Commit Graph

7222 Commits

Author SHA1 Message Date
roboomp 7fcdfd048f fix(hashline): rejected malformed snapshot tag suffixes
Aligned the runtime header parser with the formal grammar's no-`#`-in-filename rule: any `#` left in the path body after detecting the trailing `#XXXX` tag means the header is malformed (short `#1A2`, non-hex `#1A2G`, over-long `#1A2B5`, stale-tag copy-paste, line-suffixed tags), not a path with an embedded hash. Mirrored the same rule on the apply_patch recovery path.

Added strict and recovery regression coverage for the three malformed-tag shapes the reviewer named.
2026-06-06 01:43:50 +00:00
roboomp 7e42c281f8 fix(hashline): rejected line suffixes after snapshot tags
Rejected headers such as ¶src/file.ts#1A2B:42 as malformed headers instead of treating the whole tail as a hashless path and failing later in body parsing.

Added strict and apply_patch-recovery regression coverage for line-suffixed snapshot tags.
2026-06-06 01:38:02 +00:00
roboomp 52f86e9445 fix(hashline): rejected stale-tag junk after section header
Tightened the relaxed header parser so a 4-hex token sitting before whitespace + more content (e.g. `¶src/a.ts#1A2B copied from read`) still raises the focused "must be ¶PATH or ¶PATH#TAG" diagnostic instead of being silently re-interpreted as a hashless path.

Also stopped rejecting hashless paths whose last five characters look like #TAG with a non-hex digit, and mirrored the same anti-junk rule in the apply_patch recovery parser.
2026-06-06 01:38:01 +00:00
roboomp cc43defbf8 fix(hashline): accepted spaces in edit paths
Parsed hashline section headers by recognizing only a trailing #TAG as the snapshot delimiter, allowing whitespace inside valid paths.

Updated recovery parsing and grammar docs to match the runtime parser, and added regression coverage for canonical and recovered headers with spaces.

Fixes #1634
2026-06-06 01:38:01 +00:00
can1357 d9f5a8c7ac chore: bump version to 15.9.5 2026-06-06 01:14:48 +02:00
can1357 2e425b7b65 docs(coding-agent): documented auto discovery mode behavior
- Described "auto" default gating MCP tools past 40-tool threshold.
- Noted late resolution in createAgentSession after registry exists.
- Updated legacy mcp.discoveryMode mapping to MCP-only.
2026-06-06 01:14:14 +02:00
can1357 06eeda029d feat(coding-agent): added atomic branch+tag push to green command
- Resolved current branch and push remote for ci-green context.
- Updated prompt to push branch and tag together via git push --atomic.
2026-06-06 01:12:39 +02:00
can1357 f5a938f859 feat(coding-agent): added auto tool discovery mode
- Made "auto" the default, hiding MCP tools past 40-tool threshold.
- Centralized discovery mode resolution in shared mode helper.
- Activated search tool in createAgentSession once full registry exists.
2026-06-06 01:12:26 +02:00
can1357 641aea9074 test(tui): gated checkpoint scrollback oracle on at-tail probe
- Tracked actual reconcile result instead of assuming it always ran.
- Skipped clean-buffer assertion for ConPTY hosts deferring dirty history.
2026-06-06 01:07:52 +02:00
can1357 4a084eb1e6 test(coding-agent): added pendingImageLinks to input controller stubs
- Updated escape and skill-queue test fixtures for new imageLinks field.
2026-06-06 01:06:45 +02:00
can1357 efd6703580 fix: fixed native scrollback behavior for append-only assistant streams
- Fixed assistant transcript blocks to expose append-only commit-safe boundaries.
- Updated TUI live-region commit and pinned-paint logic to clamp commit-safe ends.
- Fixed long streamed assistant replies to remain in native scrollback on overflow.
2026-06-06 00:43:16 +02:00
can1357 23be7bad0b fix(tui): forced history rebuild on resize ED3 erase
- Treated terminal resize as explicit reconcile to erase mis-wrapped scrollback.
- Prevented viewport-repaint capping from leaving corrupt history on screen.
2026-06-06 00:32:59 +02:00
can1357 ca143a4e08 feat(coding-agent): pinned turn-ending provider errors above editor
- Added a persistent error banner so stream errors survive transcript scroll.
- Cleared the banner when the next turn starts.
- Skipped pinning for aborts and normal stops.
2026-06-06 00:23:07 +02:00
can1357 340ac31122 fix(coding-agent): appended queued image messages synchronously
- Removed async image-link materialization between user message_start and addMessageToChat.
- Fixed steering bubbles rendering below the tool output they were sent to steer.
- Materialized clickable image links via synchronous blob-store fallback instead.
2026-06-05 23:57:01 +02:00
can1357 47e34f9ba6 fix(agent): surfaced Anthropic output-blocked stream errors
- Emitted content-filter blocks as normal assistant error lifecycle events.
- Prevented interactive clients from silently dropping the streaming bubble.
- Finalized an existing assistant stream when blocked mid-stream.
2026-06-05 23:56:00 +02:00
can1357 388e6462c3 fix(coding-agent): fixed cold-launch scrollback and frozen abort labels
- Cleared native scrollback on `omp`/`omp -c` so the resumed transcript no longer stacks on the prior run's welcome screen.
- Tracked assistant block finalization so aborted streaming messages stay repaintable when status rows land beneath them on ED3-risk terminals.
2026-06-05 23:50:49 +02:00
can1357 da636e3f51 feat(coding-agent): enabled clickable image and path links across chat and tools
- Added image-reference rendering to make `[Image #N]` placeholders clickable in chat.
- Added MIME-aware image blob materialization with extensioned sidecar paths.
- Added clickable path, line, and URL hyperlinks for read, search, and fetch outputs.
- Hardened OSC8 hyperlink emission with URI validation and control-byte/idempotency checks.
2026-06-05 23:38:22 +02:00
can1357 70c94efabe fix(coding-agent): froze live region by block finalization state
- Replaced bottom-most-block liveness with a finalization check so the live region spans every still-mutating block.
- Kept unfinalized tools repaintable when out-of-band inserts append finalized blocks below them.
- Recomputed blocks as they cross out of the live region to seal their final content.
2026-06-05 23:34:05 +02:00
can1357 3f757f9d58 refactor(tui): unified resize handling into clean reset + redraw
- Replaced conditional viewport-repaint/history-rebuild branches with an unconditional reset on any geometry change.
- Multiplexer panes still repaint in place since pane scrollback cannot be erased.
- Dropped no-overflow and confirmed-scrolled guards: scrolled readers snap to bottom and shell scrollback is cleared.
- Updated and removed tests reflecting the new reset behavior.
2026-06-05 23:18:25 +02:00
can1357 9114607ce6 feat(coding-agent): surfaced active model in system prompt
- Rendered the active model identifier into the project prompt.
- Rebuilt the cached base prompt on model switch to avoid staleness.
2026-06-05 23:08:44 +02:00
can1357 78700a2c77 feat(ollama): added OLLAMA_HOST and OLLAMA_CONTEXT_LENGTH support
- Used OLLAMA_HOST for implicit discovery when OLLAMA_BASE_URL is unset.
- Applied OLLAMA_CONTEXT_LENGTH override to discovered context budgeting.
2026-06-05 22:47:40 +02:00
can1357 388deb1c14 chore: bump version to 15.9.4 2026-06-05 21:59:43 +02:00
can1357 510f3ad33f fix(web-search): rendered full markdown answer when expanded
- Stopped capping the synthesized answer at 12 lines while sources expanded in full.
- Rendered the answer through Markdown so headings, bold, lists, and code display formatted.
- Added regression tests for expanded/collapsed answer rendering.
2026-06-05 21:57:20 +02:00
can1357 4e8fa1672f test(tui): added regression coverage for process terminal reflow and scrollback behavior
- Added a deterministic ProcessTerminal render harness with real TUI and resize simulation.
- Added reflow tests for OS resize fallback, in-band precedence, and split in-band parsing.
- Added a regression test ensuring stale live-region rows are cleared after rerender.
- Removed the duplicate in-band authority assertion from terminal-appearance tests.
2026-06-05 21:06:06 +02:00
can1357 5868b9b076 Merge remote-tracking branch 'origin/farm/b61bffd8/plugin-install-local-path' 2026-06-05 20:43:15 +02:00
can1357 45d2baa5c5 Merge remote-tracking branch 'origin/farm/7f076fbd/bound-local-model-memory' 2026-06-05 20:43:11 +02:00
can1357 19f7858cab Merge remote-tracking branch 'origin/farm/db4fe133/run-watch-honor-explicit-repo' 2026-06-05 20:42:49 +02:00
can1357 723b3a04f5 Merge remote-tracking branch 'origin/farm/f7d7ced2/openai-stream-idle-timeout' 2026-06-05 20:42:46 +02:00
can1357 51b7d77623 fix(tui): kept mutable live-region rows out of native scrollback
- Prevented foreground streams from committing live rows, which left a stale pending tool box above the running box.
- Added initial live-region pinned paint for ED3-risk hosts with unknown viewport.
- Reconciled stale cached DEC 2048 geometry against live OS dims on resize so content reflows.
2026-06-05 20:42:41 +02:00
can1357 5184b565e1 fix(eval): kept Python kernel alive when parallel() cell interrupted
- Resolved in-flight bridge calls the instant the cell's signal aborts.
- Let the kernel unwind via KeyboardInterrupt instead of being hard-killed.
- Preserved persistent session state across wide subagent fan-out teardown.
2026-06-05 20:42:29 +02:00
roboomp 3b3bb696d8 fix(ai): honored openai idle timeout for ollama streams
Route the lazy native Ollama stream watchdog through the OpenAI-family idle timeout resolver so PI_OPENAI_STREAM_IDLE_TIMEOUT_MS can floor first-event waits when the generic first-event timeout is lower.\n\nFixes #1952
2026-06-05 18:36:29 +00:00
roboomp 7a76333d93 style: bun run fix 2026-06-05 18:14:45 +00:00
roboomp bc55af78ad fix(github): revalidated cwd repo before trusting run_watch head
The no-selector run_watch guard was using resolveDefaultRepoMemoized via tryResolveCurrentRepo, so a long-lived process could validate against a stale cwd-to-repo cache entry after the checkout or GitHub remote at that path changed. That allowed the guard to trust the current HEAD for an explicit repo based on the old cached repository.

Add a fresh best-effort cwd repo lookup for safety checks and use it before deriving branch/HEAD. Cached lookup remains for search default scoping where stale data only affects a convenience fallback. Added a regression test that populates the cache, changes the mocked repo at the same cwd, and asserts run_watch rejects before issuing API calls.

Refs #1949 #1951
2026-06-05 18:14:40 +00:00
roboomp c46cfb252a style: bun run fix 2026-06-05 18:10:23 +00:00
roboomp c10809faec fix(github): accepted case-only run url repo matches
resolveGitHubRepo rejected calls that supplied both an explicit repo and a full Actions run URL when the two owner/repo slugs differed only by casing. GitHub repository paths are case-insensitive, so this was the same class of false mismatch as the cwd guard fixed earlier.

Compare repo slugs through a shared ASCII case-insensitive helper and use it for both the run-URL consistency check and the cwd guard. Added a regression test for repo=cagedbird043/cxf with a run URL under CagedBird043/CXF.

Refs #1949 #1951
2026-06-05 18:10:18 +00:00
roboomp 1f32b8aaf9 fix(github): compared run_watch repo guard case-insensitively
GitHub owner/repo slugs are case-insensitive; `gh repo view` returns
the canonical casing while callers may pass any casing. The new guard
used strict equality, so a caller in the correct repo who typed
`owner/repo` while the canonical form was `Owner/Repo` was forced to
pass a redundant `branch`/`run` selector. Normalize both sides via
toLowerCase() before deciding the cwd is a different repository.

Regression test covers the casing-only match.

Refs #1949 #1951
2026-06-05 18:06:39 +00:00
roboomp 8135c91f3d style: bun run fix 2026-06-05 18:02:51 +00:00
roboomp 31950067f1 fix(github): honored explicit repo in run_watch instead of falling back to cwd
executeRunWatch passed undefined for the explicit `repo` to
resolveGitHubRepo, so a call like
`{op: "run_watch", repo: "owner/cxf", branch: "main"}` from a nested
or umbrella workspace silently fell through to `gh repo view` in cwd
and streamed `watching <sha> on <cwd-repo>` against the wrong
repository.

Route params.repo through resolveGitHubRepo so the explicit owner/repo
wins over both cwd inference and run-URL inference. When no `branch`
or `run` selector is given, refuse to derive the watched commit from
`git HEAD` unless the cwd actually points at the resolved repo —
otherwise raise a ToolError telling the caller to pass `branch` or
`run` instead of silently rebinding to an unrelated commit.

Also deduped resolveSearchRepoScope's best-effort cwd resolution into a
shared tryResolveCurrentRepo helper used by the new guard.

Fixes #1949
2026-06-05 18:02:45 +00:00
roboomp 7b488b5675 fix(cli): routed plugin install local paths through link instead of npm
`omp plugin install .` (and any cwd-relative, absolute, or tilde-prefixed
spec) failed with `Invalid package name: .` because
`classifyInstallTarget` only emitted `marketplace` / `npm`, so local paths
fell through to `validatePackageName`, which rejects every non-npm name.

The classifier now emits a third `local` arm for `.`, `..`, `./…`,
`..\…`, `~`, `~/…`, `~\…`, `/…`, `C:\…`, `C:/…`, and `\\unc` specs.
`handleInstall` dispatches that arm to `PluginManager.link()` — the same
code path as `omp plugin link <path>` — so the two verbs are
interchangeable for local plugin directories. `--dry-run` short-circuits
before any filesystem work, `--scope`/`--force` surface a warning since
they are no-ops here (link is idempotent, and scope only governs
marketplace installs).

Coverage: thirteen-case classifier matrix in `marketplace/cli.test.ts`
plus a new `plugin-install-local.test.ts` with spy-based routing checks
for `./`, `../`, `/`, `~/`, plus a real-filesystem test that stages a
plugin folder, invokes `runPluginCommand`, and verifies the resulting
symlink + lockfile entry. The new test calls `mock.restore()` in
`afterEach` so `piUtils` / `MarketplaceManager.prototype` spies do not
leak into sibling suites.

Fixes #1945
2026-06-05 17:48:54 +00:00
can1357 6e32b30a64 test(tui): forced sync output for wrapper-bracketing assertions
- Set PI_FORCE_SYNC_OUTPUT in beforeEach to keep BSU/ESU pairs deterministic.
- Restored saved sync-output env vars in afterEach.
- Prevented CI's unknown TERM from disabling sync output.
2026-06-05 19:15:39 +02:00
roboomp 6252972ab0 fix(providers): recycled failed local model workers
Hard-killed the tiny-model subprocess after worker-reported execution errors so ONNX native allocations are released before retries.

Added a fake-worker regression for the unknown-failure path and queued local completions.

Fixes #1940
2026-06-05 16:48:08 +00:00
can1357 61f11a6ce0 fix(tui): blocked destructive scrollback replay on unknown terminal viewports
- Blocked checkpoint scrollback replay unless native viewport-at-bottom proof succeeded.
- Expanded ED3-risk terminal detection to include SSH, multiplexer, WT-like, and unknown profiles.
- Added sync-output defaults with PI_TUI_SYNC_OUTPUT and PI_FORCE_SYNC_OUTPUT overrides.
- Deferred transcript thawing until native scrollback refresh returned true.
- Adjusted non-escape parsing to emit one Unicode scalar and raised timeout to 75ms.
2026-06-05 17:47:47 +02:00
can1357 492b454141 fix(archive): read zip central directory without inflating members
- Parsed zip metadata via central directory and lazy ranged reads.
- Inflated member contents only when a specific entry is read.
- Prevented large or corrupt zips from freezing directory reads.
2026-06-05 17:38:24 +02:00
can1357 dea068ca30 test(ai): made first-event timeout retry deterministic with fake timers
- Added onIteratorStart hook to detect the hung first attempt.
- Drained microtasks and advanced fake timers to fire the watchdog.
2026-06-05 17:14:27 +02:00
can1357 529a9dd351 chore: bump version to 15.9.3 2026-06-05 16:36:02 +02:00
can1357 1002ba0242 feat(search): accepted internal URL selectors as line filters
- Added selectorLineRanges to extract ranges from raw/conflicts selectors.
- Routed internal URLs through URL-aware splitter in content search.
- Treated display-mode selectors as whole-resource searches instead of rejecting.
2026-06-05 16:29:58 +02:00
can1357 0e706c7d69 Merge remote-tracking branch 'origin/farm/80ff1f29/parameterize-bot-login-in-system-prompts' 2026-06-05 16:28:21 +02:00
can1357 d24f3235ed fix(tui): guarded against invalid codepoints in text extraction
- Returned empty string for out-of-range or surrogate codepoints.
- Prevented String.fromCodePoint from throwing on bad cell data.
2026-06-05 16:27:57 +02:00
can1357 f75cb3d416 fix(tui): dropped eager rebuild mode immediately when stream settled
- Disabled eager native-scrollback rebuild at once when no render is pending, so later content mutations don't inherit foreground-stream privileges.
- Deferred ED3-risk unknown-viewport shrinks completely instead of padded-repainting over scrolled history.
- Skipped suffix-suppression and offscreen-mutation branches on resize so geometry reflow repaints at the new size.
2026-06-05 16:27:26 +02:00
roboomp ae89b68b90 fix(robomp): parameterized bot identity in system prompts
system_append.md and system_append_pr_review.md hardcoded the literal
'robomp' as the bot persona, so the agent self-mentioned an account
that does not exist when deployments configure ROBOMP_BOT_LOGIN to a
different login. Affected users saw the agent ask for @robomp mentions
that GitHub never resolved to the actual bot.

Thread the configured login through persona.system_append and
persona.system_append_pr_review as a bot_login keyword, render it
via the existing {{bot_login}} placeholder, and pass
settings.bot_login at the worker callsite. Regression test asserts the
templated login lands in both prompts and the legacy literal is gone.

Fixes #1932
2026-06-05 14:15:07 +00:00