates, result details)
  to absolute paths against it; ACP requires absolute paths for
  client-side file mapping.
- edit/modes/patch: emit the destination path for moves in the diff
  result so post-edit "open file" actions land on the new file.

Permissions
- agent-session: pass cwd into `extractPermissionLocations` and resolve
  raw `path`/`file`/etc. fields against it before sending
  `session/request_permission`.
- agent-session: gate the permission wrapper on
  `bridge.capabilities.requestPermission && bridge.requestPermission`,
  matching the read/write/bash capability+method pattern.

acp-agent
- `authenticate`: validate `methodId` against the methods advertised by
  `initialize` and reject anything else, so malformed clients fail fast.
- `setSessionConfigOption(MODE_CONFIG_ID)`: also emit
  `current_mode_update` so clients tracking `modes.currentModeId` see
  the same transition `session/set_mode` would produce.
- Pass `runtime.notifyConfigChanged` to builtins; emit
  `available_commands_update` from a shared `reloadPlugins` helper
  reused by `/reload-plugins`, `/marketplace`, and `/plugins`.
- prompt resource handling: route `resource` content with `image/*`
  MIME into the `images` array instead of dropping it as an opaque
  blob; non-image blobs still fall back to the URI placeholder.
- pass session cwd to the event mapper.

Builtins
- model: call `runtime.notifyConfigChanged()` after a successful
  `setModel` so the ACP config selector reflects the new model
  immediately.
- mcp: redact query strings and userinfo from MCP server URLs before
  emitting them in `/mcp list` (prevents leaking `?exaApiKey=…` style
  secrets); wire `manager.setAuthStorage(...)` before `prepareConfig`
  in `/mcp test|resources|prompts` so OAuth servers can refresh tokens.
- ssh: reject non-integer `--port` values via a `^\d+$` guard instead
  of silently coercing through `Number.parseInt`; list project hosts
  first and dedupe user-scope duplicates to match capability-loader
  precedence.
- export: reject clipboard aliases (`--copy`, `clipboard`, `copy`)
  before passing them to `exportToHtml` as a filename.
- compact / force / move / browser: surface underlying failures via
  `usage(errorMessage(...))` instead of letting them crash the command.
- session save|delete: route through the active SessionManager so the
  persist writer is consulted and stale storage references are removed.
- marketplace / plugins / reload-plugins: call `runtime.reloadPlugins()`
  on install/uninstall/upgrade and enable/disable so slash command
  registries and command lists refresh consistently.
- shared.usage: make async and `await runtime.output(...)` so
  `sessionUpdate` text is never dropped or reordered.
- types: document the new `reloadPlugins` and `notifyConfigChanged`
  runtime hooks.

bash tool
- Use a shared `fireKill()` from the abort listener so `session/cancel`
  terminates the remote command immediately instead of waiting for the
  next `currentOutput()` round trip.
- Race `currentOutput()` against the abort signal so a stuck
  `terminal/output` RPC cannot delay cancellation.
- Kill the terminal before reading final output on timeout so a slow
  output read cannot let a timed-out command keep running past the
  enforced timeout.

Tests
- acp-agent.test: extend the existing config-option assertions to
  verify both `model` and `thinking_level` changes emit
  `config_option_update` notifications scoped to the right session.
- acp-builtins.test: cover `/model` emitting both
  `notifyTitleChanged` and `notifyConfigChanged`; lock in the parsed
  `mcp add` / `ssh add` call shapes so future arg-parser regressions
  fail the test instead of silently writing different configs; add a
  `reloadPlugins` stub plus a typed `notifyConfigChanged` slot to the
  shared test runtime factory.
- acp-stdout-hygiene.test: drain stderr in parallel and assert no
  JSON-RPC frame leaks onto it; terminate the spawned process so the
  stderr pump resolves deterministically.

CHANGELOG: itemize the above under `[Unreleased] > Fixed`.

CI
- bun run check: clean (TS + Rust)
- bun run test: 4128 pass / 689 skip / 0 fail (TS); 252 pass / 0 fail
  (Rust nextest)
- bun run ci:test:smoke: --version / --help / `stats --help` all OK
2026-05-13 06:00:45 +02:00
Ogrodev 1a44cd2e36 Fix ACP review follow-ups 2026-05-13 06:00:45 +02:00
Ogrodev 9ae60cd793 Fix assistant image fixture path 2026-05-13 06:00:45 +02:00
Ogrodev d4f775c5df Fix Rust clippy warnings 2026-05-13 06:00:45 +02:00
Ogrodev be36c7c24f Fix ACP review comments 2026-05-13 06:00:45 +02:00
Ogrodev 4f62e3c0e3 docs(coding-agent): update changelog for ACP feature release
- Documents new ACP server mode, ClientBridge permission gating, built-in slash commands, tool routing, and edit diff content under [Unreleased]
2026-05-13 06:00:45 +02:00
Ogrodev d8e38bcc62 test(acp): add comprehensive ACP and edit tool test suites
- AcpAgent integration tests: initialize→run→notify cycle, notification structure, message-ID continuity
- ACP built-in slash command unit tests across all command handlers via fake runtime
- ACP event mapper unit tests: text chunks, thinking, tool calls/results, errors → SessionNotification
- ACP initialize conformance: terminal auth capability negotiation, agentInfo/agentCapabilities contract
- stdout hygiene smoke test: first bytes on omp acp stdout must be a valid JSON-RPC frame
- AgentSession permission gate: allow-once, reject-once, allow-always, abort-during-pending, non-gated tools
- BashTool ACP terminal routing: bridge dispatch vs local PTY fallback
- EditTool diff content propagation: patch, replace, and multi-file aggregation paths
- ReadTool and WriteTool ACP filesystem permission tests
- Shared ACP schema test helper
2026-05-13 06:00:45 +02:00
Ogrodev 0e43db53c3 feat(acp): add ACP built-in slash command framework and all handlers
- Introduces AcpBuiltinCommandSpec registry and executeAcpBuiltinSlashCommand dispatcher
- Defines shared types (ParsedAcpCommand, AcpBuiltinCommandRuntime, result union) and utility helpers
- Implements 24 built-in command handlers: /mcp (add/list/enable/disable/remove/test/search), /todo (append/start/done/drop/copy/import/export), /marketplace, /ssh (list/add/remove profiles), /usage, /model, /memory, /session, /compact, /context, /format, /fast, /force, /browser, /changelog, /commands, /dump, /export, /jobs, /move, /plugins, /reload-plugins, /rename, /share, /tools
2026-05-13 06:00:44 +02:00
Ogrodev a1ba6bf003 fix(edit): propagate per-file oldText/newText diff content through edit pipeline
- EditTool now carries oldText/newText in per-file results for patch, replace, and multi-file aggregation paths
- Renderer updated to display diff content for all edit modes
- Enables downstream consumers (ACP event mapper, TUI) to render accurate diffs
2026-05-13 06:00:44 +02:00
Ogrodev 5c922856e5 feat(acp): route bash/read/write tools through ACP client bridge
- BashTool dispatches execution through the client bridge terminal channel when a bridge is present, falling back to local PTY otherwise
- ReadTool and WriteTool gate filesystem access through ACP permission checks
- Exports new tool wiring in the tools barrel
2026-05-13 06:00:44 +02:00
Ogrodev 275108974a feat(acp): add acp CLI subcommand and wire terminal-auth into launch
- Adds omp acp subcommand that launches the agent as an ACP stdio server
- Registers the subcommand in the CLI dispatcher
- Threads terminal-auth args and ACP flags through the launch and main orchestrators
- Exports AgentSession on the public SDK surface
- Updates skills loader to support skill→slash-command conversion and prompt injection
- Updates input-controller to dispatch ACP built-in slash commands
2026-05-13 06:00:44 +02:00
Ogrodev f81d9b7fef feat(acp): extend AcpAgent with session management and model negotiation
- Adds create/resume/list/page session lifecycle handling to AcpAgent
- Implements mode switching (default vs. plan), MCP server configuration, and model/thinking config negotiation with the connected client
- Routes incoming ACP connections to AgentSession via the new ClientBridge
2026-05-13 06:00:44 +02:00
Ogrodev b707cdaa08 feat(acp): implement ACP protocol adapters and terminal-auth support
- Adds AcpClientBridge, adapting an ACP AgentSideConnection to the internal ClientBridge interface
- Adds ACP event mapper translating AgentSessionEvents to ACP SessionUpdate/SessionNotification wire payloads (tool-kind classification, content truncation, text normalization)
- Adds terminal-auth flag constant and prepareAcpTerminalAuthArgs helper for authenticated terminal handles
2026-05-13 06:00:44 +02:00
Ogrodev 7f5ea5d9be feat(acp): add ClientBridge interface and AgentSession permission gating
- Introduces ClientBridge — the abstract boundary between AgentSession and external clients (ACP, TUI), defining terminal handle and permission request contracts
- Adds ACP permission gating in AgentSession for destructive tools (bash, edit, write, ast_edit): allow-once, reject-once, allow-always with caching
- Wires todo tracking, model cycling/retry-fallback chains, and auto-compaction into the session lifecycle
2026-05-13 06:00:44 +02:00
can1357 205bb60ab4 fix(coding-agent/task): sanitized review preview and finding titles before rendering
- Flattened newlines and tabs in summary explanations before generating the review preview text, and trimmed the extracted sentence before truncating.
- Sanitized finding titles during render by normalizing tabs/newlines to spaces after stripping priority prefixes.
2026-05-13 05:59:35 +02:00
can1357 142c39569b chore: changelog update 2026-05-13 05:49:11 +02:00
can1357 5a37fd4516 fix(ai): resolved ai auth credential_disabled queueMicrotask flushing
- Deferred initialize to flush queued credential_disabled events via queueMicrotask and event splicing.
- Added tests for pre-initialize credential_disabled emissions and onError propagation of handler failures.
- Replaced auth credential disable flow with CAS checks in #tryDisableAuthCredentialIfMatches and matching SQL statement.
- Retried OAuth getApiKey after disable failures; added peer-rotation race test for fresh token and active credential retention.
- Updated CHANGELOG for deferred microtask flushing plus eval import renames and diff URL/quoted-path parsing fixes.
2026-05-13 05:33:03 +02:00
can1357 a498d45900 feat(task): updated task launch responses with live ids and coordination guidance
- Updated the task tool output to list newly started background jobs by live task id with optional descriptions.
- Extended the async task prompt guidance to distinguish IRC-enabled versus standard coordination and cancellation behavior.
2026-05-13 05:32:31 +02:00
can1357 23dd7bf5f6 chore: changelog update 2026-05-13 05:26:02 +02:00
can1357 db1a3fd7b1 fix(packages/coding-agent): corrected js import rewriting empty AST body
- Added guard for ASTs with no body and trimmed trailing EmptyStatement nodes before final-expression capture.
- Exposed wrapCode via context-manager export for external JS import-rewrite callers.
- Added regression test asserting final-expression wrapping when trailing semicolons follow await.
2026-05-13 05:24:33 +02:00
can1357 218fe8b892 fix(packages/coding-agent): resolved JS display fallback for noncloneable values
- Handled structured-clone failures in JsRuntime.display by falling back to text output.
- Added regression coverage for non-structured-cloneable JS display output.
2026-05-13 05:24:33 +02:00
can1357 76bb773de9 fix(packages/coding-agent): corrected internal URL parse and read routing
- Hardened `parseUrl` to decode each internal segment and reject empty, `.` or `..` segments.
- Added `AbortSignal` propagation through `ReadTool` into internal URL resolution to honor cancellation.
- Adjusted markdown rendering in `read` output so raw selector reads bypass markdown formatting.
- Aligned `conflict://` help text in `read`/`write` with URI read-path examples for scope conflicts.
2026-05-13 05:24:33 +02:00
can1357 fc1ff60294 fix(packages/coding-agent): corrected interactive submit shutdown handling in coding-agent
- Updated submitInteractiveInput to await checkShutdownRequested after submission, avoiding premature teardown (#1020).
- Mapped extension UI shutdown hook to set ctx.shutdownRequested for deferred teardown handling (#1020).
- Added regression coverage for interactive shutdown propagation and issue #1020 teardown behavior.
2026-05-13 05:24:33 +02:00
can1357 a14a2c402c fix(packages/coding-agent): resolved compaction queue plan ordering
- Pinned final plan path before handleCompactCommand so queued messages use approved plan, not draft.
- Added regression coverage for setPlanReferencePath timing before compaction queue flush.
2026-05-13 05:24:33 +02:00
can1357 087124d559 fix(packages/coding-agent): corrected github-cache hard-TTL purge on open
- Removed one-shot eviction in openDb(), preventing cache rows from being purged before settings load.
- Moved hard-TTL enforcement to getOrFetchView() sweepIfDue() so configured retention applies per lookup.
- Extended github-cache tests to verify row persistence across reopen and expiry under stricter hardTtl.
2026-05-13 05:24:33 +02:00
can1357 ecc6d23bed test(packages/coding-agent): updated system-prompt template assertion
- Updated system-prompt test assertion to match revised surgical edit wording.
2026-05-13 05:24:33 +02:00
can1357 724ef3784a chore: fix mentions of read tool in backticks causing confusing against bash read 2026-05-13 05:22:41 +02:00
can1357 b513fee874 docs(coding-agent/prompts): adjusted system prompt wording to soften hardline constraints
- Revised the system prompt wording in collaboration guidance from absolute prohibitions to explicit "avoid" directives.
- Adjusted multiple policy lines to reduce rigid phrasing around handling difficult user proposals, harness docs, and unnecessary file reads.
- Kept the behavioral intent intact while making the instructions more nuanced in the high-reliability prompt text.
2026-05-13 05:13:18 +02:00
can1357 c53c63e96d fix(coding-agent/internal-urls): patched numeric host diff path parsing
- Extended short-form diff URL parsing to treat `<scheme>://N/diff` as a diff path across schemes, so `issue://N/diff` now follows the issue no-diff rejection path.
- Kept repository listing behavior unchanged for `<scheme>://owner/diff` by limiting diff short-form disambiguation to numeric hosts.
- Added regression coverage asserting `issue://9/diff`, `issue://9/diff/all`, and `issue://9/diff/3` now reject with the issue no-diff error.
2026-05-13 04:52:27 +02:00
can1357 1ccc56aca6 fix(coding-agent/eval): routed JS import calls through session-aware import helper
- Updated JS import rewriting to route top-level `import` declarations through `__omp_import__` with support for import attributes.
- Added AST traversal to replace `import(...)` call callee nodes with `__omp_import__` so dynamic imports resolve via session-aware helper.
- Updated runtime `__omp_import__` to accept an optional options object and pass it through to `import(target, options)`.
2026-05-13 04:47:49 +02:00
can1357 e7b4b4c20d fix(coding-agent): fixed read tool streaming routing and result expansion behavior
- Updated event-controller read-tool streaming handling to wait for a parseable target before routing tool calls, avoiding early component binding for unresolved arguments.
- Allowed internal-URL read calls to bypass the regular read grouping path and fall through to direct tool execution.
- Adjusted read tool rendering to honor the computed `expanded` flag for completed output instead of forcing expanded output.
2026-05-13 04:42:43 +02:00
can1357 e70084976b fix(coding-agent): corrected issue-pr diff URL parsing to list outputs
- Fixed `issue://owner/diff` and `pr://owner/diff` parsing so they resolve to issue and PR list outputs.
- Fixed `pr` short-form parsing by requiring `scheme==='pr'` and a numeric host before `diff` matching.
- Fixed PR unified-diff parsing to decode quoted header paths and count `----`/`++++` hunk lines as one deletion/addition.
- Fixed `read` error rendering to emit status blocks with cleaned, range-aware, tab-normalized lines.
- Stopped `github-cache` from chmod-ing existing parent directories, preserving pre-existing permission modes.
2026-05-13 04:39:16 +02:00
can1357 e1589bb137 fix(coding-agent/modes): parsed selection from path before language detection
- Updated read entry syntax highlighting to derive language from a path split from selection suffixes.
2026-05-13 04:34:08 +02:00
can1357 ed64b3bd64 fix(coding-agent): hardened URL and repo default-resolution cleanup
- Guarded session manager lookup in internal URL cwd resolution to handle missing managers safely.
- Replaced `Promise.finally` cleanup with explicit `then` handlers so default-repo in-flight entries are removed on both success and failure.
2026-05-13 04:32:51 +02:00
can1357 322095dd78 fix(coding-agent/tools): used split file path when determining read tool language
- Updated language detection to use the base file path from splitPathAndSel before calling getLanguageFromPath.
2026-05-13 04:32:47 +02:00
can1357 64b4aa1ae0 feat(coding-agent): implemented PR diff URL parsing for pr://<N>/diff
- Replaced `op: pr_diff` with `pr://<N>/diff` URL variants and routed PR diffs through URL parsing.
- Added `readArgsHaveTarget` checks to gate read-call tracking on `path`/`file_path` targets.
- Added auth-key-aware GitHub caching with scoped rows, default auth resolution, and hard-TTL invalidation.
- Added markdown output rendering for read with markdown-cell layout, ANSI-aware truncation, and expand-width cache reuse.
- Updated PR diff and cache tests, replacing deprecated `pr_diff` cases with `/diff` and auth/TLL coverage.
2026-05-13 04:32:16 +02:00
can1357 c888a9fa36 docs(coding-agent/prompts): strengthened coding-agent prompts with stricter directive wording
- Updated system and subagent prompts to replace soft prohibitions with stricter NEVER/IMMEDIATE wording where behaviors were previously expressed as DO NOT.
- Added a dedicated system-conventions block to the main system prompt to formalize RFC-2119 and tag-authority guidance.
- Reworded multiple tool prompt guides (AST, file lookup, search/read, browser, hashline) to tighten behavioral constraints and clarify invalid command usage.
2026-05-13 04:10:39 +02:00
can1357 d483531b6b fix(coding-agent): decoupled internal URL read calls from read tool grouping
- Added readArgsTargetInternalUrl in the read tool group component to detect targets handled by InternalUrlRouter from path or file_path arguments.
- Updated event-controller and UI helper read rendering paths to skip grouping read tool calls when those arguments target internal URLs.
- Passed session cwd and settings into internal URL resolution in read.ts and added tests for internal versus non-internal target detection.
2026-05-13 04:05:23 +02:00
can1357 a733390462 feat: added issue:// and pr:// handlers with sqlite cache ttl refresh
- Added issue:// and pr:// URL handlers for single lookups and list queries with query filters.
- Added a SQLite-backed GitHub cache with soft/hard TTLs, stale hits, and background stale refresh.
- Removed issue_view and pr_view tool operations, inputs, and docs, requiring reads via issue:// and pr:// URLs.
- Added github-cache and issue-pr-protocol tests with temporary cache DB setup and OMP_GITHUB_CACHE_DB teardown.
2026-05-13 04:04:45 +02:00
can1357 569438fdc5 test: drop stale inspect_image guidance assertion 2026-05-13 03:26:05 +02:00
can1357 c27d007828 feat(docs): added NEVER/AVOID guidance to agent/tool/system prompts
- Standardized prompt templates across agents, tools, system, memory, and compaction to NEVER/AVOID wording.
- Reinforced policy language to ban edits/builds, state changes, and unsolicited JSON/code or filler output.
- Renamed stripRfc2119Bold to normalizeRfc2119, mapped NEVER/AVOID aliases, and skipped inline-code replacements.
- Updated the unreleased changelog to document the prompt-terminology migration.
2026-05-13 03:10:39 +02:00
can1357 1d4ea04769 fix(coding-agent): honor path-scoped enabledModels in default fallback
The SDK default-model fallback used `modelRegistry.getAll()` and only
filtered by stored credentials, ignoring the path-scoped `enabledModels`
allow-list. When the configured `modelRoles.default` was filtered out by
`disabledProviders`, the fallback could pick a model from a provider that
`enabledModels` did not permit for the current path.

Add `resolveAllowedModels(modelRegistry, settings, prefs)` which returns
`getAvailable()` intersected with the path-scoped `enabledModels`
patterns (or just `getAvailable()` when no patterns are configured), and
use it for both the default-role resolution and the fallback scan. When
`enabledModels` is set but no allowed model has usable credentials, the
fallback now surfaces a message instead of silently picking a disallowed
provider.

Fixes #1022.
2026-05-13 03:06:22 +02:00
can1357 b8d238b4ee docs(docs): documented RFC2119 terms to stay uppercase without bold
- Removed markdown bold from RFC 2119 MUST/SHOULD/REQUIRED across agent, tool, system, compaction, and memory prompts.
- Updated SKILL guidance to require uppercase RFC 2119 terms without bold emphasis.
- Renamed `boldRfc2119Keywords` to `stripRfc2119Bold` and made prompt formatting strip `**keyword**` markers.
- Preserved substantive prompt instruction wording while switching emphasis-only formatting in markdown templates.
2026-05-13 03:05:32 +02:00
can1357 2654859712 fix(coding-agent): wire ctx.shutdown() to InteractiveMode.shutdownRequested
The extension shutdown context action installed by
ExtensionUiController.initializeHookRunner was an empty stub, so
ctx.shutdown() in interactive mode silently did nothing while extensions
fell back to process.exit(0), bypassing session flush and terminal
restore. Flip InteractiveModeContext.shutdownRequested so the main
loop's existing checkShutdownRequested() drives the graceful path.

Fixes #1020.
2026-05-13 02:58:02 +02:00
can1357 a376cf8205 fix(tools): corrected github tool search parsing for /search/issues responses
- Switched issue and PR search handlers to `gh api /search/issues` with `is:issue`/`is:pr` queries.
- Added REST search response models and mapped issue/code/commit/repo payloads to normalized results.
- Updated code, commit, and repo search parsing to read `{items}` envelopes and convert snake_case fields.
- Fixed merged-PR output state by deriving it from `pull_request.merged_at` in test fixtures.
2026-05-13 02:55:30 +02:00
Can Bölük 8f063c4a66 Merge pull request #1036 from OutlineDriven/feat/plan-mode-approve-compact-context
feat(coding-agent/plan-mode): add "Approve and compact context" approval choice
2026-05-13 02:47:07 +02:00
Can Bölük f72e7ddbea Merge branch 'main' into feat/plan-mode-approve-compact-context 2026-05-13 02:46:59 +02:00
can1357 eac29966eb chore: reformat 2026-05-13 02:34:46 +02:00
can1357 e80f9c76ad Merge PR #1025: fix(ollama): retry on 5xx for chat and model list endpoints
Ollama Cloud has documented 503 windows under load that hard-failed the
turn. Adds bounded backoff (2s/5s/10s, ~17s worst case) for /api/chat
and /api/tags, wired through a shared abortableSleep so the retry
respects abort signals. Local Ollama uses a different code path and is
untouched.

Closes #1025
2026-05-13 02:32:59 +02:00
can1357 efad62e808 Merge PR #1033: feat(skill-command): route /skill:* through the submission keybinding
Slash skill invocations bypassed the Enter / Ctrl+Enter contract that
every other slash command honors. Now Enter steers, Ctrl+Enter queues
a follow-up, sharing one #invokeSkillCommand helper between the editor
submit handler and handleFollowUp. Compaction short-circuit ordering
preserved.

Closes #1033
2026-05-13 02:32:52 +02:00