Commit Graph
9801 Commits
Author SHA1 Message Date
roboomp 5f47afba16 fix(session): validate blob refs before path join
parseBlobRef sliced the blob:sha256: suffix and returned it unvalidated;
get/getSync then fed it into path.join(this.dir, hash), so a crafted ref
like blob:sha256:../../../etc/passwd escaped the blob directory and read
arbitrary files into resolved image history (base64, raw UTF-8, and the ACP
sync path).

Reject any suffix that is not a canonical 64-char lowercase hex hash in
parseBlobRef, the single choke point for every resolution entry point. Reuse
the shared BLOB_HASH_RE in gc-cli instead of its duplicate HASH_RE.

Fixes #4088
2026-07-23 19:51:53 +00:00
roboomp 34fef55d25 fix(session): serialize ArtifactManager first-use init
#ensureDir checked #initialized then set it across an await
#scanExistingIds() gap, so two concurrent first-use save/allocatePath
callers both re-seeded #nextId=maxId+1 and allocateId() handed both the
same id — silently overwriting the first artifact (same toolType) or
making artifact:// resolution ambiguous (different toolTypes).

Memoize the initial scan as a single in-flight #initPromise so all
concurrent callers share one initialization and receive distinct ids.

Fixes #4091
2026-07-23 19:46:30 +00:00
roboomp af3883c052 fix(mcp): bound oauth discovery and smithery poll fetches with abort timeouts
MCP OAuth endpoint discovery ran metadata, well-known, and recursive
authorization-server fetches with no AbortSignal, and the Smithery
browser-login poll received a never-aborting signal. An endpoint that
accepts the TCP connection but never responds stalled /mcp add,
/mcp reauth, the add wizard, or /mcp smithery-login indefinitely; the
5-minute login/poll deadlines run only after discovery resolves or
between polls, so a hung fetch never reached them.

- discoverOAuthEndpoints and fetchResourceMetadataScopes gain an optional
  signal and wrap every fetch in withTimeoutSignal(DISCOVERY_FETCH_TIMEOUT_MS,
  opts?.signal), threaded through the recursive authorization_servers call.
- pollSmitheryCliAuthSession wraps its fetch in
  withTimeoutSignal(SMITHERY_POLL_TIMEOUT_MS, signal) so a hung poll aborts
  and the loop reaches its 5-minute deadline.

Fixes #4103
2026-07-23 19:45:41 +00:00
roboomp 15577406f8 fix(mcp): serialize mcp.json config writes and use unique temp path
Every exported read-modify-write on mcp.json (add/update/remove server, disabled/force-enabled lists) now runs under a per-file withFileLock, so overlapping in-process or cross-process mutations no longer lose updates. writeMCPConfigFile writes to a pid+uuid temp file instead of a shared ${filePath}.tmp, so concurrent writers cannot rename each other's temp out from under them (ENOENT / clobber).

Fixes #4104
2026-07-23 19:40:13 +00:00
Alexander Kirilin 88296f9c55 fix(cli): preserve cache benchmark affinity diagnostics 2026-07-23 15:40:07 -04:00
roboomp 06661566dd fix(tts): played buffered audio when streaming backend exits nonzero
`omp say` for a short single-segment clip printed `spoke` but produced no
sound on hosts where the first streaming backend (bundled ffmpeg without a
pulse/alsa output device) spawns then exits nonzero. The single pipe write
succeeds into the OS buffer before the backend dies, so the drain's
broken-pipe replay never fires, and `player.end()` sets `#inputClosed`
before the exit lands, so the early-exit handler short-circuits and never
advances to paplay/aplay. The end-of-stream cleanup awaited the exit but
ignored its code.

StreamingAudioPlayer now retains the utterance PCM and, when the streaming
backend exits nonzero, replays it through per-file playback so short clips
still reach the speakers. Added injectable backend/file-playback seams and a
regression test exercising the nonzero-exit, clean-exit, and no-backend
paths.

Fixes #5875
2026-07-23 19:21:39 +00:00
roboomp 93d032a144 fix(tui): re-resolve transient status colors on theme swap
Status presenters (showWarning/showError/showStatus and extension/tool
error presenters) baked theme.fg() into Text at construction, so a
warning shown while the auto-theme default guess was dark kept the
dark-mode color after async appearance detection switched the active
theme to light — dark-catppuccin Mocha yellow on the light Latte
background (1.12:1 contrast, effectively invisible).

Add Text.setStyleFn(), a foreground styler evaluated at render time, and
route the transient status presenters through it. Because the coding
agent invalidates status components on onThemeChange, a theme swap now
re-shapes them against the live theme instead of replaying the palette
active when they were constructed.

Fixes #6337
2026-07-23 19:20:53 +00:00
roboomp 70e92d32a6 fix(tool): expand internal urls inside backtick substitutions
isInsideShellQuote opened an expansion context for $() command
substitution but never tracked legacy backtick substitution, so an
unquoted skill:// (or other supported scheme) nested directly inside a
backtick pair within double quotes kept the outer quote active and was
left literal. Treat an unescaped backtick as an expansion-context
boundary on the same substitution stack, restoring the outer quote when
the pair closes, matching $() behavior including nesting in either
order. Single-quoted and escaped-backtick text stay literal.

Fixes #5645
2026-07-23 19:20:08 +00:00
Alexander Kirilin 9c471a5088 feat(cli): benchmark prompt cache reuse 2026-07-23 15:18:37 -04:00
Alexander Kirilin 1fa847dfdf feat(catalog): model Bedrock prompt cache limits 2026-07-23 15:18:37 -04:00
roboomp 662e4392da fix(edit): aligned relative path resolution
- Shared unique workspace suffix resolution between read and direct edit modes.

- Preserved create destinations and ambiguous-path failures while resolving existing update targets.

- Added direct replace, patch, and apply_patch regression coverage.

Fixes #6359
2026-07-23 19:14:09 +00:00
roboomp 116b8f4597 fix(compaction): judged remote-preserve reuse against the active model
After an OpenAI remote compaction, prepareCompaction decided whether to
keep the provider-native replay boundary or re-expand its originals by
asking whether *any* compaction candidate (every role model plus the
largest-context available model) shared the payload's provider. In a
multi-role setup where a role such as modelRoles.smol stays on OpenAI,
the check passed forever, so a session switched to a non-OpenAI active
model kept a placeholder-only summary and never recovered the compacted
span for the rest of the session.

Judge reusability against the active model — the one that assembles the
request context every turn — instead of the candidate set. When the
active model cannot replay the payload, re-expand the originals into a
portable local summary, matching the self-healing already present for
single-provider migrations.

Fixes #6343
2026-07-23 19:12:50 +00:00
roboomp d4b1fd5107 fix(browser): bound open timeout and lease browser across tab acquisition
The browser tool's open action only passed the requested timeout to acquireTab; acquireBrowser ran under the caller signal alone, so CDP discovery/connect could run through its own fixed 5s/30s waits past the requested deadline. A freshly-created browser also sat in the registry at refCount 0 during worker/surface acquisition: the worker-abort branch released it only on tempHold (never on the fresh refCount-0 case), orphaning the handle, and two different-name opens sharing one refCount-0 browser let a single failure dispose it out from under the survivor.

Compose one open deadline from the caller signal and params.timeout and thread it through both acquireBrowser and acquireTab; caller cancellation stays ToolAbortError, the requested timeout becomes a timeout ToolError. Hold one explicit registry lease across tab acquisition, released exactly once on the mutually-exclusive success/rollback paths, and make the worker-abort browser release mirror the error paths' refCount-0 check.

Fixes #6365
2026-07-23 19:02:38 +00:00
roboomp 03489d1ebe fix(eval): coalesced python kernel replacement
Tracked retained Python kernel generations and shared one replacement promise per dead generation. Reset and disposal now invalidate and drain replacement work before allowing a new session to take ownership.

Added deterministic fake-kernel coverage for concurrent callers, cancellation, reset, owner/global disposal, and independent cwd keys.

Fixes #6367
2026-07-23 19:00:08 +00:00
can1357 fcf2274b2f fix(coding-agent): cancelled pending saves on discarded settings instances
- discarding a Settings instance (test reset, re-init) now disarms its
  debounced save timers and refuses chained background writes, so a
  dropped instance can never race a successor's file locks
- resetSettingsForTest sweeps a weak registry of ALL constructed
  instances, covering isolated (non-singleton) instances too
- fixes deterministic cross-file failure of the model-role replay test
  when settings-reload-cwd ran first in the same process
2026-07-23 20:59:52 +02:00
roboomp 7877df00e4 fix(coding-agent): made pdf image cache content-aware
- Snapshotted source bytes before deriving path-and-content cache generations.
- Coalesced cold extraction with independent caller cancellation and atomic publication.
- Covered replacement, mutation, concurrency, cleanup, isolation, and component limits.

Fixes #6368
2026-07-23 18:58:58 +00:00
roboomp eeb3fa6ace fix(coding-agent): propagated cancellation from lsp reload instead of false restart
reloadServer caught every error from both fallback mechanisms in bare
catch blocks, so a caller cancel or tool timeout was swallowed and fell
through to `proc.kill(); return "Restarted"` -- reporting a successful
restart while killing the server with no replacement.

- Propagate ToolAbortError/timeout from both the rust-analyzer request
  and the didChangeConfiguration notification fallback.
- Gate the fallback on genuine method-not-found via isMethodNotFoundError
  instead of any error.
- Replace the blind proc.kill with shutdownClientInstance: remove the
  client from the registry by identity and await confirmed process exit,
  surfacing a truthful teardown error when the process outlives the kill.

Fixes #6369
2026-07-23 18:58:15 +00:00
can1357 c64e7146e0 refactor(coding-agent): consolidated jujutsu logic into a centralized utility module
- Consolidated Jujutsu (jj) integration logic into a centralized utility module with working-copy and status handling.
- Removed deprecated jj-info helper modules and their corresponding test files.
- Updated status line component and associated tests to consume the new centralized jj utility API.
- Added comprehensive test coverage for working-copy label parsing, status summary mapping, and repository root resolution.
2026-07-23 20:47:42 +02:00
can1357 5b3275c7ae feat(coding-agent): introduced ordered provider priority lists for search and images
- Replaced single-provider preferences with ordered priority lists for web search and image generation.
- Added a `MultiSelectSubmenu` component supporting toggle and reordering interactions in settings.
- Implemented migration logic to convert legacy single-provider preferences into ordered priority lists.
- Updated setup wizard scenes, image generation fallback logic, and search provider chains to use priority lists.
2026-07-23 20:44:50 +02:00
roboomp c232c3af76 fix(write): reject local read-selector-shaped write targets
A read-only step that mis-dispatches read as write passes the full read
expression (src/foo.tsx:1-260:raw) as the target. Because a literal colon
filename is legal on POSIX (#4618), write resolved it to filesystem creation
and reported success, leaving a stray zero-byte file the model could not
recover from - the local analogue of the xd:// near-miss guard (#6123).

assertNotReadSelectorMisfire now fails closed when the tail parses as a
read-tool selector, the literal target is missing, and content is empty,
pointing at the equivalent read(...). Non-empty content stays the escape
hatch and existing literal colon filenames remain writable.

Fixes #6387
2026-07-23 18:39:36 +00:00
roboomp bdceb660d3 fix(tts): preserved playback across internal turns
Moved vocalizer clearing from each assistant/tool continuation boundary to the start of a new agent run.

Added regression coverage for uninterrupted internal turns and new-run interruption.

Fixes #6375
2026-07-23 18:39:11 +00:00
can1357 878b8fd556 Merge PR #6029: feat(omp): configure web search provider order (@riverpilot)
# Conflicts:
#	packages/coding-agent/src/modes/controllers/selector-controller.ts
2026-07-23 20:18:08 +02:00
can1357 344714aea7 Merge PR #4890: feat(coding-agent): use Grok 4.5 for xAI web search (@metaphorics)
# Conflicts:
#	packages/coding-agent/src/web/search/providers/xai.ts
2026-07-23 20:16:05 +02:00
can1357 3a62af9dc0 chore: promoted vibe persistence changelog entry to unreleased 2026-07-23 18:16:02 +02:00
can1357 da1056226e Merge PR #5464 port: persist vibe sessions across restarts (@roboomp) 2026-07-23 18:07:22 +02:00
can1357 5d66eb7f2a Merge PR #5464: fix(coding-agent): persist vibe sessions across restarts (@roboomp) 2026-07-23 18:06:11 +02:00
can1357 2ffb67e3c7 fix: reconciled merged tests and dead code with current main structure
- warp completion test updated to event-taking notification signature
- hindsight test config gained required timeout fields
- dropped orphaned parseBillingConfig and advisor secret-collection dupes
- deduped fixture key; formatter pass on merged files
2026-07-23 18:02:31 +02:00
pr-evalandcan1357 424458e99d chore(secrets): dropped drive-by changes unrelated to secret placeholders
Reverted branch-side edits to spawn-policy prompts/tests, settings tab
groups, mermaid cache typing, prewalk todo gating, and packages/ai test
churn back to merge-base content; trimmed their changelog entries. These
repaired stale CI against an older main and are stale or conflicting
against current main.
2026-07-23 17:56:29 +02:00
can1357 c0c1622012 Merge PR #4636: feat(secrets): add friendly names to secret placeholders (@Mathews-Tom)
# Conflicts:
#	packages/ai/test/pi-native-client.test.ts
#	packages/coding-agent/src/advisor/runtime.ts
#	packages/coding-agent/src/prompts/tools/eval.md
2026-07-23 17:56:24 +02:00
can1357 4af619433b fix(coding-agent): counted queued-but-uninjected async-result follow-ups as pending async work
A completed delivery hands off from the AsyncJobManager to the session's
yield queue before the follow-up is injected (idle flush runs on a delayed
post-prompt task; mid-turn entries wait for the next step boundary). In
that window hasPendingAsyncWork() read false from manager state alone, so
a terminal yield observed there terminated the run and silently dropped
the delivered result - the stale-success class the quiescence barrier
exists to prevent. The wake predicate now also counts queued async-result
entries on the yield queue; added a session-level contract test that
pinned the window (failed before, passes after).
2026-07-23 17:52:52 +02:00
can1357 c522eceff2 Merge PR #6119: feat: lift subagent async/auto-background limits via owner-routed delivery and quiescence (@korri123)
# Conflicts:
#	packages/coding-agent/src/task/executor.ts
2026-07-23 17:52:52 +02:00
can1357 dee5fa63be fix(coding-agent): pointed retry backstops at renamed persistence helper 2026-07-23 17:50:15 +02:00
can1357 e50d67d471 chore(coding-agent): dropped drive-by prompt and spinner drift unrelated to error.notify 2026-07-23 17:49:20 +02:00
can1357 3829bff31a Merge PR #4637: feat(notifications): add error turn notifications (@Mathews-Tom)
# Conflicts:
#	packages/coding-agent/src/modes/controllers/event-controller.ts
#	packages/coding-agent/src/prompts/tools/eval.md
#	packages/coding-agent/src/session/agent-session.ts
#	packages/coding-agent/src/task/index.ts
2026-07-23 17:49:06 +02:00
can1357 01e6ba9217 fix(bash): bound poll-tick output read and terminal release awaits 2026-07-23 17:41:55 +02:00
can1357 c507a590bf Merge PR #4270: fix(bash): bound ACP terminal lifecycle with abort/timeout (@metaphorics)
# Conflicts:
#	packages/coding-agent/src/tools/bash.ts
#	packages/coding-agent/test/bash-acp-terminal.test.ts
2026-07-23 17:41:55 +02:00
can1357 41fe3e1c31 fix(direnv): honored direnv's allow list instead of auto-allowing .envrc
Removed the direnv-allow preflight so an .envrc the user never allowed is
skipped silently (debug log) and never executed; only already-allowed files
export. Updated the setting description, changelog, and rewrote the tests to
allow explicitly per content change.
2026-07-23 17:38:29 +02:00
can1357 4838ec3686 Merge PR #4455: feat(coding-agent): auto-load direnv environment into the bash session (@mattwilkinsonn)
# Conflicts:
#	packages/coding-agent/src/exec/bash-executor.ts
#	packages/coding-agent/test/bash-executor.test.ts
2026-07-23 17:38:28 +02:00
can1357 08be77c483 fix: repaired mis-applied conflict resolutions from title-state merge 2026-07-23 17:34:13 +02:00
can1357 154d4ace9f Merge PR #4448: feat(todo): add blocked status with block/unblock ops (@mattwilkinsonn)
# Conflicts:
#	packages/coding-agent/src/modes/interactive-mode.ts
#	packages/coding-agent/src/prompts/tools/todo.md
2026-07-23 17:32:43 +02:00
can1357 8490654df3 refactor(coding-agent): expressed run state via the title separator instead of prefix glyphs
Kept the bare 'π' brand per owner direction: the separator between the
brand and the session label now carries the state — '>' when it's the
user's turn (idle), animated spinner frames while working, '!' when the
agent is blocked on the user. Disabled ('tui.titleState' off) renders the
pre-state 'π: label' layout. Updated the state/runtime tests to the new
contract.
2026-07-23 17:31:30 +02:00
can1357 e1e5e0b530 fix(coding-agent): kept attention title until the last approval prompt resolved 2026-07-23 17:31:30 +02:00
can1357 0dac3d45b5 Merge PR #4451: feat(coding-agent): reflect agent run state in terminal title (@mattwilkinsonn)
# Conflicts:
#	packages/coding-agent/src/modes/controllers/event-controller.ts
#	packages/coding-agent/src/modes/interactive-mode.ts
2026-07-23 17:31:30 +02:00
can1357 bcd23ee7c1 fix: kept seeded workspace roots lazy until the session file is durable
Seeding additionalDirectories at launch (via --add-dir or the
workspace.additionalDirectories setting) called #rewriteAtomically on a
brand-new session manager, which materialized a header-only JSONL and a
fresh breadcrumb before any assistant output. Launching and exiting with
configured roots therefore created an empty resumable session that
--continue picked over the previous conversation.

Gated all three workspace-directory mutators behind the existing
#shouldHaveSessionFile() lazy-persistence gate (one shared helper), and
made setAdditionalDirectories a no-op when the normalized list is
unchanged so resuming large sessions no longer rewrites the whole JSONL
on every startup. Roots set before the gate is crossed land in the
header with the first durable write; added a regression test.
2026-07-23 17:30:34 +02:00
can1357 26726fdcb9 Merge PR #6255: add dynamic multi-root workspace context (@maatheusgois-dd) 2026-07-23 17:30:33 +02:00
can1357 9d5f158e23 fix(coding-agent): preserved default markdown rendering for internal-URL reads
Gated the read.renderMarkdown opt-in at read time (details tagging) instead
of inside the renderer. The renderer gate silently flipped every
protocol-supplied text/markdown read (skill://, pr://, issue://, history://,
rule://, omp://, agent://, vault://, local://, memory://, ssh://) from the
formatted markdown cell to the raw code cell when the setting was off, which
regressed default TUI behavior. Local file tagging now happens only when the
setting is enabled, so the default render path is byte-identical to the
pre-setting behavior while opt-in previews still work end-to-end.

Also inlined the tautological isMarkdownContentPath wrapper, pinned the
widened prose-summary bypass (.mdx stays verbatim when prose summaries are
off) with a test, and documented it under Changed in the changelog.
2026-07-23 17:30:33 +02:00
can1357 42a3da21de Merge PR #4001: feat(coding-agent): opt-in Markdown read previews (@oldschoola) 2026-07-23 17:30:33 +02:00
can1357 1435f8dbce perf: restored lazy export-module loading by splitting /export arg parsing into export/html/args.ts 2026-07-23 17:30:33 +02:00
can1357 f898e258c5 fix: kept dark export links bright and made light links AA-legible; removed duplicate changelog entry from released 16.5.2 2026-07-23 17:30:33 +02:00
can1357 c76221095f Merge PR #6349: support light, dark, and system themes in HTML exports (@anatoli-tsinovoy) 2026-07-23 17:30:32 +02:00