Commit Graph
9801 Commits
Author SHA1 Message Date
Mathews-Tom 224796b13a fix(mcp): sweep group SIGKILL after a cooperative detached leader exit
terminateStdioProcess() treated a detached leader's cooperative SIGTERM
exit as proof the whole process group was gone, so close() skipped the
group SIGKILL and left a SIGTERM-trapping/ignoring grandchild running as
an orphan — exactly the process tree this change set out to reap. A
detached transport now always sweeps the group SIGKILL after SIGTERM,
even when the leader itself already exited.

waitForProcessExit() also left its losing Bun.sleep() timer running
after Promise.race settled from the other side, holding the event loop
open for up to the full grace window on every close(). It now uses a
cancellable setTimeout cleared in a finally block.

Adds a regression test spawning a non-trapping leader with a
SIGTERM-trapping grandchild to cover the gap the first fix closes.
2026-07-18 00:02:21 +05:30
roboomp 913ec0baae fix(kimi-code): preserved k3 native effort contract
- Parsed live named efforts, mandatory-thinking state, and model protocol metadata.

- Sent native Kimi named efforts and adaptive Anthropic override efforts without generic token budgets.

Fixes #5893
2026-07-17 18:19:00 +00:00
roboomp f662d79ffd fix(tui): keep hidden-pending summary when actives fill the todo cap
selectCollapsedTodos took the active-overflow branch at active.length >= cap, so exactly cap actives plus trailing pending returned the cap rows with an empty summary — the pending work vanished with no '… N more' indicator.

Use a strict '> cap' guard so equality falls through to the normal branch, which counts every hidden row.

Fixes #5873
2026-07-17 18:06:47 +00:00
roboomp 939d6761f7 fix(tui): shared walking-viewport policy for collapsed todos
The first pass anchored a slice on the active task, which still showed completed rows, kept the active item mid-window, and gave the two views divergent selection logic. Per reviewer, replace it with one shared policy both collapsed views run.

selectCollapsedTodos (todo.ts) omits completed/abandoned, pulls every active task (in_progress or subagent-matched pending) to the head in todo order, fills remaining rows with following pending tasks, and emits '… N more active todos' when active work alone exceeds the cap; it falls back to closed tasks for a settled phase so HUD persistence still renders. renderTreeList gains a trailingSummary primitive so item selection lives in the todo domain. The transient tool result reaches live subagent matches via setActiveTodoDescriptionsProvider, wired from interactive mode's observer registry, so both views share the active set.

Fixes #5873
2026-07-17 18:03:13 +00:00
Mathews-Tom fcbcf73769 feat(tui): allow re-answering a past ask from the session tree
Selecting an ask toolResult in /tree previously just repositioned the
leaf onto the stale answer without re-running the interactive picker
(issue #5642). navigateTree() now detects an ask toolResult target and
returns { reopenAsk: { toolCallId, questions } } recovered from the
original toolCall's persisted arguments, instead of mutating anything.
The TUI's tree selector re-opens the ask picker via a standalone
AskTool.execute() call (reusing the live tool-execution UI context),
then calls navigateTree() again with { reanswerAskResult } to branch a
*new* sibling toolResult off the same ask toolCall -- the original
answer's branch stays fully reachable. Non-ask toolResults, and ask
toolResults whose original arguments can't be recovered (legacy/
corrupted sessions), keep the existing plain leaf-move behavior.

This implements direction 2 from the issue's maintainer triage
(re-answer as a new sibling branch), not direction 1 (resuming the
agent turn) or direction 3 (docs-only).
2026-07-17 23:29:35 +05:30
Mathews-Tom c30c3ab0fb fix(mcp): process-group kill and SIGKILL escalate on stdio transport close
Before: StdioTransport.close() did a bare `this.#process.kill()` — a single
direct SIGTERM to the immediate child, with no wait and no escalation. On
Linux (and other non-Windows/non-macOS POSIX hosts), the MCP server is
spawned detached (setsid, its own session leader) so terminal job-control
signals can't stop it. A detached server that traps/ignores SIGTERM — or a
grandchild it spawns inside that session — survived omp process exit and
was orphaned, re-parented to PID 1.

After: close() runs a bounded, idempotent teardown:
  1. End stdin first (cooperative EOF) so a well-behaved server can exit on
     its own before any signal is sent.
  2. Send SIGTERM: to the whole process group (negative-pid `process.kill`)
     when this transport actually spawned detached on a POSIX host, else to
     the direct child only. A negative-pid signal is never attempted for a
     non-detached transport, since it could hit an unrelated group. ESRCH
     from the group signal means the group is already gone (treated as
     success); any other group-signal failure falls back to a direct-child
     signal.
  3. Wait up to ~1s for the direct child to exit; if it hasn't, escalate to
     SIGKILL (group-or-direct, same rule as step 2) and wait a further
     bounded ~0.5s before returning. Total worst case (~1.5s) stays well
     inside the ~3s MCP disconnect-all budget in agent-session.ts dispose().

`#process` is captured into a local and nulled before the first `await`, so
repeat/concurrent close() calls see it already cleared and skip re-signaling
— idempotent per the existing contract documented above close().

Extracted the signal/escalate logic into an exported `terminateStdioProcess`
(plus a `KillableSubprocess` structural type, decoupled from the stdio pipe
generics) so tests can drive group-signal escalation with an explicit
`detached` flag — `StdioTransport.connect()` ties `detached` to the host's
real `process.platform` via `resolveStdioSpawnCommand()`, so a POSIX
detached session can't be reproduced end-to-end through `connect()` on a
non-Linux dev/CI host, but a real detached process group can still be
spawned directly on any POSIX host to exercise it.

Tests added to stdio.test.ts: detached child trapping SIGTERM escalates to
SIGKILL; a detached parent's SIGTERM-trapping grandchild is only reached by
the group SIGKILL (proves group, not direct-child-only, signaling); a
well-behaved child closes promptly without escalating; a non-detached
transport never attempts a group signal. Extended
test/mcp-stdio-transport.test.ts's existing close() idempotency coverage
with a case where the first close() had to run the full escalation path.

Fixes #5578.
2026-07-17 23:22:06 +05:30
roboomp 67ca037b17 fix(ai): allowed custom oauth fingerprint headers
Added an opt-in compatibility flag for non-official Anthropic OAuth endpoints while preserving authoritative OAuth and Cloudflare credentials.

Fixes #5888
2026-07-17 17:44:47 +00:00
roboomp bacc24e12e fix(agent): preserved signed thinking-only stops
- Treated non-empty thinking signatures as terminal provider content.
- Added regression coverage for empty visible thinking with a valid signature.

Fixes #5881
2026-07-17 17:08:15 +00:00
roboomp aaac0ace1d fix(extensions): created legacy auth database directory
Create the resolved agent database parent before the synchronous compatibility store opens SQLite, and cover a fresh nested agent directory.

Fixes #5879
2026-07-17 17:06:15 +00:00
roboomp 7e8c4fc01f fix(extensions): restored legacy provider compatibility
Restored the historical assistant-message stream factory and synchronous auth-storage facade needed by pi-provider-kimi-code.

Fixes #5879
2026-07-17 16:54:47 +00:00
roboomp e6fd29ec21 fix(tui): keep active todo visible in collapsed views
Both collapsed todo renderers took fixed edge slices: the tool result kept the tail eight (truncateFrom start) and the HUD kept the head five (base.slice), so a mid-phase in_progress task fell in the omitted middle of both.

Add an anchorIndex option to renderTreeList that slides the collapsed window over the anchored item with two-sided '… N more' summaries, and anchor both call sites on the in_progress task (HUD falls back to the first subagent-matched pending task).

Fixes #5873
2026-07-17 16:33:28 +00:00
roboomp f10658fe3a docs(coding-agent): clarified async job lifecycle contract
- Documented settled snapshot delivery consumption and process-local retention.
- Clarified completion semantics in task receipts and hub guidance.
- Added model-facing contract regression coverage.

Fixes #5869
2026-07-17 16:06:18 +00:00
vmcall 131d06075d fix(task): preserved essential load mode 2026-07-17 17:46:07 +02:00
vmcall 4121c19781 test(eval): aligned allowed-agent prompt expectation 2026-07-17 17:38:12 +02:00
vmcall d53cf023b0 fix(task): reconciled structured subagents with upstream
- Preserved the plan-mode capability clamp after upstream removed report_finding.
- Updated persisted-revival coverage for mounted xdev tool activation.
- Applied current formatter output to conflicted runtime files.
2026-07-17 17:38:12 +02:00
vmcall b4952e27c4 refactor(eval): removed dead isolation recovery formatter 2026-07-17 17:38:12 +02:00
vmcall 1dbedbedf5 fix(task): restored restricted spawn policy description 2026-07-17 17:38:12 +02:00
vmcall 2aaa639b69 fix(task): marked dynamic task schema non-strict
Caller-provided output schemas are free-form JSON and cannot be represented by OpenAI strict tool schemas. Keep todo strict while explicitly sending task as non-strict.
2026-07-17 17:38:12 +02:00
vmcall 414ef80c41 fix(task): restored goal activation outside restricted sessions
- Preserved goal-mode tool injection for ordinary explicit tool lists.
- Kept plan-mode LSP and IRC unavailable under the host capability clamp.
- Added regressions for both capability boundaries.
2026-07-17 17:36:59 +02:00
vmcall d944879f21 feat(task): unified structured subagent execution
- Added per-invocation task schemas with strict and permissive validation.
- Shared task and eval agent policy, artifacts, isolation, and lifecycle handling.
- Enabled host-restricted plan-mode eval agents and persisted their capability clamp.

Fixes #5279
2026-07-17 17:36:59 +02:00
roboomp 66837a96be fix(hub): restored persisted peers after resume
Moved persisted roster discovery out of the Agent Hub UI so model-facing coordination can use the same disk-backed registration path.

Rehydrated parked peers before an empty hub list response and added a crash-resume regression test.

Fixes #5864
2026-07-17 15:20:43 +00:00
roboomp 189ac462cc fix(mcp): narrowed failed DCR block to unapproved clients
Only a 403 response that identifies unapproved_client now blocks generateAuthUrl before its clientless probe. Invalid metadata, invalid redirect, generic forbidden, retryable, and server failures preserve the probe path.

Consolidated fallback coverage across 400, 403, 429, and 503 responses.

Fixes #5852
2026-07-17 14:56:56 +00:00
roboomp 490686602c fix(mcp): excluded retryable 4xx DCR statuses from reauth block
Added #isDefinitiveRegistrationRejection so only non-retryable 4xx DCR errors block generateAuthUrl; 408/425/429 fall through to the clientless authorization probe alongside transport and 5xx failures.

Fixes #5852
2026-07-17 14:49:51 +00:00
roboomp 7faa6eb2dd fix(mcp): scoped reauth block to definitive DCR rejections
Only a 4xx DCR client error blocks generateAuthUrl; transport (status 0) and 5xx failures fall through to the clientless authorization probe so providers accepting client-less authorization keep working.

Fixes #5852
2026-07-17 14:45:56 +00:00
roboomp 33f2f00d58 fix(mcp): blocked reauth after failed client registration
Surfaced rejected dynamic client registration from generateAuthUrl before probing or returning an authorization URL without client_id.

Added coverage for a Cropwise-style 403 unapproved_client response.

Fixes #5852
2026-07-17 14:39:15 +00:00
roboomp e5f65fcd5f fix(cli): preserved carriage-return progress boundaries
Normalized lone carriage returns before terminal output is buffered while retaining CRLF as a single line boundary across chunk splits.

Fixes #5845
2026-07-17 13:58:45 +00:00
roboomp ea78e346d0 fix(tui): dropped stale hidden-lines footer on expanded output
Expanded `!` bash and `eval` execution output kept rendering the
`… N more lines (ctrl+o to expand)` footer after Ctrl+O revealed every
line, because `hiddenLineCount` was computed from the collapsed preview
window regardless of the `#expanded` (or sixel-passthrough) state.

Zero the hidden count whenever the full output is shown so
`buildStatusFooter()` stops advertising hidden lines and ctrl+o.

Fixes #5842
2026-07-17 13:11:52 +00:00
roboomp 28689a88cb docs: clarified process-wide history scope
Accounted for concurrent top-level ACP sessions registered in the process-global AgentRegistry while retaining the persisted-file limitation for unregistered top-level sessions.

Fixes #5839
2026-07-17 12:34:25 +00:00
roboomp 05afc94ec5 docs: narrowed history:// contract to current session tree
The system prompt claimed history:// serves any agent whose session file
persists on disk. In practice sessionFilesFromDisk() scans only
artifactsDirsFromRegistry() and keys by <agentId>.jsonl, so independent
top-level OMP sessions (MAIN_AGENT_ID="Main", persisted as
<timestamp>_<uuid>.jsonl in the session directory) are unreachable.
Narrowed the wording to match the implementation.

Fixes #5839
2026-07-17 12:30:16 +00:00
roboomp 6558b5ec05 feat(config): added PI_CONFIG_FILES settings overlay env var
Loaded a platform-delimited (: on Unix, ; on Windows) path-list of settings overlays from PI_CONFIG_FILES before explicit --config overlays, so wrapper-based setups can inject settings without argv surgery.

Dropped the earlier global --config extraction as too risky; --config remains a launch/acp/models flag as before.

Fixes #5685
2026-07-17 10:35:19 +00:00
roboomp db91dbe3ea fix(lsp): returned pull diagnostics promptly
Raced document diagnostic pulls against the push polling interval so completed full reports return without waiting for the deadline.

Covered inline edit writethrough delivery for an immediate pull-only response.

Fixes #5825
2026-07-17 10:17:00 +00:00
roboomp 58b1d4440f fix(lsp): supported pull diagnostics
Advertised document diagnostic support and tracked static and dynamic server capabilities.

Pulled full reports within the existing diagnostics wait window while preserving push precedence.

Fixes #5825
2026-07-17 10:10:11 +00:00
roboomp c74e9d324f fix(extensions): disambiguated .agent dirs provider tab label
The /extensions dashboard built one tab per provider from its displayName.
The .agent/.agents config-standard provider used "Agents (standard)", which
collided with the first-class /agents subagents feature even though the tab
only surfaces skills, rules, prompts, commands, and context/system files.
Renamed DISPLAY_NAME to "Agent Dirs (.agent/.agents)".

Fixes #5821
2026-07-17 09:04:40 +00:00
roboomp 22a8524058 fix(tools): recognized zip-family archives and pruned unconvertible extensions
- Treated ZIP-based .jar/.war/.ear/.apk as zip archives in archiveFormatFromPath and parseArchivePathCandidates so read/write member access works.
- Shared one archive-extension alternation between format detection and path splitting to stop them drifting.
- Derived the markit convertible-extension set from a single source of truth (utils/markit) matching the registered converters (pdf/docx/pptx/xlsx/epub), dropping legacy .doc/.ppt/.xls/.rtf that had no converter and only produced Unsupported format errors.
- Updated read/write tool prompts to document the zip-family extensions.

Fixes #5808
2026-07-17 08:04:10 +00:00
roboomp 67727c8de5 fix(session): resumed queued messages after compaction reconnects
The #5800 drain guard suppressed the abort-finally stranded-message
drain while the session was disconnected from the agent event stream.
newSession/switchSession drop the agent queues on transition, so nothing
is lost there. compact() preserves the queues and only reconnected in
its finally — it never re-drained — so a steer/follow-up arriving during
compaction (async IRC, an xd:// mount notice, an SDK steer) stayed
stranded until the next explicit prompt.

Re-drain in compact()'s finally after #reconnectToAgent (and after the
compaction AbortController is cleared, so isCompacting is false and the
scheduled agent.continue() actually runs). Added a regression test that
queues a follow-up mid-compaction and asserts it resumes.

Fixes #5800
2026-07-17 08:03:03 +00:00
roboomp dc7238f5a4 fix(read): supported history URL selectors
Added history to selector-aware internal URL schemes so read paging resolves the agent id before applying transcript ranges.

Fixes #5806
2026-07-17 07:46:37 +00:00
roboomp e5d5aec189 fix(read): enforced exact line selector bounds
- Removed implicit padding and syntactic boundary expansion from explicit ranges.
- Covered local, converted, multi-range, and artifact reads.

Fixes #5802
2026-07-17 07:45:39 +00:00
roboomp 33d66643d3 fix(read): refreshed URL responses on each invocation
Removed process-local URL response reuse so read and URL-backed search paths fetch current content.

Added regressions for repeated reads and searches.

Fixes #5803
2026-07-17 07:45:06 +00:00
roboomp ca874cf134 fix(lsp): raised timeout ceiling to 300 seconds
Allowed explicit LSP request budgets above 60 seconds and exposed the 5–300 second range in the tool schema.

Fixes #5804
2026-07-17 07:43:40 +00:00
roboomp 4d685bf761 fix(session): made /new an atomic boundary against queued steers
newSession() disconnects the agent listener and awaits abort() before
agent.reset(). abort()'s finally clears #abortInProgress and calls
#drainStrandedQueuedMessages(), which scheduled agent.continue() on the
still-old context — starting an unsolicited provider turn (e.g. from a
queued xdev-mount hidden steer) that raced the reset and appended its
late output to the fresh session.

Guard the drain to no-op while the session is disconnected from the
agent event stream (#unsubscribeAgent === undefined): a transition owns
the queue, and there is no listener to persist or render output. A plain
user-interrupt abort() stays connected, so its legitimate stranded drain
still runs.

Fixes #5800
2026-07-17 07:43:06 +00:00
roboomp 6b88e69057 fix(prompting): hid xd tools from direct inventory
- Filtered xd-mounted names from compact and inline tool inventories.

- Added regression coverage for both inventory rendering modes.

Fixes #5797
2026-07-17 07:09:23 +00:00
can1357 eac51b6a04 Merge: darkphilosophy/feat/advisor-per-agent-toggle
Brings the per-advisor toggle, status-line glyphs, quota display, and the
failing-advisor stall/abort fix (f4c8143) onto main's rewritten advisor
runtime. Conflict reconciliation kept main's architecture (fingerprint
prefix reconciliation, host-level onTurnError recovery + fallback chains,
terminal-failure classification) and ported the branch semantics onto it:

- #failing latch: waitForCatchup resolves immediately while an advisor is
  mid-failure; parked waiters wake the moment a turn fails, before any
  async hook or retry sleep.
- Turn-end render containment: a formatter bug restores the cursor/prefix/
  dedup snapshot and never propagates into the primary's turn-end callback
  (per-advisor try/catch boundary in AgentSession).
- Quota pause: when host recovery declines a usage-limit failure, the
  runtime latches quotaExhausted, requeues the batch, and notifies —
  cleared only by an explicit reset.
- Hard halt after a permanent rejection or three backlog-drop cycles.
- #recoverAdvisorTurn also marks usage limits for structural errors thrown
  before any assistant turn is recorded.
2026-07-17 07:37:29 +02:00
DarkPhilosophy f4c81434d0 fix(advisor): never let a failing advisor stall or abort the primary agent
A broken advisor could hold the primary agent on the per-turn catch-up
gate for its full 30s budget while retrying, and an exception thrown from
onTurnEnd propagated into the primary's turn-end callback.

- waitForCatchup resolves immediately while the advisor is mid-failure
  (new #failing latch, set at the failure catch BEFORE any async hook,
  cleared on the next successful turn or reset/seed).
- Every parked waiter is woken the moment an advisor turn fails.
- The turn-end boundary isolates advisor exceptions per advisor: a
  throwing advisor loses its delta, the primary and sibling advisors
  continue untouched.
- A failed render (poisoned message, formatter bug) restores the delta
  cursor and dedup state, so the delta is re-rendered next turn instead
  of silently lost; the size probe itself is guarded and falls back to
  the deferred renderer.
2026-07-17 07:24:30 +03:00
roboomp 39c864034c fix(session): resumed stalled Cursor tool turns
Continued from completed Cursor exec-channel results instead of replaying side effects when the provider stream stalls.

Fixes #5790
2026-07-17 04:10:17 +00:00
can1357 2a6d551063 revert(status-line): restored single-row status bar with priority drop
- Reverted PR #5751 (issue #5749): continuation rows wrapped the editor
  top border onto extra lines, which is unacceptable for the input frame.
- EditorTopBorder is back to a single content/width pair; narrow widths
  drop right segments, shrink the path, then drop left segments.
2026-07-17 05:49:13 +02:00
roboomp 940f19d8c4 fix(browser): supported authenticated cmux tcp relays
Dialed loopback CMUX_SOCKET_PATH endpoints over TCP and completed the cmux relay HMAC challenge before sending JSON-RPC requests.

Loaded relay credentials from the session environment or the per-port cmux auth file while preserving Unix socket behavior.

Fixes #5788
2026-07-17 03:42:01 +00:00
can1357 adb2a3c7e2 style: formatted files from owner-approved merges 2026-07-17 05:33:19 +02:00
can1357 fcb368263b merge PR #5507 via eval/pr-5507: feat(telemetry): support full OTel — log and metric export 2026-07-17 05:32:51 +02:00
can1357 450bea6cc7 feat(coding-agent): disabled generate_image by default
Lands the intent of #5318 on the established generate_image.enabled
gate instead of introducing a parallel imagegen.enabled key; sessions
must opt in before the tool registers top-level or as an xd:// device.
2026-07-17 05:32:51 +02:00
can1357 e00eb7cfbc fix telemetry export signals 2026-07-17 05:29:46 +02:00