Commit Graph

900 Commits

Author SHA1 Message Date
can1357 8acd667005 Merge PR #6780: fix(shell): correct kill signal handling (@roboomp) 2026-07-27 15:57:47 +02:00
can1357 8facd237d5 feat(build): migrated native pipeline to bazel with remote caching
- Replaced the napi-cli/cargo-zigbuild/cargo-xwin/sccache build path with
  Bazel: rules_rust + crate_universe over Cargo.lock, hermetic zig cc
  toolchains (linux-gnu pinned to glibc 2.17, linux-musl), host Xcode for
  darwin, and a repo-local hermetic clang-cl + llvm-ml + xwin toolchain for
  windows-msvc (bazel/toolchains/msvc).
- All eight shipped addons build as //:natives-<target> via the release
  transition in bazel/defs.bzl (opt, thin LTO, cgu=16, stripped, canonical
  .node naming); scripts/bazel-natives.ts is the single driver for local
  dev and CI.
- Rust validation moved to bazel test + clippy aspects (strict workspace
  policy for opted-in crates, default lints elsewhere, mirroring cargo
  semantics) and the rustfmt aspect; cargo stays as the dev-iteration
  surface, with brush-core/brush-builtins promoted to workspace members
  and excluded from cargo dev tasks to keep their historical scope.
- CI caches through an in-cluster bazel-remote action cache (TLS + basic
  auth, cluster-internal only); GitHub-hosted runners never touch the
  infrastructure and use an actions/cache-backed disk cache instead.
- Deleted the hand-rolled caching machinery: ci-target-cache,
  ci-native-artifact-cache, ci-build-native, native-source-hash,
  find-native-artifacts, restore-linux-native, native-prewarm workflow,
  ensure-* toolchain actions, and all sccache/Swatinem wiring.
- Warm native rebuilds drop from ~20 minutes to seconds; a cold client
  with a warm remote cache rebuilds the linux x64 pair in ~2.5 minutes.
2026-07-27 12:22:19 +02:00
roboomp 0c1fd7f5d8 fix(shell): preserved negative pid when clap eats --
clap consumes the -- marker before execute for the default-signal and -s/-n forms, so kill -- -10 and kill -s TERM -- -10 previously misread the negative PID as a signal. Captured post-marker operands via a dedicated last=true field and treated a preselected -s/-n signal as closing the option position.

Added a regression covering both marker-consumed forms.

Fixes #6779
2026-07-27 09:42:32 +00:00
roboomp 0e0fa77a51 fix(shell): continued kill after target failures
Recorded per-target PID and jobspec errors while continuing through every remaining operand, then returned a non-zero aggregate status.

Added a regression with a stale PID between two live processes.

Fixes #6779
2026-07-27 09:32:21 +00:00
roboomp fb6a62c227 fix(shell): preserved negative pid operands in kill
Restricted -sigspec parsing to the option position and consumed the -- end-of-options marker, so negative PIDs (process groups) and post-marker operands are signaled rather than parsed as signals.

Added a process-group regression covering kill -TERM -- -<pgid> <pid>.

Fixes #6779
2026-07-27 09:27:57 +00:00
roboomp 38e143d7cf fix(shell): corrected kill signal handling
Accepted numeric signal specifications, signaled every process operand, and restored SIGTERM as the default.

Added process-level regressions for multi-target SIGKILL and graceful default termination.

Fixes #6779
2026-07-27 09:14:13 +00:00
roboomp b351c8e467 fix(natives): surfaced sort worker panic instead of silent truncation
Returning end-of-input from chunks::read on a disconnected receiver
also masked a panicking ext_sort sorter thread (comparator or Rayon
panic in sort_by), letting sort exit 0 with truncated or empty output.
Retain the sorter JoinHandle and join it after read_write_loop, mapping
a thread panic to an error; drop the sorted-chunk receiver first so a
still-running sorter unblocks instead of deadlocking the join. Added an
external multi-chunk sort test covering the spill-to-files join path.

Fixes #6736
2026-07-27 06:04:06 +02:00
can1357 7d3f9d382c chore: bump version to 17.1.5 2026-07-27 05:30:59 +02:00
can1357 31457c3798 Merge PR #6760: fix(natives): stopped sort panicking on disconnected receiver (@roboomp) 2026-07-27 05:29:14 +02:00
roboomp a67a1db52d fix(natives): stopped sort panicking on disconnected chunk receiver
The vendored uu-sort reader unwrapped the chunk-channel send at
chunks.rs:248, panicking with `SendError(..)` whenever the receiver
disconnected early (a consumer thread stopping after an error or a
closed output). Diverge from upstream: on a failed send, stop reading
gracefully and report end-of-input, matching the pattern already used
by the sorter thread. Added a regression test that drives read against
a dropped receiver.

Fixes #6736
2026-07-27 03:23:40 +00:00
roboomp 00efb769d3 fix(shell): reject missing Windows statfs operands
Validate the operand with std::fs::metadata before querying its volume.
This keeps Windows stat -f from succeeding for a missing path whose
containing volume exists.

Fixes #6723
2026-07-26 18:57:12 +00:00
roboomp 43166203a9 fix(shell): report allocated size for Windows stat %b
%b promised allocated 512-byte blocks but used Metadata::len() (logical
size), overstating allocation for sparse or compressed files. Query the
on-disk size via GetCompressedFileSizeW and fall back to the logical
length only when the call fails.

Fixes #6723
2026-07-26 18:55:16 +00:00
roboomp 53e9753d23 fix(shell): implement native Windows stat builtin
The vendored uu-stat routed every non-Unix invocation to a stub that
printed "stat: unsupported on this platform" and exited 1, so the bash
tool's stat builtin was dead on native Windows even though it was still
advertised and registered.

Add a Windows-native backend that reimplements the GNU stat directives on
top of std::fs::Metadata, the windows_by_handle metadata extensions
(inode, hard-link count, and device via GetFileInformationByHandle), and
the Win32 volume APIs for --file-system mode. Permission bits, file type,
and timestamps are synthesized from Windows attributes; ownership fields
that have no Windows equivalent report 0/UNKNOWN. The format parser,
printer, and BSD-compat layer are now shared across platforms and Unix
behavior is unchanged.

Fixes #6723
2026-07-26 18:46:57 +00:00
can1357 6d2a8de1bb chore: bump version to 17.1.4 2026-07-26 17:01:19 +02:00
can1357 4b8323b872 fix(natives): use Self for capture reference in desktop batch dispatch
- Clippy use_self violation introduced by the PR #6595 dispatch-closure refactor surfaced under -D warnings.
2026-07-26 15:48:29 +02:00
can1357 8df56b58d7 Merge PR #6595: fix(natives): settle macOS input before capture (@wolfiesch) 2026-07-26 15:45:31 +02:00
Wolfgang Schoenberger a23b99f7ba test(natives): cover macOS post-input settle ordering
Drive desktop batches from a shared action, settle, and capture sequence so the regression test exercises the same ordering as DesktopWorker::execute. Add external contributor attribution to the unreleased changelog entry.
2026-07-26 02:59:00 -07:00
Wolfgang Schoenberger 0b2e5a1157 fix(natives): settle macOS input before capture 2026-07-26 02:58:59 -07:00
Anatoli Tsinovoy 7a40add686 fix(natives): preserve buffered playback tail 2026-07-25 23:17:57 +03:00
Anatoli Tsinovoy b0364a5d7d chore(natives): address PulseAudio review 2026-07-25 22:23:29 +03:00
Anatoli Tsinovoy b8a30a04cd fix(natives): buffer forwarded PulseAudio playback 2026-07-25 22:22:14 +03:00
Anatoli Tsinovoy 2a9615510f fix(natives): support large PulseAudio capture fragments 2026-07-25 21:55:45 +03:00
can1357 0491f2961a chore: bump version to 17.1.3 2026-07-25 01:10:32 +02:00
can1357 f23bc266a8 feat(natives): enabled per-language rewrite rules for mixed-language paths
- Remove uniform language inference requirement, allowing mixed-language paths to rewrite each file in its own language.
- Update `ast_edit_blocking` in `crates/pi-natives/src/ast.rs` to compile rewrite rules per language and skip unsupported languages gracefully.
- Update `ast-edit.md` prompt documentation to reflect mixed-language path support.
- Add test coverage verifying mixed-language tree rewrites.
2026-07-24 21:52:29 +02:00
can1357 a569385b8e fix(shell): captured find -exec child stdio into scope streams
- find -exec/-execdir children inherited the omp process's real
  stdout/stderr, spamming output into the TUI terminal and bypassing
  shell redirects; they also inherited the host env instead of the
  shell's exported environment.
- Added pi_uutils_ctx::run_captured (moved from uu-xargs' private
  helper): stdin null, stdout streamed into scope stdout, stderr
  drained on a helper thread and forwarded after exit.
- uu-find exec matchers now use env_clear + env_snapshot and
  run_captured; MultiExecMatcher rebuilds a std Command from the
  argmax command's accumulated state (argmax only Derefs immutably).
- uu-xargs reuses the shared helper; added pi-shell regression test
  asserting -exec child stdout flows through the shell redirect with
  the exported env.
2026-07-24 20:06:29 +02:00
can1357 7ebf141743 chore: bump version to 17.1.2
- fixed rustfmt drift and clippy errors in pi-shell moreutils builtins (combine, errno, ifne, isutf8, sponge, ts) that blocked the release check gate
2026-07-24 16:53:52 +02:00
can1357 5d4f1cf6b5 feat(pi-shell/moreutils): implemented six moreutils-inspired shell builtins
- Added six builtin commands: ts, sponge, ifne, isutf8, combine, and errno to pi-shell.
- Created moreutils module with independent implementations for all tools.
- Added jiff dependency for timestamp and timezone functionality.
- Integrated builtins into shell execution pipeline with in-process execution.
- Added integration tests verifying pipe chains like ts | sponge with isutf8.
2026-07-24 14:52:16 +02:00
can1357 02114a6bf7 fix(natives): made non-macos devicecheck stub a const fn
clippy missing_const_for_fn (-D warnings) fails the linux rust checks; the cfg(not(macos)) stub is invisible to local macos clippy.
2026-07-24 09:47:53 +02:00
can1357 c36826cbac chore: bump version to 17.1.1 2026-07-24 09:18:41 +02:00
can1357 c1d4e38aa6 feat(coding-agent): added live session delegation with turn-based transcript display
- Added `LIVE_DELEGATION_MESSAGE_TYPE` constant and delegation message handling for voice sessions.
- Implemented turn-based transcript coalescing with user and assistant turn counters.
- Added transcript display row with normalized rendering in the live visualizer.
- Refactored controller to send delegation messages via `sendCustomMessage` with configurable frame styling.
- Removed microphone permission error reporting from silence detection logic.
2026-07-24 09:16:50 +02:00
can1357 c9c0882724 feat(audio): replaced Chromium browser audio with native audio stack
- Switched from `miniaudio` to `maudio` Rust crate and added `AudioCapture` and `AudioPlayback` native classes.
- Removed browser-side audio infrastructure including Web Audio API, audio worklet processor, and WebRTC runtime.
- Migrated STT recorder and transcriber modules to use native `AudioCapture` with callback-based streaming.
- Replaced streaming audio player with native `AudioPlayback` that writes PCM directly without TypeScript intermediaries.
- Removed ffmpeg, wav, and platform-specific playback commands from the audio toolchain.
2026-07-24 08:54:16 +02:00
can1357 b76c07ece2 feat(pi-natives): added LiveWebRtcPeer and deviceCheckGenerateToken bindings
- Replaced puppeteer-based WebRTC with native LiveWebRtcPeer for cross-platform live audio delivery.
- Added cross-platform microphone capture via miniaudio and Opus codec integration for live encoding/decoding.
- Added Apple DeviceCheck attestation token generation via raw Objective-C FFI for macOS.
- Updated live session model to "gpt-live-1-codex" and default voice to "sol" across protocol and controller.
- Added LiveWebRtcPeer and deviceCheckGenerateToken to the public native bindings API.
2026-07-24 08:22:22 +02:00
can1357 269c267397 feat(pi-shell): implemented cmp utility for embedded shell
- Added cmp builtin with full POSIX-compatible flag support including `-b`, `-i`, `-l`, `-s`, `-x`, `-h`, `-z`.
- Integrated into shell builtin registry and coreutils module.
- Added comprehensive tests using tempfile for temporary directories.
2026-07-24 08:05:12 +02:00
can1357 11eb003fc8 fix: screenshot latency, somehow calling screencapture is faster ??? 2026-07-24 06:39:49 +02:00
usr-bin-roygbiv 68ac163e2c fix(computer): harden native desktop execution 2026-07-24 01:40:05 +00:00
can1357 681d7daf65 feat(computer): unified native addon, /computer toggle, function tool
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
  a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
  XTest input with keysym mapping) compiled into the core addon on every
  published target; Linux arm64 and musl are now supported and headless
  hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
  lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
  build dependencies, and the now-unreferenced vendored libspa crate;
  reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
  XTest layouts reject negative origins and coordinates beyond 0..=32767,
  batch coordinates stay bound to the frame last returned to JS with
  intermediate screenshots deferred, coordinate input requires a
  previously returned frame, and failed chord releases still release
  every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
  no input is emitted after expiry and wait-heavy batches are rejected
  upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
  scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
  a regular function tool with a typed GA action schema across OpenAI,
  Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
  session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
2026-07-24 01:40:05 +00:00
usr-bin-roygbiv 57f8acdd18 fix(native): harden desktop input and compatibility 2026-07-24 01:40:05 +00:00
usr-bin-roygbiv 87f37bcb1f fix(native): support Ubuntu 22 desktop builds 2026-07-24 01:40:05 +00:00
usr-bin-roygbiv b9504f65e7 feat: add native Codex computer use 2026-07-24 01:40:04 +00:00
can1357 5e63cc5696 chore: bump version to 17.1.0 2026-07-24 02:49:18 +02:00
can1357 639bac596d chore: bump version to 17.0.9 2026-07-23 14:40:52 +02:00
can1357 52ad6516ef feat(diff): implemented native UTF-16 diff processing and removed jsdiff
- Implemented native UTF-16 text processing in Rust diff module with support for unpaired surrogates.
- Removed `similar` crate from Rust workspace and `diff` npm package from coding-agent, hashline, and natives.
- Removed jsdiff fallback wrappers and `isWellFormed()` guards from TypeScript diff implementations.
- Added comprehensive test suite for native diff functions covering random inputs and edge cases including surrogates and emoji.
- Renamed model `codex-auto-review` to `gpt-5.3-codex-spark` with updated pricing and context window.
2026-07-23 01:35:31 +02:00
can1357 1db0d71825 style(iso): wrapped FICLONE comment for rustfmt 2026-07-23 00:56:36 +02:00
can1357 52e2fcb746 fix(iso): used libc::Ioctl for FICLONE request type on musl targets
- musl defines ioctl's request parameter as c_int while glibc uses
  c_ulong; the hardcoded libc::c_ulong constant broke linux musl
  x64/arm64 native builds.
2026-07-23 00:53:11 +02:00
can1357 9b54d9e9ac chore: bump version to 17.0.8 2026-07-23 00:41:54 +02:00
can1357 dd80dcd035 test(catalog): adapt ChatGPT-only retention test to multi-account discovery API
- #6266 replaced openaiCodexModelManagerOptions' accessToken field with resolveAccounts; #6219's authoritative-pruning test predates that and silently skipped discovery, leaving the absent static model unpruned.
2026-07-22 21:19:53 +02:00
can1357 eadfc9a4ec Merge PR #6280: perf(mnemopi): run recall vector kernels natively (@wolfiesch) 2026-07-22 21:13:24 +02:00
can1357 9a0a154e53 Merge PR #6279: perf(coding-agent): compute edit and word diffs natively (@wolfiesch) 2026-07-22 21:13:23 +02:00
can1357 1581a9719d fix(rm): skip empty operands in progress pre-count
count_files resolved "" to the scoped cwd, so rm -r --progress with an
empty operand walked the whole working directory and inflated the
progress total even though remove() rejects the operand.
2026-07-22 21:13:20 +02:00
roboomp bb7faf62ca fix(rm): rejected empty operand instead of deleting cwd
The in-process rm builtin passed each operand through
pi_uutils_ctx::resolve, which joins "" onto the shell working
directory and yields the cwd itself. rm -rf "" therefore resolved to
the cwd and recursively deleted it -- a real data-loss path when a
failed command substitution left an empty variable in a cleanup line.

Reject empty operands at the top of remove(), before resolution,
mirroring GNU rm: report ENOENT for an empty operand and stay silent
under -f. Added a regression test that runs the builtin rm -rf "" in a
scoped temp cwd and asserts the cwd and a sentinel file survive.

Fixes #6287
2026-07-22 11:45:27 +00:00