Commit Graph

525 Commits

Author SHA1 Message Date
Slava Zavadsky 9885ee34fc fix(agent): stop leaking scout into prompts when it is disabled
Hard-coded 'scout' references reached the model even when the scout
agent was disabled via task.disabledAgents or absent from the session
spawn list. Gate every such reference on scout actually being spawnable:
the task tool description, the delegation gates, the plan-mode and
workflowz notices, the glob/grep/ast-grep guidance, and the task
specialization advisory. Prompt shape is otherwise unchanged; only
erroneous references to the unavailable subagent are dropped.

Closes #7313
2026-08-01 23:50:33 -04:00
roboomp 57732e9dcd fix(coding-agent): detach hard-aborted refs so ensureLive can't route into a dead session
Preserving aborted refs on dispose exposed a latent invariant break: the
executor's hard-abort path (finalizeSubagentLifecycle) set status `aborted`
and disposed the session without detaching it. With the ref now retained, it
kept a dangling pointer to the disposed session, and ensureLive returns any
non-null ref.session before its revivability check — so hub focus / transcript
chat could route into a dead session.

- finalizeSubagentLifecycle: detach the session before disposing on the
  terminal hard-abort path, upholding the AgentRef invariant (session === null
  when aborted).
- release(tombstone): detach before dispose too (capture the live session
  first), same invariant.
- unregisterUnlessParked: preserve `aborted` refs only when already detached;
  an aborted ref still holding a live session is a bug and is unregistered
  rather than kept reachable.
- Regression test now asserts ensureLive rejects a tombstoned id as terminal.

Fixes #7250
2026-08-01 09:42:41 +00:00
can1357 bd96752b83 fix(rpc): serialize IRC wake finalization 2026-07-31 19:28:43 +02:00
can1357 e02510f8c9 Merge PR #7108: fix(rpc): restore frames for IRC-revived subagents (@roboomp) 2026-07-31 19:28:42 +02:00
can1357 305ad95a20 fix(task): guard deferred launch work 2026-07-31 19:16:56 +02:00
Wolfgang Schoenberger dc292d4c84 fix(task): track deferred model refresh 2026-07-30 18:34:40 -07:00
Wolfgang Schoenberger 37a4adfcea perf(task): defer subagent launch setup 2026-07-30 15:16:47 -07:00
roboomp d686375b8c fix(rpc): monitored IRC wakes on cold-revived subagents
- Extracted the shared attachIrcWakeTurnMonitor from the executor reviver closure.
- Installed it in the persisted cold-revive path, forwarding the top-level event bus.
- Covered that a resumed process's parked subagent emits wake lifecycle frames.

Fixes #7105
2026-07-30 20:08:21 +00:00
roboomp b2d18b6920 fix(rpc): restored frames for IRC-revived subagents
- Monitored autonomous IRC wake turns with the task executor lifecycle and progress channels.
- Preserved monitoring after idle-TTL parking and session revival.
- Covered RPC subscriptions for both idle and parked keep-alive agents.

Fixes #7105
2026-07-30 19:42:58 +00:00
Kyle McCleary dba303e2e0 Merge remote-tracking branch 'origin/main' into feat/security-native 2026-07-29 20:31:08 -07:00
can1357 2905a23fc1 fix(coding-agent): prevented duplicate rows in task execution scrollback
- Updated task tool execution to pin live regions and drop partial snapshots once rows commit.
- Tracked background task frozen styled rows and render timestamps to prevent clock drift on committed history.
- Added tests verifying detached and blocking task progress do not duplicate rows in scrollback.
2026-07-30 04:01:06 +02:00
Kyle McCleary 089a9963f8 feat(security): OMP-native security subsystem (planner handoff) 2026-07-29 18:47:51 -07:00
Nik Divjak c3011fff3c fix(task): let task.softRequestBudget lower bundled subagent budgets
The soft request budget resolved to `SOFT_REQUEST_BUDGET[agent.name] ??
configured`, so the bundled entries for scout and sonic replaced the
configured value outright. Lowering `task.softRequestBudget` to tighten
the guard therefore did nothing for exactly the two agents that spawn
most often: a scout kept its 100-request budget no matter how small the
user set the knob. Only 0 (disable) and raising the value for
non-bundled agents had any effect.

Treat both numbers as upper bounds and take the smaller one. The bundled
entries stay ceilings, so a runaway scout is still stopped at 100 by
default and existing behavior is unchanged for anyone who has not
lowered the setting; a configured 0 still disables the guard entirely.
Resolution moves into `resolveSoftRequestBudget`, which also normalizes
negative and fractional inputs, so the rule is testable without standing
up a subprocess run.

This composes with `task.maxEffort` on a separate axis: effort caps how
hard each request thinks, this caps how many requests a run may spend.

(cherry picked from commit f0db29f8f725f11390b64ca9342300c482ff5c5d)
2026-07-29 23:09:01 +02:00
can1357 c7b10c3340 Merge PR #6763: fix(cli): preserve live task-isolation sandboxes on worktree clear (@roboomp) 2026-07-28 10:59:37 +02:00
can1357 d16a251777 chore: reorg tests 2026-07-27 16:43:53 +02:00
can1357 8c5dc16344 fix(task): enforced per-spawn effort ceiling across retry fallbacks
- task.maxEffort only clamped the initial thinking level; a retry
  fallback candidate could clamp back up to its model floor and run a
  low-capped spawn at high.
- The ceiling now rides the session as thinkingLevelCeiling: clamped in
  ModelControls (constructor, setThinkingLevel, auto classifier,
  restore) and in applyRetryFallbackCandidate; fallback candidates whose
  floor exceeds the ceiling are skipped.
- Effort value import moved to @oh-my-pi/pi-catalog/effort; changelog
  attribution added.
- Review follow-up for PR #6794.
2026-07-27 16:09:28 +02:00
Wolfgang Schoenberger bd1605e8f5 feat(task): add per-spawn effort ceiling 2026-07-27 03:39:55 -07:00
can1357 0388946e85 feat(coding-agent/task): added task.enableEffort setting to gate effort parameter
- Introduce task.enableEffort setting defaulting to false to hide per-spawn effort parameters.
- Conditionally include effort in single and batch task schemas and descriptions based on the new setting.
2026-07-27 07:01:09 +02:00
roboomp 01429d83e2 fix(cli): bind isolation ownership to process start-time token
A crashed owner's pid can be recycled by an unrelated long-lived
process, so kill(pid, 0) succeeds and the leftover sandbox was pinned
live forever, unreachable by a non-`--all` clear.

The ownership marker now records a process-instance start-time token
alongside the pid (Linux /proc/<pid>/stat field 22, other Unix via
`ps -o lstart`). A live pid whose current token no longer matches the
recorded one is a recycled pid and counts as dead; platforms that can't
report a token degrade to the prior pid-only check.

Fixes #6761
2026-07-27 03:52:30 +00:00
roboomp eeca809193 fix(cli): preserve live task-isolation sandboxes on worktree clear
`omp worktree clear` (without `--all`) removed every task-isolation dir
under the worktree base, including sandboxes owned by subagents running
right now, and the "no live task owns it" reason was asserted from the
mere presence of the `m` mount dir with no ownership check.

`ensureIsolation` now stamps each sandbox base dir with a pid-bearing
ownership marker before the backend materialises `m`, and the worktree
scanner classifies a sandbox as live while its owning process is alive,
so `clear` reclaims only crashed leftovers.

Fixes #6761
2026-07-27 03:42:33 +00:00
roboomp 583ff590f2 fix(prewalk): apply same-model effort downgrades instead of skipping
The prewalk arm/switch guard compared model identity only (modelsAreEqual /
provider+id), discarding the resolved thinkingLevel. A legal same-model target
at a cheaper effort (e.g. prewalk: "@task" resolving to the active model at a
lower level) was dropped as a no-op, so the session ran the expensive effort for
the whole run while still paying the plan/continue nudges — silently on the
session path, logger.debug only on the subagent path.

Compare (provider, id, effective thinking level) via a shared prewalkWouldBeNoop
helper. Effort-only deltas on the same model now switch; a genuine no-op emits a
user-visible notice on the session path and never arms on the subagent path.

Fixes #6659
2026-07-26 02:20:03 +00:00
can1357 db937bd149 feat(coding-agent): added coarse effort parameter to task tool
- Add `effort` (`lo`/`med`/`hi`) parameter to task spawn parameters and prompts.
- Implement `resolveTaskEffortLevel` to map coarse task effort onto model-supported thinking ranges.
- Pass effort configuration through executor options and structured subagent requests.
2026-07-24 15:51:34 +02:00
can1357 9f8aa87dbf feat(task): removed per-call model override from task tool
- Removes `model` field from task item/schema, TaskParams, and TaskItem types.
- Removes model selector validation, formatting, and approval display logic.
- Updates task tool priority docs to reflect that model is no longer per-call overridable.
- Updates eval agent() helper docs and prompt templates to remove model parameter.
- Updates tests to reflect removal of model override capability.
2026-07-24 14:51:48 +02:00
can1357 0689092866 Merge PR #6445: feat(extensions): expose session service tiers (@atyrode) 2026-07-24 02:24:29 +02:00
Alex TYRODE e0928070c2 feat(extensions): expose session service tiers 2026-07-23 21:49:20 +00:00
TechDufus 890dd88597 fix(coding-agent): make mixed-agent task batches atomic and inspectable 2026-07-23 16:47:51 -05:00
can1357 5d66eb7f2a Merge PR #5464: fix(coding-agent): persist vibe sessions across restarts (@roboomp) 2026-07-23 18:06:11 +02:00
pr-eval 424458e99d chore(secrets): dropped drive-by changes unrelated to secret placeholders
Reverted branch-side edits to spawn-policy prompts/tests, settings tab
groups, mermaid cache typing, prewalk todo gating, and packages/ai test
churn back to merge-base content; trimmed their changelog entries. These
repaired stale CI against an older main and are stale or conflicting
against current main.
2026-07-23 17:56:29 +02:00
can1357 c522eceff2 Merge PR #6119: feat: lift subagent async/auto-background limits via owner-routed delivery and quiescence (@korri123)
# Conflicts:
#	packages/coding-agent/src/task/executor.ts
2026-07-23 17:52:52 +02:00
can1357 26726fdcb9 Merge PR #6255: add dynamic multi-root workspace context (@maatheusgois-dd) 2026-07-23 17:30:33 +02:00
can1357 49782ecce6 Merge PR #6326: feat(coding-agent): configure isolated task apply behavior (@korri123) 2026-07-23 11:48:54 +02:00
can1357 db3a6a1407 Merge PR #6318: fix(tui): show fallback models in Agent Hub (@roboomp) 2026-07-23 11:37:13 +02:00
can1357 c818e77240 Merge PR #6328: fix(task): only point follow-up hints at transcripts that exist (@paralin) 2026-07-23 11:37:12 +02:00
panosAthDBX bfef3f7eea fix(task): reject sparse model fallback arrays 2026-07-23 09:53:54 +01:00
panosAthDBX 1c8d9db6dd feat(task): allow per-call model selection 2026-07-23 09:42:39 +01:00
Christian Stewart 0ff5312744 fix(task): only point follow-up hints at transcripts that exist
The aborted-task follow-up hint always references history://<agentId>,
including when no transcript can actually be served. Following that link
then fails.

Add hasResolvableTranscript beside sessionFilesFromDisk, mirroring the
availability half of HistoryProtocolHandler's resolution semantics: a
registered ref's live session, a retained session file verified on disk,
or a disk-scanned .jsonl under a known artifacts dir (which still serves
hard-aborted children whose refs were unregistered). Probing never
throws; a stale path or unreadable artifacts subtree reads as unavailable
instead of failing delivery of the settled result. Render the transcript
clause from that check, independently of the resume affordance, so a
still-resumable idle/parked agent keeps its hub resume hint and a
disk-backed transcript keeps its link. Idle-completion hints are
unchanged.

Signed-off-by: Christian Stewart <christian@aperture.us>
2026-07-22 20:22:37 -07:00
Kormákur c2fde74ef0 feat(coding-agent): configure isolated task apply behavior 2026-07-23 00:48:48 +00:00
can1357 242bcbef8c revert #6130: doesn't really work well 2026-07-22 23:54:15 +02:00
roboomp 00aed97ed1 fix(tui): flagged fallback badges for observer-only hub rows
- Threaded a resolvedModelIsFallback flag through AgentProgress and SingleResult.
- Set the flag from the executor retry-fallback handlers and settled results.
- Rendered the observer/no-session hub path as fallback -> provider/model.
- Added an observer-only fallback-badge regression test.

Fixes #6316
2026-07-22 19:19:08 +00:00
can1357 b39b49a2c4 docs(coding-agent): fix grammar in resolveSpawnItems doc comment 2026-07-22 21:13:23 +02:00
can1357 9c6c53435b Merge PR #6130: feat(coding-agent): add capture-only apply control to the task tool (@korri123) 2026-07-22 21:13:23 +02:00
can1357 9952adbc82 Merge PR #6242: fix(mcp): route task proxies through source tool and mark tools non-strict (@roboomp) 2026-07-22 21:13:21 +02:00
can1357 59db75d6d4 Merge PR #6205: fix(task): surface actionable shape error for batch calls (@roboomp) 2026-07-22 21:13:20 +02:00
can1357 5477e74bb3 Merge PR #6307: fix(coding-agent): align bundled task prewalk display (@roboomp) 2026-07-22 21:13:18 +02:00
can1357 a1bdf4a352 Merge PR #6214: fix(tui): refresh prewalked subagent model (@roboomp) 2026-07-22 21:13:18 +02:00
roboomp e2dc801d44 fix(coding-agent): aligned task prewalk dashboard state
Shared the bundled task prewalk default between runtime execution and the Agent Control Center. Added dashboard regression coverage for task.prewalk.

Fixes #6306
2026-07-22 17:14:36 +00:00
Kormákur b84ec8abdf Merge remote-tracking branch 'upstream/main' into feat/task-apply-control 2026-07-22 12:29:00 +00:00
Kormákur 1b83629ef1 fix(coding-agent): enforce capture-only isolation 2026-07-22 12:28:46 +00:00
maatheusgois-dd 6c15874d15 Clear workspace.additionalDirectories setting for isolated worktree subagent runs
Setting options.additionalDirectories to undefined wasn't enough:
createAgentSession also merges settings.get('workspace.additionalDirectories').
Now createSubagentSettings gets an override to clear the setting
when worktree is set, ensuring isolated runs can't edit outside the
worktree.

Co-authored-by: oh-my-pi <https://omp.sh>
2026-07-22 02:52:42 -03:00
maatheusgois-dd 2fa43ad5a6 Omit additionalDirectories for isolated (worktree) task runs
Isolated tasks clone only cwd into the worktree. Forwarding the
parent's additional directories would let the subagent edit absolute
paths under the original extra roots, bypassing isolation. Now
additionalDirectories is undefined when worktree is set.

Co-authored-by: oh-my-pi <https://omp.sh>
2026-07-22 02:44:56 -03:00