Commit Graph

167 Commits

Author SHA1 Message Date
can1357 58a2acd330 test(coding-agent): align ctx fixtures with settled-component cache and todo commit-on-execute
- Added transcriptMessageComponents to every InteractiveMode ctx test literal; #6033's reuse cache made the field required and addMessageToChat populates it unconditionally.
- Wired setTodoPhases into the eager-todo ToolSession fixture to mirror sdk.ts; the test relied on the stale message_end todo replay #6148 removed.
2026-07-22 21:32:12 +02:00
Mathews-Tom d7f6ce5e04 Merge remote-tracking branch 'upstream/main' into feat/tree-ask-reanswer 2026-07-21 19:25:33 +05:30
can1357 3c6ade647b Merge PR #4784: fix(coding-agent): persist bash shortcut cwd changes (@jeffscottward) 2026-07-20 22:50:05 +02:00
can1357 60cbcc8c9d Merge PR #5055: feat(coding-agent): add timestamp to per-turn token-usage row (@zommiommy) 2026-07-20 22:50:05 +02:00
Mathews-Tom f2338da9a3 fix(coding-agent): match tree-selector onSelect(entryId, options) contract in ask-reanswer test
Upstream's shift+enter pre-answer feature (merged via upstream/main) changed
TreeSelectorComponent's onSelect callback to accept a second (options)
parameter carrying summarize state. The pickEntry() test helper still called
onSelect with a single argument, so options.summarize threw undefined-object
errors once merged.
2026-07-19 15:05:03 +05:30
Mathews-Tom ab1d7db7d1 Merge remote-tracking branch 'upstream/main' into feat/tree-ask-reanswer
# Conflicts:
#	packages/coding-agent/src/modes/controllers/selector-controller.ts
2026-07-19 15:02:33 +05:30
can1357 32dc282517 test: aligned read-tool and logout tests with landed contracts
- tools.test.ts still asserted the pre-#5812 ±context expansion for offset/
  limit and archive-entry reads; updated to the exact-bounds contract.
- selector-controller-logout.test.ts mocked the old modelRegistry.refresh;
  #5786 switched logout to a provider-scoped refreshProvider(id, 'online'),
  so the mock never resolved and the test timed out.
2026-07-18 21:58:03 +02:00
can1357 157e940d5e Merge PR #5786: fix(auth): scoped post-login model refresh and stripped cache credentials (@roboomp)
# Conflicts:
#	packages/catalog/src/model-cache.ts
2026-07-18 20:14:11 +02:00
Derek Zeng 9a452077b2 fix(coding-agent): clear inline images when disabled 2026-07-18 18:12:08 +08:00
Mathews-Tom 737dcb26d7 fix(coding-agent): reach ask re-answer flow from the active leaf in /tree
The interactive /tree selector's own no-op guard ("Selecting the current
leaf is a no-op") fired before ever reaching navigateTree()'s
allowAskReopen path added in 743c8ab7d, so that fix was unreachable from
the actual UI whenever the selected ask toolResult was already the
current leaf (interrupted right after answering, or navigated there by
another caller).

Let a current-leaf selection fall through to the reopen path when the
entry is an ask toolResult, mirroring the same targetIsAskResult check
navigateTree() uses.

Fixed in response to Codex review threads posted as PR review bodies
(not inline comments) on #5895 at 20:24:48Z and 21:54:30Z, which
predate 743c8ab7d and were never addressed.
2026-07-18 05:13:33 +05:30
Jeff Scott Ward 3e24087111 fix(coding-agent): persist bash shortcut cwd changes 2026-07-17 16:58:32 -04:00
can1357 ac3d779fad merge PR #5592 via eval/pr-5592: feat(warp): emit native CLI-agent events 2026-07-17 05:29:29 +02:00
roboomp c654abc980 fix(auth): scoped post-login model refresh and stripped cache credentials
Native /login and /logout (plus setup-wizard sign-in and RPC login)
refreshed model discovery with the default all-provider
online-if-uncached strategy, which reused a fresh authoritative cache row
and never re-ran fetchDynamicModels with the just-persisted credential,
so newly authenticated models stayed unavailable in-session and stale
endpoint data survived a relogin. Each auth-completion path now awaits a
provider-scoped refreshProvider(providerId, "online").

Also fixed writeModelCache serializing credential-bearing request headers
(Authorization, X-Api-Key, api-key, cookie, proxy-authorization) into the
plaintext models.db; they are now stripped before persistence and
re-derived on load from AuthStorage / provider config.

Fixes #5780
2026-07-17 03:03:25 +00:00
Gerben Meijer 1e083eb832 feat(coding-agent): support per-project model roles 2026-07-17 01:22:23 +04:00
robomp-bot b7e21155cd fix(coding-agent): skip legacy completion notify under Warp protocol 2026-07-16 20:12:25 +09:00
can1357 f9977f5c69 fix: reconciled test contracts with merged behavior changes
- google boolean-subschema coercion, column-cap truncation semantics, caller-owned plan-review hide, rebuild image-visibility setting
- added flushPendingCommandOutput and refreshSkills stubs to event-controller and ACP mock contexts
- removed the never-passing acp stdio EOF subprocess test (covered by postmortem-epipe contracts)
2026-07-16 04:27:53 +02:00
can1357 ebaed59dda fix(tui): preserve deferred alternate exit 2026-07-16 03:32:00 +02:00
can1357 2a05d36be5 merged PR #5476: fix(tui): prevent stale-buffer flicker 2026-07-16 03:32:00 +02:00
can1357 404ebb0fb0 Merge remote-tracking branch 'origin/farm/ae7a5593/ttsr-inline-regex-flags-and-scope-quoting' 2026-07-15 09:54:46 +02:00
roboomp 02efdee788 fix(omfg): compiled generated-rule conditions via inline-flag helper
The /omfg generated-rule path validated conditions with raw new RegExp in normalizeConditionRegex and isValidRegexCondition, so a generated rule with a leading (?i)/(?m)/(?s) inline flag was rejected as "Invalid condition regex" before reaching TtsrManager.addRule. Route all three validation sites through compileRuleCondition.

Fixes #4796
2026-07-15 06:45:41 +00:00
can1357 1121a0018d Merge PR #5516: fix(auth): route OSC 5522 paste into login prompts (@roboomp) 2026-07-14 23:11:09 +02:00
can1357 413949ccf4 Merge PR #5450: fix(todo): signal removal intent so agent stops rebuilding cleared todos (@roboomp) 2026-07-14 22:58:47 +02:00
roboomp e49638ddac fix(auth): routed enhanced paste into login prompts
Forwarded OSC 5522 text from the focused login dialog to its credential input and added regression coverage for direct API-key prompts.

Fixes #5394
2026-07-14 20:06:14 +00:00
roboomp 68f84d7c20 fix(tui): prevented stale-buffer flicker
- Kept fullscreen replacement overlays mounted through asynchronous transcript rebuilds.
- Fused alternate-screen exit with destructive repaint and removed resize-time buffer switches.
- Preserved statically detected synchronized output when DECRQM probing is inconclusive.

Fixes #5319
2026-07-14 18:23:45 +00:00
roboomp fd3f15c915 fix(todo): signal removal intent so agent stops rebuilding cleared todos
The /todo rm reminder was a generic "user manually modified" message
showing an empty list, so the model read the cleared list as missing and
re-populated it on the next turn. buildSystemReminder now emits an explicit
do-not-recreate / do-not-re-add directive for removals while keeping
status mutations (done/drop) neutral.

Fixes #5258
2026-07-14 17:33:21 +00:00
can1357 594a02e24a Merge PR #5248: feat(ai): report Cursor account usage (@riverpilot) 2026-07-14 19:16:09 +02:00
can1357 e42589d43d test(coding-agent): validated session persistence and downshift logic
- Added comprehensive tests for downshifting model behavior, including plan nudge injection and completion safety mechanisms.
- Verified session persistence accuracy by validating that from-disk rebuilds match the live agent state.
- Confirmed correct cache key propagation during tan commands to ensure provider caching is preserved.
- Removed obsolete reasoning slide tests.
2026-07-13 06:03:48 +02:00
can1357 0a98aa252b feat(coding-agent/modes): hardened tan fork isolation and session sync
- Clear inherited todo list state and persist empty edit at fork creation to prevent parent task reminders from affecting the tangential session.
- Re-inject the fork notice after each auto-compaction event to ensure the boundary between the parent and child session survives history summarization.
- Align the provider cache key with the parent's actual pinned key to correctly mirror cached session context.
- Update `AgentSession` to perform a full entry rewrite during tool result pruning to ensure session files match pruned state for reliable resuming and branching.
2026-07-13 06:00:30 +02:00
can1357 46ed33f27b feat(coding-agent): initialized session metadata during tan creation
- Initialized session metadata including system prompt, task, and toolset within the controller.
- Added session initialization tracking to the clone creation flow to ensure session state visibility.
- Updated unit tests to verify that session initialization data is correctly appended when a tan is created.
2026-07-13 01:09:42 +02:00
can1357 87a64b2f6a feat(coding-agent): improved background job lifecycle and display
- Stop propagating real-time updates for backgrounded Bash jobs to avoid UI flickering once a job enters the background.
- Refine background task tracking in `EventController` to distinguish between persistent background tasks and transient backgrounded Bash commands.
- Update UI rendering to display cleaner background job metadata in the footer instead of inline text notices.
2026-07-13 00:54:51 +02:00
Alexander Kirilin 965f5b0bb9 feat(ai): report Cursor account usage
Expose Cursor OAuth and access-token quota reporting through the shared usage APIs and CLI views, with parser and presentation coverage.
2026-07-11 20:41:40 -04:00
can1357 d39a3ed453 chore: fix stale tests 2026-07-11 19:10:40 +02:00
can1357 408a92d91a feat(coding-agent): enabled asynchronous background task execution
- Enabled granular task execution by allowing batches to interleave blocking items with non-blocking async background spawns.
- Updated task orchestration to support simultaneous inline result collection and persistent background job tracking.
- Improved agent visibility in the job tool by reporting running subagents even when not explicitly linked to a backing job ID.
- Enhanced terminal state handling to prevent premature tool block closures while async background operations remain active.
2026-07-11 16:17:03 +02:00
can1357 59d08172c1 feat(coding-agent): introduced model hub for unified management and search
- Replaced the legacy model selector with a full-screen Model Hub, introducing mouse support and a fuzzy-searchable browser.
- Integrated comprehensive model management, including role assignment, thinking-level visualization, and manual provider discovery.
- Implemented a cancellable OAuth login flow and integrated it directly into the Model Hub for provider authentication.
- Centralized model logic and migrated existing tests to support the new component architecture.
2026-07-11 15:10:53 +02:00
Tommaso Fontana 705a6118f6 feat(coding-agent): added timestamp to per-turn token-usage row
The token-usage row shown under assistant messages (display.showTokenUsage) now leads with the turn's local wall-clock time down to the second (YYYY-MM-DD HH:mm:ss), sourced from the assistant message's persisted timestamp so live, rebuilt, and restored transcripts all show the turn time rather than the view time.

createUsageRowBlock takes timestamp as an optional trailing argument, preserving its (usage, durationMs, ttftMs) public call contract on the package's ./modes/components/* export surface.
2026-07-10 10:32:41 +02:00
roboomp 497d385ce0 fix(auth): decoupled login success from model refresh
Switched interactive OAuth login to start model discovery in the background after credentials are saved.

Added a regression test that keeps model refresh pending and asserts the success transcript appears immediately.

Fixes #4989
2026-07-09 22:12:17 +00:00
can1357 4a20b51ca8 feat: implemented auto-sealing for transcript blocks and TUI row emission
- Added auto-sealing logic to `FinalizableBlock` to finalize displaceable snapshots when they enter the scrollback area.
- Updated TUI frame emission to publish committed rows and clamp them to segment bounds, ensuring accurate component updates.
- Introduced component tracking and cleanup in event controller tests to prevent resource leaks during finalization.
- Validated state transitions and post-emit synchronization through comprehensive new test suites for transcript and TUI components.
2026-07-09 20:37:09 +02:00
can1357 2e189b6f9e test: aligned full suite with merged sweep contracts
- container stubs gained disposeChildren for the stale-renderer teardown paths
- login-stored API key assertions include the new source provenance field
- bash timeout test covers the zero-disable contract alongside the clamp
- skill keyword steering activates a task tool for the gated workflow notice
2026-07-08 16:52:28 +02:00
can1357 355314262f merge PR #3224: feat(coding-agent): recognize #<number> as a GitHub issue/PR reference 2026-07-08 15:23:50 +02:00
Dylan Bohlender 54f0a00dd2 fix(oauth): copy-safe URL chunks and loopback-only launch URLs
Resolves the two Codex P2s raised on #4420 that merged unaddressed:

- wrapUrlRows indented every continuation chunk. A multi-row terminal
  selection includes the newline plus that indent; address bars strip
  newlines but preserve or percent-encode embedded spaces, so the
  reassembled URL was corrupted at every chunk boundary - silently,
  when the damage landed inside a query value. Chunk rows now carry
  zero leading bytes (label rows keep their indent), and the test
  reassembly helper concatenates chunks raw instead of stripping the
  indent that previously masked exactly this defect.

- #launchUrlIfSafe advertised a localhost /launch copy target for
  flows whose redirectUri never returns to the loopback server. Its
  catch-comment assumed custom-scheme URIs are non-parseable, but
  new URL('vscode://gitlab.gitlab-workflow/authentication') parses
  fine and sailed through the pathname check. The guard now requires
  an http(s) loopback redirectUri (localhost / 127.0.0.1 / [::1]);
  custom schemes, non-loopback hosts, and unparseable URIs all
  suppress the launch URL. Regression tests cover the GitLab Duo
  vscode:// shape and a fixed non-loopback HTTPS redirect.

Refs #4418
2026-07-05 16:01:30 -06:00
can1357 302f1c3beb test(coding-agent): implemented verification for sdk model selection logic
- Updated event controller fixture to include requestComponentRender mock.
- Added test case for resolving deferred role-alias model patterns.
- Added test case for parsing and falling back comma-delimited model patterns.
2026-07-05 15:57:24 +02:00
Jagrav Naik 27d2109ca3 fix(session-selector): Backspace on empty search deletes session
macOS laptops have no dedicated Forward Delete key. Fn+Backspace is the
only way to send \e[3~, and many macOS terminals (Terminal.app, some
iTerm2 profiles) deliver \x7f for that combo instead — so the keystroke
landed in the search box, not the delete handler, making session deletion
unreachable for those users.

Add a Backspace-on-empty-search handler alongside the existing Delete
check. With a typed query, Backspace stays bound to the search Input so
users can still edit their filter text. The existing confirmation dialog
guards against accidents.

Footer hint updated: [Del delete] -> [Del/⌫ delete].
2026-07-04 21:16:40 -04:00
can1357 53e8a8b807 test(ci): fixed event-controller and auth-storage test failures
- Mocked messagePersistenceKey in event-controller-error-banner.test.ts and safe-guarded it in event-controller.ts to prevent TypeError.
- Updated thinking loop retry test expectations to handle new dynamic recoveredErrors structure.
- Updated schema version assertions in auth-storage-email-dedupe.test.ts to v5, preserving v6 for future schema test.
- Simulated scrollback commitment in event-controller-message-start.test.ts by rendering container and committing rows before advancing timers.
2026-07-04 14:21:01 +02:00
can1357 3046718695 chore: update chanelogs 2026-07-04 05:16:58 +02:00
roboomp 6f76f5d9cd style: bun run fix 2026-07-03 17:45:13 +00:00
roboomp 1d4e9a5384 fix(mcp): width-wrap the full authorize URL so narrow viewports cannot truncate
@DylanBohlender's follow-up caught that MCPAuthorizationLinkPrompt.render
still ignored `width` and emitted `Copy URL: <full URL>` as one composed
row. On any viewport narrower than the row (~272 columns for a
Linear-shaped authorize URL), TUI#prepareLine's
`truncateToWidth(..., Ellipsis.Omit)` silently clipped the trailing
`code_challenge_method=S256` — the exact #4418 fingerprint reappearing
inside the remote-safety fix. A remote user on a narrow terminal
copying the rendered line would lose the S256 method again; the local
shortcut below cannot help them (localhost isn't reachable), and the
OSC 52 clipboard staged full URL isn't visible in their local browser.

Component-level fix: honor `width` in render.

- New `wrapUrlRows(label, url, width)` helper.
  - When `label + " " + url` fits in `width`, emit one inline row.
  - Otherwise emit the label on its own row and slice the URL into
    chunks of `width - indent`, each on its own row.
  - Floors the effective width at 16 columns so degenerately narrow
    terminals still emit every character; browsers strip whitespace
    when a multi-row selection is pasted into the address bar, so the
    reassembled URL is byte-identical.
- `render(width)` now uses the helper for both the primary `Copy URL:`
  row and the additive `Local shortcut (this machine only):` row.

Regression tests in
`packages/coding-agent/test/modes/controllers/mcp-authorization-link.test.ts`:

- Wide viewport (1000 cols): inline `Copy URL: <url>` layout preserved.
- Narrow viewport (80 cols) + Linear-shaped URL: every row's visible
  width ≤ 80, and the chunks reassemble byte-for-byte to the URL —
  explicitly asserting the trailing `code_challenge_method=S256`
  survives.
- Launch shortcut also wrapped at 80 cols; every row fits.
- Degenerate viewport (4 cols): URL still reconstructs exactly; the
  16-col floor governs chunk width.
- Full URL remains the primary target even when a launch URL is
  present, and the shortcut row is omitted when launchUrl is absent
  or identical to the full URL.
2026-07-03 17:45:08 +00:00
roboomp 721f6d4a08 fix(mcp): make full URL the primary OAuth copy target so SSH sessions work
Codex review flagged that advertising `launchUrl`
(http://localhost:<omp-port>/launch) as the visible `Copy URL:` breaks
SSH/WSL/headless users: their local browser resolves the URL against
the local machine (no OMP listening) and fails before ever hitting the
provider. On terminals without OSC 8 support, they lose the manual
`/login <redirect>` path entirely.

Every OAuth-facing surface now shows the full authorization URL as the
primary copy target and offers `launchUrl` as an additional "Local
shortcut (this machine only)" line for wide-terminal local users who
want the truncation-safe convenience:

- MCPAuthorizationLinkPrompt renders `Copy URL:` with the full URL and
  appends the local-shortcut row only when `launchUrl` differs. OSC 52
  clipboard staging in the MCP onAuth handler switches to the full URL
  (OSC 52 is a wire-level protocol — the terminal writes to the
  caller's LOCAL clipboard even when OMP is on a remote SSH box).
- LoginDialogComponent.showAuth, selector-controller onAuth,
  setup-wizard sign-in, and the auth-broker CLI mirror the pattern:
  full URL first, launchUrl as an optional local shortcut.
- Setup wizard uses `wrapTextWithAnsi`, not truncation, so the RFC
  7636 §4.3 downgrade bug that motivated launchUrl is unreachable
  through it; still surfaces launchUrl for wide-terminal convenience.

Regression tests in
`packages/coding-agent/test/modes/controllers/mcp-authorization-link.test.ts`
now assert:
- Full URL is the primary `Copy URL:` line so SSH sessions can complete.
- launchUrl still appears beneath as `Local shortcut (this machine only): …`
  when it differs from the full URL.
- No shortcut row when launchUrl is absent OR equals the full URL.
2026-07-03 08:57:55 +00:00
roboomp 97c1d08cce fix(mcp): surface a short launch URL and log Windows opener failures for OAuth
Two independent defects broke /mcp reauth against S256-only providers on
Windows boxes whose PATH no longer references System32:

1. openPath spawned bare rundll32 and swallowed the
   `Executable not found in $PATH` throw with a bare `catch {}`, so the MCP
   controller's outer try/catch was dead and the transcript unconditionally
   claimed "Opening browser automatically...".
2. TUI#prepareLine silently truncates any composed row wider than the
   viewport. MCPAuthorizationLinkPrompt rendered `Copy URL: <full URL>` as a
   single ~271-column line whose trailing parameter is
   code_challenge_method=S256. On the reporter's 270-col terminal the cut
   landed inside that parameter, dropping the method while keeping
   code_challenge — which RFC 7636 §4.3 treats as plain PKCE, which Linear
   correctly rejects with "The plain PKCE method is not allowed. Use S256
   instead."

OAuthCallbackFlow now hosts a `GET /launch` route on the same loopback
callback server it already runs; the route 302-redirects to the pending
authorization URL and is advertised as `OAuthAuthInfo.launchUrl` — a
~30-char copy target no viewport can meaningfully truncate. The MCP OAuth
fallback, /login, setup wizard, auth-broker CLI, and login-dialog all
prefer the launch URL for the visible copy target, keep the full URL in
the OSC 8 hyperlink for click-through, and the MCP flow additionally
stages the copy target on the clipboard via OSC 52 (same pattern the
setup wizard uses).

openPath now resolves rundll32.exe through %SystemRoot%\System32 (with a
C:\Windows fallback when SystemRoot is unset) and logs both synchronous
spawn throws and non-zero exits via the shared logger, so silent
misconfigurations show up in ~/.omp/logs/omp.*.log. The dead try/catch
around openPath in the MCP controller is removed.

Fixes #4418
2026-07-03 08:19:14 +00:00
roboomp 30527aee0c fix(tui): cut TUI CPU overhead during interactive sessions
Four tightly-scoped hot-path fixes covering the highest-impact items in the
reporter's CPU profile (13.1 s profiled / 30 s window):

1. `event-controller.ts:handleEvent` no longer fires a blanket
   `statusLine.invalidate() + ui.requestRender()` before every session event.
   The pre-render was a leftover from #4145 when `updateEditorTopBorder()`
   still eagerly rebuilt the border; the lazy provider added in #4145 made
   it redundant. It fired on every `message_update`/`tool_execution_update`
   during streaming — the pre-render's frame ran while the handler was
   awaiting, then the handler's own `requestRender` scheduled a second
   identical frame. Every handler that mutates visible state already calls
   `requestRender()`.

2. `shimmer.ts:shimmerSegments` iterates the segment string in place instead
   of building a code-point array with `Array.from(seg.text)` every animation
   frame. Runs of same-tier chars are emitted via a single `slice` per run
   rather than accumulating into `runBuf`. Surrogate pairs stay atomic — the
   code-point index still advances by 1 per emoji. Microbench over 30k
   frames: 45 ms → 18 ms (2.53x), allocation rate down from ~N-per-frame to
   a handful per frame. New tests cover mixed BMP+surrogate and all-emoji
   inputs. `Array.from` was the #1 self-time hotspot in the reporter's
   profile at 10.2%.

3. `Markdown.setText` gains an equality guard mirroring `Text.setText`
   (returns `false` when `text === #text`). Providers re-emit identical text
   on ticks with no delta (throttled frames, reconciled tool-execution
   updates); each of those now short-circuits instead of dropping
   `#cachedLines` and forcing a full lex + wrap on the accumulated paragraph
   (the reporter's #3 hotspot at 8.4%). New test asserts render-reference
   stability + return-value semantics.

4. `SPINNER_RENDER_INTERVAL_MS` aligned with `SPINNER_GLYPH_ADVANCE_MS`
   (both 80 ms). The previous 33 ms cadence emitted ~2.4 paints per glyph
   step; the differential-output dedup only skips the write, not the
   compose walk. Visually identical (glyph advance was already 12.5fps),
   halves paints during tool execution.

Skipped (out of scope for a bug fix, deserve dedicated PRs):
- Freezing streaming prefix on single `\n` boundaries — correctness-bound
  to `\n\n` block separators (CommonMark loose-list continuation).
- Compose-phase idle gate + adaptive-backpressure moving-average — need a
  component-level dirty flag; the 200 ms cap in `#scheduleRender` was set
  for a reason (#4145 tail-latency guard).

Tests updated: two IRC-expiry tests in event-controller-message-start.test.ts
that were asserting the pre-render's second `requestRender` call now expect
one.

Fixes #4353
2026-07-02 22:11:26 +00:00
can1357 5f1ed0fcde chore: reformat 2026-07-01 23:14:36 +02:00