Commit Graph

104 Commits

Author SHA1 Message Date
Wolfgang Schoenberger 88cb0729b0 docs(rpc): clarify unknown-frame fallback 2026-07-30 15:16:54 -07:00
Wolfgang Schoenberger 0f033ed706 fix(rpc): harden Python protocol compatibility 2026-07-30 15:16:54 -07:00
Frederico Luz 8e91af7b78 fix(rpc): expose fast mode in Python client 2026-07-29 20:26:39 +01:00
Frederico Luz ecbf759ec2 fix(rpc): preserve fast state in Python client 2026-07-29 20:17:09 +01:00
can1357 a9b7df8821 feat(python): implemented host tool event normalization and error checks
- Added `_normalize_host_tool_event` to `RpcClient` to remap transport tool events to executed host tools.
- Updated worker tool-end handling to verify `is_error` is false before marking terminal actions complete.
- Added test coverage in `test_client.py` and `test_worker.py` for host tool event normalization and errored review submission behavior.
2026-07-27 07:11:18 +02:00
can1357 e21f7c18ea feat(python/omp-rpc): added blocker field and blocked status to todo items
- Add blocked todo status and optional blocker attribute to todo items.
- Update RPC client and worker serialization logic to support todo blockers.
- Add test coverage for parsing session state with blocked todos.
2026-07-27 05:22:10 +02:00
can1357 bebcc8003f test(robomp): cover issues opened/reopened -> triage_issue dispatch mapping
The queue-level dispatch of issue events had no test at all; a revert of
the reopened mapping in WorkerPool._dispatch would silently reintroduce
the routing gap #5891 fixes. Mirrors the existing PR-review dispatch
test convention.
2026-07-23 22:15:24 +02:00
roboomp 3967ad0d5d fix(robomp): route issues.reopened to admission-gated re-triage
The finalized-issue boilerplate promises "reopen and I'll triage again from
scratch," but github_events.route() dropped issues.reopened to the ignored
skip branch (only opened/closed handled), while pull_request.reopened was
already routed. A user following the instruction got silence.

Route issues.reopened like issues.opened (submitter-attributable triage_issue,
same per-user rate budget) and dispatch it in queue._dispatch(). triage_issue
now tears down a stale finalized workspace (merged/closed/abandoned) before
re-provisioning, mirroring the maintainer directive-reopen teardown so the
re-triage branches afresh from default instead of a merged/deleted branch.

Fixes #5891
2026-07-23 19:18:48 +00:00
can1357 04a57c958b feat(python/robomp): retried transient 5xx errors for idempotent requests
- Add automatic retries for transient 5xx status codes on idempotent request methods.
- Ensure non-idempotent methods like POST fail immediately without retry.
2026-07-23 20:41:36 +02:00
can1357 33f3cea9ce chore(robomp): carried over sandbox test from shared worktree 2026-07-23 17:38:54 +02:00
can1357 2da45f9f9a chore: aligned blocked-todo test, added robomp sandbox scaffolding
- Aligned the blocked-todo reconciliation test with the debounced
  subagent-lifecycle observer on main (fake timers + 100ms advance).
- Carries in-progress robomp queue/sandbox/config scaffolding from the
  shared worktree (.env.example, config.py, queue.py, sandbox.py).
2026-07-23 17:35:35 +02:00
can1357 f833810d0e fix(rpc): stream v2 chunk frames with backpressure and recover stale page cursors
Two fixes on top of the paged transport:

- Near-limit v2 framing no longer materializes the full base64 transport:
  chunk lines are generated lazily from a single serialization, the 64 MiB
  reassembly ceiling is enforced via Buffer.byteLength before any
  full-payload allocation, and RPC stdout writes drain with backpressure
  one physical line at a time. Peak RSS for a 63 MiB response drops
  ~686 MB -> ~521 MB; a rejected 80 MiB response drops ~507 MB -> ~259 MB
  (parity with the v1 path).

- get_messages_page errors now carry a machine-readable code
  (session_busy | stale_cursor). Both bundled clients' high-level
  getMessages() drains discard partial pages and fall back to the legacy
  snapshot on either code — previously a cursor invalidated by a
  background mutation (e.g. an appended bash message) threw instead of
  falling back. Direct page calls remain strict.
2026-07-23 12:38:13 +02:00
Wolfgang Schoenberger 00a9167223 fix(rpc): accept exact-boundary v2 chunks 2026-07-22 19:13:53 -07:00
Wolfgang Schoenberger a0cb946057 fix(rpc): preserve v2 snapshot semantics 2026-07-22 19:00:48 -07:00
Wolfgang Schoenberger ce8c9dc75f feat(rpc): page stable message histories 2026-07-22 18:38:03 -07:00
can1357 bb15939414 **no more vouching! let's see how it goes for a week :)** 2026-07-23 02:41:47 +02:00
Wolfgang Schoenberger e0712265f2 fix(coding-agent): reconstruct compacted RPC prompt histories 2026-07-18 15:13:09 -07:00
can1357 6a77a4815c feat(robomp): added TUI wontfix rule and prohibit editing prompts and tool shapes
- Adds TUI scrollback classification rule classifying it as wontfix with explanation.
- Adds system rule prohibiting editing prompt files or changing tool shapes; flags root causes instead of modifying them.
2026-07-18 21:20:49 +02:00
can1357 8a57bcd4f0 Revert "Merge PR #5886: fix(robomp): defer rate-limited submissions (@roboomp)"
This reverts commit 81102634c8, reversing
changes made to 5c9b5f7b64.
2026-07-18 21:15:38 +02:00
can1357 81102634c8 Merge PR #5886: fix(robomp): defer rate-limited submissions (@roboomp) 2026-07-18 19:57:45 +02:00
can1357 8640c0dded refactor(python/robomp): renamed typecheck npm script to check:types
- Renamed `typecheck` script to `check:types` in the web package.
- Updated AGENTS.md documentation to reference the renamed script.
- Removed duplicate `start` script from metaharness package.json.
2026-07-18 19:26:41 +02:00
roboomp 4d494cc512 fix(robomp): promote deferred events on periodic sweep
Ran deferred-submission promotion on an independent timer in addition to the empty-queue path, so a sustained ordinary queue can no longer starve a rate-limited submitter after their rolling window frees. Added ROBOMP_DEFERRED_PROMOTION_SCAN_SECONDS to tune or disable the sweep.

Fixes #5882
2026-07-17 17:33:23 +00:00
roboomp aecef46436 fix(robomp): deferred rate-limited submissions
Stored a bounded per-login overflow backlog and promoted deferred events oldest-first as rolling-window capacity became available. Surfaced the deferred state through the dashboard contract and documented admission behavior.

Fixes #5882
2026-07-17 17:26:39 +00:00
can1357 e426186e46 feat(robomp): added local issue indexing and commit-search tool support
- Added `ROBOMP_ISSUE_INDEX_SYNC_SECONDS` configuration and lifecycle-managed issue indexing through startup/shutdown hooks.
- Added issue/PR index tables with FTS5 triggers plus upsert and keyword/filter search helpers for indexed records.
- Added GitHub backend/proxy support for `IssueIndexEntry` and issue-index page retrieval, including webhook ingestion and periodic watermark-driven sync.
- Updated `gh_search_issues` to prefer local index queries when synchronized and added `search_commits` host tool with query modes and validation.
2026-07-15 00:46:08 +02:00
can1357 3e6ae36c7c feat(robomp): added repo-scoped issue search to issue triage flow
- Added `search_issues` support to the GitHub backend and client, including `state_reason` and `is_pull_request` in issue summaries.
- Added the `gh_search_issues` host tool with repo-prefixed query handling, non-empty/restricted `repo:` validation, default and bounded `limit` values, and inbound issue filtering.
- Added proxy integration for issue search with a new `/gh/v1/search_issues` endpoint and matching proxy-client method/response parsing.
- Updated triage prompts to perform pre-`classify_issue` duplicate and already-fixed checks via search, and added tests for search query formatting, validation, and state-aware match rendering.
2026-07-15 00:30:15 +02:00
can1357 539c132094 feat(python/robomp): refined issue triage prompts with stricter bug classification rules
- Updated the system prompt to require additional bug-gate checks, including repo-owned-defect and premise-verification before labeling a report as `bug`.
- Added non-bug routing guidance for upstream-caused failures, environment/user errors, duplicate audit batches, and out-of-scope or already-possible scenarios.
- Adjusted host-tool and issue kick-off prompt instructions to call out upstream vs this-repo cause checks and expanded wontfix rationale wording.
2026-07-15 00:17:00 +02:00
can1357 79faf94f26 feat(python/robomp): added the wontfix primary classification and comment-only triage path
- Added `wontfix` to primary classification handling by updating host-tool classification metadata and issue taxonomy prompts.
- Updated kickoff/follow-up/system prompt guidance to treat intentional-design reports as `wontfix`, with maintainer-intent signals stopping work and ending in a single explanatory comment.
- Added tests to verify `classify_issue` persists a `wontfix` classification and returns a no-PR, comment-only next step.
2026-07-15 00:09:00 +02:00
can1357 55f5ebec49 chore: reformat 2026-07-15 00:08:50 +02:00
can1357 465f463ada fix(python/robomp): ensured omp run directory remained writable for all slots
- Added entrypoint setup for `/srv/agent-home/.omp/run` to enforce `omp` group ownership, group-write access, and setgid permissions so any sandbox slot can create or enter daemon state directories.
- Updated worker startup to skip generic home normalization on `.omp/run` and added a root-only run-dir preparation pass that reasserts `omp` ownership and writable, setgid permissions before launching subprocesses.
2026-07-14 17:56:37 +02:00
can1357 d469064d1a fix: handle stale tests 2026-07-11 07:54:19 +02:00
can1357 d435385ab1 feat: introduced max reasoning effort tier across model and rpc systems
- Introduced `Max` as a first-class reasoning effort tier across all packages, including AI providers, coding agent configurations, and RPC protocols.
- Refactored model effort ladders to use wire-exact mappings and removed legacy effort aliasing (e.g., `max-to-xhigh` mapping).
- Updated model registry and provider configurations to support `Max` tier routing, color themes, and UI icon associations.
- Expanded test suites to provide end-to-end coverage for the new reasoning tier, including updated compatibility and fallback scenarios.
2026-07-10 13:39:42 +02:00
can1357 b3c7646b4c feat(python/robomp): enforced commit message repair failures
- Make commit message repair mandatory once broken escapes are detected.
- Implement a failure handler that halts execution and provides manual correction instructions when git operations fail during the rewrite process.
- Ensure that partial states are avoided by refusing the push instead of allowing it with uncorrected messages.
2026-07-02 22:58:03 +02:00
can1357 22e9224ae8 feat(robomp): integrated linting amends and commit message sanitization
- Updated `_run_pre_publish_bun_fix` to amend `bun run fix` output into HEAD instead of creating standalone `style:` commits.
- Added `_repair_commit_message_escapes` to detect and rewrite commit messages containing shell-literal `\n` sequences into real newlines.
- Enforced safety checks during `bun run fix` to ensure HEAD is mutable and locally authored before amending.
- Improved documentation in prompts and README regarding commit message formatting and formatter workflow changes.
2026-07-02 22:55:07 +02:00
metaphorics 16600e89ab fix(robomp): harden sandbox cleanup, git-probe, and worktree-add paths
A diff-scoped review of the event-loop-hang fixes surfaced gaps in the new
timeout/error-handling code and its tests. All at/above the medium floor,
each mutation-verified.

- remove_workspace: prune on any nonzero `git worktree remove` (not just a
  present checkout) and RAISE on a failed prune, so a killed remove that
  leaves a dangling pool registration is cleared or retried instead of
  recording success over stale metadata. Gate git ops on the pool being a
  real clone (ensure_clone mkdir's the dir before cloning, so a failed first
  clone leaves a non-git dir where `git worktree prune` would error), and
  only speculatively prune a missing checkout when ws_root still exists.
- _worktree_add: new helper wrapping the three worktree-add sites; on a
  failed add (incl. the new 124 timeout) it removes the partial checkout and
  prunes the pool before re-raising, so the event retry starts clean. Raises
  a failed prune chained from the add error.
- _reset_origin_url: a timed-out (124) `git remote get-url origin` probe is
  indeterminate; raise before fetch instead of silently skipping the rewrite,
  so a legacy credentialed origin cannot persist and be reused.
- tests: assert the subprocess timeout is passed in the _safe_run/_run
  timeout fakes; add a real-`git worktree prune` integration test; make the
  cancel-drain test deterministic (loop-turn pump, no wall-clock sleep) and
  cover the repeated-cancel branch; add regressions for the prune-failure,
  checkout-gone-on-entry, non-git-pool, and repeat-close cleanup paths.

Op: correct
Restores: spec:pool-cleanup-clears-or-retries-dangling-registration
Restores: spec:indeterminate-git-probes-raise-not-silently-proceed
2026-07-02 13:04:19 +09:00
metaphorics dfaa41f6b3 fix(robomp): prune pool metadata on any failed worktree remove
`remove_workspace` guarded its rmtree+prune fallback on `repo_dir.exists()`.
But a `git worktree remove` that is killed (incl. a 124 timeout) mid-operation
can delete the checkout *before* it clears the pool's worktree registration.
In that window `repo_dir` is already gone, so the exists() guard skipped the
prune and left dangling metadata — the next `git worktree add` for the same
path then failed with "missing but already registered worktree".

Guard the fallback on the remove command's return code instead; prune runs on
any nonzero exit regardless of whether the checkout was already deleted. Added
a regression test for the remove-deleted-checkout-then-died case, which the
existing test (checkout survives) never covered.

Op: correct
Restores: spec:failed-worktree-remove-must-prune-dangling-pool-metadata
2026-07-02 10:24:06 +09:00
metaphorics b7bcc0bbf0 fix(robomp): address PR #4184 review nits
- log the worker thread's exception when a workspace op raises during
  caller cancellation, so a persistently failing setup surfaces instead
  of being buried behind CancelledError.
- raise on a timed-out (124) git symbolic-ref probe in the repo-exists
  path, matching the rev-parse probes, instead of silently accepting the
  caller-supplied branch.
- assert the subprocess timeout is passed in the two _chown_workspace
  test fakes so a refactor cannot silently drop the bound.

Op: correct
Restores: spec:indeterminate-git-probes-raise-not-silently-proceed
2026-07-02 09:58:14 +09:00
metaphorics 6d16c19a04 fix(robomp): run sandbox setup/teardown off the event loop safely
Workspace setup/teardown (git clone/fetch, worktree add/remove, chown)
ran synchronously on the asyncio dispatcher loop, so one stalled
subprocess froze the entire process.

- Offload every ensure_workspace/remove_workspace call to a worker thread
  via a new _run_workspace_op helper that drains the thread to completion
  on cancellation, so a cancelled event cannot reap/release a slot the
  setup thread still owns.
- Serialize same-repo setup with a per-repo threading.RLock while letting
  distinct repos run concurrently.
- Bound the direct git/chown subprocesses with a 120s timeout
  (returncode 124); treat a timed-out branch probe as an error rather
  than "branch absent" to avoid silently rebasing a follow-up onto the
  default branch and losing the PR's commits.
- When a timed-out worktree remove leaves the checkout behind, rmtree it
  and run `git worktree prune` so the pool's dangling registration cannot
  trip a later worktree add for the same path.

Adds regression tests for event-loop liveness, cancellation-safe offload,
per-repo lock serialization, subprocess timeout mapping, the branch-probe
timeout guard, and worktree-prune after a failed remove.

Op: correct
Restores: spec:dispatcher-event-loop-never-blocks-on-workspace-io
2026-07-02 08:10:37 +09:00
can1357 958a923a42 feat(python/robomp): implemented retry logic for transient network errors
- Added exponential backoff retry mechanisms to `GitHubClient` and `GitHubProxyClient` request methods.
- Included handlers for `httpx.ConnectError` and `httpx.TimeoutException` to improve resilience against transient network failures.
2026-06-24 17:22:42 +02:00
can1357 93f8548f6a security(git): hardened git operations by neutralizing malicious local config
- Constrained git configuration for smart-HTTP requests by explicitly overriding proxy, sslVerify, and credential helpers across all relevant path suffixes.
- Prevented potential credential capture by disabling repo-configured credential helpers that could otherwise execute malicious commands during authentication challenges.
- Hardened git operations against attacker-injected proxies by exhaustively blanking configuration keys for all identifiable git request endpoints.
- Excluded sslCAInfo/sslCAPath from overrides to prevent premature TLS negotiation failure while maintaining security via mandatory proxy neutralization.
2026-06-24 15:30:29 +02:00
can1357 7bcbbc7d1a security(proxy): prevented malicious refspec injection via input validation
- Added `_require_fetch_ref` validator to enforce strict alphanumeric character sets and disallow special git characters (e.g., `:`, `--`, `..`, `*`).
- Integrated validation into `git_fetch_ref_endpoint` to block malicious refspec inputs before git execution.
- Added test cases in `test_proxy_server.py` to verify rejection of attempted shell and refspec injections.
2026-06-24 15:30:29 +02:00
can1357 02d4de9453 test(git): validated git configuration hardening against security bypasses
- Added test suite to verify git configuration overrides for auth tokens.
- Validated that repo-local git configurations cannot override security-critical settings such as proxy, sslVerify, and credential helpers.
- Confirmed that smart-HTTP path-specific overrides are correctly applied to prevent proxy-based MITM attacks.
- Ensured system CA locations remain untouched to prevent disruption of TLS verification.
2026-06-24 15:30:29 +02:00
can1357 1344be8ae7 fix(python/robomp): restricted URLs starting with a hyphen in proxy server
- Added a check to reject remote URLs that begin with a hyphen to prevent command-line option injection.
- Updated the test suite to verify that option-shaped URLs are correctly blocked.
2026-06-23 20:26:44 +02:00
can1357 c58f72d943 chore: update changelogs 2026-06-23 20:22:31 +02:00
can1357 c752aee69d security(python-robomp): implemented git remote validation and credential hardening
- Sanitized git subprocess environment variables to prevent leakage of parent authentication tokens.
- Enforced strict HTTPS protocol restrictions and source validation for all git repositories.
- Implemented secure remote URL handling to neutralize malicious push URLs and prevent credential exfiltration.
- Applied scoped token injection during git operations to restrict token exposure to intended targets.
2026-06-23 20:19:14 +02:00
runbgp bc41b2ed3e fix(robomp): refused token-bearing git ops to attacker-controlled origins
- Extracted `_pat_safe_remote` and rejected HTTP(S) origins with embedded credentials or mismatched host/repo.
- Guarded `clone` via `_assert_clone_url_safe` on the caller-supplied `clone_url` (pool has no `origin` yet).
- Asserted origin safety before `fetch`, `fetch_ref`, and `fetch_pr_head` inject the PAT header.
- Appended POSIX `--` separator in `omp_local` so prompts starting with `-` aren't parsed as flags.
- Added proxy tests covering attacker-origin fetch rejection and unsafe `clone_url` refusal.

Co-authored-by: can1357 <me@can.ac>
2026-06-23 19:57:15 +02:00
can1357 69d0ac4dd3 fix(python/robomp): updated mention regex to correctly reject suffixes
- Updated the mention extraction regex to prevent partial matching when a suffix follows the `[bot]` identifier.
- Added a regression test to ensure that invalid extended suffixes are correctly rejected.
2026-06-21 19:26:42 +02:00
can1357 24a0c8428a feat(python/robomp): implemented has_authorized_impl_event in the
- Implement `has_authorized_impl_event` in the database to retrieve historical authorization state.
- Update `_enforce_impl_authorization` to permit actions if prior events on the issue provided implementation authorization.
- Normalize maintainer logins by stripping `[bot]` suffixes and allow match-regex to ignore them.
2026-06-21 19:18:37 +02:00
can1357 4b2e4085e0 feat(robomp): improved authorization and login normalization
- Implemented case-insensitive normalization for bot logins to handle mention handles and `[bot]` suffixes consistently.
- Added support for `ROBOMP_MAINTAINER_LOGINS` to allow authorized non-owner users to execute implementations.
- Refined authorization logic to distinguish between personal repository owners and organizational accounts.
- Updated documentation and added comprehensive tests to verify authorization handling across tasks, workers, and directive processing.
2026-06-21 19:14:13 +02:00
can1357 4b9f7cd8fa feat(python/robomp): allowed personal repository owners to authorize implementations
- Updated configuration to strip the '@' prefix from bot login names.
- Granted personal repository owners authorization to trigger implementations regardless of their GitHub author association.
2026-06-21 19:05:31 +02:00
can1357 5a99705797 feat(python/robomp): added authorizes_impl support to task directive processing
- Included authorizes_impl field when attaching threads to directives.
- Added a test case to ensure the author authorization flag is preserved during directive hydration.
2026-06-21 18:51:24 +02:00