Commit Graph

232 Commits

Author SHA1 Message Date
can1357 1696047d8e fix(coding-agent): reserve all builtin slash-command names against extension commands 2026-06-10 09:51:46 +02:00
can1357 db3a54cbe5 Merge pull request #2108: feat(memory): add runtime API and exact vector index 2026-06-10 08:32:09 +02:00
DarkPhilosophy 001c16eaa0 feat(memory): expose runtime to extensions 2026-06-10 08:31:32 +02:00
Theo Mathieu b0063a08f0 fix(acp): include builtin aliases in reserved-command filter for extensions
ACP_BUILTIN_SLASH_COMMANDS only carries primary names; the reserved set
passed to getRegisteredCommands was therefore missing aliases like
"models" (/model) and "force:" (/force). An extension registering one
of these aliases would appear in the palette but the builtin would win
at dispatch time (lookupBuiltinSlashCommand searches aliases too).

Export ACP_BUILTIN_RESERVED_NAMES from acp-builtins — the union of all
primary names and aliases for ACP-surfaced builtins — and use it as the
reserved set. Widen getRegisteredCommands parameter to ReadonlySet since
it only calls .has().

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-10 08:26:07 +02:00
can1357 a25d521cab refactor(catalog): baked thinking metadata into buildModel pipeline
- Replaced minLevel/maxLevel range with explicit efforts array plus baked effortMap/supportsDisplay wire facts.
- Removed runtime enrichment layer and modelOmitsReasoningEffort; providers now read baked fields.
- Fixed dotted Opus 4.7/4.8 ids missing adaptive display via classifier-based predicates (#1373).
- Bumped model cache schema to v4 to invalidate pre-efforts rows.
2026-06-10 07:22:11 +02:00
can1357 ae415199dc feat: added build-time compatibility in ModelSpec/buildModel pipeline
- Centralized catalog and registry handling on `ModelSpec` and `buildModel`, resolving compatibility at model build time.
- Removed runtime compatibility detectors and switched provider request flows to direct `model.compat` reads.
- Added compat fields (`supportsReasoningParams`, `alwaysSendMaxTokens`, `strictResponsesPairing`, `whenThinking`).
- Persisted explicit compatibility overrides through `compatConfig` in discovery and cache merge paths.
2026-06-10 06:20:51 +02:00
can1357 dc5c93462f feat: rerouted worker subprocesses through the bundled CLI host entrypoint
- Rerouted sync, tab, js-eval, and tiny workers to re-enter CLI modes via `__omp_*` selectors.
- Adjusted `cli.ts` startup to dispatch worker entrypoints before parsing and exit 1 on uncaught errors.
- Bundled CLI as `dist/cli.js` in prepack, switching `omp` binary and published files.
- Removed explicit Bun `--compile` worker entrypoints from build/release scripts in favor of host-entry dispatch.
- Added `declareWorkerHostEntry()` and `workerHostEntry()` environment helpers and `PI_COMPILED` binary detection.
2026-06-10 03:57:31 +02:00
can1357 69a8a6aa6c Merge remote-tracking branch 'origin/farm/73573d1a/legacy-pi-compat-override-fallback' 2026-06-09 19:19:38 +02:00
roboomp fe34d0f392 fix(task): forward extension paths to subagents, rebind extensions per session
Same shape of bug the reviewer flagged for custom tools: forwarding
`LoadExtensionsResult` from parent to subagent reused Extension instances
whose factories closed over the parent's `ExtensionAPI` — cwd, eventBus,
and runtime all pointed at the parent. Any tool/handler/command that
referenced `api.exec()`, `api.events`, or `api.runtime` still acted on the
parent session/worktree from inside an isolated subagent.

Forward only the path list; each session rebuilds extensions through
`loadExtensions` so factories see the right `ExtensionAPI`.

- `extensibility/extensions/loader.ts`: extract `discoverExtensionPaths`
  (FS scan only) from `discoverAndLoadExtensions`. The combined helper now
  composes the two. New export added to the package barrel.
- `sdk.ts`:
  - Add `discoverSessionExtensionPaths()` (the `disableExtensionDiscovery`-aware
    path-only counterpart of `loadSessionExtensions`).
  - Add `preloadedExtensionPaths?: string[]` to `CreateAgentSessionOptions`.
    Three loader branches: `preloadedExtensions` (CLI same-process reuse,
    still shallow-cloned), `preloadedExtensionPaths` (subagent: skip scan,
    reload locally), or full discovery.
  - Document `preloadedExtensions` as same-process-only; subagent
    forwarding MUST use `preloadedExtensionPaths`.
- `tools/index.ts`: `ToolSession.extensionsResult` → `extensionPaths:
  string[]` for the same reason.
- `task/executor.ts` and `task/index.ts`: forward `extensionPaths`. Drop
  the forward for the isolated `runSubprocess` branch — worktree cwd ≠
  parent cwd, so the subagent re-discovers extensions against its own
  tree.
- New `test/sdk-extensions-per-session-binding.test.ts` pins the contract:
  two `loadExtensions` calls on the same path with different `cwd` and
  different `EventBus` instances yield distinct Extension + runtime
  objects whose factories close over the per-call bindings.
- Updated `executor-pass-through` and `sdk-preloaded-extensions-isolation`
  tests for the new option name and comment context.

Refs PR review on #2193
2026-06-09 14:19:47 +00:00
roboomp dde53a8f18 fix(task): forward custom-tool paths to subagents, rebind tools per session
Reviewer flagged that forwarding `LoadedCustomTool[]` from a parent session
to a subagent reused tool instances whose factories had closed over the
parent's `CustomToolAPI` — `cwd`, `exec`, `pushPendingAction`, and `ui` all
pointed at the parent. In isolated tasks the tool would `exec` against the
parent worktree and queue pending actions on the parent session.

Forward only the path list; let each session rebuild tools through
`loadCustomTools` so factories see the right `CustomToolAPI`.

- `extensibility/custom-tools/loader.ts`: extract `discoverCustomToolPaths`
  (FS scan only) from `discoverAndLoadCustomTools`; export
  `ToolPathWithSource`. The combined helper is now `discoverCustomToolPaths`
  + `loadCustomTools`.
- `sdk.ts`: replace `preloadedCustomTools` (`LoadedCustomTool[]`) with
  `preloadedCustomToolPaths` (`ToolPathWithSource[]`). The custom-tools
  block runs `loadCustomTools` unconditionally; only the path scan is
  skipped when the caller pre-discovered it.
- `tools/index.ts`: `ToolSession.loadedCustomTools` →
  `ToolSession.customToolPaths` for the same reason.
- `task/executor.ts` and `task/index.ts`: forward `customToolPaths`.
  Drop the forward for isolated subagents — the worktree shifts `cwd`, so
  the subagent re-discovers tools against its own working tree.
- New `test/sdk-custom-tools-per-session-binding.test.ts` pins the contract:
  two `loadCustomTools` calls on the same path with different `cwd` and
  different `pushPendingAction` callbacks yield distinct tool instances
  whose factories see the per-call bindings.
- Updated `executor-pass-through` and `sdk-preloaded-extensions-isolation`
  tests for the new option name and added a `ToolPathWithSource` fixture.

Refs PR review on #2193
2026-06-09 14:09:37 +00:00
roboomp 4a6362192d fix(legacy-pi-compat): validated package-root override targets before rewrite
The package-root override branch of `resolveCanonicalPiSpecifier` returned
the bunfs override path without checking the target was actually present,
so when `bun --compile` quietly dropped one of the extra entrypoints
(observed on macOS arm64 release binaries), the static rewrite emitted a
`file://` URL to a missing module. The #1216 fallback only fired on the
throwing `getResolvedSpecifier` path, so the override never threw and the
rewrite committed the bad URL — extensions silently failed to load.

Each override target is now checked with `fs.existsSync` at module init.
Missing entries are dropped from `LEGACY_PI_PACKAGE_ROOT_OVERRIDES` so
`resolveCanonicalPiSpecifier` falls through to `getResolvedSpecifier`,
which throws under bunfs and triggers the existing rewrite catch — Bun
then resolves the canonical `@oh-my-pi/pi-*` specifier from the
extension's own `node_modules`.

Fixes #2168
2026-06-09 06:33:53 +00:00
can1357 eb1a46baf5 feat: added injectable fetch transport across AI and coding network flows
- Added optional FetchImpl fields to compaction, proxy, AI, coding-agent, and mnemopi options.
- Threaded injected fetch implementations through OAuth, discovery, and search/LLM request flows.
- Removed exported hookFetch utility and its package entrypoint from utils.
- Replaced global-fetch test monkeypatching with per-test FetchImpl mocks across test suites.
2026-06-09 04:51:17 +02:00
can1357 31b6f0bf31 refactor(ai): consolidated provider config into single-source registry
- Derived descriptors, default-model map, env keys, login list, and refresh dispatch from one ProviderDefinition per provider.
- Disabled OpenAI Codex stream obfuscation and interrupted whitespace-only tool-call argument deltas.
- Derived auth-broker callback ports and paste-code login set from the registry.
2026-06-08 18:48:43 +02:00
can1357 bda3102451 ux(coding-agent): updated status glyphs and fixed extension model discovery refresh
- Added status.done and tool.* symbols to theme mappings and presets.
- Replaced generic success glyphs with contextual +/-, tool icons, and warnings.
- Mapped tool/task/job completions to status.done or status.enabled with icon overrides.
- Triggered runtime provider refresh after extension registration and warned on failure.
2026-06-08 18:28:15 +02:00
Guts 83c8105be6 fix(mcp): declare approval tier for MCP tools to prevent hangs in non-yolo mode
MCPTool and DeferredMCPTool now declare approval = 'write' instead of
implicitly defaulting to 'exec'. Without this, the approval system
requires user confirmation for every MCP tool call in non-yolo modes,
but the confirmation prompt never renders in the TUI while streaming,
causing the agent to hang indefinitely.

Also propagate the approval property through customToolToDefinition()
in sdk.ts, which was silently dropping it during CustomTool ->
ToolDefinition conversion.
2026-06-07 16:22:33 +02:00
can1357 e5e93ff762 feat(packages/coding-agent): enabled setup-version-gated startup flow
- Deferred setup wizard import until setup was forced or version stale.
- Dynamically loaded ACP, RPC, and print mode runners only when used.
- Added a marketplace auto-update scheduler with off-mode early exit and non-blocking errors.
- Added setup-version assertions to keep CURRENT_SETUP_VERSION aligned with scenes.
2026-06-06 22:58:33 +02:00
can1357 8a5b99a967 feat(coding-agent): enabled anonymous Perplexity fallback and updated web-search checks
- Added anonymous Perplexity authentication mode for unauthenticated web searches.
- Switched web-search setup checks to use `isExplicitlyAvailable` and removed key enforcement in doctor.
- Updated Perplexity OAuth flow to reuse auth handling for all non-key searches and anonymous responses.
- Updated CLI and provider option help text to mark the Perplexity key optional with fallback.
2026-06-06 19:42:16 +02:00
can1357 40ed8852b5 feat(coding-agent): added app.display.reset bound to Ctrl+L
- Added `TUI.resetDisplay()` to force an immediate full-frame replay including native scrollback.
- Moved the persistent model selector default from Ctrl+L to Alt+M, preserving existing user remaps.
- Reserved Alt+M so extensions cannot shadow the model selector shortcut.
2026-06-06 17:19:57 +02:00
can1357 f7974e0f23 Merge remote-tracking branch 'origin/farm/f646bd45/fix-windows-ctrl-enter-followup' 2026-06-06 13:38:52 +02:00
can1357 2e425b7b65 docs(coding-agent): documented auto discovery mode behavior
- Described "auto" default gating MCP tools past 40-tool threshold.
- Noted late resolution in createAgentSession after registry exists.
- Updated legacy mcp.discoveryMode mapping to MCP-only.
2026-06-06 01:14:14 +02:00
can1357 06eeda029d feat(coding-agent): added atomic branch+tag push to green command
- Resolved current branch and push remote for ci-green context.
- Updated prompt to push branch and tag together via git push --atomic.
2026-06-06 01:12:39 +02:00
roboomp c4fa93e460 fix(plugins): preserved null package import exclusions
Kept explicit null package imports as exclusions so exact entries and active conditions do not fall through to wildcard or fallback targets.\n\nFixes #1889
2026-06-05 07:59:28 +00:00
roboomp 590799b0af fix(extensions): reserved ctrl+q so extensions can't shadow the follow-up default
ExtensionRunner#getShortcuts() accepted ctrl+q because #RESERVED_SHORTCUTS
predated the new default, and InputController registers extension
shortcuts before the followUp keybinding, so the editor's custom-key
map silently overwrote the extension handler. Now ctrl+q is reserved
alongside the other built-in chords and the extension authoring docs
list it as such.

Addresses code review on #1905.
2026-06-05 05:34:06 +00:00
roboomp 994ae513f5 fix(plugins): skipped non-source package import targets
Returned null from resolveSourceModuleFile when a package imports alias points at a JSON, WASM, or other non-code asset so the on-load rewrite hook no longer claims it and forces it through the JS loader. Bun resolves these targets natively. Added a regression where #schema maps to a .json file imported with a JSON type assertion.\n\nFixes #1889
2026-06-04 21:54:33 +00:00
roboomp 251d9152fc fix(plugins): honored package import condition order
Selected conditional package import targets by package.json object order for supported Bun runtime conditions, including node, instead of probing a fixed precedence list. Added a regression where node precedes import and must be selected for a plugin-local #src/* import.\n\nFixes #1889
2026-06-04 21:51:26 +00:00
roboomp 6e47ae8150 fix(plugins): matched side-effect imports in compat rewrite
Extended the legacy Pi, TypeBox, package-import alias, and extension graph regexes to recognise the bare \"import \\"specifier\\";\" shape so side-effect-only loads such as \"import \\"#src/register\\";\" walk into the source graph and get their legacy @(scope)/pi-* imports rewritten. Added a regression that loads a plugin with a side-effect alias import whose target contains a legacy scope import.\n\nFixes #1889
2026-06-04 21:49:06 +00:00
roboomp b2c6b7becf fix(plugins): loaded package import extensions
Resolved plugin-local package import aliases while loading extension source graphs so legacy Pi plugins with TypeScript source imports like #src/* register correctly under OMP. Added a regression covering legacy scope rewrites through a package import module.\n\nFixes #1889
2026-06-04 21:42:52 +00:00
Can Bölük 8d6771490a Merge pull request #1803 from fabkho/fix/agent-skills-spec-compat
fix: recognize disable-model-invocation from Agent Skills spec
2026-06-04 06:07:43 +03:00
can1357 7f271f9b9d feat(coding-agent): added native selection markers to ask dialogs
- Added `selectionMarker`, `checkedIndices`, and `markableCount` options to render radio/checkbox glyphs per row.
- Moved checkbox rendering from inline label prefixes into the selector component.
- Kept trailing control rows like "Other"/"Done" on the plain cursor.
2026-06-04 03:43:17 +02:00
can1357 dc4aeb7b88 refactor(coding-agent): renamed todo_write tool to todo
- Renamed `TodoWriteTool` to `TodoTool` and its source/prompt files.
- Updated tool registration, schema, renderers, and gating to `todo`.
- Adjusted cursor provider native tool names and tests to match.
- Renamed strike-animation constants and `todo-error-reminder` type.
2026-06-04 02:45:30 +02:00
fabkho 6e49d33b71 fix: recognize disable-model-invocation from Agent Skills spec
The Agent Skills standard (agentskills.io/specification) uses
`disable-model-invocation: true` to hide skills from auto-discovery.
OMP only recognized `hide: true`. This patch treats both as equivalent,
improving compatibility with skills authored for Pi, Claude Code, and
other harnesses following the standard.

Changes:
- Check `disableModelInvocation` (camelCase after frontmatter parsing)
  in all 3 skill-loading paths
- Add `disableModelInvocation` to SkillFrontmatter type with JSDoc
- Add regression test for disable-model-invocation frontmatter
- Add changelog entry

Ref: https://agentskills.io/specification#frontmatter-required
2026-06-03 22:23:53 +02:00
can1357 bce01ce0db refactor(jj): restructured exports into namespaced repo and diff objects
- Grouped `isRepository`, `workspaceRoot`, and `clearWorkspaceRootCache` under a `repo` namespace (`repo.is`, `repo.root`, `repo.clearRootCache`).
- Promoted `diff` to a named export with a `changedFiles` sub-method via `Object.assign`.
- Added `ensureAvailable` check and `nameOnly` support to `diff`.
- Updated callers and tests to use the new API surface.
2026-06-03 00:13:05 +02:00
Patrik Sundberg f5114a4ba9 Support JJ workspaces in review 2026-06-02 10:45:58 +01:00
can1357 b2fa0ad0f9 Merge remote-tracking branch 'fork-jacobzyy/fix/marketplace-plugin-skills-loading' 2026-06-02 10:33:38 +02:00
JacobZyy 8790736173 fix: remove plugin: prefix from marketplace skill names
The plugin:name prefix (e.g. hyperpiemia:whistle-rules) broke skill://
URL parsing because colons are ambiguous with port separators. Skills
from marketplace plugins are now registered under their plain names.
Name collisions are handled by the existing capability-layer dedup
based on provider priority ordering.
2026-06-02 15:36:22 +08:00
can1357 ab935e992c fix(legacy-pi-compat): scope rewrite hook to the import graph, not a dir
Address review of the in-place loader: the directory-subtree filter had two
regressions vs the old mirror.

- It only rewrote files under the entry's package root, so a `dist/`
  entry importing `../../shared/helper.ts` (or a symlink-escaping sibling)
  left that module's legacy `@(scope)/pi-*` / `@sinclair/typebox` imports
  un-rewritten.
- `findExtensionRoot` walked up to the nearest package.json, which for an
  ad-hoc extension under a project (e.g. `/repo/.omp/extensions/foo.ts`)
  resolved to the project root — so the permanent onLoad hook would then
  rewrite unrelated project/host source imported later.

Replace the directory filter with a precise scope: pre-walk the entry's
relative-import graph (static + dynamic `./`/`../` specifiers), collect each
module's realpath, and build the onLoad filter as an exact-path alternation
of just those modules. This matches exactly the set the old mirror tracked
(minus the copy): it covers `../src`/symlinked siblings and never touches
the host, other extensions, node_modules deps, or unrelated project files.

Adds a regression test that a non-imported sibling stays outside the rewrite
scope, and renames the ../src test to reflect graph-following.
2026-06-02 09:15:44 +02:00
can1357 c5e3698f45 fix(legacy-pi-compat): load extensions in place instead of mirroring
Legacy Pi extensions were mirrored module-by-module into a flat temp dir
(`omp-legacy-pi-file/entry-<hash>/`) with imports rewritten to absolute
URLs. Running from that temp root made `import.meta.url`/`__dirname`
resolve to the mirror, so `readFileSync(join(__dirname, "ui.html"))`-style
asset loads ENOENT'd — e.g. @plannotator/pi-extension's HTML never loaded
and it auto-approved plans (#1674). The standing remedy (#1675) copied
~30MB of .html/.css per startup with a fragile extension whitelist.

Bun's runtime plugins don't fire onResolve for transitive imports, which
is why the mirror pre-resolved everything. But onLoad does fire
transitively for file-namespace modules matching its filter, and a real
file import keeps import.meta.url pointing at the source. So:

- Load the extension entry in place via `import(pathToFileURL(real))`;
  realpath first so the path matches what Bun hands onLoad (macOS
  /var->/private/var, bun link/pnpm symlinks).
- Register one Bun.plugin() onLoad per extension *package root* (nearest
  package.json), filtered to that root's .js/.ts but excluding any
  node_modules segment, that rewrites only `@(scope)/pi-*` and the bare
  `@sinclair/typebox` specifier to absolute bundled/shim URLs.
- Everything else — relative siblings (incl. ../src), the extension's own
  node_modules deps (CJS/ESM), and bundled assets — resolves natively.

Removes the flat mirror, the temp-dir writes, the asset-copy problem, and
the now-dead `omp-legacy-pi-file:` namespace machinery. import.meta.url is
the real source file, so assets resolve exactly as under the original Pi
runtime. Adds an in-place load regression test covering asset reads,
submodule .css siblings, node_modules-excluded native deps, and
package-root-scoped ../src rewrites.

Fixes #1674.
2026-06-02 09:15:44 +02:00
Can Bölük 52a29e5df5 Merge branch 'main' into feat/assistant-thinking-renderer 2026-06-01 18:16:42 +03:00
rimless-casualty 3c7d50d292 Improve ask option rendering 2026-06-01 17:37:26 +08:00
shoucandanghehe fbb24fb7dc fix(coding-agent): tighten thinking renderer semantics 2026-05-31 20:59:15 +08:00
shoucandanghehe 569cc3442b feat(coding-agent): add assistant thinking renderers 2026-05-31 20:44:02 +08:00
can1357 14bd572f49 refactor(shake): removed shake-summary mode and local-model compressor
- Dropped `summarizeShakeRegions`, the shake-summary prompt, and related types.
- Removed `shake-summary` compaction strategy and `providers.shakeSummaryModel` setting.
- Migrated existing `shake-summary` configs to plain `shake` on load.
- Simplified `/shake` to `elide` and `images` modes only.
2026-05-31 14:14:37 +02:00
can1357 19be67921d feat(coding-agent): added shake configuration and type modeling
Introduce shake-related configuration and types: strategy options, action enums, and shake result types.
2026-05-31 07:39:51 +02:00
Can Bölük 7ad52b25ff Merge pull request #1503 from erik-sv/upstream-pr/extension-flag-initial-message
fix(coding-agent): strip extension flags from the initial prompt
2026-05-31 07:25:03 +03:00
can1357 b48b825344 fix(coding-agent): process @file before session creation; drop built-in flag-name list
Two review fixes for the extension-flag/initial-prompt work:

1. @file ordering — `processFileArguments` runs `process.exit(1)` on a
   missing/unreadable file. It had been moved after `createSession`, which
   writes the terminal breadcrumb eagerly (SessionManager.create →
   #newSessionSync), so `omp @missing.md "x"` left a junk session/breadcrumb
   behind before exiting.

   Resolve extension-registered CLI flags BEFORE creating the session: load the
   session's extensions up front (new `loadSessionExtensions` helper, the single
   source of createAgentSession's discovery-branch logic), build an
   ExtensionFlagSink straight from the loaded extensions + runtime, re-parse
   argv, then process @file args — all before any session exists. The loaded
   result is handed back to createAgentSession via `preloadedExtensions` (now
   checked before `disableExtensionDiscovery`, so it can't double-load) and the
   same EventBus is shared, so no extra work. This keeps the P1#1 fix
   (`--flag @value` is the flag's value, not a file) while failing fast with no
   session side effects.

2. "Can we avoid the big list of names?" — removed the hand-maintained
   `BUILTIN_FLAG_NAMES` set (and its stale "rejected at registration" doc).
   `applyExtensionFlags` now always falls back to recovering a flag's value from
   argv when parseArgs didn't surface it; the recovery scan mirrors parseArgs's
   consumption rules (flag-looking space-form values stay their own flag) and is
   a no-op for flags that were absent or already surfaced, so no list of
   built-in names is needed.

Adds `ExtensionRunner.aggregateFlags` (static) so getFlags and the CLI's
pre-session sink share one implementation.

Tests: pre-session flag resolution via the exact main.ts sink pattern;
list-free recovery of an arbitrary colliding built-in (`--model`); and the
flag-looking-value rule. Verified typecheck + extension/runner/acp suites.
2026-05-31 06:23:15 +02:00
can1357 9f547d8e4f refactor(mnemosyne/core): typed embedding provider outputs and tightened normalization
- Defined `EmbeddingRow` and `EmbeddingOutput` in runtime options and exported them from core embeddings.
- Updated `EmbeddingProvider`, `MnemosyneEmbeddingProvider`, and `provider` runtime option types to return `EmbeddingOutput` instead of `unknown`.
- Refactored embedding result normalization to accept typed rows and sync/async batches and coerce them into validated `Float32Array` vectors.
2026-05-31 05:32:28 +02:00
can1357 495c570ed4 fix(coding-agent): normalize hosted plugin git shorthands
Addresses review feedback on #1527.
2026-05-31 04:47:39 +02:00
oldschoola 84a50e8921 fix(coding-agent): classify git+ and unprefixed scp specs as git
Codex review on #1527 flagged that the documented forms
`git+https://github.com/user/repo` and `git@github.com:user/repo` still
fell through to the npm install path. `git+https` was rejected by the
package-name validator; scp-style `git@…` passed the validator but then
resolved `actualName` via `extractPackageName` to `git` (everything before
the `@`), causing the post-install package.json lookup to fail at
`node_modules/git/package.json`.

- `parseGitUrl`: strip leading `git+` (forwarded to bun/git as-is) and
  extend the protocol gate to also accept scp-like `git@host:user/repo`.
  The scp form is unambiguous — no local path starts with `git@` — and
  matches what `git clone` itself takes.
- `isGitSpec` now returns true for both forms, routing them through the
  snapshot/diff path in `PluginManager.install` so the real package name
  is discovered correctly.
- Tests: flip the two cases that asserted rejection, add ref and
  `git+ssh` coverage. Verified end-to-end:
  `PluginManager.install('git+https://github.com/oldschoola/omp-insights')`
  installs `@oldschoola/omp-insights@1.2.3`.
2026-05-31 04:46:08 +02:00
oldschoola 22e564a85d feat(coding-agent): accept GitHub/git URLs in plugin install
Extends `omp plugin install` to accept git sources alongside npm specs and
marketplace refs. Bun's installer already understands git URLs; the blocker
was `PluginManager.install`'s strict npm-name validator and the assumption
that the actual package name could be derived from the spec.

- `git-url.ts`: `parseGitUrl` now recognizes npm-style namespaced shorthand
  (`github:user/repo`, `gitlab:`, `bitbucket:`, `codeberg:`, `sourcehut:` /
  `srht:`), with optional `#ref` and `.git` suffix. Exposes `isGitSpec` as
  `parseGitUrl(s) !== null`. Existing protocol-URL and `git:` shorthand paths
  are untouched.
- `manager.ts`: `install()` branches on `isGitSpec`. Git specs go through a
  separate `validateGitSpec` (shell-metachar rejection only — `/`, `:`, `@`,
  `#`, `+` are legal) and the real package name is discovered by snapshotting
  `plugins/package.json` deps before `bun install` and diffing afterwards.
  Falls back to value-match on force-reinstall where the key already exists.
- Help text in `plugin-cli` documents the new sources and adds a github:
  example.

Smoke tested end-to-end on Windows with both forms against the test repo:
  PluginManager.install('github:oldschoola/omp-insights')
  PluginManager.install('https://github.com/oldschoola/omp-insights')
both resolve `@oldschoola/omp-insights@1.2.3` and write a correct lock entry.
Shell-injection probe (`github:foo/bar; rm -rf /`) is rejected.
2026-05-31 04:46:08 +02:00
Erik Svilich 38d2341300 fix(coding-agent): preserve built-in-colliding extension flags instead of rejecting
The previous collision guard threw in registerFlag, which broke loading the
bundled plan-mode example extension (it registers `--plan`, also a built-in)
even when `--plan` was never passed — making a documented extension unusable.

Registering a built-in-named flag is a supported pattern: `--plan` is both the
built-in plan-model selector and plan-mode's boolean mode toggle, and the value
must reach both. So instead of rejecting, preserve delivery: remove the guard,
and in applyExtensionFlags recover a colliding flag's value from argv
(resolveCollidingFlag) when parseArgs routed it to the built-in branch and it
never reached unknownFlags. Non-colliding flags are unchanged (peer-* etc.).

Verified the real bundled plan-mode.ts loads with --plan registered and
delivered; replaced the reject-test with a loads-without-throwing regression
plus colliding-flag delivery coverage.
2026-05-31 04:45:51 +02:00