Commit Graph
9801 Commits
Author SHA1 Message Date
roboomp 52b5e7f838 fix(coding-agent): restored legacy pi automode compatibility
Restored the historical clampThinkingLevel export through the legacy pi-ai shim and exposed ModelRegistry.getApiKeyAndHeaders for extension request authentication.

Added compatibility and auth result regression coverage.

Fixes #6648
2026-07-25 22:14:11 +00:00
usr-bin-roygbiv c898f513fa fix(computer-use): report Azure runtime fallback 2026-07-25 21:00:35 +00:00
roboomp 7ca59dc6bd fix(secrets): avoided hashline placeholder collisions
- Switched newly generated secret placeholders to double-dollar delimiters.
- Preserved trusted stored-session restoration for legacy hash-delimited tokens.
- Updated redaction regressions and changelog coverage.

Fixes #6631
2026-07-25 20:24:27 +00:00
usr-bin-roygbiv e851ec4dc7 Merge remote-tracking branch 'origin/main' into agent/codex-computer-use-followup 2026-07-25 20:14:09 +00:00
roboomp f1f118acd0 fix(advisor): rebind identity on every provider-session change
Advisor provider-identity refresh was only invoked from resetSessionState(), so transitions that update the primary identity without re-priming the advisor (branch with skipConversationRestore, fork) left the advisor emitting the previous session id/metadata/telemetry. Move the refresh into #syncAgentSessionId() via a new SessionAdvisors.refreshProviderIdentity() so it fires on every provider-session change regardless of conversation restore. Add a fork regression test.
2026-07-25 17:55:48 +00:00
roboomp f6a93a34b4 fix(advisor): forwarded session metadata to overflow compaction
The advisor overflow-compaction one-shot calls compact() directly, bypassing the advisor Agent and its metadata resolver, so it omitted metadata.user_id. Resolve the advisor's session metadata per candidate provider (after credential selection) and pass it into the compact() options alongside sessionId/promptCacheKey. Add a regression test asserting the direct compaction request carries the advisor session id.
2026-07-25 17:49:21 +00:00
roboomp 8a998ca429 fix(advisor): refreshed provider identity on session switch
Rebind the live advisor Agent's provider session id, prompt cache key, credential resolver, metadata resolver, and telemetry identity whenever AgentSession crosses a conversation boundary. Add a regression test proving /new preserves the advisor Agent while assigning and emitting a distinct new provider session UUID.
2026-07-25 17:39:12 +00:00
roboomp c5af78d403 fix(advisor): propagate advisor provider session id via metadata
The advisor Agent is constructed separately in session-advisors.ts with
its own advisorProviderSessionId, but unlike AgentSession it never had a
metadata resolver installed. Its outbound requests therefore omitted the
metadata.user_id session identity that main and subagent requests carry,
so custom Anthropic-compatible proxies saw advisor traffic with no stable
session id to route or attribute on.

Extract buildSessionMetadata into session/session-metadata.ts and install
it as the advisor agent's metadata resolver, scoped to the advisor's own
provider session id and resolved live so token refreshes surface the
current account_uuid.

Fixes #6625
2026-07-25 17:30:18 +00:00
can1357 667111575e feat: implemented credential lifecycle tracking and management APIs
- Added `listDisabledCredentials` and `refreshSnapshot` methods to credential stores along with API endpoints and wire schemas.
- Added `authorizedAt` timestamps and Anthropic OAuth grant TTL constants to track credential lifecycles.
- Updated the usage CLI to render auto-disabled credential tombstones and grant expiration warnings.
- Added comprehensive unit and broker integration tests covering the new credential management features.
2026-07-25 18:02:43 +02:00
roboomp 576bb548a0 fix(coding-agent): isolated gateway catalog from local model config
The pi-native-only filter still let any non-pi-native models.yml provider override (baseUrl/apiKey/headers) reach the broker-backed gateway: config keys shadowed broker credentials (bypassing account pooling, refresh, and accounting) and a custom baseUrl redirected the broker bearer to a configured endpoint. Generalized the flag to ignoreLocalModelConfig, which short-circuits loadCustomModels so the gateway serves bundled plus broker-discovered catalog metadata only, applying no local overrides, config API keys, custom models, or custom discovery.

Fixes #6615
2026-07-25 13:42:41 +00:00
roboomp 4362598cf8 fix(coding-agent): prevented auth-gateway self-routing
Gateway catalog construction now ignores models.yml provider entries whose transport is pi-native. This keeps the registry's bundled, cached, and upstream-discovered models while preventing client-side gateway base URLs and bearer keys from being applied to server-side dispatch.

Added a regression test proving a normal client registry retains pi-native routing while the gateway registry restores the bundled provider route before indexing the model.

Fixes #6615
2026-07-25 13:33:45 +00:00
roboomp df3018e89b fix(coding-agent): source auth-gateway catalog from ModelRegistry
runServe built /v1/models and the resolveModel behind /v1/chat/completions from getBundledModels only, freezing the gateway catalog on the compiled-in snapshot. Every discovery-only model omp itself reaches (ids released after the build date) was unroutable through the gateway while the same broker credential answered it in the TUI.

Source the catalog from ModelRegistry (bundled + cached + discovered) like every other omp surface, via a shared indexModelsByRequestId helper that preserves the credential scoping and qualified/bare-id registration. Rebuild it every 15m so a long-lived serve tracks newly discovered models without a restart; a failed refresh keeps serving the previous catalog.

Fixes #6615
2026-07-25 13:22:32 +00:00
roboomp bac71f4654 fix(coding-agent): stopped blocked vibe reset loops
Disable reset-mode loops when vibe mode prevents the required session transition, so the prompt is not resubmitted into the unchanged session.

Added focused regression coverage for the blocked transition.

Fixes #6607
2026-07-25 12:05:54 +00:00
roboomp c8ef3cc8ff fix(coding-agent): handled vibe session commands safely
Blocked interactive session transitions before they reach the AgentSession vibe guard, preserving the active session and rendering the existing exit-vibe warning instead of rejecting the input callback.

Added regression coverage for new, drop, fork, and move transitions.

Fixes #6607
2026-07-25 11:57:53 +00:00
roboomp 6a3fcc98fa fix(tui): restored GitHub refs in slash arguments
Preserved numeric GitHub reference completion after slash-command argument providers decline an input while leaving prompt-action tokens literal.

Added a provider-level regression for prompt-bearing skill commands.

Fixes #6604
2026-07-25 11:22:13 +00:00
usr-bin-roygbiv 83c3e9c869 fix(model-registry): rebuild immediate runtime models 2026-07-25 08:44:12 +00:00
usr-bin-roygbiv 9ceebb2a4d fix(workers): isolate compiled host selectors 2026-07-25 08:31:54 +00:00
usr-bin-roygbiv 8e1bffb60f style(coding-agent): format worker host changes 2026-07-25 07:50:26 +00:00
RC Branham f15e3aa897 fix(tui): keep multi-file pastes out of the whole-path fallback
The whole-text-as-path fallback added in the previous commit claimed any
single-line payload starting with an absolute-path anchor, including one
holding several paths. Dragging two files at once emits
`/tmp/a.png /tmp/b shot.png`, which the segment splitter also refuses
because `shot.png` is not explicit, so the fallback fused the pair into
one unresolvable path. `handleImagePathPaste`'s ENOENT branch only
surfaces a status and — unlike its too-large and generic-error branches
— never re-pastes the text, so both paths vanished.

On `main` the bracketed route returned undefined for that payload and
fell through to a text paste, so this was a regression introduced by the
previous commit rather than behavior inherited from the clipboard route.
It is reachable by the same gesture that motivated #6578, with one more
file selected: macOS screenshot names always contain spaces.

`extractWholeTextImagePath` now rejects payloads carrying a second
absolute-path anchor after unescaped whitespace. The anchor alternation
moves into a shared `ABSOLUTE_PATH_PREFIX_SOURCE` so the leading-anchor
and second-anchor tests cannot drift apart across the POSIX, `~/`,
`file://`, UNC and Windows-drive families. Escaped whitespace is exempt,
since the escape is the terminal asserting the space belongs to the path.

Guarding the shared helper rather than the bracketed caller also settles
`extractImagePathFromText`, whose JSDoc already claimed multi-path text
falls through to a text paste while the fallback leaked around it.

Ambiguous input — a directory whose name ends in a space, as in
`/tmp/odd dir /sub/x.png` — is treated as multi-path and pastes as text:
a text paste loses nothing, a bogus attach loses everything.

11 tests added covering each anchor family, tab separation, the
escaped-space exemption and the unchanged splitter-success path.
2026-07-25 03:48:12 -04:00
usr-bin-roygbiv 237692deab fix(computer-use): re-enter single worker host 2026-07-25 07:45:56 +00:00
usr-bin-roygbiv a7e988b604 fix(computer-use): isolate worker process entry 2026-07-25 07:13:12 +00:00
roboomp 7f1da393df fix(coding-agent): re-export estimateTokens from legacy pi shim
Legacy pi's @earendil-works/pi-coding-agent re-exported estimateTokens
from its coding-agent package root. In omp it lives in
@oh-my-pi/pi-agent-core/compaction and the coding-agent barrel does not
forward it, so the shim's `export * from "../index"` left it off the
surface. A named import tripped Bun's static export check during plugin
validation (e.g. `omp plugin install pi-blackhole`).

Re-export estimateTokens from the shim and pin it with a regression test.

Fixes #6583
2026-07-25 05:35:08 +00:00
roboomp ca0d3e3e5b fix(config): resolved shell setting source paths
Tracked the effective global, project, overlay, or runtime source of shellPath so resolution errors identify the configuration users must edit.

Covered custom agent directories and higher-precedence settings layers with focused regressions.

Fixes #6579
2026-07-25 05:32:40 +00:00
RC Branham 178af71d3e fix(tui): attach drag-dropped image paths with unescaped spaces
The bracketed-paste (drag-drop) image route required every whitespace-split
segment to look path-like, so a raw macOS screenshot path (spaces unescaped,
per the attachment convention terminals implement) degraded to literal text.
Extract the keybind route's whole-text-as-path pass into a shared helper and
apply it when the segment splitter fails; route the bracketed extractor
through the stripped-marker one so both share identical detection.

Fixes #6578
2026-07-25 01:26:14 -04:00
usr-bin-roygbiv f1fb05df80 fix(eval): statically link rejection interceptor 2026-07-25 04:24:25 +00:00
usr-bin-roygbiv 93fd23f9e0 fix(catalog): rebuild runtime-rerouted models 2026-07-25 03:20:14 +00:00
usr-bin-roygbiv 9bab62ee55 fix(computer-use): address routing review gaps 2026-07-25 02:14:36 +00:00
roboomp 9bba7ac007 fix(plan-mode): compared canonical local urls for scan membership
The scan-membership test used a raw string includes, so a resumed single-slash local:/ state path failed to match the scanner's local:// entry and wrongly gained precedence over a newer draft. Normalize both sides via normalizeLocalScheme before comparing.

Fixes #6569
2026-07-25 01:58:12 +00:00
roboomp 28068f53d3 fix(plan-mode): promoted reviewed plan path into state before refine
handlePlanApproval and the ACP rejection path selected a resolved draft that could differ from PlanModeState.planFilePath but never updated the state, so a refine turn was rebuilt by #buildPlanModeMessage() from the stale path. Both paths now promote the reviewed path into plan-mode state.

Fixes #6569
2026-07-25 01:51:52 +00:00
roboomp c7ac15e974 fix(plan-mode): kept out-of-scan state plan ahead of scanned artifacts
A state plan the artifact scan can't surface (cwd-relative, or a local file not ending in plan.md) has no mtime to compete on, so it now keeps precedence over scanned drafts; an in-scan state plan still competes on newest-first order.

Fixes #6569
2026-07-25 01:44:28 +00:00
roboomp 926f523a15 fix(plan-mode): preferred newest draft during review
Preferred the newest session-local plan artifact over a stale state path when the submitted title cannot reconstruct the draft filename.

Added regression coverage for completed-plan re-entry.

Fixes #6569
2026-07-25 01:38:29 +00:00
usr-bin-roygbiv fe985551c5 fix(eval): preserve process bootstrap boundary 2026-07-25 01:30:04 +00:00
usr-bin-roygbiv c34e3ae819 fix(computer-use): preserve lazy native pairing 2026-07-25 00:53:58 +00:00
usr-bin-roygbiv d9a2782258 fix(eval): preserve worker after floated rejection 2026-07-25 00:42:23 +00:00
usr-bin-roygbiv 8e2d654880 fix(computer-use): route enabled desktop control 2026-07-25 00:42:23 +00:00
usr-bin-roygbiv 40937af750 test(computer): exercise packaged desktop session 2026-07-25 00:42:23 +00:00
usr-bin-roygbiv 8af48840fe fix(coding-agent): statically dispatch computer worker 2026-07-25 00:42:23 +00:00
usr-bin-roygbiv c8d465803a fix(computer): default missing actions to read approval 2026-07-25 00:42:23 +00:00
Rod Vagg e20af5b49d fix(update): optionally use GITHUB_TOKEN | GH_TOKEN when calling GH 2026-07-25 10:41:15 +10:00
roboomp a04b315eb2 fix(tui): expand pinned provider errors inline on ctrl+o
While a provider error is pinned in the banner above the editor the inline transcript block is suppressed, so the prior guard skipped re-rendering on Ctrl+O and the full body stayed unreachable until the next turn.

- Track whether the message carries a truncatable error regardless of pinning, so setExpanded re-renders while pinned.
- Render the inline error block in full when expanded even while pinned; keep it suppressed only while pinned and collapsed.
- Disable the streaming fast path whenever the inline error block is drawn.

Fixes #6555
2026-07-25 00:40:23 +00:00
roboomp 62d8b0d3ad fix(tui): initialized provider errors from expand state
New live, rebuilt, and transcript-builder assistant components now inherit the active tool-output expansion state before provider errors render.

Added regression coverage for an error arriving after expanded mode was already enabled.

Fixes #6555
2026-07-25 00:32:52 +00:00
roboomp 104c3ad218 fix(tui): make provider error blocks expandable via ctrl+o
Turn-ending provider errors rendered inline through
AssistantMessageComponent#appendErrorBlock, capped at 8 lines with no
setExpanded method, so isExpandable filtered the component out of the
Ctrl+O tool-output expansion and the truncated tail was unreachable in
the live TUI (full text was persisted but not shown).

- Add setExpanded to AssistantMessageComponent; when expanded the error
  block renders the full body (tabs replaced, blank lines preserved,
  Text word-wraps to width).
- Collapsed view appends a dim "+N more lines (Ctrl+O to expand)" hint so
  the truncation and its remedy are discoverable.
- Only re-render on toggle when the last render produced a truncatable
  error block, so expansion skips ordinary turns.

Fixes #6555
2026-07-25 00:26:40 +00:00
Rod Vagg 17a62618ad fix(update): verify release binary digests 2026-07-25 10:12:30 +10:00
can1357 bef97a69bb Merge PR #6529: fix(coding-agent): guard retain renderer streaming args (@roboomp) 2026-07-25 00:59:14 +02:00
can1357 8851e93d21 Merge PR #6551: fix(coding-agent): use session settings in file guards (@roboomp) 2026-07-25 00:59:14 +02:00
roboomp 144043ad48 fix(coding-agent): used session settings in file guards
Passed session-scoped settings through Edit and Write generated-file checks and fell back to schema defaults when no global singleton exists.

Guarded inline image sizing against an uninitialized global settings proxy and added isolated-session regression coverage.

Fixes #6549
2026-07-24 22:42:38 +00:00
Anthony "Asterisk" Ambuehl 29625f08c2 feat(mcp): add mcp_notification extension event + multi-listener API
Convert MCPManager's dangling single-slot setOnNotification callback into
a multi-listener API and expose server-initiated MCP notifications as an
extension event so extensions can bridge push-capable MCP servers (e.g.
peer messaging, ticket nudges) into session behavior.

API changes:
- Removed: MCPManager.setOnNotification(handler) — single-slot, zero callers
- Added:   MCPManager.addNotificationListener(listener): () => void
           Multi-listener with per-listener error isolation, returns unsub.
- Added:   'mcp_notification' extension event
           Payload: { server: string; method: string; params: unknown }

Wired in sdk.ts: one listener bridges to extensionRunner.emitMcpNotification,
captured under postmortem for teardown.

Tests: 3 new (multi-listener fanout, error isolation, unsubscribe),
fixture pattern matches neighboring mcp tests. bun check passes (biome +
tsgo).

Docs: extensions.md (new MCP notifications subsection with bridging
example), mcp-runtime-lifecycle.md (Server-initiated notifications
section), CHANGELOG.
2026-07-24 13:36:03 -07:00
can1357 f23bc266a8 feat(natives): enabled per-language rewrite rules for mixed-language paths
- Remove uniform language inference requirement, allowing mixed-language paths to rewrite each file in its own language.
- Update `ast_edit_blocking` in `crates/pi-natives/src/ast.rs` to compile rewrite rules per language and skip unsupported languages gracefully.
- Update `ast-edit.md` prompt documentation to reflect mixed-language path support.
- Add test coverage verifying mixed-language tree rewrites.
2026-07-24 21:52:29 +02:00
Jeff Scott Ward 050388b486 fix(advisor): bound Codex SSE retries 2026-07-24 15:24:14 -04:00
roboomp d7c7ca033d fix(coding-agent): guarded retain renderer streaming args
- Treated transient non-array retain items as absent during TUI streaming.
- Added regression coverage for malformed partial renderer arguments.
- Documented the fix in the coding-agent changelog.

Fixes #6528
2026-07-24 15:52:01 +00:00