Commit Graph
864 Commits
Author SHA1 Message Date
can1357 a868a7d2d5 Merge PR #4471: fix(ai): separate Codex orchestration usage (@roboomp) 2026-07-05 13:03:08 +02:00
can1357 2e86e655c8 Merge PR #4524: fix(coding-agent): scoped /model search to the active provider tab (@roboomp) 2026-07-05 13:03:07 +02:00
can1357 d082c5ee0c Merge PR #4534: fix(tui): suppress empty assistant token badges (@roboomp) 2026-07-05 13:03:06 +02:00
can1357 686008b056 Merge PR #4544: fix(tui): avoid auto-linked token rate format (@roboomp) 2026-07-05 12:44:17 +02:00
Jagrav Naik 27d2109ca3 fix(session-selector): Backspace on empty search deletes session
macOS laptops have no dedicated Forward Delete key. Fn+Backspace is the
only way to send \e[3~, and many macOS terminals (Terminal.app, some
iTerm2 profiles) deliver \x7f for that combo instead — so the keystroke
landed in the search box, not the delete handler, making session deletion
unreachable for those users.

Add a Backspace-on-empty-search handler alongside the existing Delete
check. With a typed query, Backspace stays bound to the search Input so
users can still edit their filter text. The existing confirmation dialog
guards against accidents.

Footer hint updated: [Del delete] -> [Del/⌫ delete].
2026-07-04 21:16:40 -04:00
roboomp 55e2b473aa fix(tui): avoided auto-linked token rate format
Rendered the status-line token rate as an explicit tok/s unit so Ghostty no longer auto-detects the numeric value as a URL.

Added a regression test for the token_rate segment rendering contract.

Fixes #4541
2026-07-04 17:42:56 +00:00
roboomp 177977856a fix(tui): kept token badges for billed empty turns
Replace the visible-anchor suppression with a billed-usage predicate so live and resume paths agree on rendering the badge whenever the turn actually consumed tokens. Only genuinely free turns (no input, output, cache, or premium requests) drop the row, so hidden automated turns keep cost transparency.

Fixes #4532
2026-07-04 16:58:50 +00:00
roboomp c5c95ecd12 fix(tui): suppressed empty assistant token badges
Suppress token-usage rows for assistant turns that have no visible text, tool call, or terminal error anchor. Share the same decision across live rendering and transcript rebuilds so resume matches live output.

Fixes #4532
2026-07-04 16:40:09 +00:00
roboomp bfa44eb8c1 fix(coding-agent): scoped /model search to the active provider tab
`#filterModels` in `packages/coding-agent/src/modes/components/model-selector.ts`
used to auto-switch to the ALL tab on any non-empty query. Typing a search from
a provider tab silently escaped the scope, so selecting the apparent match could
persist a same-named model from a different provider (e.g. a custom-proxy
`glm-5.2` while the user was on the openrouter tab wanting
`z-ai/glm-5.2`) under the default role.

Keep the search scoped to the active provider tab; empty results now name the
active tab and point at ALL as the explicit escape. Regression tests in
`test/model-selector-provider-search-scope.test.ts` cover the scoped search,
the still-global ALL-tab search, and the empty-state hint.

Fixes #4522
2026-07-04 14:45:56 +00:00
can1357 10043a5990 feat(coding-agent): gated block lifecycle and state transitions
- Enforced strict history protection by gating ephemeral block removal on uncommitted state across controllers and UI components.
- Optimized settled-row calculations using explicit mermaid fence detection and improved scrollback integrity.
- Refactored transience management to target only actively streaming blocks, preventing redundant label rendering.
- Implemented persistent compaction for auto-retry errors and enabled consistent terminal title updates during session renaming.
2026-07-04 12:13:34 +02:00
can1357 42fc4e6b0a refactor(agent): unified transcript block finalization logic
- Replaced commit-based stability checks with a unified `isTranscriptBlockFinalized` tracking mechanism.
- Removed deprecated provisional rendering configuration and flags across tool and renderer interfaces.
- Standardized native scrollback boundary logic to pin at the first unfinalized block using settled row verification.
- Updated and refactored test suites to validate block finalization and settled row boundaries instead of deprecated commit stability methods.
2026-07-04 11:22:05 +02:00
can1357 6e2bba871e feat(agent): implemented automated retry recovery and transcript compaction
- Introduced an automated retry recovery system to track, manage, and persist recovered error states within agent sessions.
- Enabled compact transcript rendering for recovered auto-retry errors by removing heuristic commit machinery.
- Improved raw read tracking and provenance in the ReadTool to support refined file snapshot recording and hashline editing.
- Excluded recovered assistant messages from default model context and updated event controllers to handle retry recovery life cycles.
2026-07-04 11:22:04 +02:00
can1357 d5e9084e65 refactor: restructured audit logic and render boundary tracking
- Removed complex snapshot caching and volatile/stable state tracking logic.
- Replaced multi-zone audit logic with streamlined tail-sample checks.
- Simplified render boundaries by deriving a single final boundary from the live region.
- Eliminated redundant audit state management and auxiliary safe-end interfaces.
2026-07-04 09:50:20 +02:00
can1357 a96f2f9292 Merge remote-tracking branch 'origin/farm/ab9741c2/fix-mcp-oauth-windows-opener-and-url-truncation' 2026-07-04 05:14:28 +02:00
can1357 4bd8f270ae Merge remote-tracking branch 'origin/farm/a6b7ad66/mcp-oauth-carry-challenge-scopes' 2026-07-04 05:13:18 +02:00
can1357 21d2c2271a Revert "fix(tui): merged scrollback offer boundary repair"
This reverts commit ae89b3ff08, reversing
changes made to 227874dcc6.
2026-07-04 05:12:18 +02:00
roboomp 7049966def fix(mcp): hydrate JSON-body OAuth scopes from resource metadata
When the error body already advertises OAuth endpoints, `/mcp add` and `/mcp reauth` use `authResult.oauth` directly and skip `discoverOAuthEndpoints`, so scopes advertised only in the RFC 9728 protected-resource metadata document never reach the grant.

Add exported `fetchResourceMetadataScopes(url, opts?)` that fetches the metadata doc and returns `scopes_supported` / `scopes` / `scope`. Hoist the shared `readMetadataScopes` reader out of `discoverOAuthEndpoints`. At all three call sites (wizard, `/mcp add`, `/mcp reauth`), when `oauth` is populated from the JSON body but `oauth.scopes` is empty and `authResult.resourceMetadataUrl` was advertised, fetch the metadata and merge scopes onto `oauth`.

Regression tests cover the resource-metadata fetch and its failure/empty-doc paths.

Refs #4467
2026-07-03 23:27:18 +00:00
roboomp a52ed682c7 fix(ai): separated codex orchestration usage
- Added a Usage.orchestration sidecar for provider-side service tokens so Responses/Codex totals and costs stay accurate without inflating visible prompt input/cache buckets.
- Updated Codex/WebSocket usage, session/status aggregates, and usage reporting to preserve orchestration-aware totals.
- Added regressions for OpenAI Responses accounting, Codex WebSocket terminal usage, cost calculation, and session aggregation.

Fixes #4469
2026-07-03 16:44:12 +00:00
roboomp debce0757b fix(mcp): carry OAuth scopes from challenge and resource metadata
MCP servers such as JIT gateways advertise required scopes via the RFC 6750 `WWW-Authenticate` challenge (`scope="..."`) and via RFC 9728 protected-resource metadata (`scopes_supported` / `scopes` / `scope`), then reject follow-up requests with `insufficient_scope` when a bearer token was issued without them. OMP's discovery only picked up `scopes_supported` from the auth-server metadata document, so `/mcp reauth`, `/mcp add`, and the MCP add wizard silently minted scope-less tokens.

- Extract `scope`/`scopes` from the WWW-Authenticate challenge into a new `AuthDetectionResult.scopes` field via `extractOAuthChallengeScopes`.

- Thread a `protectedScopes` option through `discoverOAuthEndpoints` and its recursion; capture `scopes_supported`/`scopes`/`scope` off resource-metadata documents; use those scopes when the auth-server metadata omits them.

- Pass `authResult.scopes` from `analyzeAuthError` into every discovery call site (`/mcp reauth`, `/mcp add`, MCP add wizard).

- Add regression tests for insufficient_scope + resource_metadata, resource-metadata `scopes_supported` passthrough, and challenge-scope threading.

Fixes #4467
2026-07-03 16:10:21 +00:00
roboomp 721f6d4a08 fix(mcp): make full URL the primary OAuth copy target so SSH sessions work
Codex review flagged that advertising `launchUrl`
(http://localhost:<omp-port>/launch) as the visible `Copy URL:` breaks
SSH/WSL/headless users: their local browser resolves the URL against
the local machine (no OMP listening) and fails before ever hitting the
provider. On terminals without OSC 8 support, they lose the manual
`/login <redirect>` path entirely.

Every OAuth-facing surface now shows the full authorization URL as the
primary copy target and offers `launchUrl` as an additional "Local
shortcut (this machine only)" line for wide-terminal local users who
want the truncation-safe convenience:

- MCPAuthorizationLinkPrompt renders `Copy URL:` with the full URL and
  appends the local-shortcut row only when `launchUrl` differs. OSC 52
  clipboard staging in the MCP onAuth handler switches to the full URL
  (OSC 52 is a wire-level protocol — the terminal writes to the
  caller's LOCAL clipboard even when OMP is on a remote SSH box).
- LoginDialogComponent.showAuth, selector-controller onAuth,
  setup-wizard sign-in, and the auth-broker CLI mirror the pattern:
  full URL first, launchUrl as an optional local shortcut.
- Setup wizard uses `wrapTextWithAnsi`, not truncation, so the RFC
  7636 §4.3 downgrade bug that motivated launchUrl is unreachable
  through it; still surfaces launchUrl for wide-terminal convenience.

Regression tests in
`packages/coding-agent/test/modes/controllers/mcp-authorization-link.test.ts`
now assert:
- Full URL is the primary `Copy URL:` line so SSH sessions can complete.
- launchUrl still appears beneath as `Local shortcut (this machine only): …`
  when it differs from the full URL.
- No shortcut row when launchUrl is absent OR equals the full URL.
2026-07-03 08:57:55 +00:00
roboomp 97c1d08cce fix(mcp): surface a short launch URL and log Windows opener failures for OAuth
Two independent defects broke /mcp reauth against S256-only providers on
Windows boxes whose PATH no longer references System32:

1. openPath spawned bare rundll32 and swallowed the
   `Executable not found in $PATH` throw with a bare `catch {}`, so the MCP
   controller's outer try/catch was dead and the transcript unconditionally
   claimed "Opening browser automatically...".
2. TUI#prepareLine silently truncates any composed row wider than the
   viewport. MCPAuthorizationLinkPrompt rendered `Copy URL: <full URL>` as a
   single ~271-column line whose trailing parameter is
   code_challenge_method=S256. On the reporter's 270-col terminal the cut
   landed inside that parameter, dropping the method while keeping
   code_challenge — which RFC 7636 §4.3 treats as plain PKCE, which Linear
   correctly rejects with "The plain PKCE method is not allowed. Use S256
   instead."

OAuthCallbackFlow now hosts a `GET /launch` route on the same loopback
callback server it already runs; the route 302-redirects to the pending
authorization URL and is advertised as `OAuthAuthInfo.launchUrl` — a
~30-char copy target no viewport can meaningfully truncate. The MCP OAuth
fallback, /login, setup wizard, auth-broker CLI, and login-dialog all
prefer the launch URL for the visible copy target, keep the full URL in
the OSC 8 hyperlink for click-through, and the MCP flow additionally
stages the copy target on the clipboard via OSC 52 (same pattern the
setup wizard uses).

openPath now resolves rundll32.exe through %SystemRoot%\System32 (with a
C:\Windows fallback when SystemRoot is unset) and logs both synchronous
spawn throws and non-zero exits via the shared logger, so silent
misconfigurations show up in ~/.omp/logs/omp.*.log. The dead try/catch
around openPath in the MCP controller is removed.

Fixes #4418
2026-07-03 08:19:14 +00:00
can1357 16267f4e6a Merge remote-tracking branch 'origin/farm/51e9b851/tui-render-cpu-overhead' 2026-07-03 00:47:33 +02:00
can1357 f577f4cb22 ux(coding-agent): visualized advisor notes to distinguish from output
- Introduced a dedicated advisor rail symbol to differentiate note cards from thinking output.
- Applied bold custom header tags and severity-tinted rails to distinguish advisor notes from surrounding text.
- Shifted note body text to the default content color to prevent blending with dimmed thinking-output styles.
2026-07-03 00:46:46 +02:00
roboomp 30527aee0c fix(tui): cut TUI CPU overhead during interactive sessions
Four tightly-scoped hot-path fixes covering the highest-impact items in the
reporter's CPU profile (13.1 s profiled / 30 s window):

1. `event-controller.ts:handleEvent` no longer fires a blanket
   `statusLine.invalidate() + ui.requestRender()` before every session event.
   The pre-render was a leftover from #4145 when `updateEditorTopBorder()`
   still eagerly rebuilt the border; the lazy provider added in #4145 made
   it redundant. It fired on every `message_update`/`tool_execution_update`
   during streaming — the pre-render's frame ran while the handler was
   awaiting, then the handler's own `requestRender` scheduled a second
   identical frame. Every handler that mutates visible state already calls
   `requestRender()`.

2. `shimmer.ts:shimmerSegments` iterates the segment string in place instead
   of building a code-point array with `Array.from(seg.text)` every animation
   frame. Runs of same-tier chars are emitted via a single `slice` per run
   rather than accumulating into `runBuf`. Surrogate pairs stay atomic — the
   code-point index still advances by 1 per emoji. Microbench over 30k
   frames: 45 ms → 18 ms (2.53x), allocation rate down from ~N-per-frame to
   a handful per frame. New tests cover mixed BMP+surrogate and all-emoji
   inputs. `Array.from` was the #1 self-time hotspot in the reporter's
   profile at 10.2%.

3. `Markdown.setText` gains an equality guard mirroring `Text.setText`
   (returns `false` when `text === #text`). Providers re-emit identical text
   on ticks with no delta (throttled frames, reconciled tool-execution
   updates); each of those now short-circuits instead of dropping
   `#cachedLines` and forcing a full lex + wrap on the accumulated paragraph
   (the reporter's #3 hotspot at 8.4%). New test asserts render-reference
   stability + return-value semantics.

4. `SPINNER_RENDER_INTERVAL_MS` aligned with `SPINNER_GLYPH_ADVANCE_MS`
   (both 80 ms). The previous 33 ms cadence emitted ~2.4 paints per glyph
   step; the differential-output dedup only skips the write, not the
   compose walk. Visually identical (glyph advance was already 12.5fps),
   halves paints during tool execution.

Skipped (out of scope for a bug fix, deserve dedicated PRs):
- Freezing streaming prefix on single `\n` boundaries — correctness-bound
  to `\n\n` block separators (CommonMark loose-list continuation).
- Compose-phase idle gate + adaptive-backpressure moving-average — need a
  component-level dirty flag; the 200 ms cap in `#scheduleRender` was set
  for a reason (#4145 tail-latency guard).

Tests updated: two IRC-expiry tests in event-controller-message-start.test.ts
that were asserting the pre-render's second `requestRender` call now expect
one.

Fixes #4353
2026-07-02 22:11:26 +00:00
can1357 a721e56bf8 Merge remote-tracking branch 'origin/farm/7a7807b2/fix-status-line-gh-pr-lookup-hang' 2026-07-02 23:43:10 +02:00
can1357 b9ce7ef103 Merge remote-tracking branch 'origin/farm/b15f12c7/ssh-repaint-topology'
# Conflicts:
#	packages/coding-agent/src/tools/renderers.ts
2026-07-02 23:42:59 +02:00
can1357 ae89b3ff08 fix(tui): merged scrollback offer boundary repair
Merged PR #4330 and fixed the remaining offered-boundary regression by stopping offer promotion at intervening live blocks.

Verified with targeted transcript/native scrollback regressions: 40 pass.
2026-07-02 23:41:53 +02:00
roboomp 49b4ef50f8 fix(tui): fixed audited scrollback tail rows
Separated audited offerable transcript rows from durable snapshot rows so lower finalized content below a live block can be repaired instead of duplicated when the live block grows.

Added transcript and virtual-terminal regressions for the lower finalized tail case.

Fixes #4326
2026-07-02 16:24:11 +00:00
roboomp ef36ce22e2 fix(tui): gated ssh reset on actual paint
- Tracked placeholder/partial-result paints via render() override so an update landing before the shape reaches the terminal skips resetDisplay().\n- Added negative-case unit tests proving no reset fires when the intermediate shape was never painted.\n\nFixes #4314
2026-07-02 13:32:37 +00:00
roboomp 5ae28437b1 style: bun run fix 2026-07-02 13:01:43 +00:00
roboomp cc97fada73 fix(tui): repainted ssh topology flips
- Added renderer hooks for first-result placeholder replacement and partial-result settle repaints.\n- Enabled the hooks for SSH and covered the streamed-placeholder and settle seams.\n\nFixes #4314
2026-07-02 13:01:24 +00:00
roboomp 8f6bd66a5f fix(status-line): routed gh pr lookup through git.github.run with timeout signal
The status-line renderer's #lookupPr method called `gh pr view` through
Bun's raw `$` shell with no signal, no timeout, and no non-interactive
environment. A stalled `gh` process (keychain prompt, network hang, auth
deadlock) wedged the await forever; because #prLookupInFlight was set
before the call and never reset, subsequent renders skipped the lookup
and the child leaked indefinitely.

Route the lookup through the existing `git.github.run` helper with
`AbortSignal.timeout(git.GIT_COMMAND_TIMEOUT_MS)` so the child inherits
GH_NON_INTERACTIVE_ENV (disabling terminal and keychain prompts) and
receives SIGTERM on the standard 5-minute deadline. Non-zero exit still
falls through to the null cache, preserving the failure-tolerant
behavior.

Fixes #4234
2026-07-02 08:42:17 +00:00
can1357 3830ad353e merge PR #3843 (surviving delta): perf: streaming-reveal/render throughput + core hot-path optimizations (@oldschoola)
# Conflicts:
#	packages/coding-agent/src/config/model-resolver.ts
2026-07-02 10:31:45 +02:00
can1357 ebf41281e7 fix(tui): stop spinner ticks for frozen pending previews
The github renderer materializes plain Text per display rebuild, so its
animatedPendingPreview opt-in requested 30fps repaints with a frozen
glyph for the whole run_watch wait; drop the flag. Custom tools with
only one of renderCall/renderResult never route to the animated generic
fallback, so gate the unregistered-renderer spinner on both being
absent. Regression tests for both no-tick contracts.
2026-07-02 10:30:06 +02:00
can1357 6429de3e83 merge PR #4172: fix(tui): animate live tool spinners (@roboomp) 2026-07-02 10:30:06 +02:00
can1357 278056025b merge PR #4200: fix(tui): stop /move overlay from statting every entry per keystroke (@roboomp) 2026-07-02 10:30:06 +02:00
can1357 95b91c7f73 feat(coding-agent/tools)!: replaced paths arrays with path strings
- Replaced `grep`, `glob`, and `ast_grep` `paths` inputs with optional single `path` strings while preserving default workspace-root behavior.
- Added shared `toPathList` normalization for legacy arrays and JSON-encoded arrays across tool execution and TUI renderers.
- Updated prompts, fixtures, shims, transcript summaries, and tests to send and display the new `path` argument.
- Updated collab-web search tool cards to read `path` while falling back to legacy `paths` for historical transcripts.
- Recorded the contiguous coding-agent changelog run for the tool-path breaking change and adjacent TTS entries.
2026-07-02 08:30:33 +02:00
roboomp cf9533ac95 fix(tui): stat-fallback /move overlay Dirents with unknown type
Some filesystems (NFS, FUSE, older SMB) return UV_DIRENT_UNKNOWN, making every Dirent.isX() return false. The prior early-return dropped real directories on those mounts. Now only reject when a known non-directory type (file/device/fifo/socket) is reported; symlink and unknown-type entries fall back to fs.statSync.
2026-07-02 04:46:36 +00:00
roboomp e04316dc52 fix(tui): stop /move overlay from statting every entry per keystroke
The overlay's directory cache stored names only, so listChildDirectories/searchDirectories called fs.statSync on every cached entry per keystroke to filter directories — a stat storm scaling with the target directory size and particularly costly on Windows.

Cache fs.Dirent[] via readdirSync({ withFileTypes: true }) instead of names, classify with entry.isDirectory(), and fall back to fs.statSync only for entry.isSymbolicLink() so a symlinked directory still counts as one. Adds a regression test that spies on fs.statSync and asserts an O(1) stat budget per keystroke.

Fixes #4199
2026-07-02 04:41:46 +00:00
Can Bölükandcan1357 8e68b26315 Merge pull request #4185 from DeprecatedLuke/feat/make-token-info-nice
feat/make token info nicer
2026-07-02 02:59:04 +02:00
can1357 2b8f6bd568 fix(coding-agent): prevented terminal layout breakage from long error strings
- Introduces `sanitizeErrorLine` to collapse newlines, replace tabs, and shorten absolute paths.
- Truncates remote error and notice text to the available terminal width to prevent layout breaking.
- Corrects a potential runtime exception in status-line by safely accessing JSON stringified length.
2026-07-02 02:40:07 +02:00
luk 62efd9ded6 feat(usage-row): use database icon for cache, add ttft + throughput display 2026-07-02 00:25:54 +01:00
luk 308eabc6b3 feat(status-line): add throughput icon and simplify cache segments 2026-07-02 00:24:55 +01:00
roboomp 5d07fe5041 style: bun run fix 2026-07-01 22:10:59 +00:00
roboomp f6adba2931 fix(tui): bound macos command-v image paste
Fixes #4178
2026-07-01 22:10:38 +00:00
can1357 e4c3cba143 Merge PR #3875 (selective): skip double-format of revealed thinking blocks (@oldschoola)
Ports only the thinking double-format fix: resolveThinkingDisplay reuses block.thinking when rawThinking is set (buildDisplayMessage already formatted it), plus a single-entry memo in formatThinkingForDisplay and a rawThinking regression test. The PR's incremental reveal slicing is superseded by the already-merged #3848 (memoized grapheme slicing).
2026-07-01 22:37:36 +02:00
can1357 d9beb9731d Merge PR #4158: fix(coding-agent): paint selectedBg band on focused HookSelector row (@roboomp) 2026-07-01 21:53:19 +02:00
can1357 debe71ae0e Merge PR #4129: fix(coding-agent): preserved explicit :auto suffix in modelRoles (@roboomp) 2026-07-01 21:53:17 +02:00
can1357 3364c3c6fd fix(collab): surface remote transcript errors after rows 2026-07-01 21:50:54 +02:00
can1357 6019be42c5 Merge PR #3938: fix(collab): reject oversized remote transcript entries (@roboomp) 2026-07-01 21:50:54 +02:00