Commit Graph
2890 Commits
Author SHA1 Message Date
Hesham Salman 7f7e742db6 fix(coding-agent): preserve parent todos in vibe mode 2026-07-27 13:52:25 -04:00
can1357 d16a251777 chore: reorg tests 2026-07-27 16:43:53 +02:00
can1357 3681faec41 Merge PR #6789: feat(coding-agent): show advisor cost separately in the status line (@paolomazzitti) 2026-07-27 15:57:46 +02:00
can1357 d220cfee9b Merge PR #6806: fix(extensions): cancel timed-out handler dialogs (@roboomp) 2026-07-27 15:57:46 +02:00
roboomp 452932b291 fix(rpc): cancelled aborted extension dialogs
Moved RPC dialog request lifecycle into a reusable helper that emits a cancel frame targeting the original request before settling an aborted local promise.

Added coverage for remote confirmation cancellation and pending-request cleanup.
2026-07-27 13:53:30 +00:00
Paolo Mazzitti 9d240ea0ad feat(coding-agent): show advisor cost separately in the status line
Render the Advisor spend next to the primary-model cost as `$2.67 (sub) + $0.41 (adv)`, leaving the status line unchanged until an Advisor cost exists.

Record the cost from finalized advisor `message_end` events in a per-session ledger instead of deriving it from the live advisor transcript, so an in-session compaction or any other history rewrite no longer resets the reported spend. The ledger is cleared for a new session and once a different-session switch commits, and survives a switch that rolls back.
2026-07-27 13:52:22 +00:00
roboomp 5e6f12b278 fix(extensions): cancelled timed-out handler dialogs
Forwarded confirmation dialog options in the interactive TUI and scoped extension UI dialogs to each handler watchdog signal.

Added regressions for direct confirmation cancellation and fail-closed tool-call timeout cleanup.

Fixes #6805
2026-07-27 13:28:24 +00:00
roboomp 4bc71bdafc fix(tui): defer large command panels during streaming to stop scrollback dupes
/usage, /session, /advisor status, /jobs, /changelog, /context, and
/memory view mounted their finalized panel immediately via ctx.present()
instead of ctx.presentCommandOutput(), the streaming-deferral path added in
#5427 for /tools and /mcp. When invoked mid-turn, the panel landed above a
still-growing live block and the append-only scrollback contract recommitted
it lower down, so it appeared twice in native scrollback.

Route all six large command panels through presentCommandOutput() so they
defer until agent_end, matching /tools and /mcp.

Fixes #6767
2026-07-27 05:49:42 +00:00
can1357 905fb283df Merge PR #6724: feat(live): add selectable voice setting (@roboomp) 2026-07-27 05:26:35 +02:00
can1357 c2e07a2028 fix(tui): remounted guarded draft editor when ask surface is restored
A failed async submission can restore the draft while a nested ask prompt
(note/custom answer) is open, re-blocking the input guard; restoreAskDialog
mounted only the ask component, routing guarded input to an unmounted
editor. Restore now mirrors the initial presentation and remounts the
draft editor whenever the guard exists.
2026-07-27 04:58:27 +02:00
roboomp 3657219bbe fix(tui): honor clear action in guarded ask draft editing
handleDraftEdit routed everything through the base editor, which reserves Ctrl+C for the parent and returns without touching the buffer, so the configured app.clear never ran and the guard's 'finish or clear the prompt' hint had no working clear key when Ctrl+C reached the guard.

handleDraftEdit now dispatches the app.clear action explicitly (onClear, falling back to clearing its own text), which empties the draft and lifts the guard without swapping the editor slot.

Fixes #6737
2026-07-26 23:46:46 +00:00
roboomp 2803bf721b fix(tui): show draft cursor while ask proxies its input
The draft editor renders an insertion cursor only when its focused flag is set, but ask holds TUI focus, so the preserved draft had no visible caret while it required finishing or clearing.

The input guard now mirrors its blocked state onto the draft editor each ask render (editor is the next sibling in the same container), showing the cursor while it owns input and dropping it once the draft clears.

Fixes #6737
2026-07-26 23:41:13 +00:00
roboomp 5a1ded4b9e fix(tui): route ask draft input through text pipeline only
Forwarding raw keys through CustomEditor.handleInput enabled its app-slot shortcuts (Agent Hub, model selector, ...) while an ask dialog was open over a draft; those clear editorContainer and orphan the pending ask promise.

handleDraftEdit bypasses the shortcut interception so only text editing, cursor movement, and submission reach the buffer.

Fixes #6737
2026-07-26 23:35:37 +00:00
roboomp 283d9a5d0c fix(tui): preserved prompt input while ask opens
- Kept a populated editor visible beneath an asynchronously opened Ask form.

- Routed input to the draft until it is submitted or cleared, then activated Ask controls.

- Added regression coverage for the focus handoff.

Fixes #6737
2026-07-26 23:27:08 +00:00
roboomp bb8c0f12d3 test(live): covered selected voice session boundary
Replaced schema self-comparisons with a controller contract test that selects vale and captures the options used to construct the live session.
2026-07-26 18:52:17 +00:00
roboomp ea60fc1df3 feat(live): added selectable voice setting
Added the supported realtime voice catalog to settings and passed the selected value into each new live session.

Covered the voice list, default, UI options, and persisted override.

Fixes #6566
2026-07-26 18:41:48 +00:00
omp-evalandcan1357 24e0497574 fix(tui): treat dot-relative anchors as multi-path signals in whole-path fallback
Codex review flagged that /tmp/a.png ./b shot.png slipped past the
interior-anchor guard (absolute prefixes only) and fused into one bogus
attach that swallows the paste. Add ./, ../ and .\ as second-path
anchors; bare relatives (dir/b shot.png) stay recoverable because an
interior token/ after a space is exactly the shape of a spaced
directory name (/Users/me/My Photos/shot 1.png). 4 tests pin both
sides of the boundary.
2026-07-26 15:45:31 +02:00
can1357 9000ab0ab3 Merge PR #6582: fix(tui): attach drag-dropped image paths with unescaped spaces (@rcbran) 2026-07-26 15:45:31 +02:00
can1357 87c0aa38bb Merge PR #6558: fix(tui): make provider error blocks expandable via ctrl+o (@roboomp) 2026-07-26 15:45:10 +02:00
can1357 60b0968e1f Merge PR #6484: fix(coding-agent): resume agent after /tree ask re-answer (@roboomp) 2026-07-26 15:41:31 +02:00
can1357 525173615c Merge PR #6500: fix(coding-agent): count only rendered skills in /context accounting (@roboomp) 2026-07-26 15:41:30 +02:00
can1357 0a83d9f364 Merge PR #6570: fix(plan-mode): prefer newest draft during review (@roboomp) 2026-07-26 15:41:30 +02:00
can1357 1ebe2cc63a Merge PR #6608: fix(coding-agent): handle vibe session commands safely (@roboomp) 2026-07-26 15:41:30 +02:00
can1357 a0f03309a9 Merge PR #6588: fix(cli): redact credential settings in config list (@wolfiesch) 2026-07-26 15:41:29 +02:00
can1357 0e3f695a56 Merge PR #6701: fix(coding-agent): stop the live advisor runtime when /settings disables it (@paolomazzitti) 2026-07-26 15:41:28 +02:00
Diogo Soares Rodrigues c7c375f5e1 fix(cursor): settle todo cards whose completion outruns the streamed block
When Cursor packs toolCallStarted and toolCallCompleted into one HTTP/2
chunk, the bridge tool_execution_end (synchronous callback, fired
mid-parse) reaches the interactive controller before the streamed
toolcall_start (queued on AssistantMessageEventStream, delivered a
microtask later). The controller found no pendingTools entry, dropped
the completion, and the card created afterwards animated forever.

Two halves, each necessary:

- Hold an early todo completion in #orphanedToolCompletions and replay
  it when the streamed block creates its component.
- Guard card creation from cumulative message_update frames with the
  turn-scoped #toolTimelineComponents map. Without this, the update
  after the replay re-lists the same toolCall block, finds pendingTools
  empty again, and spawns a second, permanently pending card. This is
  also why emitting a synthetic tool_execution_start from the bridge
  (previous attempt, reverted) could not work.

Both maps are cleared together at the existing transcript-anchor reset
sites. The normal ordering (start first) is covered by a control test.
2026-07-26 09:29:13 -03:00
Diogo Soares Rodrigues cc210094ef fix(cursor): refuse todo dependency graphs and sanitize failure text
Two review findings on the native todo sync.

- TodoItem.dependencies is a graph the local model cannot store: rows
  are keyed by content, carry no id, and hold no edges. An imported
  dependent row files as plain pending and nextActionableTask then
  offers work the server considers blocked. Refuse snapshots with an
  edge pointing at an unfinished row; edges whose blockers already
  finished constrain nothing and still mirror.

- The todo failure warning interpolated the provider error verbatim.
  Collapse and truncate it at the render boundary.

Also documents two known, unfixed defects: an async cursorOnToolResult
transformer resolving after the buffer drain, and the todo card
lifecycle race. Emitting a synthetic tool_execution_start for the
latter was measured and rejected -- the completion deletes the entry it
creates, so the late streamed block adds a second card.
2026-07-26 09:29:13 -03:00
Paolo Mazzitti 81bc0d4368 fix(coding-agent): stop the live advisor runtime when /settings disables it
Disabling the Advisor from /settings persisted the setting but left the
live Advisor runtime running until the session restarted.
SelectorController.handleSettingChange had no case for "advisor.enabled",
unlike other session-managed toggles (autoCompact, steeringMode, ...), so
the change never reached session.setAdvisorEnabled — the same call /advisor
off already uses to stop the runtime immediately.
2026-07-26 12:25:19 +00:00
Wolfgang Schoenberger 914afc0d6c fix(cli): redact credential settings in config list
omp config list printed every configured value, including auth.broker.token,
searxng.token, searxng.basicPassword and dev.autoqaPush.token, in both the
human and --json output. Nobody asked for those specific credentials; the
command dumps everything.

Credentials are marked with a top-level credential flag rather than ui.secret,
because four of them have no settings-panel entry and so have nowhere to put a
UI-level flag. isCredential is the single accessor both the CLI and the panel
consult, so the two spellings cannot produce different behaviour on different
surfaces.

Human output shows dots. JSON omits value and marks the entry redacted instead
of substituting a placeholder, which a consumer could not distinguish from a
real value and might write back.

config get <path> is deliberately unchanged: that is an explicit request for a
single value, and masking it would break a retrieval API with no way to read
your own token back.
2026-07-26 02:58:38 -07:00
Éverton Toffanetto fbd3ebffc6 feat(coding-agent): add opt-in max ceiling for auto thinking
`max` became a first-class effort tier in d435385a, but the `auto`
classifier prompt still offers only `low|medium|high|xhigh`. On a model
that exposes the tier, `auto` can therefore never reach it — only the
`ultrathink` keyword can, because it bypasses the classifier entirely.

`providers.autoThinkingMaxEffort` (`xhigh` | `max`, default `xhigh`) lifts
that ceiling. Opting in adds `max` to the classifier vocabulary, gated on
the target model actually supporting the tier, and scopes the tie-break
exception to that prompt variant so the default renders byte-for-byte as
before. A classification above the configured ceiling is clamped before
the model clamp, so a hallucinated `max` cannot cross a ceiling the user
did not opt into. The on-device 3-bucket classifier stays capped at
`xhigh`, and the provisional/fallback level still never provisions `max`.

Also corrects the two `Auto-detect per prompt (low-xhigh)` labels and the
stale `xhigh auto ceiling` comment, which the new setting makes wrong.
2026-07-26 03:16:56 -03:00
roboomp bac71f4654 fix(coding-agent): stopped blocked vibe reset loops
Disable reset-mode loops when vibe mode prevents the required session transition, so the prompt is not resubmitted into the unchanged session.

Added focused regression coverage for the blocked transition.

Fixes #6607
2026-07-25 12:05:54 +00:00
roboomp c8ef3cc8ff fix(coding-agent): handled vibe session commands safely
Blocked interactive session transitions before they reach the AgentSession vibe guard, preserving the active session and rendering the existing exit-vibe warning instead of rejecting the input callback.

Added regression coverage for new, drop, fork, and move transitions.

Fixes #6607
2026-07-25 11:57:53 +00:00
roboomp 6a3fcc98fa fix(tui): restored GitHub refs in slash arguments
Preserved numeric GitHub reference completion after slash-command argument providers decline an input while leaving prompt-action tokens literal.

Added a provider-level regression for prompt-bearing skill commands.

Fixes #6604
2026-07-25 11:22:13 +00:00
RC Branham f15e3aa897 fix(tui): keep multi-file pastes out of the whole-path fallback
The whole-text-as-path fallback added in the previous commit claimed any
single-line payload starting with an absolute-path anchor, including one
holding several paths. Dragging two files at once emits
`/tmp/a.png /tmp/b shot.png`, which the segment splitter also refuses
because `shot.png` is not explicit, so the fallback fused the pair into
one unresolvable path. `handleImagePathPaste`'s ENOENT branch only
surfaces a status and — unlike its too-large and generic-error branches
— never re-pastes the text, so both paths vanished.

On `main` the bracketed route returned undefined for that payload and
fell through to a text paste, so this was a regression introduced by the
previous commit rather than behavior inherited from the clipboard route.
It is reachable by the same gesture that motivated #6578, with one more
file selected: macOS screenshot names always contain spaces.

`extractWholeTextImagePath` now rejects payloads carrying a second
absolute-path anchor after unescaped whitespace. The anchor alternation
moves into a shared `ABSOLUTE_PATH_PREFIX_SOURCE` so the leading-anchor
and second-anchor tests cannot drift apart across the POSIX, `~/`,
`file://`, UNC and Windows-drive families. Escaped whitespace is exempt,
since the escape is the terminal asserting the space belongs to the path.

Guarding the shared helper rather than the bracketed caller also settles
`extractImagePathFromText`, whose JSDoc already claimed multi-path text
falls through to a text paste while the fallback leaked around it.

Ambiguous input — a directory whose name ends in a space, as in
`/tmp/odd dir /sub/x.png` — is treated as multi-path and pastes as text:
a text paste loses nothing, a bogus attach loses everything.

11 tests added covering each anchor family, tab separation, the
escaped-space exemption and the unchanged splitter-success path.
2026-07-25 03:48:12 -04:00
RC Branham 178af71d3e fix(tui): attach drag-dropped image paths with unescaped spaces
The bracketed-paste (drag-drop) image route required every whitespace-split
segment to look path-like, so a raw macOS screenshot path (spaces unescaped,
per the attachment convention terminals implement) degraded to literal text.
Extract the keybind route's whole-text-as-path pass into a shared helper and
apply it when the segment splitter fails; route the bracketed extractor
through the stripped-marker one so both share identical detection.

Fixes #6578
2026-07-25 01:26:14 -04:00
roboomp 28068f53d3 fix(plan-mode): promoted reviewed plan path into state before refine
handlePlanApproval and the ACP rejection path selected a resolved draft that could differ from PlanModeState.planFilePath but never updated the state, so a refine turn was rebuilt by #buildPlanModeMessage() from the stale path. Both paths now promote the reviewed path into plan-mode state.

Fixes #6569
2026-07-25 01:51:52 +00:00
roboomp a04b315eb2 fix(tui): expand pinned provider errors inline on ctrl+o
While a provider error is pinned in the banner above the editor the inline transcript block is suppressed, so the prior guard skipped re-rendering on Ctrl+O and the full body stayed unreachable until the next turn.

- Track whether the message carries a truncatable error regardless of pinning, so setExpanded re-renders while pinned.
- Render the inline error block in full when expanded even while pinned; keep it suppressed only while pinned and collapsed.
- Disable the streaming fast path whenever the inline error block is drawn.

Fixes #6555
2026-07-25 00:40:23 +00:00
roboomp 62d8b0d3ad fix(tui): initialized provider errors from expand state
New live, rebuilt, and transcript-builder assistant components now inherit the active tool-output expansion state before provider errors render.

Added regression coverage for an error arriving after expanded mode was already enabled.

Fixes #6555
2026-07-25 00:32:52 +00:00
roboomp 104c3ad218 fix(tui): make provider error blocks expandable via ctrl+o
Turn-ending provider errors rendered inline through
AssistantMessageComponent#appendErrorBlock, capped at 8 lines with no
setExpanded method, so isExpandable filtered the component out of the
Ctrl+O tool-output expansion and the truncated tail was unreachable in
the live TUI (full text was persisted but not shown).

- Add setExpanded to AssistantMessageComponent; when expanded the error
  block renders the full body (tabs replaced, blank lines preserved,
  Text word-wraps to width).
- Collapsed view appends a dim "+N more lines (Ctrl+O to expand)" hint so
  the truncation and its remedy are discoverable.
- Only re-render on toggle when the last render produced a truncatable
  error block, so expansion skips ordinary turns.

Fixes #6555
2026-07-25 00:26:40 +00:00
can1357 3c80e6f9cd fix(coding-agent): expose live tool rebuild options 2026-07-24 16:29:27 +02:00
can1357 68e76c6243 fix(coding-agent): preserve shared live tools across rebuilds 2026-07-24 16:26:59 +02:00
can1357 2bc26d3d4c Merge PR #6519: fix(coding-agent): avoid duplicate tools in transcript rebuilds (@roboomp) 2026-07-24 16:26:42 +02:00
roboomp 484fa319eb fix(coding-agent): keep running async task handles during rebuild dedup
The rebuild dedup dropped any preserved pendingTools component whose toolCallId
had a persisted toolResult. A background task's initial async.state=="running"
result is persisted while EventController#handleToolExecutionEnd deliberately
keeps its component in pendingTools so a later tool_execution_update/_end can
settle it. Dropping that still-live handle stranded those updates on the running
snapshot. Only terminal results are now owned by the replay; running async
handles stay preserved. Added a regression covering the running-task case.
2026-07-24 13:53:43 +00:00
roboomp 759e551e8c fix(coding-agent): dropped resolved tools from mid-stream rebuild preservation
rebuildChatFromMessages preserves the live pendingTools components across its
clear+replay so streaming keeps routing into them. That preservation assumed
every pending-tool component was still dangling (its result outside
state.messages). Once a tool's result had landed in the session entries while
its component still lingered in pendingTools (a rebuild racing the
tool-completion event, or a background/displaceable snapshot), the replay
reconstructed the completed block from the persisted toolResult AND the
preserved live component was re-appended, so the same tool block rendered twice.

Resolved tool calls are now dropped from the preserved live set and owned by the
replay; only genuinely in-flight (dangling, replay-stripped) calls are preserved.

Fixes #6516
2026-07-24 13:40:57 +00:00
can1357 de00e7f136 feat(tui): renamed large-paste local refs to paste-N.md
- Large-paste menu now saves pastes as local://paste-N.md instead of
  local://attachment-N, giving the artifact a markdown extension and a
  clearer name.
2026-07-24 12:25:40 +02:00
roboomp e9ae836a46 fix(coding-agent): count only rendered skills in /context accounting
computeNonMessageBreakdown estimated Skills tokens from the unfiltered
session.skills registry and subtracted that from the first system-prompt
block, which only ever contained the rendered (filtered) skills. Hidden
explicit-only skills (hide/disable-model-invocation) and all skills when
the read tool was absent inflated Skills and clamped System prompt to 0.

Add a renderedSkills helper mirroring buildSystemPrompt's filter and use
it for the Skills estimate so the category split matches the provider
prompt.

Fixes #6498
2026-07-24 09:21:58 +00:00
can1357 17735c7786 feat: added x-oai-attestation header for ChatGPT-OAuth Codex requests
- Add `CodexAttestationProvider` hook and `getCodexAttestationHeader` resolver that gates on ChatGPT-OAuth credentials.
- Integrate attestation into WebSocket transport, SSE event stream, and OpenAI compaction requests.
- Wire `setCodexAttestationProvider(generateCodexAttestation)` in model-registry init for OAuth sessions.
2026-07-24 09:17:00 +02:00
can1357 c1d4e38aa6 feat(coding-agent): added live session delegation with turn-based transcript display
- Added `LIVE_DELEGATION_MESSAGE_TYPE` constant and delegation message handling for voice sessions.
- Implemented turn-based transcript coalescing with user and assistant turn counters.
- Added transcript display row with normalized rendering in the live visualizer.
- Refactored controller to send delegation messages via `sendCustomMessage` with configurable frame styling.
- Removed microphone permission error reporting from silence detection logic.
2026-07-24 09:16:50 +02:00
can1357 c9c0882724 feat(audio): replaced Chromium browser audio with native audio stack
- Switched from `miniaudio` to `maudio` Rust crate and added `AudioCapture` and `AudioPlayback` native classes.
- Removed browser-side audio infrastructure including Web Audio API, audio worklet processor, and WebRTC runtime.
- Migrated STT recorder and transcriber modules to use native `AudioCapture` with callback-based streaming.
- Replaced streaming audio player with native `AudioPlayback` that writes PCM directly without TypeScript intermediaries.
- Removed ffmpeg, wav, and platform-specific playback commands from the audio toolchain.
2026-07-24 08:54:16 +02:00
can1357 75cc0a054f feat(coding-agent/tools): added default card fallback for tool rendering
- Extracted #formatToolExecution into a standalone formatDefaultToolExecution module.
- Updated xdev renderXdevCall and renderXdevResult to use the default card when no mounted renderer exists.
- Added fallback rendering that shows tool label, args, and output with appropriate theming.
- Added integration test verifying generic card renders for mounted tools without bespoke renderers.
2026-07-24 08:19:13 +02:00