Commit Graph
1446 Commits
Author SHA1 Message Date
vmcall 414ef80c41 fix(task): restored goal activation outside restricted sessions
- Preserved goal-mode tool injection for ordinary explicit tool lists.
- Kept plan-mode LSP and IRC unavailable under the host capability clamp.
- Added regressions for both capability boundaries.
2026-07-17 17:36:59 +02:00
vmcall d944879f21 feat(task): unified structured subagent execution
- Added per-invocation task schemas with strict and permissive validation.
- Shared task and eval agent policy, artifacts, isolation, and lifecycle handling.
- Enabled host-restricted plan-mode eval agents and persisted their capability clamp.

Fixes #5279
2026-07-17 17:36:59 +02:00
roboomp 66837a96be fix(hub): restored persisted peers after resume
Moved persisted roster discovery out of the Agent Hub UI so model-facing coordination can use the same disk-backed registration path.

Rehydrated parked peers before an empty hub list response and added a crash-resume regression test.

Fixes #5864
2026-07-17 15:20:43 +00:00
roboomp 22a8524058 fix(tools): recognized zip-family archives and pruned unconvertible extensions
- Treated ZIP-based .jar/.war/.ear/.apk as zip archives in archiveFormatFromPath and parseArchivePathCandidates so read/write member access works.
- Shared one archive-extension alternation between format detection and path splitting to stop them drifting.
- Derived the markit convertible-extension set from a single source of truth (utils/markit) matching the registered converters (pdf/docx/pptx/xlsx/epub), dropping legacy .doc/.ppt/.xls/.rtf that had no converter and only produced Unsupported format errors.
- Updated read/write tool prompts to document the zip-family extensions.

Fixes #5808
2026-07-17 08:04:10 +00:00
roboomp dc7238f5a4 fix(read): supported history URL selectors
Added history to selector-aware internal URL schemes so read paging resolves the agent id before applying transcript ranges.

Fixes #5806
2026-07-17 07:46:37 +00:00
roboomp e5d5aec189 fix(read): enforced exact line selector bounds
- Removed implicit padding and syntactic boundary expansion from explicit ranges.
- Covered local, converted, multi-range, and artifact reads.

Fixes #5802
2026-07-17 07:45:39 +00:00
roboomp 33d66643d3 fix(read): refreshed URL responses on each invocation
Removed process-local URL response reuse so read and URL-backed search paths fetch current content.

Added regressions for repeated reads and searches.

Fixes #5803
2026-07-17 07:45:06 +00:00
roboomp ca874cf134 fix(lsp): raised timeout ceiling to 300 seconds
Allowed explicit LSP request budgets above 60 seconds and exposed the 5–300 second range in the tool schema.

Fixes #5804
2026-07-17 07:43:40 +00:00
roboomp 940f19d8c4 fix(browser): supported authenticated cmux tcp relays
Dialed loopback CMUX_SOCKET_PATH endpoints over TCP and completed the cmux relay HMAC challenge before sending JSON-RPC requests.

Loaded relay credentials from the session environment or the per-port cmux auth file while preserving Unix socket behavior.

Fixes #5788
2026-07-17 03:42:01 +00:00
can1357 adb2a3c7e2 style: formatted files from owner-approved merges 2026-07-17 05:33:19 +02:00
can1357 4e0e53c183 merge PR #5321 via eval/pr-5321: feat(coding-agent): generate_image per-request provider + Codex-subscription images 2026-07-17 05:29:29 +02:00
can1357 87bd6c7b94 Merge branch 'sweep/2026-07-17' into eval/pr-5321
# Conflicts:
#	packages/coding-agent/src/config/settings-schema.ts
#	packages/coding-agent/src/tools/image-gen.ts
#	packages/coding-agent/test/tools/image-gen.test.ts
2026-07-17 05:23:41 +02:00
can1357 ab39a4b18b Merge branch 'sweep/2026-07-17' into eval/pr-5546 2026-07-17 05:22:13 +02:00
can1357 a4c9ffb434 fix: preserve bash timeout and abort semantics 2026-07-17 05:18:39 +02:00
can1357 22ae8045f2 merge PR #5768 via eval/pr-5768: fix(tools): keep essential built-ins top-level when re-registered without loadMo 2026-07-17 04:42:10 +02:00
can1357 05e1314bd9 merge PR #5760 via eval/pr-5760: fix(coding-agent): restored xdev for explicit tool sessions
Resolved plan-mode exit overlap with #5662 (kept restore/rollback
structure, routed pending-switch clearing through
clearPendingPlanModelSwitch) and unioned additive test blocks with
#5672/#5662.
2026-07-17 04:42:10 +02:00
can1357 b4dcbda74d merge PR #5729 via eval/pr-5729: fix(write): guarded xd approval evaluation failures 2026-07-17 04:40:03 +02:00
can1357 83bfb9d490 merge PR #5719 via eval/pr-5719: fix(read): preserved workspace suffix precedence 2026-07-17 04:39:16 +02:00
can1357 4ded610d38 merge PR #5500 via eval/pr-5500: fix(review): fall back to per-file API when PR diff exceeds 20k lines 2026-07-17 04:37:08 +02:00
can1357 f3f5745200 fix(review): guard per-file diff fallback limits 2026-07-17 04:16:46 +02:00
roboomp 7715132e71 fix(browser): guard cmux selector funnel against non-string selectors
CmuxTab.#selectorSpec bypassed the puppeteer-backend guards and called
normalized.startsWith(...) directly, so tab.click(await tab.ref("e5")) on a
cmux surface still threw the opaque TypeError instead of the named ToolError.
Apply assertSelectorString at the cmux funnel too.

Fixes #5776
2026-07-17 02:14:58 +00:00
roboomp 9f836712e8 fix(browser): rejected non-string tab selectors with a named error
tab.click/type/fill/waitFor*/scrollIntoView route their selector through
parseAriaRefSelector (.trim) and normalizeSelector (.startsWith) before any
validation, so passing the ElementHandle from tab.id(n)/tab.ref(...) (or an
un-awaited Promise of one) crashed with the opaque minified
"A.trim is not a function" instead of an actionable error.

- Added assertSelectorString guard at both selector funnels; throws a ToolError
  naming the recovery ((await tab.id(n)).click() or a string selector) and
  distinguishing ElementHandle / Promise / primitive.
- Corrected browser.md: handles are called directly, not fed to tab.click.
- Regression tests in both selector suites.

Fixes #5776
2026-07-17 02:10:55 +00:00
roboomp 5340a9517a fix(tools): keep essential built-ins top-level when re-registered without loadMode
Extension/SDK/RPC registerTool defaulted an omitted loadMode to
"discoverable". A UI-only re-register of an essential built-in
(read/write/bash/edit/glob) then became discoverable and, with tools.xdev
on, was unmounted from the top-level schema. read/write dropping also
broke the xd:// transport (read xd://, write xd://<tool>), leaving the
model with no callable coding essentials.

- Add defaultLoadModeForToolName: omitted loadMode resolves to "essential"
  for known essential built-in names, "discoverable" otherwise.
- Apply it at all four adapter boundaries (extension wrapper, custom-tools
  wrapper, sdk customToolToDefinition, rpc normalizeHostToolDefinitions).
- Transport invariant: read/write never mount under xdev regardless of
  loadMode (they carry the transport).
- Regression test covering the demotion, transport invariant, and a drift
  guard tying the essential-name set to the tool classes.

Fixes #5764
2026-07-16 23:08:02 +00:00
Victor Araújo 323ef8ec73 fix(coding-agent): restored xdev for explicit tools 2026-07-16 18:41:58 -03:00
roboomp 912dd44068 fix(write): guarded xd approval evaluation failures
Schema-invalid JSON objects can reach mounted approval functions before xdev dispatch validates their arguments. Fall back to the exec tier when an approval function throws, preserving fail-closed prompting and allowing dispatch to surface its normal schema error.

Added regression coverage for ast_edit payloads containing null paths.

Fixes #5727
2026-07-16 17:29:17 +00:00
roboomp 5445beb6f5 fix(write): evaluate function-valued xd:// device approvals
The write approval gate discarded a mounted tool's function-valued
approval and never decoded the device JSON payload, defaulting the tier
to exec. Read/write xd:// operations then prompted in non-yolo modes
that permit them.

Now decode valid object payloads and resolve the mounted tool's normal
approval decision via resolveToolTier; malformed JSON, non-object
payloads, and unknown devices still fall back to exec and prompt.

Fixes #5727
2026-07-16 17:24:22 +00:00
roboomp c543ee75ec fix(read): preserved workspace suffix precedence
Tried existing unique workspace suffix matches before recovering a missing cwd path from the active approved plan. Added regression coverage for the precedence rule.
2026-07-16 14:55:17 +00:00
roboomp b01cc405fd fix(read): recovered approved plan cwd aliases
Recovered the active local plan when a model rewrites its local URL as a missing same-basename cwd-root path. Real working-tree files retain precedence.

Fixes #5704
2026-07-16 14:46:36 +00:00
can1357 7363684cb6 merged PR #5453: fix(browser): bound tab teardown waits
# Conflicts:
#	packages/coding-agent/src/tools/browser/registry.ts
#	packages/coding-agent/src/tools/browser/tab-supervisor.ts
2026-07-16 03:43:17 +02:00
can1357 1678607617 fix(eval): preserve column truncation metadata 2026-07-16 03:32:03 +02:00
can1357 a049ed4ca7 merged PR #5422: fix(tools): stop column cap from faking window truncation 2026-07-16 03:32:03 +02:00
can1357 f9cc18c45a fix(tools): skip incompatible image providers 2026-07-16 03:32:01 +02:00
can1357 a3283a157c merged PR #5443: fix(tools): prefer active image provider and fall back 2026-07-16 03:32:01 +02:00
can1357 3601692c8d merged PR #5515: fix(skills): reload runtime skill state 2026-07-16 03:31:59 +02:00
roboomp f512d99614 fix(tool): strip leading colon before Windows path shapes
expandPath's leading-colon strip only fired before POSIX prefixes
(`/`, `~/`, `./`, `../`), so Windows-mangled inputs like `:C:\repo\file`
or `:.\src` slipped through and path.resolve treated them as relative
children of cwd. The omp grep subcommand is the Windows grep path, so it
hit the common Windows form of the same bug.

Broaden the lookahead to admit `\` separators, `.\`/`..\` relatives, and
drive-letter absolutes (`[A-Za-z]:`). Add expandPath regression tests
for the Windows forms and the bare-token non-strip cases.

Fixes #5624
2026-07-15 22:25:44 +00:00
can1357 d25d9300ed chore: fixed remaining stale tests after prompt and session api changes
- coordination advisory now points at hub, not irc
- eval description renders 'Allowed:' list instead of removed default-agent prose
- task description no longer renders spawn-policy text; assert agent-list filtering instead
- issue-2750 mock session gained getEnabledToolNames (renamed session api)
2026-07-15 19:50:46 +02:00
can1357 46ad908245 fix(coding-agent): renamed settings keys to avoid nested-value lookup collisions
- Updated schema and runtime paths to use `dev.autoqaConsent` and `todo.remindersMax`, including auto-QA consent reads/persistence and todo reminder limit checks.
- Adjusted settings expectations so obsolete BM25-discovery keys were dropped on load and `tools.xdev` now kept its default unless explicitly set.
- Added/updated tests for the setting key migration and refreshed issue-consent flows, plus a new `refreshMCPTools` test for steered `xdev-mount-notice` updates without prompt rebuilds.
2026-07-15 19:08:37 +02:00
can1357 bf3764fa4d feat(coding-agent): stabilize system-prompt cache across xd:// mount changes via delta notices
Instead of including the xd:// device inventory in the system-prompt signature, mount/unmount events now inject a steered `xdev-mount-notice` message so the system prompt (and its provider cache prefix) stays byte-stable across MCP connects and disconnects. Full device docs are picked up opportunistically on the next unrelated rebuild.

Also caps external (dynamic-mount) device descriptions to 200 chars in `docsAll` to prevent server-controlled prose from consuming prompt budget; built-ins keep their full curated docs, and `read xd://` always returns the untruncated text.

Legacy `discoveryMode: "off"` → `tools.xdev: false` migration is removed; the setting keeps its own default without inference from the deprecated key.
2026-07-15 19:07:31 +02:00
can1357 9afedb591e feat(coding-agent): added opt-in task prewalk and tightened --tools and xdev behavior
- Added a `task.prewalk` option (default `false`), removed default task `prewalk` flags, and updated prewalk resolution so bunded generic task execution only prewalks when explicitly enabled.
- Enforced strict `--tools` validation in CLI parsing, making unknown tool names fail fast with `CliUsageError` instead of being silently filtered.
- Migrated legacy discovery settings (`tools.discoveryMode`, `tools.essentialOverride`, MCP discovery keys) into updated `tools.xdev` handling with preserved explicit override behavior.
- Hardened xdev/ACP execution flow by capping `docsAll` payloads with overflow listing and remapping `xd://` dispatches/approval gating for correct execute/read behavior and reduced duplicate prompts.
2026-07-15 18:39:36 +02:00
serverinspector d52084f536 fix(browser): observe raw promises before target close 2026-07-15 14:35:44 +00:00
roboomp 8621b0459d fix(tui): showed task job model badges
Forwarded async task progress metadata into job snapshots so polling rows can render the effective resolved model and reasoning selector.

Added focused renderer coverage for enabled, disabled, malformed, and bash job rows.

Fixes #5060
2026-07-15 13:58:16 +00:00
can1357 5ff277349c refactor(coding-agent): consolidated tool surface onto xd:// devices and hub
- Added the `xd://` virtual device protocol (`internal-urls/xd-protocol.ts`, `tools/xdev.ts`): tools declaring `loadMode: "discoverable"` are unmounted from the request tools array and driven via `read xd://` (list/docs+schema) and `write xd://<tool>` (execute), gated by the `tools.xdev` setting (default on) and inlined into the system prompt.
- Merged the `irc`, `job`, and `launch` tools into a single `hub` tool (`tools/hub/`, `async/job-manager.ts`): messaging keeps `send`/`inbox`/`list`, job control maps to `wait`/`cancel`/`jobs`, process supervision keeps `start`/`logs`/`stop`/`restart`/`describe` with `ps`, and the unified `wait` races background jobs against peer messages; SDK `IrcTool`/`JobTool`/`LaunchTool` are replaced by `HubTool`.
- Removed the hidden `resolve` tool in favor of the `xd://resolve`/`xd://reject`/`xd://propose` resolution devices, auto-including `write` whenever a deferrable tool or plan mode is present.
- Removed the BM25 tool-discovery system: the `search_tool_bm25` tool, the `tool-discovery` module, the `tools.discoveryMode`/`mcp.discoveryMode`/`mcp.discoveryDefaultServers`/`tools.essentialOverride` settings, per-tool MCP selection, and the `mcp_tool_selection` message type.
- Unified tool presentation on `ToolLoadMode` (`essential`|`discoverable`), replacing the custom-tool `xdev?: boolean` opt-out; custom, extension, MCP, RPC host, image-generation, and TTS tools now default to `discoverable`, and added a `satisfies` predicate to `SoftToolRequirement`.
- Removed the standalone `ssh` command tool and `ssh/ssh-executor` (the `ssh://` read/write/search protocol stays), and made `--tools` address hidden built-ins.
- Updated collab-web to render `xd://` dispatches and `hub` op families, dropped the `search_tool_bm25`/`ssh`/`report-finding` renderers, refreshed tool docs and prompts, and migrated the affected tests and changelogs.
2026-07-15 15:16:29 +02:00
can1357 c32ea55ba3 fix(coding-agent): kept todo active for prewalk subagents and fixed prewalk gate deadlock
- Updated prewalk gating in `AgentSession` to key the todo gate on active tools instead of registry presence, so deactivated todo tools no longer block prewalk handoff.
- Changed subprocess tool filtering so `todo` is stripped for normal subagents but retained when prewalk is armed, and propagated the prewalk state through tool-session setup.
- Added regression tests for restricted active-tool slates and prewalk/non-prewalk subagent tool propagation to verify todo is handled correctly in each case.
2026-07-15 05:45:59 +02:00
oldschoola 596a20517f fix: render bash timeout with warning border instead of error
Bash command timeouts now render with a warning (yellow) border instead
of an error (red) border, reflecting that the timeout ran its course
rather than the command failing.

The timeout is no longer thrown as a ToolError — instead #buildCompletedResult
returns a non-throwing error result (isError=true, keeping the model-facing
contract) with details.timedOut=true. The renderer reads this flag to pick
state="warning" (yellow) instead of state="error" (red).

The timedOut flag is propagated from bash-executor.ts, which now sets
timedOut=true on timeout return paths and leaves it unset on user-abort
paths. This distinguishes timeouts from user Esc-cancels — previously both
returned cancelled=true with no way to tell them apart in bash.ts.
2026-07-14 20:21:59 -07:00
roboomp ea320d745b fix(bash): resolved nested internal URLs
- Tracked quote context independently inside command substitutions.
- Covered unquoted skill URLs nested under outer double quotes.

Fixes #5535
2026-07-14 22:21:53 +00:00
can1357 a9c038818d feat(tools): removed separate selector args from read and grep APIs
- Removed `selector`/`sel` arguments from read and grep tool schemas and related execution arg handling.
- Reworked read and grep path processing to parse line selectors from `path` suffixes instead of separate fields, including inline range propagation.
- Updated delegation and execution call paths (including JS/Python preludes and executor tests) to pass selectors embedded in `path`.
- Updated read/grep prompt docs and changelog for the breaking inline-selector API, and removed obsolete selector-specific tests and expectations.
2026-07-15 00:04:02 +02:00
can1357 ad396fb8fe Merge PR #5529: fix(tools): strip stray leading colon from tool paths (@roboomp) 2026-07-14 23:11:12 +02:00
can1357 5447312c5f Merge PR #5498: fix(tools): accept empty GitHub search date placeholders (@roboomp) 2026-07-14 23:11:12 +02:00
can1357 6b381eb765 Merge PR #5451: fix(eval): honor timeout zero and classify session deadlines (@roboomp) 2026-07-14 22:58:49 +02:00
can1357 6f8a3ab94a Merge PR #5458: fix(browser): bound headless browser close to unblock tab cleanup (@roboomp) 2026-07-14 22:58:47 +02:00