The SQLite read helper is documented as a structured selector path
with explicit pagination, while raw SQL already has a separate
q=SELECT escape hatch. This change rejects SQL control syntax outside
quoted strings so helper filters cannot override LIMIT/OFFSET, while
still allowing semicolons inside quoted literals such as LIKE '%;%'.
Constraint: Preserve the documented q=SELECT raw SQL path unchanged
Rejected: Replace where= with a new filter DSL | too broad for a regression fix
Confidence: high
Scope-risk: narrow
Directive: Keep table?where=... as a structured helper; if broader SQL is needed, route it through q=SELECT instead
Tested: bun --cwd=packages/natives run build; bun --cwd=packages/coding-agent run check; bun --cwd=packages/coding-agent test test/tools/sqlite.test.ts
Not-tested: Manual interactive omp read invocation against a live SQLite file
The structured SQLite helper interpolates `where=` directly into SQL.
A crafted clause like `where=1=1 LIMIT 1000000 --` could comment out
the helper's bound `LIMIT ? OFFSET ?`, returning the full table in
violation of the documented pagination contract.
Validate where= at the selector boundary and reject SQL comments,
statement terminators, and pagination/attach/pragma keywords. Raw SQL
remains available via ?q=SELECT... for callers that need it.
Fixes#735
Extracts a single `formatMatchPath` helper used by both the
fast-glob/native code paths and the streaming onMatch callback so
relative paths, trailing-slash handling, and directory markers are
produced consistently. Also drops the retry-without-gitignore fallback
when the gitignored pass returns zero matches, so a broad hidden-file
pattern that is fully ignored stays fully ignored instead of silently
flipping gitignore off on the second attempt.
resolveMultiSearchPath now reports `exactFilePaths` when every token
resolves to a plain file (no globs, no suffix glob) and accepts a
single resolvable token so partially-missing lists still search the
resolvable subset. grep iterates those exact files individually
instead of collapsing them into a brace-union glob, which preserves
the user's explicit file set even when siblings share a basename.
Also adds a small `[grep] match lines use ':'; context lines use '-'`
banner when context lines are rendered, and splits the per-file
rendering helpers so files with no remaining matches no longer emit
empty headers.
Apply now recomputes per-file replacement counts from the actual apply
pass and compares them against the preview. If totals or per-file
counts drift (file changed between preview and apply, or apply matched
nothing), the tool returns an isError result explaining that the
preview is stale instead of silently claiming success with mismatched
numbers.
The resolve tool now preserves the underlying tool result's details on
ResolveToolDetails.sourceResultDetails instead of dropping them, and
the renderer distinguishes a failed apply ("Failed") from a user
discard ("Discard") so errored applies are no longer mislabelled.
When a bash tool call requests a timeout outside the allowed 1-3600s
range, the effective clamped value and the originally requested value
are now emitted as a notice appended to the tool output and exposed on
BashToolDetails via requestedTimeoutSeconds. The renderer shows the
clamped+requested pair inline in the timeout badge.
Slots a new "apply_patch" variant alongside the existing edit modes
(replace, patch, hashline, chunk, vim). The mode accepts a single input
string containing a Codex *** Begin Patch / *** End Patch envelope,
parses it with a new lenient parser (heredoc-tolerant), and fans each
file-op out to the existing executePatchSingle so LSP writethrough,
plan-mode guards, fs-cache invalidation and diagnostics are shared
with the patch mode.
Exposes both tool shapes from the spec: the JSON function-tool variant
(§1.2, {input: string}) and the OpenAI custom-tool / Lark-grammar
"freeform" variant (§1.1, raw patch string). The edit tool advertises
a Lark grammar via customFormat and a wire name via customWireName;
openai-responses emits it as a grammar-constrained custom tool when a
model opts in with applyPatchToolType: "freeform" in models.json.
custom_tool_call / custom_tool_call_output are plumbed end-to-end
through the shared responses code (emission, streaming, history
replay), and the agent-loop dispatcher matches tool calls by either
name or customWireName so returned calls route correctly.
Also threads preview/diff rendering for apply_patch through the TUI
(tool-execution + edit renderer) so streaming patches show per-file
diffs like the other edit modes.
Default edit mode is unchanged (hashline); opt in via edit.mode or
PI_EDIT_VARIANT=apply_patch.
- Standardized missing-file read errors and now return `File not found: <path>` for absent edit targets.
- Centralized AI provider, usage, and OAuth helpers into shared modules to remove duplicated logic.
- Migrated OAuth/API-key login flows to shared factory helpers and removed inline prompt/token-exchange code.
- Reused shared tools and formatter utilities for discovery, stream tails, LSP batching, and source formatting.
- Consolidated repeated test helpers and fixtures into shared modules, replacing inline helper duplicates.
- Refactor path normalization to combine expandPath and normalizeLocalScheme
- Add validation in utils.ts to reject local:// paths as filesystem paths
- Fix bash-skill-urls regex to handle hyphen-prefixed local:/ patterns
- Add tests for hyphen-prefixed and @local: patterns
- Add negative lookbehind to regex in bash-skill-urls to prevent matching local:/
inside paths like /repo/local:/PLAN.md
- Normalize local scheme before expanding paths in path-utils
- Add test cases for both changes
Expands the regex pattern to match local:/ (single-slash) URLs in addition to local:// (triple-slash), preventing potential Linux path leaks.
- Add regex patterns for single-quoted, double-quoted, and unquoted local:/ URLs
- Add test coverage for all three quote styles
Extract duplicate normalizeLocalScheme regex pattern into a shared function in path-utils.ts. Updated interactive-mode.ts, approved-plan.ts, agent-session.ts, bash-skill-urls.ts, and plan-mode-guard.ts to use the shared utility. Also fixed error message formatting (removed extra backslashes).
On Linux, Node's path.normalize() collapses the double slash in
local://PLAN.md to local:/PLAN.md, creating a directory called local:
in the project root instead of routing through the local:// protocol handler.
Defense-in-depth fixes across 5 layers:
1. resolveToCwd() now throws if a path starts with any internal URL
scheme prefix (local:, agent:, skill:, etc.), preventing all 59
call sites from treating URIs as relative filesystem paths.
2. resolvePlanPath() now matches on local: prefix (not just local://)
and normalizes local:/ to local:// before resolution, catching
all slash variants.
3. Bash URL expansion regex and early-exit checks now also match
local:/ (single slash), and normalize before resolution.
4. Edit preview/diff functions now gracefully skip internal URL paths
instead of crashing via the resolveToCwd guard.
5. All startsWith('local://') checks updated to startsWith('local:')
with normalization in agent-session, interactive-mode, and
approved-plan modules.
Also adds local: to .gitignore to prevent accidental commits of the
leaked directory.
- Updated todo start handling to set the requested task to in_progress while demoting all other in_progress tasks to pending.
- Added task note rendering in summary output by prefixing each note line with "Note:".
- Set GIT_OPTIONAL_LOCKS to 0 in git execution options and added tests for out-of-order start jumps and note summaries.
- Replaced todo_write's `ops` payload with top-level mutation fields (`phases`, `complete`, `start`, `add_notes`, etc.).
- Removed in-place task content and note updates; moved note writes to append-only `add_notes` calls.
- Matched `add_tasks.phase` by phase ID or name and appended new note text to existing notes.
- Changed execution to drop strict in-progress update sequencing, support `start`, and auto-promote next pending task.
- Updated tests and prompt docs to use direct payloads (`phases`, `complete`, `add_tasks`) instead of `ops`.
- Removed the standalone vim tool and normalized built-in/requested tooling to edit.
- Updated session and SDK tool activation to dedupe lowercase names and track edit state via the edit key.
- Added vim-mode argument detection and delegated edit rendering/execution into Vim handlers under edit.
- Updated Vim step handling to auto-reorder numeric-positioned commands, including cc/C/S/s/i/I/A cases.
- Renamed prompt/changelog text and test expectations to reflect edit-only tool naming and usage.
- Fixed Vim path normalization to allow colon-prefixed targets without raising ToolError.
- Documented the new Vim path behavior in the package changelog.
- Updated chunk-edit benchmark prompts to read `test.rs` for edit and retry operations.
- Updated vim benchmark flow to use `vim`+`read`, import expected content, and display final expected output.
- Expanded benchmark fixtures to generate Rust `test.rs`, compute unified diffs, and add richer pool logic.
- Updated vim tool prompts to keep file paths separate from commands and to stress bottom-up multi-location edits.
- Added automatic reordering of simple `NGo`/`NGO` insertion steps to execute from highest to lowest line.
- Added command-path validation and Vim parser fixes for counted `i` inserts and clearer `;`/`,` error guidance.
- Removed live Vim preview state fields and priming/cleanup flow from tool execution and rendering.
- Changed vim insert-mode exit logic to close insert mode unless the final step is paused.
- Updated changelog entries and Vim edit-file prompts to clarify insertion behavior and examples.
- Updated vim tool argument handling to clone args directly and ignore __toolCallId/__cwd metadata.
- Added vim tool-call IDs across EventController, UiHelpers, and ToolExecution for per-call preview mapping.
- Extended Vim type and command parsing with update/write, edit, global, yank, and put handling.
- Added Vim engine support for new commands and motions, including gJ, g*, g#, g_, |, and gu/gU/g~.
- Reworked Vim tool flow to cache per-file engine clones, reuse tool details, and stream inserts in chunks.
- Updated vim.md and changelog to document new vim keys, ex aliases, and fixed :global preview behavior.
- Added parser and renderer tests plus a tmp/vim_test.txt fixture for chunked, cursor, and partial-insert cases.
- Removed `SearchDb` APIs and `searchDb` fields, dropping db-backed state from native and agent sessions.
- Replaced crate export `fff` with `fd`, moving fuzzy-find bindings into `fd.rs`.
- Removed `SearchDb`/picker fast-path logic from `glob` and `grep`, simplifying scan flow and dropping db args.
- Removed `SearchDb`/`getSearchDb` wiring from extension, tool, and task context constructors across coding-agent.
- Added over-indentation validation warnings in chunk-edit normalization for suspicious `~` body line formatting.
- Removed `bytes`, `fff-grep`, `fff-search`, and `blake3` deps, adding `grep-searcher = "0.1"`.
- Added rollback handling for pending INSERT-mode changes whenever a non-final kbd sequence leaves insert mode, and updated the resulting VimInputError with guidance for using `insert` and escaping insert transitions.
- Hardened VimTool execution by resetting stale insert state before processing commands and by only applying empty inserts when Vim remains in INSERT mode.
- Adjusted Vim search handling to mimic Vim magic escaping and taught `o`/`O` numeric prefixes to act like `Go`/`GO` line inserts, then updated the expected error message test.
- Clarified the Vim tool prompt to require `file` and clearly separate key commands from insert text.
- Added updated usage examples and best-practice guidance for whole-file replacement, line edits, search/replace, and undo.
- Documented key/mode constraints, including insert-entry requirements and required `<Esc>` handling between non-final commands.
- Fixed `G`/`gg` motions to distinguish "no count" (go to last/first line) from explicit count.
- Added parsing for literal `\x1b`/`\r` bytes and backslash escape sequences (`\r`, `\e`, `\n`, `\t`).
- Updated `#readCount` to return `hasCount` flag propagated through operator and motion resolution.
- Synced vim buffer fingerprint from disk on reuse to handle LSP writethrough reformats.
- Added `toolStrictMode` support with `all_strict`/`none`/`mixed` options to OpenAI compatibility.
- Fixed OpenAI-completion strict-mode flows by capturing failed HTTP responses and retrying once as non-strict.
- Fixed completion error reporting by surfacing captured status, headers, and JSON `type`/`param`/`code` details.
- Improved strict-schema enforcement with WeakMap memoization and circular-schema detection in sanitization.
- Fixed OpenRouter provider lookup by resolving fallback model IDs for suffix and date variants in registry resolution.
- Refactored benchmark tooling and added async RPC error-window tracking for scheduled run execution.
- Replaced deprecated `await` tool wiring with `poll` in tool exports and built-in tool registry.
- Updated bash and task prompts plus start-result messaging to direct users to the `poll` tool.
- Added effective timeout metadata to Bash tool results and rendered output to show that effective timeout.
- Implemented bounded auto-background wait logic that backgrounds jobs when the timeout window is exhausted.
- Propagated `combinedSignal` into `doGlob` so cancellation is honored during glob execution.
- Skipped fallback `doGlob(false)` when `timeoutSignal` was aborted to avoid redundant work.
- Sorted `result.matches` by descending `mtime` in JS to return the most recent hits first.
- Added `vim` as an edit variant in benchmark CLI/config and rating script coverage.
- Expanded benchmark execution so `vim` is treated as a mutation tool for retries, stats, and edit intent checks.
- Adjusted `TaskTool` output schema precedence so explicit params override agent frontmatter.
- Fixed `TaskTool` success counting by excluding aborted tasks from success totals.
- Improved validation guidance in `SubmitResultTool`/`TodoWriteTool` for clearer recovery when payloads are missing or invalid.
- Added background command PID regression coverage in `executeBash` to confirm a real, terminateable PID is returned.
- Added `VimTool` in `src/tools/vim.ts` with `open`, `kbd`, `insert`, and `pause` actions.
- Implemented `src/vim/{buffer,engine,parser,commands,render,types}.ts` for interactive Vim modes and operators.
- Updated `src/tools/index.ts` to normalize `edit`/`vim` tool selection and skip the inactive edit variant.
- Added `vim` registration in `BUILTIN_TOOLS` and `toolRenderers` for discoverability and output formatting.
- Added streaming renderer snapshots with viewport, caret focus, and diff output for `vim` calls.
- Added `test/tools/vim.test.ts` and `scripts/vim-edit-benchmark.py` coverage for the new editor stack.
- Added `vim` as a supported edit mode and resolved mode-specific active tool names.
- Migrated chunk-edit requests from legacy `op`/`content` to `path` plus `write`, `replace`, and `insert`.
- Replaced chunk-edit internals with `put`/`replace`/`delete` operations and ID-based selection.
- Updated chunk prompts/output docs to document ID-based selectors and `write: null` deletions.
- Switched chunk and grep render output to `@`/dash-style anchors and updated file-count behavior for multi-file edits.
- Updated multi-file result rendering with distinct file counting and pending-file progress indicator.
- Refreshed chunk-mode and chunk-tree tests for the new contract and anchor style.
- Added multi-file edit payload support by requiring per-entry `edits` arrays across patch, hashline, replace, and chunk modes.
- Changed edit schemas and validators to move `path` (and `sel`->`path`) and op data into each edit entry.
- Changed edit execution flow to parse `file:selector` paths, run single-entry executors per file, and return grouped per-file results.
- Updated chunk diff rendering and test expectations to emit consistent anchor gutters with spaced pipes and `^` head-line markers.
- Added hierarchical chunk grep output grouped by directory, file, and chunk with aligned chunk anchors.
- Updated chunk rendering to show clipped head/tail context with explicit truncation and expand markers.
- Changed chunk edit and streaming validation to use chunkToolEditSchema-based checks for safe edit detection.
- Enhanced grep rendering to use structured ChunkedGrepMatch data with displayPath and chunk checksum metadata.
fixed retained-kernel restart and owner cleanup edge cases during recovery and disposal
tracked async user_python hooks during disposal-sensitive execution paths and hardened startup warmup tracking
strengthened cleanup and kernel lifecycle regressions to remove deadlocks, false positives, and timing flakes
scoped retained-kernel ownership to agent sessions and cleaned it up on session disposal
cleaned up warmed python owners on session startup failure and rejected new direct and tool-based python starts during disposal, including async hook, preflight, and warmup races
- Added bash.autoBackground.enabled and bash.autoBackground.thresholdMs settings with defaults for background job behavior.
- Added auto-backgrounding support for long foreground bash commands with managed job state and timeout threshold.
- Updated bash prompts, job-protocol messages, and tool activation checks to use async and auto-background support.
- Added background bash completion integration with AsyncJobManager and end-to-end tests for short/long auto-background scenarios.
- Added SQLite path parsing and candidate validation for `.sqlite`, `.db`, `.db3`, and `.sqlite3` targets in read/write flows.
- Added SQLite read operations for table lists, schema views, row lookups, paginated queries, and raw SELECT mode.
- Added SQLite write operations for insert, update-by-key, and delete-by-key using JSON5 row payloads.
- Updated selector routing to validate SQLite headers and fall back to normal file reads/writes when not databases.
- Secured read mode by enforcing query validation to block destructive SQL execution on SQLite inputs.
- Added canonical model equivalence types, cache helpers, and registry APIs for provider variant lookup.
- Changed model resolution to apply canonical ID overrides/excludes with provider order before fallback matching.
- Added canonical and provider model views in list-models and selector UI with canonical sorting/persistence.
- Updated role/model persistence to store selectors while runtime now resolves concrete canonical-backed provider models.
- Reduced default image size limits to 1568px and 500KB to match Anthropic's internal thresholds.
- Optimized screenshot compression with 1024px max dimensions, 150KB budget, and 70% JPEG quality for aggressive payload reduction.
- Added fast-path optimization to skip re-encoding when images fit dimensions and are within 25% of byte budget.
- Refactored image encoding strategy to JPEG-only in quality/dimension reduction loops with improved quality ladder steps.
- Extracted result building logic into reusable buildResult function to eliminate duplication across three code paths.
- Consolidated import of natives module to use namespace import instead of destructured imports for consistency.
- Reorganized signal timeout initialization to occur before conditional branches for clarity.
- Added test case verifying mtime-based sorting of recursive filename matches.
- Added `extractReadableFromHtml()` utility function with dual-path content extraction using Readability library and CSS selector fallback.
- Integrated Turndown library with GitHub Flavored Markdown plugin for improved HTML-to-markdown conversion supporting tables, strikethrough, and task lists.
- Refactored `getPageReadable()` action to use new extraction function, consolidating content parsing logic and improving maintainability.
- Added TypeScript type declarations for turndown-plugin-gfm module with custom Turndown rules for enhanced markdown formatting.
- Extracted tab width resolution from pi-natives to pi-utils with EditorConfig caching support.
- Made tabWidth parameter required in native text functions (visibleWidth, truncateToWidth, wrapTextWithAnsi, sliceWithWidth, extractSegments).
- Removed process-wide tab width state management from pi-natives text module.
- Consolidated wrapper node promotion logic in chunk classification with abbreviated string representations.
- Removed path-clean and pathdiff dependencies from pi-natives.
- Updated all consuming packages to import tab width functions from pi-utils and pass explicit tabWidth parameters.
- Migrated language classifiers from imperative methods to declarative semantic rule tables with ClassifierTables and StructuralOverrides.
- Extracted node shape analysis into dedicated shape module with field priority constants and helper functions for AST traversal.
- Added schema module with language-aware node metadata and thread-local language context management.
- Centralized environment variable parsing across codebase using $flag(), $envpos(), and isBunTestRuntime() utilities.
- Added PI_CHUNK_AUTOINDENT configuration to control indentation normalization in chunk read/edit operations.
- Enhanced system prompt with instruction priority, output contract, tool persistence, and completeness guidelines.