Commit Graph

17314 Commits

Author SHA1 Message Date
enieuwy 77ee3f2e7e fix(task): key subagent fallback chains off the pre-expansion model role
A single-model subagent is pinned to a `subagent:<id>` role whose
`retry.fallbackChains` entry shadows every configured role chain, so the
chain it inherits decides where the child retries. Inheritance resolved
the role by re-deriving it from the child's `modelPatterns` — but every
spawn path expands the role alias into `modelOverride` before calling
`runSubprocess` (`modelPatterns = normalizeModelPatterns(modelOverride ??
agent.model)`), so `@task` never reached the derivation and it returned
`undefined` every time. Every task subagent inherited `chains.default`.

With `modelRoles.task: anthropic/claude-sonnet-5`, `task` chained to
sonnet alone, and `default` chained to sonnet plus a second provider, a
transient stall on sonnet routed the child onto the default chain's
second model — one the operator had deliberately kept out of the `task`
chain — and a quota error there killed a 28-minute run.

#7694 fixed only the shape where an unexpanded alias reaches the
executor, which no production caller produces; its tests supplied a bare
`agent.model: ["@smol"]` with no `modelOverride`. The incident above
happened on v17.2.10, which contains that fix.

Route inheritance off the role identity the spawn path already computes
and passes as `modelRole`. Since that leaves the pattern-derived operand
unreachable, drop it and the parameter it was the only user of.

The vibe worker path had the same defect independently: `#resolveWorker`
expanded `@task`/`@smol` for the bundled `task`/`sonic` workers and kept
no role, so vibe children inherited `default` no matter what the
executor did. It now carries `modelRole` on `ResolvedVibeWorker` and
`VibeRecord` through both the spawn and rehydrate sites.

To stop the two halves drifting apart again — the mistake that caused
this bug — `resolveAgentModelSelection` returns the expanded `patterns`
and the pre-expansion `role` from one call, and both spawn paths take
both from it. `resolveAgentModelSource` is removed: its only use was
being fed to `resolveExplicitModelRole`, and keeping it invites the same
split derivation. `resolveAgentModelPatterns` stays for the UI callers
that legitimately want patterns alone.

Tests cover the producible shapes: the incident's chain layout (role
chain equal to the primary, default chain a superset), role identity
surviving expansion for every alias-routed bundled agent, and the
patterns/role pairing itself. #7694's two tests are re-anchored to a
shape a real caller produces.
2026-08-07 21:16:27 +08:00
can1357 ab78d3091e fix(hashline): warn instead of erroring on empty named-register paste
PUT ... @name with no matching capture no longer fails the patch: it
pastes nothing (a span target is still removed, i.e. it degrades to a
cut) and surfaces a warning naming the available registers. Anonymous
empty/ambiguous pastes still error. validateClipboardSequence now only
guards anonymous sequencing; applyEdits threads clipboard warnings into
ApplyResult.warnings.
2026-08-07 06:00:08 +02:00
can1357 102eaa4543 feat(cli): added omp share command for saved sessions
Shares a saved session by id prefix or .jsonl path without launching the
agent - same encrypted upload, store selection, and share.redactSecrets
handling as the /share slash command.
2026-08-07 06:00:07 +02:00
can1357 35ab3ece48 refactor(secrets): extracted buildSecretObfuscator from sdk session setup
Moved the obfuscator assembly (secrets.yml + env entries + built-in
credential patterns, placeholder-key minting rules, redaction-only
fallback) from createAgentSessionScoped into the secrets module so other
entrypoints can build the same obfuscator.
2026-08-07 05:59:58 +02:00
can1357 2ad61c7b92 feat(discovery): added Agent Plugins 1.0.0 standard support
- New agent-plugins provider discovers packages with a root plugin.json
  targeting the canonical schema (agent-plugins.org) from marketplace
  installs, --plugin-dir, and configured extension roots; skills/ and
  mcp.json load per spec with closed-schema validation,
  ${PLUGIN_ROOT}/${PLUGIN_DATA} expansion, reserved subprocess
  environment, instance-keyed data dirs, and per-component isolation.
- Package-boundary containment (spec §4.1) is enforced before every
  read via the new contained-path helpers, including skill:// resource
  access from the read tool and bash; plugin skill files must
  realpath-resolve inside the plugin root (skills carry containRoot).
- Legacy claude-plugins/omp-plugins providers yield skills and MCP
  surfaces of standard-targeting roots to the new provider and skip
  fatally invalid packages.
2026-08-07 05:59:52 +02:00
can1357 b94bfba025 feat(mcp): enforced header precedence and origin policy on remote transports
- Client-generated HTTP/MCP/authorization headers win over configured
  headers case-insensitively (Agent Plugins §7.2.1) via the new
  header-policy fetch wrapper used by the HTTP and legacy SSE transports.
- headerPolicy: "origin-locked" pins configured headers to the configured
  URL's origin: never forwarded across cross-origin redirects, and
  method-changing redirects of JSON-RPC POSTs are refused.
- envPolicy: "literal" exempts stdio env values (and origin-locked
  headers) from config-value resolution: no ambient env-name lookup, no
  __omp_shell("command execution, empty values preserved.")
2026-08-07 05:59:36 +02:00
can1357 bd6e87b297 feat(utils): added repair and rawKeys options to parseFrontmatter
- repair: false disables lenient recovery (ambiguous-scalar quoting, tab
  replacement, leading HTML-comment stripping) so spec-conformant loaders
  reject malformed input instead of silently repairing it.
- rawKeys: true preserves frontmatter keys verbatim; exported
  normalizeFrontmatterKeys for callers that validate raw keys first.
2026-08-07 05:59:19 +02:00
can1357 3a8591a8af test: hardened two ci-flaky timing tests
- mnemopi provider parity 'diagnose, validate, graph' does ~6.7s of real
  work under bun --parallel=8 on loaded runners; raised its per-test
  timeout to 30s (default 5s flaked twice in three CI runs).
- utils LRUCache updateAgeOnGet drove a 30ms TTL with real 20ms sleeps
  (10ms margin); now drives performance.now() via a mocked clock, so the
  contract is asserted deterministically with no wall-clock wait.
2026-08-06 14:48:57 +02:00
can1357 6e40e3e9fd fix(utils/marked): closed lists at an end-of-input blank run
- A blank run at EOF now breaks the list without consuming the blank,
  matching real marked: '- item\n\n' lexes as a tight list plus a space
  token instead of a loose list whose raw includes the blank.
- Completes the 17.2.10 mid-document fix; same-marker continuation and
  indented item content across blanks are unaffected.
- Added list/blank boundary token-shape tests (verified against marked
  v15) since the tui incremental tests compare the lexer to itself.
2026-08-06 14:40:13 +02:00
can1357 3e2e715b09 test(ai): aligned deepseek flash ladder expectations with #7668
- deepseek-v4-flash bakes the wire-exact [low, high, max] ladder on
  every host since 736b496cc6; V4 Pro stays [high, max].
- The stale xhigh alias-filter assertions now expect the flash ladder.
2026-08-06 14:18:50 +02:00
can1357 d9d911a58d fix(coding-agent): kept mid-turn command deferral silent
- Reverted the status-line acknowledgment added for deferred panel
  commands: showStatus mounts a Spacer+Text into the transcript, and any
  mid-turn transcript mount re-renders rows below the growing live block,
  duplicating them in native scrollback (issues #4806/#6767).
- The queue still flushes at every settle, terminal or not.
2026-08-06 14:18:50 +02:00
can1357 d4ac069053 docs(utils): noted marked list tokenizer and template lookup fixes 2026-08-06 14:18:33 +02:00
can1357 0992c9314f fix(utils/template): added handlebars lookup builtin
- {{lookup obj key}} resolves proto-safe obj[key] like Handlebars'
  built-in; a user-registered lookup helper still takes precedence.
- Restores slash-command/prompt-template arg consumption via
  {{default (lookup . "arguments") "none"}}.
2026-08-06 14:18:32 +02:00
can1357 ef39946bfe fix(utils/marked): kept list-trailing blank line out of the list token
- A blank line before a non-continuing top-level line (including plain
  paragraphs) now closes the list without consuming the blank, so it
  always lexes as a separate space token like real marked.
- List token shape no longer depends on the follower's block type,
  restoring the TUI streaming lexer's freeze invariant (lex(prefix) ++
  lex(tail) == lex(full) under append-only growth).
- A list followed by a paragraph is now tight, not loose, per CommonMark.
2026-08-06 14:18:32 +02:00
can1357 43c1b245e7 chore: bump version to 17.2.10 2026-08-06 13:32:34 +02:00
can1357 dedd4449c9 refactor(utils/marked): removed biome lint ignore comment from generic token interface
- Removed the biome-ignore lint comment for explicit any on the Generic token interface.
2026-08-06 13:32:15 +02:00
can1357 9e738dc880 chore: reformat + rewrite changelogs 2026-08-06 13:30:08 +02:00
can1357 52ec788afb fix(coding-agent): enforce exact trusted extension paths 2026-08-06 13:24:29 +02:00
can1357 9628c2e2e6 Merge PR #7754: feat(omp): load only explicitly trusted extensions (@oleksoleksoleks) 2026-08-06 13:24:29 +02:00
Alexander Kirilin 9154c56a69 feat(omp): load only explicitly trusted extensions
Co-authored-by: Eric Singer <singer.ericm@gmail.com>
2026-08-05 16:32:45 -04:00
can1357 86375c130a style: reflowed window id doc comment with cargo fmt 2026-08-05 22:19:57 +02:00
can1357 1d181161b0 style: formatted legacy-pi shim changes with biome 2026-08-05 22:18:05 +02:00
can1357 c5cce0f325 chore: normalized changelogs after merging 14 pull requests 2026-08-05 22:17:01 +02:00
can1357 d49e7da281 test(tui): isolate explicit platform Warp assertions 2026-08-05 22:16:53 +02:00
can1357 ccd5a5c988 Merge PR #7697: test: fix Windows portability of bash ACP, Warp capability, and logger closure tests (@metaphorics)
# Conflicts:
#	packages/utils/test/logger-runtime-closure.test.ts
2026-08-05 22:16:53 +02:00
can1357 2759b11b0a test(release): exercise checksum generation end to end 2026-08-05 22:16:29 +02:00
can1357 4e62f3b7fd Merge PR #7660: ci(release): add SHA256SUMS.txt to GitHub releases (@andrew-scott-fischer) 2026-08-05 22:16:29 +02:00
can1357 afe926329d docs(ci): update local TypeScript runner comment 2026-08-05 22:16:29 +02:00
can1357 a1316bb22b Merge PR #7726: ci: ran the mnemopi suite in the workspace bucket (@Cyrus580529) 2026-08-05 22:16:29 +02:00
can1357 cac0887fee Merge PR #7708: fix(coding-agent): preserve shell quoting in POSIX $EDITOR commands (@metaphorics) 2026-08-05 22:16:29 +02:00
can1357 a6918d3397 Merge PR #7669: fix(catalog): exposed low effort tier for deepseek-v4-flash (@roboomp) 2026-08-05 22:16:29 +02:00
can1357 ae84aff853 Merge PR #7675: fix(memory): hide disabled memory protocol (@roboomp) 2026-08-05 22:16:28 +02:00
can1357 ca3884039b test(session): canonicalize hashed migration cwd 2026-08-05 22:16:28 +02:00
can1357 0474e797da Merge PR #7678: fix(session): migrate hashed session dirs back to legacy names (@roboomp) 2026-08-05 22:16:28 +02:00
can1357 1e3419ebac Merge PR #7688: fix(tui): detach plan approval dispatch from serialized event chain (@roboomp) 2026-08-05 22:16:28 +02:00
can1357 ee026fa2e3 Merge PR #7704: fix(natives): gate wayland capture capability on pipewire feature (@roboomp)
# Conflicts:
#	crates/pi-natives/src/desktop/linux/wayland/mod.rs
2026-08-05 22:16:16 +02:00
can1357 65132b3373 fix(computer): correct Wayland recovery guidance 2026-08-05 22:15:47 +02:00
can1357 307ba8b9f3 Merge PR #7711: fix(computer): correct Wayland foreground delivery (@roboomp) 2026-08-05 22:15:47 +02:00
can1357 dee516a3a0 Merge PR #7712: fix(computer): accept backend-minted window ids in Wayland capture (@roboomp) 2026-08-05 22:15:47 +02:00
can1357 21a7a32eb6 fix(plugins): only rewrite imported createRequire calls 2026-08-05 22:15:47 +02:00
can1357 c20d95fecc Merge PR #7730: fix(plugins): resolve createRequire deps in legacy-pi shim (@roboomp) 2026-08-05 22:15:47 +02:00
can1357 677b6f10f5 Merge PR #7735: fix(coding-agent): return ToolInfo[] from getAllTools extension API (@roboomp) 2026-08-05 22:15:46 +02:00
can1357 1b7b8bb0c7 Merge PR #7743: fix(agent): strip output statuses from remote compaction (@roboomp) 2026-08-05 22:15:46 +02:00
can1357 0b0e7dd530 chore: normalized changelogs after merging 20 pull requests 2026-08-05 21:50:46 +02:00
can1357 f92f402456 Merge PR #7693: fix(install): make install.ps1 compatible with Windows PowerShell 5.1 (@metaphorics) 2026-08-05 21:50:26 +02:00
can1357 6c84c3e8fc Merge PR #7691: fix(utils): support PowerShell as custom shellPath (@metaphorics) 2026-08-05 21:50:25 +02:00
can1357 fa8922b40c Merge PR #7667: fix(web-search): keep GPT-5.6 hosted tools top-level (@roboomp) 2026-08-05 21:50:25 +02:00
can1357 c01d18eb57 Merge PR #7657: fix(read): split semicolon-delimited internal URLs (@revofusion) 2026-08-05 21:50:25 +02:00
can1357 dd1035fe98 Merge PR #7665: fix(model-hub): separate status glyph from role label (@jamesarch) 2026-08-05 21:50:25 +02:00
can1357 9c4f81f816 fix(coding-agent): move Bash preview fix to Unreleased 2026-08-05 21:50:25 +02:00