Commit Graph
9801 Commits
Author SHA1 Message Date
can1357 ed67dfa5e8 Merge PR #4450: feat(statusline): make git segment jj-aware (@mattwilkinsonn) 2026-07-23 17:30:32 +02:00
can1357 09d02c641f fix(coding-agent): closed bash approval rule bypasses
Tested the shell-control guard against the raw command: whitespace
normalization collapsed newlines/CR before the guard ran, so
'git status\nrm file.txt' rode a 'git *' allow rule while bash executed
both lines. Honored tool-owned allow/prompt policies in yolo mode so
per-command prompt rules were no longer silently discarded under the
default approvalMode. Added precision regression tests through the real
matcher (separators, subshells, redirects, env prefixes, path/quoting
variants) that fail on the unfixed head.
2026-07-23 17:30:32 +02:00
can1357 794515fd1a Merge PR #6363: feat(coding-agent): support per-command bash approval rules (@WahidinAji) 2026-07-23 17:30:32 +02:00
can1357 4e78d12428 fixed live queue trim to compact consumed prefix and resync parser 2026-07-23 17:30:15 +02:00
can1357 ebf2b86790 Merge PR #4269: fix(bash): bound interactive bash live display write queue (@metaphorics) 2026-07-23 17:30:15 +02:00
can1357 73b3a2ad53 fix(hindsight): bypassed retention cache on forced retains
Forced retains returned early with an empty incremental slice when no new
messages arrived since the last successful auto-retain, so a user-visible
/memory enqueue rebuild sent nothing and could not recover a deleted or
unmaterialized upstream document. Also removed the public modifier from the
test fake per the root AGENTS.md class-privacy rule and added a forced-retain
resend test.
2026-07-23 17:30:15 +02:00
can1357 0829fc6143 Merge PR #4275: perf(hindsight): cache full-session retention transcript incrementally (@metaphorics) 2026-07-23 17:30:15 +02:00
can1357 2c42715263 fix(compaction): charged pre-archive kept region in rescue budget
Also stamped dead-end warnings before the auto_compaction_end event so the result-driven TUI rebuild shows the badge (Codex round 6 on #6362).
2026-07-23 17:30:15 +02:00
can1357 15f1fb2c7c Merge PR #6362: fix(compaction): rescue snapcompact archives stuck past the maintenance threshold (@HugoLopes45) 2026-07-23 17:30:14 +02:00
can1357 b2eedd944f Merge PR #6383: fix: preserve oauth links across wrapped rows (@ondrejsojka) 2026-07-23 16:35:47 +02:00
can1357 da5da41169 Merge PR #6382: feat(ai): report Anthropic extra usage in omp usage (@LunarECL) 2026-07-23 16:35:47 +02:00
can1357 fadcd1a650 fix(ai): made credential-pattern redaction opt-in
- Credential-shaped token redaction now requires explicit opt-in via `configureCredentialRedaction` and is disabled by default, so user-supplied credential-like strings reach providers unmodified unless the host enables redaction.
- Wired the `secrets.enabled` ("Hide Secrets") setting to `configureCredentialRedaction` in the coding-agent so the pattern redaction follows the existing secret-obfuscation toggle.
2026-07-23 16:23:08 +02:00
Ondřej Sojka 9bde7217b1 Merge remote-tracking branch 'origin/main' into fix/wrapped-oauth-links 2026-07-23 14:45:59 +02:00
black lodge resident a04488abff Merge remote-tracking branch 'origin/main' into pr-6383 2026-07-23 14:30:30 +02:00
LunarECL e7fdc99afd feat(ai): report Anthropic extra usage 2026-07-23 21:25:15 +09:00
Hugo Lopes d8554c92d0 fix(compaction): charge the kept tail in the rescue budget and badge the active entry
Review follow-ups (Codex on #6362, round 5):
- #computeSnapcompactRescueMaxFrames now subtracts the kept tail AFTER the
  archive (plus the existing fixed-context reserves) so the budget mirrors
  what #compactionCreatedHeadroom will measure, and returns 0 when not even
  one frame fits — the rescue bails instead of appending a rebuild that can
  never create headroom (and would wedge prepareCompaction behind its
  last-entry guard once elide fixes the real tail).
- Dead-end warnings now stamp the branch's LATEST compaction entry: the
  post-pass path no longer badges the entry the rescue just superseded, and
  the no-preparation path badges the rebuilt entry when the rescue appended
  without creating headroom.

Claude-Session: https://claude.ai/code/session_014rh4JyWFkxgMhgFaEf8VBY
2026-07-23 14:03:12 +02:00
can1357 0f54c0df70 fix(tools): autoqa consent handling from default off to opt-in 2026-07-23 13:24:45 +02:00
Hugo Lopes f48004a182 fix(compaction): only frame-rescue archives that are the actual overflow source
Review follow-up (Codex on #6362, round 4): rebuilding a non-tail archive
appends the replacement compaction at the leaf, so the branch tail becomes a
compaction entry that prepareCompaction's last-entry guard can never
summarize past — even after elide shrinks the oversized kept tool result
that was the real culprit. The rescue now estimates the kept tail AFTER the
latest archive and bails when it alone exceeds the recovery band, leaving
that shape to the elide/image tiers.

Claude-Session: https://claude.ai/code/session_014rh4JyWFkxgMhgFaEf8VBY
2026-07-23 13:15:23 +02:00
Hugo Lopes d9417927bc fix(compaction): surface the frame rescue as a real compaction to the TUI and extensions
Review follow-ups (Codex on #6362):
- #rescueSnapcompactFrameOverflow now returns the CompactionResult and emits
  session_compact for the rebuilt entry, so extensions see the entry that is
  actually active instead of (only) the one the rescue superseded.
- The no-preparation auto_compaction_end now carries that result instead of
  {result: undefined, skipped: true} when the rescue rewrote history — the
  TUI rebuilds the transcript on result, so a successful rescue is no longer
  presented as a benign no-op.

Claude-Session: https://claude.ai/code/session_014rh4JyWFkxgMhgFaEf8VBY
2026-07-23 12:59:15 +02:00
can1357 f833810d0e fix(rpc): stream v2 chunk frames with backpressure and recover stale page cursors
Two fixes on top of the paged transport:

- Near-limit v2 framing no longer materializes the full base64 transport:
  chunk lines are generated lazily from a single serialization, the 64 MiB
  reassembly ceiling is enforced via Buffer.byteLength before any
  full-payload allocation, and RPC stdout writes drain with backpressure
  one physical line at a time. Peak RSS for a 63 MiB response drops
  ~686 MB -> ~521 MB; a rejected 80 MiB response drops ~507 MB -> ~259 MB
  (parity with the v1 path).

- get_messages_page errors now carry a machine-readable code
  (session_busy | stale_cursor). Both bundled clients' high-level
  getMessages() drains discard partial pages and fall back to the legacy
  snapshot on either code — previously a cursor invalidated by a
  background mutation (e.g. an appended bash message) threw instead of
  falling back. Direct page calls remain strict.
2026-07-23 12:38:13 +02:00
can1357 3e09e4b1ea Merge PR #6330: feat(coding-agent): add lossless paged RPC transport (@wolfiesch) 2026-07-23 12:27:38 +02:00
Cakrawala 6d7457663f feat(coding-agent): support per-command bash approval rules 2026-07-23 17:11:41 +07:00
can1357 38efea12ed feat(coding-agent): enabled MCP Markdown result rendering by default
mcp.renderMarkdownResults now defaults to true; set false to keep raw
text. Non-JSON detection and structured JSON-tree rendering unchanged.
2026-07-23 11:54:21 +02:00
can1357 80ec1cb6ae Merge PR #6347: feat: optionally render MCP results as Markdown (@zeroknots) 2026-07-23 11:53:05 +02:00
can1357 49782ecce6 Merge PR #6326: feat(coding-agent): configure isolated task apply behavior (@korri123) 2026-07-23 11:48:54 +02:00
can1357 8205d3ee31 style: applied biome formatting to merged fix commits 2026-07-23 11:39:15 +02:00
Hugo Lopes ef952c6d88 fix(compaction): mirror post-compaction bookkeeping in the frame rescue
Review follow-up (Codex on #6362): the rescue's replaceMessages() rebuild
drops the transient plan-reference message, so clear #planReferenceSent
(#1246) and reset advisor runtimes / todo phases exactly like the regular
compaction append path.

Claude-Session: https://claude.ai/code/session_014rh4JyWFkxgMhgFaEf8VBY
2026-07-23 11:37:59 +02:00
can1357 ca27ad0b06 Merge PR #4927: feat(coding-agent): rewrite /guided-goal interviewer for loop engineering (@metaphorics) 2026-07-23 11:37:14 +02:00
can1357 536d37ac07 Merge PR #5137: perf(coding-agent): avoid cold LSP startup on format-only writes (@wolfiesch) 2026-07-23 11:37:13 +02:00
can1357 db3a6a1407 Merge PR #6318: fix(tui): show fallback models in Agent Hub (@roboomp) 2026-07-23 11:37:13 +02:00
can1357 bf15acb25d fix(coding-agent): hub cancel reaches the registration behind a settled job row
A budget-aborted keep-alive subagent's job row (job id == agent id) settles
failed and is retained ~5 min; executeCancel short-circuited to
already_completed for that window, leaving the zombie registration
unkillable exactly when the user wants it dead. Fall through to
cancelAgentRegistration for settled rows; keep already_completed when no
lingering registration exists.

Also stop wiring AgentLifecycleManager.global() onto SDK sessions created
with a caller-supplied agentRegistry: the global lifecycle releases through
AgentRegistry.global(), so it would report a cancel while releasing an
unrelated global ref. Without a lifecycle, cancel falls back to
dispose + unregister on the session's own registry.

Addresses both Codex P2 review findings on #6319.
2026-07-23 11:37:13 +02:00
can1357 9756fea7af Merge PR #6319: fix(coding-agent): let hub cancel kill a jobless agent registration (@roboomp) 2026-07-23 11:37:13 +02:00
can1357 be94acbf71 fix(extensions): handle TypeScript import-equals require specifiers
Collect TSImportEqualsDeclaration/TSExternalModuleReference targets so
legacy .ts/.cts extensions using `import x = require("pkg")` get their
bare dependencies pinned like plain require() calls. Fold of the #6256
follow-up (comicchang/oh-my-pi@1e54b68) requested on #6324.
2026-07-23 11:37:12 +02:00
can1357 27fc2d60d1 Merge PR #6324: fix(extensions): resolve transitive CJS dependencies (@jeffscottward) 2026-07-23 11:37:12 +02:00
can1357 c818e77240 Merge PR #6328: fix(task): only point follow-up hints at transcripts that exist (@paralin) 2026-07-23 11:37:12 +02:00
can1357 39c3f2a054 Merge PR #6329: fix(settings): expose Hindsight API token (@salmonumbrella) 2026-07-23 11:37:12 +02:00
can1357 bacb51dffd Merge PR #6331: Add firecrawl keyless mode support (@CoderTCY) 2026-07-23 11:37:11 +02:00
can1357 395e5ba288 fix(coding-agent): bypass anonymous-connect guard when a tool auth challenge is present
Servers may allow the unauthenticated MCP handshake yet protect individual
tool calls via _meta["mcp/www_authenticate"]. The 'reauthorization is not
required' guard would silently abort the tool-challenge reauth path.
2026-07-23 11:37:11 +02:00
can1357 7880c459b7 Merge PR #6346: fix(coding-agent): retry MCP tool auth challenges (@spenceresin8) 2026-07-23 11:37:11 +02:00
can1357 370045b310 fix(sdk): always await in-flight runtime discovery in deferred --model retry
The getDiscoverableProviders() guard skipped awaiting runtimeDiscoveryPromise
when no config-discovery providers exist, so a cold deferred selector backed
only by runtime model managers (extension fetchDynamicModels) with implicit
local discovery disabled still resolved against the offline cache. Awaiting
unconditionally is free when no runtime managers are registered
(refreshRuntimeProviders early-returns); the full refresh fallback stays
gated on discoverable providers.
2026-07-23 11:37:11 +02:00
can1357 e581452c04 Merge PR #6355: fix(rpc): await background model discovery in get_available_models, set_model, and deferred --model resolution (@ReqX) 2026-07-23 11:37:11 +02:00
can1357 e488d09751 fix(coding-agent): keep failed tails visible in read-only session history
Route loadSessionMessagesReadOnly through transcript mode (collapsed to the
latest compaction) so history:// transcripts of on-disk sessions retain
failed/aborted assistant tails that the provider-context builder now drops.
2026-07-23 11:37:10 +02:00
can1357 6fe0cc99bc Merge PR #6357: fix(coding-agent): guard session context replay tail (@honsunrise) 2026-07-23 11:37:10 +02:00
can1357 b184b22fef Merge PR #6358: feat(ai): add Synthetic usage reporting (@Gareth-Rouse) 2026-07-23 11:37:10 +02:00
can1357 ebddcc3839 Merge PR #6360: feat(task): allow per-call model selection (@panosAthDBX) 2026-07-23 11:37:10 +02:00
Hugo Lopes 42f530f187 fix(compaction): gate frame-rescue success on real headroom and cap rescue frames
Review follow-ups (Codex on #6362):
- The !preparation frame rescue now counts as complete only when the rebuild
  actually created headroom; otherwise the elide/image tiers still run and the
  no-progress warning stays — a frame-count shrink alone must not suppress it
  when the oversized tail is a kept message/tool result the archive rescue
  cannot touch.
- #computeSnapcompactRescueMaxFrames now applies the same MAX_FRAMES_DEFAULT /
  maxFramesForDataBudget caps as #computeSnapcompactMaxFrames, so a
  threshold-derived count can never exceed what the rebuilt prompt can attach.

Claude-Session: https://claude.ai/code/session_014rh4JyWFkxgMhgFaEf8VBY
2026-07-23 11:35:09 +02:00
Hugo Lopes 756fed844c fix(compaction): rescue trailing snapcompact archives past the maintenance threshold
A branch whose last entry is a snapcompact CompactionEntry billed past the
compaction threshold (FRAME_TOKEN_ESTIMATE x frames) dead-ended on every
resume: prepareCompaction returns undefined (nothing after the entry to
summarize), and the #4786 elide/image rescue tiers only inspect
"message"/"custom_message" entries, so a type:"compaction" tail escaped both
and the "Compaction freed too little context" warning re-fired forever.

Add a dedicated first rescue tier that rebuilds the SAME archive locally (no
LLM, no network) by re-running snapcompact.compact() over the entry's
carried-forward source text at a maxFrames derived from the trigger
threshold's recovery band instead of the window-fit budget: planArchive
truncates the oldest chars to fit, so the rebuilt entry genuinely shrinks.
Persisting through appendCompaction lets the write-time
superseded-compaction elision drop the stale frame payload from the JSONL,
and the pass skips the misleading no-progress warning.

Fixes the loop reported in
https://github.com/can1357/oh-my-pi/issues/4786#issuecomment-5056055342

Claude-Session: https://claude.ai/code/session_014rh4JyWFkxgMhgFaEf8VBY
2026-07-23 11:31:00 +02:00
can1357 b4a3abe445 feat: added hasProvider method to detect known model providers
- Implemented ModelRegistry.hasProvider to return true when a provider has live models, is discoverable, or is registered at runtime.
- Replaced AgentSession's internal provider check with #isKnownProvider that delegates to the new hasProvider method, updating related fallback logic.
2026-07-23 11:17:00 +02:00
panosAthDBX bfef3f7eea fix(task): reject sparse model fallback arrays 2026-07-23 09:53:54 +01:00
ReqX 838e37417f fix(rpc): await background model discovery in get_available_models, set_model, and deferred --model resolution
Three read paths raced background model discovery on cold start:

1. `get_available_models` RPC (rpc-mode.ts) read the registry
   synchronously and returned a partial catalog containing only
   statically-bundled models.
2. `set_model` RPC (rpc-mode.ts) read the registry synchronously and
   rejected discovery-backed selectors with "Model not found".
3. `--model <provider>/<pattern>` CLI flag deferred retry (sdk.ts:2078)
   resolved synchronously after extension registration, before
   discovery-backed providers had populated `#models`.

Paths 1 and 2 are fixed by exposing the existing in-flight background
refresh promise (`#backgroundRefresh`, already tracked and cleared by
`refreshInBackground`) via a new public
`ModelRegistry.awaitBackgroundRefresh()` method, and awaiting it at each
RPC read site. No-op when no refresh is in flight (warm sessions
unaffected).

Path 3 mirrors the cold-cache race fix already applied to the
default-role fallback on this branch (issues #6114, #6162, sdk.ts:2343):
when a deferred pattern is unresolved and any discoverable provider is
registered, run a cache-aware `refresh("online-if-uncached")` pass
before the retry. Reuses the existing discovery machinery rather than
introducing a new ordering dependency.

The `omp models` CLI never had this bug because it awaits
`modelRegistry.refresh()` directly before listing.

Behavioral characteristics:
- **Warm-session fast path preserved**: when no refresh is in flight
  (`#backgroundRefresh === undefined`), `await undefined` resolves in a
  microtask. No regression for sessions that don't need discovery or
  have already settled.
- **Failure isolation preserved**: `refreshInBackground()` already
  swallows discovery errors via `.catch(...)`, so `awaitBackgroundRefresh()`
  resolves even when discovery fails — callers then read whatever models
  made it into `#models` (built-in + cached). No new failure modes.
- **Scoped**: doesn't change `refreshInBackground()` semantics. Adds a
  new read-only awaiter with minimal API surface. Reuses the
  well-established `refresh("online-if-uncached")` pattern for the
  deferred retry path.

Reproduction (get_available_models RPC, with any discovery-backed
provider configured in `~/.omp/agent/models.yaml`):

  cd ~
  {
    sleep 1
    printf '%s\n' '{"id":"m1","type":"get_available_models"}'
    sleep 5
  } | timeout 15 omp --mode rpc-ui --approval-mode yolo 2>/dev/null \
    | grep '"id":"m1"' | jq '.data.models | {count: length, providers: ([.[].provider]|unique)}'

Before: discovery-backed provider absent from the response on cold start.
After:  discovery-backed provider present.

Reproduction (--model CLI flag, same config):

  omp --mode rpc-ui --model <discovery-provider>/<model-id> --approval-mode yolo

Before: exits 1 with "Model \"<discovery-provider>/<model-id>\" not found".
After:  starts rpc-ui session with the requested model selected.
2026-07-23 08:46:31 +00:00