Commit Graph
9801 Commits
Author SHA1 Message Date
roboomp 777e5e0982 fix(advisor): applied configured fallback chains
- Switched advisor turns to the next configured model after provider quota or rate-limit failures.
- Emitted fallback applied and succeeded lifecycle events without reporting advisor unavailability after recovery.
- Added an end-to-end advisor quota fallback regression test.

Fixes #5740
2026-07-16 19:56:24 +00:00
roboomp c6e9763068 fix(lsp): returned null for missing configuration
Answered unconfigured workspace/configuration sections with the spec-required null value and covered the Roslyn post-initialization pull path.

Fixes #5745
2026-07-16 19:55:50 +00:00
roboomp d2aeaeced6 fix(tui): reinstated host stdin listeners removed during tool load
The host guard's stdin restore only dropped listeners a module added; a
module that removed a snapshot listener (e.g. a factory calling
process.stdin.removeAllListeners("data") when a subagent re-runs preloaded
factories against a live parent TUI) permanently stripped ProcessTerminal's
input handler. Reconcile each guarded event back to the pre-load snapshot:
when membership changed, removeAllListeners then re-add the snapshot in
order, restoring both additions dropped and removals reinstated. Snapshot
via rawListeners so once-wrapped handlers round-trip intact.

Fixes #5618
2026-07-16 19:48:08 +00:00
roboomp 1fea9b149f fix(tui): guarded stdin against custom-tool import hijack
Custom tool/extension/hook/plugin modules under ~/.claude/tools are
evaluated with live side effects during createAgentSession. A module that
attaches a stdin consumer at import time — an MCP StdioServerTransport
built at module top level, or a bare process.stdin.resume() — steals
Bun's single stdin reader, so the TUI receives exactly one data event and
goes permanently deaf after the first keypress. Under tmux the terminal's
automatic DA1 reply is that one event, so the first user keystroke is
already dead: the input-deafness reported in #5378/#5618.

Broadened the loader's withExitGuard (renamed withHostGuard) to also
snapshot and restore process.stdin around third-party module evaluation:
any data/readable/end/close/error listener the module adds is removed, and
the stream's paused and raw-mode state is restored to the pre-load
snapshot. The exit guard already fenced process.exit; stdin is the same
class of host-state hijack.

Fixes #5618
2026-07-16 19:35:43 +00:00
roboomp 447eb51f29 fix(session): persist /new boundary so autoResume does not resume pre-/new transcript
New-session persistence is lazy: after `/new`, the JSONL is not created
until assistant output exists. Exiting before any assistant message left
the per-terminal breadcrumb pointing at a not-yet-materialized file, which
`readTerminalBreadcrumbEntry` rejected (missing target), so `continueRecent`
fell back to `findMostRecentSession` and resurrected the pre-`/new` transcript.

`/new` now records a durable `fresh` breadcrumb boundary. The reader returns a
fresh breadcrumb even when its target is absent (with `exists:false`), and
`continueRecent` honors it by starting fresh instead of falling back. The crumb
is re-stamped non-fresh once the session materializes, so a genuinely
stale/deleted breadcrumb still falls back to the most-recent session. The
breadcrumb write is now synchronous so the fresh->materialized re-stamp cannot
reorder.

Fixes #5730
2026-07-16 18:01:14 +00:00
roboomp 4d0f9c1b66 fix(advisor): reconciled rewritten transcript prefixes
- Tracked delivered message identities alongside the numeric cursor.
- Re-primed advisor context when a live transcript prefix diverged.
- Covered accepted empty-stop pruning before the next real user turn.

Fixes #5731
2026-07-16 17:37:40 +00:00
roboomp 912dd44068 fix(write): guarded xd approval evaluation failures
Schema-invalid JSON objects can reach mounted approval functions before xdev dispatch validates their arguments. Fall back to the exec tier when an approval function throws, preserving fail-closed prompting and allowing dispatch to surface its normal schema error.

Added regression coverage for ast_edit payloads containing null paths.

Fixes #5727
2026-07-16 17:29:17 +00:00
roboomp 5445beb6f5 fix(write): evaluate function-valued xd:// device approvals
The write approval gate discarded a mounted tool's function-valued
approval and never decoded the device JSON payload, defaulting the tier
to exec. Read/write xd:// operations then prompted in non-yolo modes
that permit them.

Now decode valid object payloads and resolve the mounted tool's normal
approval decision via resolveToolTier; malformed JSON, non-object
payloads, and unknown devices still fall back to exec and prompt.

Fixes #5727
2026-07-16 17:24:22 +00:00
roboomp a9ef0c9fa4 fix(debug): bundled all same-day pid logs
Report bundles now concatenate every same-day omp.<date>.<pid>.log tail oldest-first, so a report from a later invocation still captures a crashed process's log after the shared-filename scheme was replaced with PID-qualified paths.

Fixes #5716
2026-07-16 15:07:42 +00:00
roboomp e518bc22c4 fix(coding-agent): stopped post-turn maintenance turns
- Prevented compaction from reopening a settled terminal answer unless queued work or an active goal remains.
- Ran auto-learn capture in an abortable detached agent with constrained tools and isolated provider state.
- Replaced primary-turn capture coverage with private-capture regression tests.

Fixes #5715
2026-07-16 14:55:27 +00:00
roboomp c543ee75ec fix(read): preserved workspace suffix precedence
Tried existing unique workspace suffix matches before recovering a missing cwd path from the active approved plan. Added regression coverage for the precedence rule.
2026-07-16 14:55:17 +00:00
roboomp e80bc9a0fb fix(tui): prevented space from submitting ask answers
Single-select Ask dialogs now require Enter before accepting the highlighted response, while multi-select dialogs retain Space toggling.

Fixes #5717
2026-07-16 14:50:11 +00:00
roboomp 7550bd887c fix(utils): isolated fatal logging teardown
Made fatal reporting bypass revoked stderr streams and armed a referenced forced-exit watchdog around bounded cleanup.

Separated rotating log and audit namespaces by PID and disabled compression pipelines so concurrent TUI processes cannot race shared rotation state.

Fixes #5716
2026-07-16 14:46:40 +00:00
roboomp b01cc405fd fix(read): recovered approved plan cwd aliases
Recovered the active local plan when a model rewrites its local URL as a missing same-basename cwd-root path. Real working-tree files retain precedence.

Fixes #5704
2026-07-16 14:46:36 +00:00
roboomp 92967e97a0 fix(tui): preserved plan review text selection
Decoupled fullscreen alternate-screen rendering from terminal mouse capture.

Disabled pointer tracking for Plan Review so terminals retain native selection.

Fixes #5711
2026-07-16 14:25:06 +00:00
roboomp 30953d3bfe fix(cli): errored on unknown __omp_worker_ selectors
Unknown reserved __omp_worker_* selectors hit the worker-host re-entry
seam, runWorkerEntrypoint returned false, and the ignored result let the
process exit 0 with empty stdout/stderr. A stale or mistyped selector
looked healthy to parent processes and install smoke paths.

Check runWorkerEntrypoint's return at the dispatch seam: an unrecognized
selector now writes "Error: unknown worker selector: <arg>" to stderr and
sets a nonzero exit code without starting a worker. Known selectors and
normal CLI arguments are unchanged.

Fixes #5712
2026-07-16 14:15:44 +00:00
roboomp eb149d1b0a fix(coding-agent/launch): handle EISDIR from realpath on drive roots
fs.realpath throws EISDIR on Windows drive roots (e.g. R:\), but
canonicalProjectDir in launch/presence.ts and launch/client.ts only
recovered ENOENT, aborting startup. Both now fall back to path.resolve()
on EISDIR, matching the existing ENOENT handling.

Fixes #5708
2026-07-16 13:55:22 +00:00
roboomp e509fc3cbc fix(mcp): escape Windows cmd shim command path too
Applied the same cmd.exe percent/quote neutralization to the resolved command token so a % in the shim path is not expanded before launch.

Fixes #5696
2026-07-16 13:49:14 +00:00
roboomp 0788933110 fix(mcp): escape Windows cmd shim args against injection
Building the cmd.exe /c command line and spawning with windowsVerbatimArguments so cmd.exe expansion cannot eat or inject on %VAR%, quote, and metacharacter args (BatBadBut / CVE-2024-24576).

Fixes #5696
2026-07-16 13:39:42 +00:00
roboomp 5fe9bb92d8 fix(tui): preserved organization suffixes in usage panel
Removed the 24-column cap from account cells so wide terminals can show full disambiguating labels.

Kept usage bars independently capped and added regression coverage for same-email organization accounts.

Fixes #5701
2026-07-16 13:25:20 +00:00
robomp-bot dfbf726eea fix(coding-agent): ring tmux for Warp attention events 2026-07-16 22:14:53 +09:00
robomp-bot 06f1f092a0 fix(coding-agent): mark TTSR and rewind continuations 2026-07-16 22:14:53 +09:00
roboomp 967befdf42 fix(mcp): corrected Windows cmd shim spawning
Passed batch commands and arguments separately to cmd.exe /c so cmd.exe no longer strips a wrapper quote into the command token.

Fixes #5696
2026-07-16 12:58:05 +00:00
robomp-bot 8a6017847b fix(coding-agent): mark session_stop continuations as willContinue 2026-07-16 20:35:01 +09:00
robomp-bot b7e21155cd fix(coding-agent): skip legacy completion notify under Warp protocol 2026-07-16 20:12:25 +09:00
roboomp dc372c67d6 fix(usage): org-qualified session marker for same-email accounts
The /usage show "in use by this session:" marker took only the bare
email from OAuthAccountIdentity, so two same-email Anthropic credentials
in different orgs were indistinguishable. Route the label through a
shared formatActiveAccountLabel that suffixes the active org, matching
the account list and login-success surfaces.

Fixes #5691
2026-07-16 11:09:05 +00:00
robomp-bot c972e44be8 fix(coding-agent): skip Warp stop when agent_end will continue 2026-07-16 20:00:45 +09:00
roboomp 385958ce6c fix(tui): deferred plan overlay hide past awaited title write
Moved #hidePlanReview from after the model restore to immediately before the synthetic execution dispatch, past the awaited sessionManager.setSessionName. Hiding earlier restored editor focus while the async title write was in flight, so operator keystrokes could submit a normal turn ahead of the approved execution turn and reorder it.

Fixes #5688
2026-07-16 10:52:21 +00:00
lycaon 9331b95eee style(session): satisfy xdev rewind checks 2026-07-16 04:49:05 -06:00
Kormákur 4a510a912f fix(mcp): match tool ownership by server name, not tool-name prefix
MCPManager evicted a server's tools by matching the raw mcp__<name>_
prefix against sanitized tool names. One server's sanitized name can
prefix another's (atlassian vs imported atlassian:atlassian), so every
reconnect of the shorter-named server dropped the sibling's tools and
re-announced them moments later, spamming paired xd:// unmount/mount
notices on each transport flap. Names containing sanitized characters
never prefix-matched at all, leaving stale tools registered after
disconnect. Replacement and removal now match mcpServerName.
2026-07-16 10:47:56 +00:00
roboomp 1824faf21e fix(advisor): recognized authorized cursor deletes
Cursor synthesizes an executed native delete as a tool call named delete. When write or edit enabled native deletion, the advisor quarantine allowlist still omitted that synthetic name and rolled back the completed turn.

Add delete to the allowlist from the same mutation-capability boolean that enables native deletion, with regression coverage for the quarantine path.

Fixes #5680
2026-07-16 10:46:42 +00:00
lycaon 2e5fe68d63 test(session): harden xdev rewind coverage 2026-07-16 04:45:37 -06:00
roboomp a59f04b507 fix(tui): closed plan review overlay before execution dispatch
The stale-buffer flicker fix (68f84d7c20, #5319) moved #hidePlanReview out of the picker's synchronous finish() into closePlanReview(), reached only after #approvePlan returns. #approvePlan awaits session.prompt of the synthetic plan-approved turn, which blocks for the whole run, so the fullscreen plan-review overlay stayed mounted while work proceeded underneath.

Hide the overlay inside #approvePlan after the async transcript rebuild (exitPlanMode/compaction, tool and model restore) completes but before the blocking dispatch. #hidePlanReview is idempotent, so the caller's trailing closePlanReview() stays a safe no-op, and #5319's stale-buffer guard is preserved.

Fixes #5688
2026-07-16 10:45:32 +00:00
robomp-bot f4eddab122 fix(coding-agent): emit Warp stop_failure for failed turns 2026-07-16 19:43:52 +09:00
roboomp 05af550d81 fix(cursor): gated native delete for read-only advisors
CursorExecHandlers.executeDelete removes files directly via fs.rmSync,
bypassing the tool map that every other exec handler consults. A background
advisor with the default read-only set (advise/read/grep/glob) could delete
workspace files from a Cursor deleteArgs frame despite holding no mutating
tool.

Add an allowNativeDelete option (default allowed, preserving the primary
agent's behavior) and set it for the advisor only when it was granted a
file-mutating tool (write/edit).

Fixes #5680
2026-07-16 10:37:25 +00:00
roboomp 0b709eff29 fix(cursor): wired advisor tools through the cursor exec bridge
The built-in advisor runs in its own Agent that was constructed without
cursorExecHandlers. On the Cursor provider every tool executes server-side
and is dispatched back through the client's exec handlers, so each advisor
tool call — including the MCP advise tool — came back toolNotFound and no
advice was ever routed. Same advisor worked on every other provider.

Build a Cursor exec bridge over each advisor's granted tool set and pass it
(plus a live cwd resolver) when constructing the advisor Agent, mirroring the
primary agent's bridge. The advisor-layer analog of #5650/#5651.

Fixes #5680
2026-07-16 10:25:16 +00:00
robomp-bot ca8a956a3a fix(coding-agent): align Warp events with session cwd and skill/error turns 2026-07-16 19:18:22 +09:00
robomp-bot b9d4c6d502 merge: sync feat/warp-cli-agent-events with upstream main 2026-07-16 19:01:06 +09:00
lycaon b26481bb7f fix(session): recognize xdev checkpoint and rewind results 2026-07-16 03:53:01 -06:00
Parsifa1 56379f9773 fix(tools): fix hub tools env selection
fix command failed when using non-POSIX shell
2026-07-16 09:46:57 +00:00
metaphorics ec666c7daa fix(coding-agent): bind Warp events to active prompts 2026-07-16 18:24:22 +09:00
black lodge resident 7011c2e929 fix: preserve oauth links across wrapped rows 2026-07-16 10:14:43 +02:00
roboomp d815a43895 fix(session): honored quiet startup for xdev notices
- Suppressed user-visible xd:// mount notices when startup.quiet is enabled.
- Preserved hidden model-facing mount delta steering.
- Added regression coverage for both behaviors.

Fixes #5670
2026-07-16 07:25:27 +00:00
roboomp e3b117678d fix(session): preserved provider session for titles
- Used the active provider session id for title credential selection.
- Covered explicit provider-session credential stickiness alongside disposal cancellation.
2026-07-16 07:25:06 +00:00
roboomp 3e38a5b514 fix(bash): drained piped output before timeout return
- Delayed reader cancellation so pipeline consumers can flush after producers are terminated.
- Kept the JavaScript watchdog behind bounded native timeout cleanup.
- Added native and executor regressions for timeout-time output draining.

Fixes #5316
2026-07-16 07:22:58 +00:00
roboomp 3cb9258875 fix(session): aborted title generation during dispose
- Routed automatic first-input and replan title requests through AgentSession lifecycle cancellation.
- Propagated disposal aborts to online provider and local tiny-model title generation.
- Added a regression test proving an in-flight title request settles when disposal begins.

Fixes #5666
2026-07-16 07:17:27 +00:00
roboomp 8a61515819 fix(extensions): isolated self-scheduled callbacks from killing the session
Extension-scheduled setInterval/setTimeout/detached callbacks ran outside
the handler-dispatch try/catch, so a throw surfaced as a process-level
uncaughtException and the global postmortem handler tore down the whole
session instead of isolating the misbehaving extension.

- Added ManagedTimers backing sanctioned ctx.setInterval/setTimeout/clearTimer:
  callbacks run with handler-dispatch isolation (throw/rejection logged and
  routed through onError), handles are unref'd, and all are cleared on
  session_shutdown.
- Wired the helpers into ExtensionRunner.createContext and the runner-less
  command-context fallback; onSession now inherits the runner context.
- Documented in-process no-isolation behavior and the managed timers in
  docs/extensions.md and docs/skills/authoring-extensions.md.

Fixes #5664
2026-07-16 07:17:10 +00:00
roboomp 8f15dbf106 fix(plugins): preserved commonjs sibling requires
- Added a graph-owned CommonJS evaluator with shared module.exports and cycle-aware caching.

- Covered sibling require interop across ESM-imported CommonJS modules.

Fixes #5658
2026-07-16 06:11:32 +00:00
roboomp 97649df208 fix(plan): reapply plan role model when reassigned mid-planning
In plan mode the active session model is the plan-role model, but
reassigning that role through the model hub only wrote settings and
never moved the live session onto the new model — planning continued on
the model plan mode was entered with until the next entry.

Subscribe InteractiveMode to onModelRolesChanged and, while plan mode is
active, re-resolve the plan role and switch onto it (deferring to the
next turn boundary when a turn is streaming). Extract the transition
decision into a pure resolvePlanModelTransition() helper with tests.

Fixes #5657
2026-07-16 06:04:18 +00:00
roboomp 2cf0c402f9 fix(plugins): refreshed commonjs helpers on reload
- Rebuilt synchronous CommonJS wrappers from current source for every legacy extension load.

- Added a same-process helper edit regression.

Fixes #5658
2026-07-16 05:53:19 +00:00