Commit Graph
10171 Commits
Author SHA1 Message Date
can1357 85acb9ab70 fix(rpc): surface drained stderr when startup fails under load
- RpcClient: when stdout closes before ready, race child.exited (which settles only after ptree drains the stderr tail for nonzero exits) for 250ms before rejecting, so the earlier-registered exit watcher rejects with the real stderr text instead of an empty 'Stderr:'.
- mock-rpc-agent fixture: await the stderr pipe write callback before process.exit so failure text cannot be dropped unflushed.
- sdk-tool-activation: restore the default extension-handler budget once the intentionally stalled activation times out, so full-suite machine load cannot also time out the genuine recovery registration.
Both tests flaked only under concurrent full-suite chunk load; 10 concurrent stress runs pass post-fix.
2026-08-14 14:23:15 +02:00
can1357 56efdfc4db Merge PR #8546: fix(coding-agent): restore Windows external editor launch (@roboomp) 2026-08-14 14:12:00 +02:00
can1357 aae72bd5ef Merge PR #8531: docs: correct /hotkeys Ctrl+D copy to match save-draft-and-exit (@roboomp) 2026-08-14 14:11:51 +02:00
can1357 d445f987da Merge PR #8515: fix(mcp): initialize sessions before opening sse stream (@roboomp) 2026-08-14 14:11:30 +02:00
can1357 04fab5ecb4 feat: replaced custom mupdf wasm pipeline with native function
- Replaced the custom MuPDF-WASM PDF extraction and rendering pipeline with the new `pdfToMarkdown` native function from `@oh-my-pi/pi-natives`.
- Removed legacy MuPDF extraction modules, WASM embedding scripts, and PDF image extraction tools.
- Added OCR warnings and browser/text redirection for unsupported PDF image reads.
- Updated native package definitions, documentation, and test suites for the new PDF inspection capability.
2026-08-14 14:08:28 +02:00
roboomp a9075ae509 fix(coding-agent): restored Windows external editor launch
Passed the cmd.exe /s /c command line through Bun verbatim so configured editors and temporary paths retain their quotes.

Added command-line regression coverage and documented the fix.

Fixes #8544
2026-08-14 11:27:13 +00:00
roboomp ff9c5189c9 docs: correct /hotkeys ctrl+d copy to match save-draft-and-exit
The /hotkeys table described app.exit (Ctrl+D) as "Exit (when editor is
empty)", implying readline/EOF-style conditional exit. The handler exits
unconditionally and snapshots the current prompt as a resumable draft
regardless of editor content (custom-editor.ts fires onExit for app.exit
with no empty check; input-controller.ts handleCtrlD calls shutdown()
unconditionally, which persists the draft). Corrected the line to
"Exit (saves current prompt as draft)".

Fixes #8530
2026-08-14 08:27:35 +00:00
roboomp 83d08936ae fix(mcp): initialized sessions before opening sse stream
Moved the optional Streamable HTTP GET listener after the initialized notification so stateful servers do not terminate the session during setup.

Added regression coverage for a server that rejects pre-initialization GET traffic.

Fixes #8514
2026-08-14 05:33:38 +00:00
usr-bin-roygbiv fe33232298 fix(gemini): preserve retry and rendering boundaries 2026-08-14 02:48:18 +00:00
usr-bin-roygbiv b1ce77c109 fix(gemini): recover malformed and thought-only turns 2026-08-14 01:35:21 +00:00
can1357 642d6c0b31 fix(coding-agent): preserved linked update ownership
Detected npm and Bun ownership from the bin link immediate target within each precise global node_modules root. Foreign aliases now update their resolved standalone binary without replacing the alias.

Fixes #8468
2026-08-14 00:27:16 +02:00
can1357 15981329d6 refactor(coding-agent): migrated external editor and removed obsolete tests
- Replaced child_process spawn with Bun.spawn in packages/coding-agent/src/utils/external-editor.ts.
- Removed the browser tab evaluation test suite from packages/coding-agent/test/tools/browser-tab-evaluate.test.ts.
2026-08-14 00:14:29 +02:00
can1357 6ecb1e3383 Revert "fix(coding-agent): routed foreign aliases to binary updates"
This reverts commit 834002adc5.
2026-08-14 00:13:49 +02:00
can1357 0d6a7146a3 feat(coding-agent): supported allSettled and any promise combinators in browser scope
- Added `allSettled` and `any` to tracked promise combinators in run scope.
- Updated browser cancellation tests to cover new promise combinators.
2026-08-14 00:11:04 +02:00
roboompandcan1357 a02f88994b fix(tools): preserve workspace-relative path in read hashline headers
formatReadHashlineHeader collapsed every relative in-workspace path to its
basename, so reading a nested file (e.g. src/settings.json) emitted
[settings.json#tag]. When a same-basename file existed at the session cwd,
a verbatim follow-up edit resolved against the cwd file; Patcher.prepare only
runs snapshot-tag path recovery when the authored path is missing, so the
valid edit was deterministically rejected with "hash is not from this
session". Keep the workspace-relative path, which names the file uniquely and
stays directly resolvable against cwd. Out-of-workspace absolute paths remain
shortened; root-level files are unchanged.

Fixes #8482
2026-08-14 00:04:59 +02:00
roboompandcan1357 834002adc5 fix(coding-agent): routed foreign aliases to binary updates
Resolved npm and bun bin-entry symlinks before selecting the update method, and preserved foreign aliases by replacing their standalone target.

Fixes #8468
2026-08-14 00:03:33 +02:00
roboompandcan1357 6fc50c3e41 fix(coding-agent): prevented post-yield TUI stalls
Kept the Bun event loop live across subagent yield drains and delayed parent result flushes. Added a timer-lifecycle regression for the idle flush.

Fixes #8462
2026-08-14 00:01:31 +02:00
can1357 58f319912e feat: introduced dynamic version discovery and rate limit parsing for google
- Added dynamic Antigravity version discovery with environment variable overrides and fallback endpoint support.
- Introduced structured Google RPC `ErrorInfo` rate limit reason parsing and backoff classification.
- Added `gemini-3.7-flash` and `deepseek-v4-pro:preview` model configurations alongside updated pricing.
- Removed system instruction injection logic and dropped unsigned thinking blocks for Antigravity requests.
2026-08-13 23:59:37 +02:00
can1357 6563b16424 fix(coding-agent): stat-poll git HEAD instead of fs.watch for branch display
- Bun's inotify-backed fs.watch permanently stops delivering events after
  observing git's atomic HEAD.lock -> HEAD rename in the watched directory
  (oven-sh/bun#24875), so the directory-watch fix for issue #8412 still froze
  the status-line branch on Linux after the first switch; CI caught it as a
  30s timeout in status-line-vcs-refresh.test.ts.
- Added git.head.watch: fs.watchFile stat-poll of the HEAD path (reftable dir
  for reftable repos) with a disposer; path-based polling survives inode swaps
  on every platform.
- Status line and footer now consume the helper; the footer previously bound
  fs.watch to the HEAD file inode and died after one switch on all platforms.
- Dropped the FSWatcher error-listener plumbing (StatWatcher has no error
  mode) and reworked the watcher lifecycle tests to the stat-poll contract;
  verified the atomic-rename regression test passes on Linux bun 1.3.14 in
  Docker where it previously timed out.
2026-08-13 20:20:49 +02:00
can1357 b279db1790 test: refactored test suites to eliminate time-based sleeps and polling loops
- Replaced time-based sleeps and polling loops with event-driven promise resolvers and fake timers across agent and tool tests.
- Migrated test suites to share in-memory auth storage and fixtures using lifecycle hooks.
- Updated catalog model definitions, metadata, and configurations.
2026-08-13 19:32:22 +02:00
can1357 28997c0d46 refactor(coding-agent): restructured transcript rendering during initialization
- Stage transcript initialization inside a detached TranscriptContainer to keep existing messages visible during incremental rendering.
- Add fallback state restoration in InteractiveMode.renderInitialMessages when chat rendering is aborted or fails.
- Update render-initial-messages tests to assert that old transcripts remain visible until replacements are fully committed.
2026-08-13 18:55:36 +02:00
can1357 a32cf5f30a Merge PR #8446: fix(coding-agent): confine browser executable probe to Linux (@roboomp) 2026-08-13 18:46:18 +02:00
roboomp cf1ff14f5f fix(coding-agent): confine browser executable probe to linux
The executable version probe added in ecb22957 ("validate Linux browser
executables") replaced the file-only check in resolveSystemChromium with
isChromiumExecutable, which spawns the candidate `--version` for every
platform. On Windows chrome.exe is a GUI-subsystem binary: `--version`
does not print to a detached stdout and can hand off to a running
instance, opening/activating the user's normal browser window, after
which the probe rejects the candidate and falls back to cached Chrome
for Testing.

Gate the spawn probe on process.platform === "linux" (its intended
platform, where non-Chromium PATH wrappers are the real risk) and trust
the executable-file check on Windows and macOS.

Fixes #8445
2026-08-13 16:28:57 +00:00
can1357 eadfbcb689 Merge PR #8440: fix(discovery): honor Claude config directory (@roboomp) 2026-08-13 18:01:31 +02:00
can1357 219123244e fix(update): serialize target swap under a per-target lock
Two overlapping `omp update` runs now share the target only for the
swap + stale-artifact sweep, guarded by withFileLock. This closes the
rollback race the unique-temp fix left open: a concurrent run's sweep
could delete a live run's .bak before its failed verification rolled it
back. The download stays outside the lock (unique temp path, safe to
overlap). Adds a regression covering a failed verification overlapping a
successful update.
2026-08-13 17:57:01 +02:00
roboomp 406306f972 fix(discovery): isolated plugin root caches by home
Included the resolved OMP plugin registry path in cache identity and covered shared Claude config directories across isolated SDK homes.
2026-08-13 15:44:02 +00:00
roboomp 3629464cf9 fix(discovery): honored claude config directory
Resolved Claude user configuration, plugin, MCP, and session paths through CLAUDE_CONFIG_DIR while retaining the legacy defaults.

Fixes #8436
2026-08-13 15:33:27 +00:00
can1357 69862139b3 Merge PR #8435: fix(update): unique temp path for concurrent self-updates (@roboomp) 2026-08-13 17:32:50 +02:00
roboomp 1d6d35bd24 fix(update): unique temp path for concurrent self-updates
Two overlapping `omp update` runs shared the fixed `<binary>.new` temp
path. downloadVerifiedBinary unlinks the target before writing, so the
second run's unlink deleted the first run's still-downloading temp file;
the first kept writing to its open fd (size and digest still passed),
then chmod hit the missing path and aborted with ENOENT.

Give the temp path the same unique per-attempt suffix the backup path
already uses (pid, timestamp, and a new process-local counter that also
covers same-millisecond, same-process collisions). Generalize the stale
backup sweep to also reclaim orphaned `.new` temp files, age-gated by the
download window so a concurrent run's in-progress temp is never deleted.

Fixes #8434
2026-08-13 15:17:41 +00:00
can1357 fcdaa2162a Merge PR #8425: fix(extensions): lower embedded omptype schemas in Type.Unsafe (@roboomp) 2026-08-13 16:57:20 +02:00
can1357 4ce4874e78 fix(cli): validate ACP tool allowlists after discovery 2026-08-13 16:57:17 +02:00
can1357 bc77dcabb6 Merge PR #8424: fix(cli): allow extension tools in --tools allowlists (@roboomp) 2026-08-13 16:57:14 +02:00
can1357 05eb8beebc Merge PR #8423: fix(extensions): populate runtime mode in context (@roboomp) 2026-08-13 16:57:11 +02:00
roboomp 3749478239 fix(cli): validated allowlists after tool discovery
Moved strict --tools validation to the completed session registry so extension modules, custom tool directories, and plugin manifest tools are all eligible while unknown names still fail startup.
2026-08-13 09:12:12 +00:00
roboomp a4adf17986 fix(extensions): preserved run properties in unsafe schemas
Require the omptype schema brand before treating a raw document's run key as the self-reference copied by a schema spread. This keeps legitimate JSON Schema properties named run intact while retaining spread-schema recovery.

Added regression coverage for a required boolean run parameter.
2026-08-13 09:06:18 +00:00
roboomp 9d7e13a158 fix(extensions): lowered embedded omptype schemas in Type.Unsafe
Legacy Pi extensions build raw tool-parameter documents against real
TypeBox, whose Type.* builders return plain JSON-Schema objects. omptype's
builders return callable schema values instead, so a legacy document that
embeds them (Type.Unsafe({ anyOf: [Type.Array(...), Other] })) or spreads
them (Type.Unsafe({ ...Schema, description })) carries functions. The shim
then structured-cloned that document during plugin install validation and
threw "The object can not be cloned.", rejecting extensions that load fine
when linked (e.g. pi-subagents, all published versions).

Type.Unsafe now lowers embedded builders to their wire JSON and rebuilds
spread documents from the copied run self-reference before cloning or
serializing, matching the plain-object schemas real TypeBox produces.

Fixes #8420
2026-08-13 08:59:50 +00:00
roboomp 6980275a50 fix(cli): allowed extension tools in allowlists
Deferred --tools validation until extension discovery, then validated against built-in and registered tool names while preserving strict rejection of unknown names.

Fixes #8421
2026-08-13 08:53:59 +00:00
roboomp 7463803c95 fix(extensions): populated runtime mode in context
Expose the Pi-compatible tui, rpc, json, or print host mode to every extension context and cover mode transitions in the runner regression suite.

Fixes #8419
2026-08-13 08:51:05 +00:00
roboomp e62814b4b0 fix(coding-agent): watch git dir so branch display tracks switches
The status-line branch watcher bound fs.watch to the .git/HEAD file.
git updates HEAD via a lock file plus an atomic rename (HEAD.lock ->
HEAD), which unlinks the watched inode, so the watch fired for the
first branch switch and then died on the stale inode. The displayed
branch froze on the previous branch while later switches went unseen.

Watch the git directory instead of the HEAD file (and, for reftable
repos, the reftable dir as before) and filter directory events for the
HEAD entry. The directory inode is stable across renames, so the watch
survives every switch.

Fixes #8412
2026-08-13 07:05:32 +00:00
can1357 a69d166e00 perf(discovery): memoized WSL host-home probe per environment
- Deduplicated the re-imported changelog bullets from the PR #8403 merge,
  keeping the condensed register with only the new #8402 entry.
- getUserHomeCandidates memoizes the WSL home candidate keyed by
  platform + WSL markers + USERPROFILE, so a wedged interop pipe costs
  one bounded probe per process instead of one 500ms stall per
  discovery loader, while env changes (tests, SDK embeddings) still
  recompute.
2026-08-13 06:51:35 +02:00
can1357 b47e3e8e35 Merge PR #8403: fix(discovery): bound WSL host-home probe with a hard timeout (@roboomp) 2026-08-13 06:49:19 +02:00
can1357 2d512cb253 refactor: generalized thinking loop guard for multiple model families
- Generalized thinking loop guard and helper functions to support Gemini, DeepSeek, and Grok model families.
- Replaced `withGeminiThinkingLoopGuard` and related Gemini-specific symbols with generalized counterparts.
- Removed deprecated `enableGeminiThinkingLoopGuard` options and associated tests.
- Updated test suites and agent session logic to use the generalized thinking loop guard and model family tokens.
2026-08-13 06:15:00 +02:00
can1357 cd72f22552 fix(lsp): restored overwritten rename target when move fails
- Displace overwritten destination into a temporary sibling directory during workspace renames.
- Restore the displaced file and clean up the temp directory if the main rename operation fails.
2026-08-13 06:05:20 +02:00
can1357 74f5f610c6 fix(lsp): reconciled executed prefix when workspace edit fails partway
- applyWorkspaceEdit takes an onExecuted callback fired after each
  filesystem mutation, so callers hold the executed prefix even when a
  later op throws.
- applyWorkspaceEditWithLsp reconciles overlays/watchers for that prefix
  best-effort before rethrowing the original apply error.
2026-08-13 05:58:40 +02:00
can1357 f52891fb82 fix(lsp): reconciled overlays from executed workspace-edit ops
- applyWorkspaceEdit now returns { applied, executed }; ops skipped via
  ignoreIfExists/ignoreIfNotExists are excluded from executed.
- applyWorkspaceEditWithLsp derives didClose/refresh/watched-file
  notifications from executed ops, so a skipped rename no longer closes
  the old URI overlay or emits phantom Deleted/Created events.
2026-08-13 05:54:28 +02:00
roboomp 4561bdc39a fix(discovery): bound WSL host-home probe with a hard timeout
resolveWindowsUserProfile() ran Bun.spawnSync(cmd.exe echo %USERPROFILE%)
with no timeout during startup discovery. When the WSL->Windows interop
pipe is wedged, cmd.exe never returns and the synchronous spawn blocks
the JS thread forever, so the TUI never paints and no log is written.

Route both best-effort probes (cmd.exe and wslpath) through a shared
runHostProbe() helper that spawns under a 500ms hard timeout with SIGKILL
and reports a killed/non-zero exit as "host home unavailable", so
discovery falls back to the Linux $HOME/~/.omp candidates instead of
hanging.

Fixes #8402
2026-08-13 03:52:31 +00:00
can1357 0af778ea54 Merge PR #8392: fix(lsp): isolate document overlays across sessions (@roboomp) 2026-08-13 05:48:27 +02:00
can1357 d8924d055b Merge PR #8399: fix(lsp): synchronize applied workspace edits (@roboomp) 2026-08-13 05:48:27 +02:00
can1357 2e6d81b528 Merge PR #8395: fix(lsp): roll back rename_file edits when the move fails (@roboomp) 2026-08-13 05:48:00 +02:00
can1357 e3771992a7 Merge PR #8396: fix(lsp): abort rename_file when willRenameFiles fails on a supporting server (@roboomp) 2026-08-13 05:47:21 +02:00