Commit Graph

115 Commits

Author SHA1 Message Date
can1357 7cd4c65574 feat(coding-agent): added auto-generated file detection controls and improved accuracy
- Added `edit.blockAutoGenerated` setting to control enforcement of auto-generated file detection.
- Improved auto-generated file detection to use language-specific comment parsing instead of broad regex patterns, reducing false positives.
- Enhanced marker detection to scan only leading header comments (1024-byte limit) rather than entire file prefix for better accuracy.
- Fixed tool argument validation to properly handle string 'null' values on optional LLM tool arguments.
- Improved type safety by changing validateToolCall and validateToolArguments return types from any to ToolCall["arguments"].
2026-03-18 10:53:37 +01:00
can1357 7d6c60f957 feat(tools): added quoted path support to grep, ast_grep, find, and ast_edit tools
- Added support for quoted paths in grep, ast_grep, find, and ast_edit tools to handle paths with spaces.
- Introduced normalizePathLikeInput() utility function for consistent path and glob parameter normalization across tools.
- Enhanced ast_grep error messaging to warn about parse issues and suggest narrowing path/glob or setting lang parameter.
- Added comprehensive tests for quoted path handling in grep, ast_grep, and find tools with pattern matching.
2026-03-16 14:26:22 +01:00
maximhar 94ad651d17 feat: add MCP tool discovery search (#352)
* Add MCP tool discovery search and live refresh

* Fix MCP discovery review feedback

* Address remaining MCP discovery review comments

* feat: compact MCP discovery search results

* fix: align MCP discovery search contract

* feat: add MCP server tool counts to discovery hints

* fix(agent): corrected stale toolChoice validation against active tools

- Fixed stale forced toolChoice passed to provider after mid-turn tool refresh by validating against active tools.
- Added refreshToolChoiceForActiveTools() to filter invalid tool choices when available tools change.
- Changed getToolChoice config to use computed function instead of static property for dynamic validation.
- Fixed MCP tool selection tracking in coding-agent to distinguish between discovery-enabled and non-discovery sessions.
- Updated search_tool_bm25 to filter already-selected tools before applying limit parameter.

---------

Co-authored-by: can1357 <me@can.ac>
2026-03-16 13:43:43 +01:00
Sense_wang 3c643bd01f fix(coding-agent): fail early when plan file is missing (#381)
Co-authored-by: haosenwang1018 <haosenwang1018@users.noreply.github.com>
2026-03-13 15:05:26 +01:00
can1357 09c0d28193 fix(coding-agent): corrected boolean coercion in fetch and executor modules
- Fixed boolean type coercion in fetch and executor modules by wrapping truncation flags with Boolean() cast.
- Removed maxBytes property from truncation metadata to simplify output metadata structure.
- Normalized optional result properties with explicit fallbacks in output-meta module.
- Updated test expectations to reflect undefined truncation properties instead of false/null values.
2026-03-13 15:05:11 +01:00
can1357 7aafa7547a feat(coding-agent): introduced pluggable code search provider system
- Added pluggable code search provider system supporting Exa and grep.app with provider selection via `providers.codeSearch` setting.
- Removed Exa-specific tools (`exa_linkedin`, `exa_company`, `exa_search_deep`, `exa_crawl`) and simplified web search tools to focus on core functionality.
- Refactored code search from Exa-only to provider-agnostic architecture with new `code_search` tool supporting context-aware grep.app queries and Exa fallback.
- Removed `exa.enableLinkedin` and `exa.enableCompany` configuration settings in favor of provider-based architecture.
- Added comprehensive test coverage for code search functionality including grep.app result normalization and provider fallback behavior.
2026-03-13 15:05:10 +01:00
can1357 2fcfc335dd fix(coding-agent): initialize settings in YouTube parallel test 2026-03-12 22:55:42 +01:00
can1357 7040d58396 feat(coding-agent): added Parallel AI provider for web search and content extraction
- Added Parallel AI provider integration for web search with fast and research modes.
- Added Parallel extract API for URL content and YouTube video extraction with fallback support.
- Added /login parallel command and PARALLEL_API_KEY environment variable authentication.
- Added providers.parallelFetch configuration setting to control Parallel extract usage.
- Integrated Parallel provider into web search priority order between Exa and Kagi.
- Updated HTML-to-text and YouTube scrapers to prefer Parallel extract over fallback providers.
2026-03-12 17:08:35 +01:00
can1357 1a5bbc3e51 feat(coding-agent): added details field to TodoItem for storing implementation specifics
- Added optional `details` field to TodoItem type for storing implementation specifics, file paths, and edge cases.
- Enhanced todo item display to show multi-line details with automatic indentation in interactive and reminder modes.
- Updated eager-todo system prompt to enforce separation of short task content (5-10 words) from detailed implementation information.
- Extended TodoWriteTool to support creating and updating tasks with details field via add_task and update operations.
- Added comprehensive test coverage for details field handling across todo operations (replace, add_task, update).
2026-03-11 00:56:54 +01:00
can1357 6535e9ce7e fix(coding-agent/tools): fixed path resolution to accept bare directory names in path lists
- Fixed path resolution to accept bare directory names without trailing slashes in comma/space-separated path lists.
- Added existence check for bare path tokens before rejecting them as invalid, allowing directory names like 'packages' to be resolved correctly.
- Added test case verifying grep tool accepts bare space-separated directory names without trailing slashes.
2026-03-11 00:55:12 +01:00
can1357 88364ee830 feat(coding-agent/tools): added multi-path search support to find, grep, ast_grep, and ast_edit tools
- Added support for comma/space-separated path lists in find, grep, ast_grep, and ast_edit tools, allowing users to search multiple directories with a single query (e.g., 'apps/,packages/,phases/' or 'apps/ packages/ phases/').
- Added resolveMultiSearchPath and resolveMultiFindPattern utility functions to path-utils for intelligent parsing and resolution of multi-path search inputs with automatic common base path detection.
- Updated tool documentation for find, grep, ast_grep, and ast_edit to clarify that path parameters accept files, directories, glob patterns, or comma/space-separated path lists.
- Refactored path resolution logic in find, grep, ast_grep, and ast_edit tools to use unified multi-path handling with intelligent delimiter detection (comma or whitespace).
2026-03-10 22:35:32 +01:00
can1357 e27afce0b2 feat: system prompt changes + better AST-grep guidance 2026-03-10 04:08:08 +01:00
maximhar 6394a87da2 feat(coding-agent): add inspect_image tool and image guidance flow (#295)
* feat(coding-agent): add inspect_image tool with dedicated renderer

Closes #280

* test(coding-agent): adapt block-images read test for inspect_image default

* fix(coding-agent): satisfy resolver test formatting

* test(coding-agent): stabilize inspect image tool tests

* test(coding-agent): normalize inspect image stubs
2026-03-10 02:49:32 +01:00
can1357 68ae4b7bee feat(coding-agent): added Tavily web search provider with OAuth auth
- Added Tavily web search provider with API key authentication and credential discovery from environment or database.
- Integrated Tavily as highest-priority search provider in fallback chain with structured response mapping and error handling.
- Added Tavily OAuth login flow in CLI and auth-storage with manual API key input and validation.
- Added comprehensive test suite for Tavily provider covering registration, response mapping, error handling, and credential validation.

Fixes #313
2026-03-09 16:11:38 +01:00
can1357 46be698745 feat(coding-agent): removed Kagi summarizer integration from fetch tool
- Removed Kagi Universal Summarizer integration from fetch tool and YouTube scraper.
- Removed `fetch.useKagiSummarizer` configuration setting from settings schema.
- Simplified renderHtmlToText() and renderUrl() functions by removing Kagi summarization fallback logic.
- Fixed indentation inconsistencies in test files from tabs to spaces.
2026-03-09 15:56:04 +01:00
can1357 6635129b7c test(coding-agent): updated 8 mock functions to accept unused parameters
- Updated 8 test mock functions to accept unused parameters for API compatibility.
2026-03-08 16:24:44 +01:00
can1357 486e585f39 refactor(coding-agent): migrated fetch mocks to hookFetch utility with resource cleanup
- Replaced vi.spyOn fetch mocking pattern with hookFetch utility across 5 test files.
- Migrated fetch mocks to use resource management with 'using' keyword for automatic cleanup.
- Removed @ts-expect-error comments related to fetch.preconnect type issues.
- Updated ts-hook-fetch rule documentation with expanded patterns and clearer lifecycle guidance.
2026-03-08 16:22:18 +01:00
can1357 005401e82a refactor: extracted fetch mocking into reusable hookFetch utility
- Extracted fetch mocking logic into reusable `hookFetch()` utility function with middleware-style handler pattern.
- Replaced manual `globalThis.fetch` assignment and restoration across 10 test files with `hookFetch()` calls using `using` statement for automatic cleanup.
- Implemented Disposable pattern with Symbol.dispose for fetch hook resource management, eliminating try-finally blocks.
- Exported `hookFetch` from utils public API to enable consistent fetch mocking across packages.
2026-03-08 16:16:54 +01:00
can1357 19feec9592 feat(bash): added env parameter to bash tool for safe variable passing
- Added `env` parameter to bash tool for safe environment variable passing without shell re-parsing.
- Added support for rendering partial environment variable assignments in command preview during streaming.
- Updated bash tool prompt to recommend `env` parameter for multiline, quote-heavy, and untrusted values.
- Refactored tool execution component to conditionally merge partial JSON arguments during streaming.
- Added helper functions for environment variable normalization, escaping, and formatting.
2026-03-08 15:53:33 +01:00
can1357 87b8716b8b style: fix biome formatting and import order 2026-03-08 04:49:26 +01:00
can1357 73355695f2 feat(coding-agent/tools): implemented path-scoped llms.txt discovery with content-quality fallback
- Moved llms.txt endpoint discovery to fallback strategy when rendered page content is low quality, prioritizing page-specific content over site-wide files.
- Enhanced llms.txt endpoint detection to scope candidates to the requested URL path, searching section-specific files before site-wide ones.
- Replaced getOrigin() with buildLlmEndpointCandidates() to generate path-scoped endpoint candidates with depth-based fallback strategy.
- Updated tryLlmEndpoints() to accept full URL and return endpoint metadata alongside content for better fallback tracking.
- Added 2 integration tests validating section-scoped llms.txt discovery and preference for rendered content over site-wide files.
2026-03-08 04:36:05 +01:00
can1357 72b036dcc0 refactor(coding-agent): simplified AST tool parameters and expanded documentation
- Renamed parameter names in ast-grep and ast-edit tools from `patterns`/`selector` to `pat`/`sel` for brevity across schema, implementation, and tests.
- Expanded ast-grep and ast-edit tool documentation with 12+ new usage guidelines, examples, and critical notes on pattern syntax, metavariable placement, and error handling.
- Updated CHANGELOG.md to document parameter renames and expanded tool guidance for AST pattern syntax and metavariable usage.
- Reformatted test assertions and type annotations across ast-edit and ast-grep test files for improved readability.
2026-03-08 03:08:38 +01:00
can1357 c3323160be feat(coding-agent): added glob parameter to grep tools for file filtering
- Added `glob` parameter to `ast_grep`, `ast_edit`, and `grep` tools for filtering files relative to `path`.
- Implemented `combineSearchGlobs()` utility to merge glob patterns from multiple sources instead of throwing errors.
- Changed `grep` tool to combine glob patterns when both `path` and `glob` parameters are provided.
- Updated tool documentation to recommend pairing `path`, `glob`, and `lang` for language-scoped search in mixed repositories.
- Added comprehensive test coverage for combined path and glob parameter handling across grep, ast_grep, and ast_edit tools.
2026-03-08 02:52:29 +01:00
can1357 568592ff77 chore(coding-agent/tools): removed obsolete TypeScript error suppressions from Kagi search tests
- Removed three @ts-expect-error comments that are no longer needed for fetch.preconnect mocking.
- The test mocks now work without requiring type suppression.
2026-03-08 00:06:12 +01:00
can1357 c4946363ca feat(coding-agent): added Ollama capability detection and improved provider integrations
- Added automatic Ollama model capability detection via /api/show endpoint to discover reasoning and input modality support.
- Improved Kagi API error handling with structured error parsing for JSON and plain text response formats.
- Fixed Cerebras streaming compatibility by omitting stream_options.include_usage parameter.
- Simplified API key credential storage to always replace credentials instead of merging for non-minimax providers.
- Updated Kagi Search API key format from 'kagi_...' to 'KG_...' and clarified beta access requirement in provider description.
Fixes #326.
Fixes #321.
Fixes #298.
2026-03-08 00:00:59 +01:00
can1357 7d5a230e26 fix: lowercased tool names in argument parsing
Fixes #324.
2026-03-07 23:53:16 +01:00
Adrian Glapiński 5770987f6e fix(coding-agent): parse Exa MCP plain-text web_search payloads (#303)
* fix(coding-agent): parse Exa MCP plain-text web_search payloads

* fix(coding-agent): preserve embedded Title lines in Exa plain-text parsing

* fix(coding-agent): support CRLF in Exa plain-text MCP parsing
2026-03-07 22:17:38 +01:00
HvC b93c6c0e12 Offer handoff as a compaction strategy (#305)
* idiomatic rust fixes

* idiomatic rust fixes

* display an image if we are fetching an image

* MIME type strictness

* codex nagging me

* codex nagging

* handoff instead of compaction as context filled strategy and surfacing

* handoff instead of compaction as context filled strategy and surfacing p2

* handoff instead of compaction as context filled strategy and surfacing p3

* handoff instead of compaction as context filled strategy and surfacing p4

* handoff instead of compaction as context filled strategy and surfacing p5

* handoff instead of compaction as context filled strategy and surfacing, fixes

* failing fetch test from the fetch tool updates

* handoff focus prompt skeleton

* handoff focus prompt skeleton p2

* fetch bugs

* further codex improvements

* further codex improvements

---------

Co-authored-by: Brit <lol@no.com>
2026-03-06 03:12:31 +01:00
HvC f70f1d2eab enable image rendering if the fetch tool gets one (#288)
* idiomatic rust fixes

* idiomatic rust fixes

* display an image if we are fetching an image

* MIME type strictness

* codex nagging me

* resize so we do not blow up the terminal we are in

* codex nagging

* codex nagging

* codex nagging

* codex nagging

* codex nagging

---------

Co-authored-by: Brit <lol@no.com>
2026-03-04 19:17:50 +01:00
can1357 50cd2310dc feat(pi-natives): added language module with 39 languages and tree-sitter bindings
- Added language module with 39 supported languages and tree-sitter parser bindings for ast-grep integration.
- Exported dedupeParseErrors utility function to remove duplicate parse error messages in tool output.
- Fixed duplicate parse error messages when multiple patterns fail on the same file.
- Replaced language alias lookup with O(1) phf::Map and added 30+ new language aliases (golang, julia, toml, zig, etc.).
- Migrated from ast-grep-language to direct tree-sitter language dependencies for improved language support.
2026-03-04 17:02:29 +01:00
can1357 d8384a488e feat(fetch): added optional Kagi summarizer toggle to fetch configuration
- Added `fetch.useKagiSummarizer` configuration setting to toggle Kagi Universal Summarizer usage in fetch tool.
- Updated fetch tool to conditionally apply Kagi summarization based on configuration setting.
- Added comprehensive test coverage for Kagi summarizer toggle behavior with mocked dependencies.
2026-03-04 02:34:47 +01:00
can1357 f9ac6b5c5f test(coding-agent): removed misaligned exa provider text assertion 2026-03-04 02:11:49 +01:00
can1357 b5a471d8db feat(ask): add back and forward multi-question navigation
Fixes #262
2026-03-03 15:09:46 +01:00
daandden 60086d8a49 fix(ask): restore ask timeout auto-select behavior (#269)
* fix(coding-agent): restore ask timeout auto-select behavior

Fixes #266

* fix(coding-agent): derive ask timeout from ui timeout events

* fix(coding-agent): enforce ask timeout during custom input

* fix(ask): preserve sub-second timeout precision in interactive flow

* fix(ask): reset hook input timeout on user activity

* fix(ask): keep expiration timeout when refreshing tick interval

* fix(ask): auto-select deterministic default on timeout

Fixes #266

---------

Co-authored-by: Vũ Anh Nguyễn <vu.anh.nguyen@mgm-tp.com>
Co-authored-by: can1357 <me@can.ac>
2026-03-03 14:45:06 +01:00
HvC 28d9de74ce Implement Windows Sixel support and terminal capability checks (#241)
* windows sixel imp

* windows sixel imp, terminal capability check, pessimistic sixel selection

* fix codex suggestions

---------

Co-authored-by: Brit <lol@no.com>
2026-03-01 22:23:05 +01:00
can1357 05ffa7ede1 fix(coding-agent): normalize Exa MCP tool payload parsing
Fixes #229
2026-03-01 11:36:34 +01:00
can1357 1643cd4673 feat(ask): migrated ask tool to AbortSignal-based cancellation for unified abort handling
- Replaced timeout-based cancellation with AbortSignal-based cancellation in ask tool for unified abort handling.
- Added signal parameter to UIContext select() and input() methods to support external cancellation propagation.
- Fixed race condition in dialog overlay handling by replacing direct resolve() calls with settled flag wrapper.
- Added comprehensive test coverage for ask tool cancellation behavior across user-initiated and timeout scenarios.
2026-03-01 11:19:32 +01:00
can1357 1c30f5c972 feat: introduced render_mermaid tool for ASCII diagram output
- Added render_mermaid tool to convert Mermaid diagrams to ASCII output with configurable rendering options.
- Added renderMermaid.enabled setting to control availability of the render_mermaid tool.
- Changed Mermaid rendering from PNG terminal graphics to ASCII text format across theme and TUI components.
- Migrated mermaid utilities from pi-tui to pi-utils package with new ASCII rendering functions.
- Removed PNG-based mermaid rendering APIs (getMermaidImage, renderMermaidToPng) in favor of ASCII alternatives.
2026-03-01 09:40:57 +01:00
can1357 6da102a11b feat(coding-agent): pass reason to apply/reject callbacks in PendingAction
PendingAction.apply() and reject() now receive the reason string that was
passed to resolve(). This lets custom tools surface the agent's rationale
in their apply/discard output or use it for logging.

- PendingAction interface: apply(reason) and reject?(reason)
- CustomToolPendingAction: same signatures, reject is optional
- CustomToolLoader: threads reject through when building PendingAction
- AstEditTool: accepts _reason (unused, reserved for future tracing)
- resolve.test: covers reason forwarding on apply and reject paths,
  and verifies reject return value replaces the default discard message
- docs/resolve-tool-runtime.md: updated interface table, built-in
  producer description, usage example, and developer guidance
2026-03-01 03:36:43 +01:00
can1357 c3d0bd9773 feat(coding-agent): deferrable tools, LIFO pending-action stack, custom tool pushPendingAction
- Introduce `deferrable?: boolean` on AgentTool, CustomTool, and ToolDefinition.
  AstEditTool sets it to true; resolve is now injected only when at least one
  active tool is deferrable (previously unconditional).

- Replace single-slot PendingActionStore (set/get/clear) with a LIFO stack
  (push/peek/pop/clear). Multiple deferrable tools can stage independent
  preview actions; resolve always consumes the topmost one first.

- Wire pendingActionStore through discoverAndLoadCustomTools / loadCustomTools /
  CustomToolLoader so custom tools can call pushPendingAction(action) to
  register a resolve-compatible pending action with label, apply callback,
  optional details, and optional sourceToolName.

- Export HIDDEN_TOOLS and ResolveTool from the SDK for manual tool composition.

- Add CustomToolPendingAction type and pushPendingAction to CustomToolAPI.

- Update createAgentSession to re-inject or remove resolve after the deferrable
  audit, consistent with createTools behavior.

- Add LIFO resolve test, update existing tests (set -> push, get -> peek).

- Add docs/resolve-tool-runtime.md covering PendingActionStore internals,
  built-in producer example, and custom tool usage guide.
2026-03-01 02:57:31 +01:00
can1357 cd6ed4ce8c refactor(tools): restructured tool rendering to inline highlighted format
- Simplified resolve tool output rendering from boxed layout to inline highlighted format for cleaner display.
- Updated resolve tool to parse source tool name from label using colon separator instead of separate metadata field.
- Replaced CachedOutputBlock with direct line rendering using padToWidth and inverse styling.
- Removed actionBadge helper function and consolidated action/state logic into single rendering path.
- Updated 1 test to verify inline rendering behavior and label parsing.
2026-03-01 02:44:52 +01:00
can1357 67e1aa40bf feat(coding-agent): introduced resolve tool for AST edit preview confirmation with reasoning
- Added `resolve` tool to apply or discard pending AST edit previews with required reasoning.
- Changed `ast_edit` tool to always return previews by default; removed `preview` parameter.
- Added `getToolChoice` callback option to dynamically override tool choice per LLM call.
- Implemented PendingActionStore for managing deferred tool action state across agent sessions.
- Updated agent loop to support dynamic tool choice resolution via optional callback.
2026-03-01 02:35:43 +01:00
can1357 69cadd7f60 chore: renamed AST tools 2026-03-01 01:45:22 +01:00
can1357 dc2fde6e0f fix(coding-agent): use vi.spyOn for fetch mocking in exa tests
Replace direct globalThis.fetch assignment with vi.spyOn + vi.restoreAllMocks
to prevent mock leaking to other test files.
2026-02-28 21:59:40 +01:00
can1357 a5470157da fix(coding-agent): fallback to Exa MCP without API key
Fixes #224
2026-02-28 21:49:58 +01:00
can1357 6a81ed9fa7 fix: resolve type errors in web-search-anthropic test 2026-02-28 21:34:28 +01:00
can1357 7d0807ec36 feat(ai,coding-agent): Google fingerprint hardening
providers/google-gemini-cli:
- parseGeminiCliCredentials() handles legacy, alias (project_id/refresh/expires),
  and enriched credential JSON formats
- shouldRefreshGeminiCliCredentials() + refreshGeminiCliCredentialsIfNeeded()
  proactively refresh OAuth tokens 60s before expiry for both providers
- normalizeAntigravityTools() converts parametersJsonSchema -> parameters
  in function declarations for Antigravity compatibility
- VALIDATED tool calling config applied for Antigravity + Claude model combos
- maxOutputTokens removed from generation config for Antigravity non-Claude models
- Antigravity system instruction injection scoped to Claude + gemini-3-pro-high models
- Antigravity session ID: signed decimal int63 derived from SHA-256 of first user
  message (or random bounded int63), replacing truncated hex hash
- Antigravity requestId uses agent-{uuid}; non-Antigravity requests omit
  requestId/userAgent/requestType from payload
- ANTIGRAVITY_DAILY_ENDPOINT corrected to daily-cloudcode-pa.googleapis.com;
  sandbox kept as fallback
- ANTIGRAVITY_SYSTEM_INSTRUCTION exported

oauth/google-antigravity:
- PKCE removed from OAuth flow (no code_challenge)
- loadCodeAssist metadata ideType changed to ANTIGRAVITY
- discoverProject uses single production endpoint; falls back to onboardUser LRO
  (up to 5 retries, 2s interval) instead of hardcoded default project ID
- ANTIGRAVITY_LOAD_CODE_ASSIST_METADATA exported

oauth/google-gemini-cli:
- PKCE removed from OAuth flow

oauth/index:
- getOAuthApiKey includes refreshToken, expiresAt, email, accountId in
  Gemini/Antigravity JSON payload for proactive refresh support

discovery/antigravity:
- Tries production daily endpoint first, sandbox as fallback
- Removed recommended/agentModelSorts filter; applies denylist instead
- ANTIGRAVITY_DISCOVERY_DENYLIST filters low-quality/internal models
- Request body no longer includes project field

coding-agent:
- gemini_image: corrected responseModalities to uppercase IMAGE/TEXT
- Gemini web search: endpoint fallback (daily->sandbox) with retry on 429/5xx,
  aligned Antigravity request metadata, ANTIGRAVITY_SYSTEM_INSTRUCTION injection
- buildGeminiRequestTools() helper for composable googleSearch/codeExecution/urlContext
- Web search schema: expose max_tokens, temperature, num_search_results params
- Web search: explicit provider falls back to auto chain when unavailable

Tests: google-antigravity-auth, google-gemini-cli-alignment, web-search-gemini
2026-02-28 21:17:57 +01:00
can1357 e7daffdda7 feat(ai,coding-agent): Claude fingerprint hardening
providers/anthropic:
- Bump claudeCodeVersion to 2.1.63; system instruction identifies as Claude Agent SDK
- X-Stainless-Os and X-Stainless-Arch now runtime-computed via mapStainlessOs/mapStainlessArch
- Remove X-Stainless-Helper-Method; update package version to 0.74.0, runtime to v24.3.0
- Remove fine-grained-tool-streaming-2025-05-14 from default beta set; add
  context-management-2025-06-27 and prompt-caching-scope-2026-01-05
- Accept-Encoding updated to 'gzip, deflate, br, zstd'
- Inject x-anthropic-billing-header block (SHA-256 payload fingerprint) and
  Claude Agent SDK identity block with ephemeral 1h cache-control for OAuth requests
- Auto-generate cloaking user IDs for OAuth metadata.user_id when absent/invalid
- applyClaudeToolPrefix / stripClaudeToolPrefix skip Anthropic built-in tool names
- buildClaudeCodeTlsFetchOptions attaches SNI + default TLS ciphers for api.anthropic.com
- Non-Anthropic base URLs now use Bearer auth regardless of OAuth status
- Prompt-caching no longer strips then re-applies; skips if blocks already have cache_control

oauth/anthropic:
- Token URL changed from platform.claude.com to api.anthropic.com
- OAuth scopes trimmed to org:create_api_key user:profile user:inference
- Code exchange strips URL fragment from callback code (fragment used as state override)
- AnthropicOAuthFlow exported
- OAuth callback server timeout extended from 2 min to 5 min

usage/claude:
- user-agent updated to claude-cli/2.1.63 (external, cli)
- anthropic-beta header extended with full production beta set

coding-agent web search:
- Anthropic provider uses buildAnthropicSearchHeaders instead of buildAnthropicHeaders

Tests: anthropic-alignment, anthropic-oauth, claude-usage-headers, web-search-anthropic
2026-02-28 21:17:57 +01:00
can1357 0a71899499 feat(ast,natives,coding-agent)!: multi-pattern ast_find and ops-based ast_replace
BREAKING CHANGE: ast_find parameter 'pattern' (string) is replaced by
'patterns' (string[]). ast_replace parameters 'pattern' + 'rewrite' are
replaced by 'ops: Array<{ pat: string; out: string }>'.

Native (pi-natives / crates/pi-natives):
- astFind accepts patterns[] array; all patterns run per file, results
  merged and sorted by path/line/column before offset+limit are applied
- astReplace accepts rewrites Record<string,string>; all patterns compiled
  once upfront and applied per file in a single pass
- Deterministic result ordering via BTreeSet/BTreeMap

Coding-agent tools:
- ast_find: multi-pattern deduplication, '>>' prefix on match-start lines,
  padded line numbers, directory-tree grouping (# dir / ## └─ file headers),
  scopePath/files/fileMatches in tool details
- ast_replace: ops[] interface with duplicate-pattern rejection, diff-style
  (-before/+after) previews grouped by directory, parse errors shown on
  zero-replacement path, fileReplacements in tool details
- Tool prompts updated to document new interfaces with multi-pattern examples
- Task item id maxLength raised from 32 to 48 characters
- Added ast_replace tool test suite
2026-02-28 20:48:27 +01:00
can1357 cba80c79c3 fix(schema): harden all provider schema normalizers with cycle detection, fixpoint iteration, and correctness fixes
## New: schema compatibility validation API

Add `validateSchemaCompatibility(schema, provider)` in
`packages/ai/src/utils/schema/compatibility.ts` that performs a static
audit of a JSON Schema against three provider targets:

- `openai-strict`: checks forbidden keys, required/properties symmetry,
  additionalProperties constraint, and that every node declares a type,
  combinator, or $ref
- `google`: checks unsupported keyword set and array-valued type
- `cloud-code-assist-claude`: checks forbidden keywords, array type,
  null type, nullable keyword, and combiner presence; also validates via
  AJV 2020 draft

Add `validateStrictSchemaEnforcement(original, result)` to assert the
fail-open contract: when strict enforcement succeeds the output must pass
openai-strict validation; when it fails the output must be the original
schema object (same reference).

Export both functions and their types from `./utils/schema/index.ts`.

## New: shared constants in fields.ts

Extract `COMBINATOR_KEYS` (`anyOf`, `allOf`, `oneOf`) and add
`CCA_UNSUPPORTED_SCHEMA_FIELDS` as exported constants, eliminating the
local duplicate in `strict-mode.ts` and providing a canonical field set
for Cloud Code Assist (much narrower than the Google set — CCA supports
validation keywords like `additionalProperties`, `minLength`,
`pattern`, etc.).

## Fix: cycle detection in all recursive schema traversals

All recursive walkers now carry a `WeakSet<object>` guard. Previously any
schema with a reference cycle (or a schema object that appears at two
nodes in the tree) would cause an infinite loop or a stack overflow:

- `sanitizeSchemaForStrictMode` / `enforceStrictSchema`
- `normalizeSchemaForCloudCodeAssistClaude`
- `normalizeNullablePropertiesForCloudCodeAssist`
- `stripResidualCombiners`
- `sanitizeSchemaImpl` (Google sanitizer)
- `hasResidualCloudCodeAssistIncompatibilities`

`hasResidualCloudCodeAssistIncompatibilities` previously returned `true`
for already-visited nodes, producing false positives that forced the CCA
fallback schema on valid (but multiply-referenced) schemas. It now
correctly returns `false`.

## Fix: stripResidualCombiners iterates to fixpoint

The previous single-pass approach missed chained combiner reductions
where one collapsed variant exposed another reducible combiner. The
rewriter now loops until no further reduction occurs.

## Fix: mergeObjectCombinerVariants required-field computation

The merged object schema now takes the intersection of all variants'
`required` arrays, then unions in own-level required properties that
exist in the merged schema. Previously the `required` field was silently
dropped from the flattened schema, making all properties effectively
optional.

## Fix: sanitizeSchemaForGoogle improvements

- Type inference for const-collapsed enums: type is derived from all
  variants (must unanimously agree), falling back to inference from enum
  values; mixed null/non-null infers the non-null scalar type and sets
  `nullable: true`
- Const→enum deduplication now uses deep structural equality instead of
  `Object.is`
- Recursion spreads the full options object so new fields (`unsupportedFields`,
  `seen`) are not silently dropped when descending into sub-schemas
- Array-valued `type` is filtered to strings before processing
- Removed incorrect stripping of `additionalProperties: false` (the
  field is valid and should be preserved)
- Parameterized `unsupportedFields` in `SanitizeSchemaOptions` enables
  code reuse between the Google and CCA sanitizers

## Fix: sanitizeSchemaForStrictMode / enforceStrictSchema

- `nullable: true` is now stripped during sanitization and expanded into
  `anyOf: [schema, {type: "null"}]` in the enforcer output, matching
  what OpenAI strict mode requires
- Type inference: `type: "array"` is inferred when `items` is present;
  a scalar type is inferred from uniform `enum` values
- Const→enum merge uses deep equality to avoid duplicate entries when
  both `const` and `enum` exist with the same value
- `additionalProperties` is now dropped unconditionally in sanitization
  (previously only object-valued `additionalProperties` was recursed;
  non-object values were passed through)
- `enforceStrictSchema` recurses into `$defs` and `definitions` blocks
- `enforceStrictSchema` handles tuple-style `items` arrays
- `enforceStrictSchema` skips double-wrapping: optional properties
  already expressed as `anyOf: [..., {type: "null"}]` are not wrapped again
- `tryEnforceStrictSchema` now caches results in a `WeakMap` keyed on
  the input schema object to avoid redundant work on repeated calls

## Fix: mergeCompatibleEnumSchemas deep equality

Uses `areJsonValuesEqual` instead of `Object.is` when deduplicating
enum members, so structurally equal objects are not duplicated.

## New: test coverage

- `packages/ai/test/schema-normalization.test.ts`: comprehensive unit
  tests for strict mode, Google, and Cloud Code Assist normalization
- `packages/ai/test/schema-compatibility.test.ts`: unit tests for all
  three provider targets in the new compatibility validator
- `packages/coding-agent/test/tools/provider-schema-compatibility.test.ts`:
  integration test that instantiates every builtin and hidden tool, runs
  their parameter schemas through all three provider pipelines, and
  asserts zero compatibility violations
2026-02-28 18:41:10 +01:00