Commit Graph
9801 Commits
Author SHA1 Message Date
can1357 00e96db590 feat(coding-agent): throttled and constrained agent hud updates
- Added throttling and debouncing to HUD data rendering and observer UI synchronization to coalesce update bursts.
- Constrained the subagent HUD display to a maximum of 8 rows with a truncation notice for hidden sessions.
- Enhanced the session observer registry to categorize update types, enabling more granular UI reconciliation.
- Verified render coalescing and display truncation behavior with comprehensive integration tests using fake timers.
2026-07-06 07:38:08 +02:00
Mathews-Tom d975cd630e chore: merge upstream/main to resolve stale mergeability 2026-07-06 10:42:29 +05:30
Mathews-Tom fac997ae30 chore: merge upstream/main to resolve stale mergeability 2026-07-06 10:42:26 +05:30
roboomp 17080bef3c fix(agent): refreshed startup llama.cpp vision metadata
Refresh cached llama.cpp runtime metadata before exposing the initial session model so local vision defaults are not treated as text-only.

Fixes #4670
2026-07-06 04:03:00 +00:00
roboomp 5f44151903 fix(rpc): included context usage in session stats
Added contextUsage to SessionStats so get_session_stats mirrors the existing getContextUsage data used by state responses.

Fixes #4668
2026-07-06 03:16:13 +00:00
roboomp 4a65d2443d fix(tui): corrected skill card header spacing
Fixed skill card headers to render one visible space between the skill tag and skill name.

Fixes #4662
2026-07-06 02:37:50 +00:00
roboomp 06f6762103 fix(agent): surfaced pending irc replies to wait
Drained pending IRC asides before parking irc wait so replies that arrive between wait calls are returned instead of being treated only as queued interrupts.

Added regression coverage for the already-aborted queued-IRC signal path and documented the fix in the coding-agent changelog.

Fixes #4657
2026-07-06 02:36:35 +00:00
roboomp 3a962c54c7 fix(agent): reset IRC wake maintenance state
Reset per-turn maintenance counters before IRC wake prompts so yielded subagents do not carry stale yield termination into later wake turns.

Add regression coverage for empty-stop retry after an IRC wake following a yielded run.

Fixes #4658
2026-07-06 02:34:23 +00:00
can1357 617966c193 chore: update changelogs 2026-07-06 04:17:21 +02:00
can1357 6e95ace3a7 Merge remote-tracking branch 'origin/farm/8b99fd4b/enabled-skill-provider-fallback' 2026-07-06 04:16:54 +02:00
can1357 f75b9514f1 Merge remote-tracking branch 'origin/farm/21632629/fix-split-commit-lock-file-validation' 2026-07-06 04:16:21 +02:00
can1357 9be287516f Merge remote-tracking branch 'origin/farm/91f334f7/detect-local-vision-model' 2026-07-06 04:16:06 +02:00
can1357 79ca069d9c feat(coding-agent): supported streaming TTS for long text inputs
- Implemented streaming synthesis in the `say` command to allow processing of arbitrarily long text without hitting model phoneme limits.
- Added file input support via the `--file` flag and updated the CLI to prevent conflicting arguments.
- Refined `SpeakableStream` segmentation logic to prioritize valid sentence and clause breaks within the maximum segment length when processing large text buffers.
- Added comprehensive tests for stream segmentation behavior under long-form input.
2026-07-06 04:12:39 +02:00
roboomp 306bde3b7e fix(coding-agent): refreshed llama vision input metadata
- Propagated llama.cpp /props input modalities through selected-model runtime refresh.
- Added a regression test for cached text-only local vision models becoming image-capable after refresh.
- Updated the coding-agent changelog for the local vision detection fix.

Fixes #4654
2026-07-06 02:00:20 +00:00
Christian Stewart 1936d4f250 fix(prompting): refresh bash guidance on tool changes
Signed-off-by: Christian Stewart <christian@aperture.us>
2026-07-05 18:15:22 -07:00
roboomp 914dc9551a fix(coding-agent): kept claude home skills user-scoped
Skipped the home directory during Claude project skill walk-up so disabling Claude user skills cannot reload the same files as project skills.

Added regression coverage for the home-skill duplicate path with an enabled agents fallback.

Fixes #4648
2026-07-06 01:06:48 +00:00
Christian Stewart 96850a1642 fix(prompting): keep eval-disabled tool state coherent
Signed-off-by: Christian Stewart <christian@aperture.us>
2026-07-05 18:04:24 -07:00
roboomp dd3375981f fix(coding-agent): preserved enabled duplicate skills
Applied source toggles before skill-name dedup so disabled higher-priority providers no longer hide enabled lower-priority authored skills.

Added regression coverage for disabled claude versus enabled agents duplicate names and managed dead-last behavior.

Fixes #4648
2026-07-06 00:51:24 +00:00
Mathews-Tom 534bbc7751 fix(coding-agent): catch a regex friendlyName that normalizes to a discovered value
Codex P2 finding on commit 9632ed5: #friendlyNameCollidesWithSecret tested
a regex-entry friendlyName's RAW spelling directly against the pattern,
which can never match a label that is already normalized (uppercased,
separators stripped) even when that label IS the normalized rendering of
a value the regex actually discovers -- e.g. friendlyName: "TOKABC123"
for content: "tok_[a-z0-9]+" discovering literal tok_abc123. Nothing
compared the label against the actual matched value either. The check
now also compares the sanitized label against the sanitized value of the
secret currently being minted (reusing #prefixIsSecretShaped), catching
this on the secret's first mint before it's recorded as previously
discovered.
2026-07-06 06:21:01 +05:30
Mathews-Tom 9632ed504e fix(coding-agent): compare friendlyName collision against the untruncated label
Codex P2 finding on commit 9b2e14d: #friendlyNameCollidesWithSecret
compared a secret's full sanitized value against the already 32-char-capped
(sanitizeSecretFriendlyName) friendly name, so a secret whose sanitized
form exceeds MAX_FRIENDLY_NAME_LEN could never be fully contained in the
truncated label -- the collision went undetected and the secret's first
32 sanitized characters leaked as an accepted placeholder prefix. The
collision check now runs against the full, untruncated sanitized label
(sanitizeForCollisionCheck(friendlyName)); the 32-char cap is applied
only afterward, to the label actually used for display.
2026-07-06 06:06:06 +05:30
Christian Stewart 25c94fadba fix(prompting): match workflowz task schema
Signed-off-by: Christian Stewart <christian@aperture.us>
2026-07-05 17:34:17 -07:00
Christian Stewart 58a3259abf test(prompt): stabilize local-date regressions
Signed-off-by: Christian Stewart <christian@aperture.us>
2026-07-05 17:30:46 -07:00
Mathews-Tom 9b2e14d91d fix(coding-agent): normalize plain-secret alias checks, preserve raw friendlyName, guard deobfuscate against forged aliases
Codex P2 findings on commit 029e838:

- secrets/index.ts:189: loadFriendlyName pre-sanitized the friendlyName
  before storing it on the SecretEntry, silently defeating the raw-label
  regex collision check for every secrets.yml-loaded entry. The loader now
  preserves the original, unsanitized string (still validating it sanitizes
  to something non-empty).
- obfuscator.ts:1232: the forged-alias guard (isGeneratedPlaceholder)
  compared the dropped prefix against RAW plain-secret values, so a
  lowercase/punctuated secret's normalized rendering slipped through. Both
  the plain-secret-value and obfuscateMappings loops now normalize the
  compared value the same way the prefix is already constrained to.

Self-discovered while verifying the above: deobfuscate()'s bare-alias
fallback had NO prefix validation at all (unlike obfuscate()'s guard),
so a forged token wrapping any real placeholder's hash suffix in a
secret-shaped prefix would restore to that secret's raw value on the
live provider-output/tool-call-argument path -- strictly worse than the
obfuscate-direction leak. Extracted the shared check into
#prefixIsSecretShaped and reused it in a new #lookupLiveAlias gate for
deobfuscate(), verified a genuine friendly-name rename still round-trips.
2026-07-06 05:52:16 +05:30
Mathews-Tom 029e838bf0 fix(coding-agent): reject forged alias prefixes matching a regex pattern
Codex P2 finding on commit dff2a8d: #isGeneratedPlaceholder's forged-alias
guard only checked a dropped friendly-name prefix against exact previously-
discovered secret strings, recorded in whatever casing they first turned
up in. A case-insensitive (or other flag-variant) regex only ever records
the one casing it actually discovered, so a forged token wrapping a
differently-cased occurrence of that secret-shaped text around a real
bare-alias suffix matched neither exact-string check and sailed through
as an already-redacted placeholder, leaking the secret-shaped text
verbatim. The guard now also tests the dropped prefix directly against
every configured regex pattern.
2026-07-06 05:30:09 +05:30
Christian Stewart 92765fc409 fix(prompting): align workflow and bash guidance with active tools
Signed-off-by: Christian Stewart <christian@aperture.us>
2026-07-05 16:59:54 -07:00
Mathews-Tom dff2a8dc88 fix(coding-agent): check regex friendlyName collision against raw label
Codex P2 finding on commit 7d3a3a2: #friendlyNameCollidesWithSecret ran a
configured regex entry's pattern against the already-sanitized (uppercased,
separator-stripped) friendly name, so a case-sensitive/punctuated pattern
like tok_[a-z0-9]+ never matched the sanitized label even when the raw
friendlyName was itself a live match for that regex — letting a
secret-shaped label slip through and stamp into every placeholder minted
for it. The regex check now runs against the raw, pre-sanitization label,
matching how the regex would encounter that text verbatim.
2026-07-06 05:16:17 +05:30
Mathews-Tom 7d3a3a23a3 fix(coding-agent): reject unresolvable regex fallback and sanitize friendly-name collision check
Two Codex P2 findings on commit 732f725:

- A default (no custom replacement) mode: "replace" regex that cannot
  escape a 1-2 char match (e.g. ".", "[\\s\\S]", "[\\s\\S]{2}") had its
  key-derived same-length fallback marker returned without checking it
  against the matched value. Since that marker is drawn from an alphabet
  the regex has already proven to match exhaustively, a real 1-2 byte
  secret coinciding with it would ship unredacted. Such entries are now
  rejected: dropped with a warning when loaded from secrets.yml, dropped
  silently as a construction-time backstop otherwise.
- #friendlyNameCollidesWithSecret compared the sanitized (uppercased,
  alnum-only) friendly name against each secret's raw value, so a
  friendlyName that was a lowercase or punctuated variant of its own
  secret slipped through and stamped most of the secret into the
  placeholder. The secret value is now sanitized the same way before
  comparing.
2026-07-06 05:05:26 +05:30
Christian Stewart b765657f28 fix(prompting): hide eval guidance when disabled
Stop advertising eval in the default prompt and workflow notice when no eval
backend is enabled. Gate bash guidance on live eval backend availability and
cover the disabled-backend rendering contract.

Agent-Milestone: tooling: hide eval prompt guidance when eval backends are disabled

Signed-off-by: Christian Stewart <christian@aperture.us>
2026-07-05 16:04:15 -07:00
Christian Stewart 722a06abce fix(coding-agent): use local date in system prompt
Signed-off-by: Christian Stewart <christian@aperture.us>
2026-07-05 16:03:44 -07:00
Christian Stewart 78d4978c51 fix(bash): support disabled command deadlines
Treat timeout 0 as an explicit no-deadline contract across the bash tool, executor, async job, and PTY paths.

Signed-off-by: Christian Stewart <christian@aperture.us>
2026-07-05 16:03:37 -07:00
Mathews-Tom f386b0107c fix(coding-agent): gate completion notification on the same agent_end turn
sendErrorNotification now reads the settled turn from event.messages,
but sendCompletionNotification still read viewSession.getLastAssistantMessage().
For a classifier-refusal turn that stale/undefined lookup no longer
matched 'aborted'/'error', so with completion.notify=on the same
failed turn fired both the error toast and a misleading 'Complete'
toast.

Thread the same agent_end event into sendCompletionNotification so
both gates read one consistent source of truth.
2026-07-06 04:12:57 +05:30
Mathews-Tom 732f72510a fix(coding-agent): address secrets review feedback
- Fix #generateRegexReplacement's pathological (match-everything) fallback
  emitting a 1-2 byte matched value unchanged when it was exactly `Z`/`ZZ`,
  the shared sentinel #generateReplacement uses for such short values.
  Falls back to a same-length, key-derived run instead, which stays a fixed
  point under re-obfuscation without being a public, guessable constant.
- Default getSecretPlaceholderKey()/getExistingSecretPlaceholderKey() to
  getAgentDir() instead of getConfigRootDir(), matching the directory
  createAgentSession() actually passes.
- Isolate the getSecretPlaceholderKey test suite under a fresh $HOME/temp
  agent dir instead of the real homedir, fixing an EACCES failure in
  sandboxed review environments.
- Revert an unrelated gc session-ordering tie-breaker bundled into this
  branch's history; out of scope for the secrets/friendly-name feature.
- Relocate this PR's CHANGELOG.md entries out of already-released sections
  (16.3.0, 16.3.5) into [Unreleased], where a stale merge had left them,
  and drop a duplicate blank line and duplicate serverSideFallback/
  softRequestBudgetNotice entries the same merge introduced.
2026-07-06 04:12:54 +05:30
Mathews-Tom b1a7d53faa fix(coding-agent): drop unrelated test/source drift from this branch
This branch tracked main forward through many merge commits over its
long life; four files carried stale fixups for intermediate states of
main that current main never needed (a test-title rename, retimed
pi-native stream fixtures, a mermaid-cache type refactor, and a
multi-path test rewrite). None relate to error.notify, and current
upstream/main's own versions of these files already pass. Restore them
to keep this PR scoped to the error-notification feature.
2026-07-06 04:03:03 +05:30
Mathews-Tom 90527a5ae4 fix(coding-agent): read the settled turn from agent_end for error notifications
Classifier-refusal failures end a turn with stopReason === "error" but
get pruned from the active context (agent-session.ts's
#removeAssistantMessageFromActiveContext) before agent_end fires.
sendErrorNotification() read viewSession.getLastAssistantMessage(),
which reflects that mutated context and silently missed the
notification for exactly the turns it should fire on.

Thread the agent_end event through #handleAgentEnd -> #finishAgentEnd
so sendErrorNotification reads the turn's own outcome from
agent_end.messages instead.
2026-07-06 04:02:48 +05:30
Dylan Bohlender 54f0a00dd2 fix(oauth): copy-safe URL chunks and loopback-only launch URLs
Resolves the two Codex P2s raised on #4420 that merged unaddressed:

- wrapUrlRows indented every continuation chunk. A multi-row terminal
  selection includes the newline plus that indent; address bars strip
  newlines but preserve or percent-encode embedded spaces, so the
  reassembled URL was corrupted at every chunk boundary - silently,
  when the damage landed inside a query value. Chunk rows now carry
  zero leading bytes (label rows keep their indent), and the test
  reassembly helper concatenates chunks raw instead of stripping the
  indent that previously masked exactly this defect.

- #launchUrlIfSafe advertised a localhost /launch copy target for
  flows whose redirectUri never returns to the loopback server. Its
  catch-comment assumed custom-scheme URIs are non-parseable, but
  new URL('vscode://gitlab.gitlab-workflow/authentication') parses
  fine and sailed through the pathname check. The guard now requires
  an http(s) loopback redirectUri (localhost / 127.0.0.1 / [::1]);
  custom schemes, non-loopback hosts, and unparseable URIs all
  suppress the launch URL. Regression tests cover the GitLab Duo
  vscode:// shape and a fixed non-loopback HTTPS redirect.

Refs #4418
2026-07-05 16:01:30 -06:00
Dylan Bohlender 862f821d76 fix(open): report Windows opener failures via Start-Process exit codes
Follow-up to the #4420 opener hardening: absolute-path rundll32 fixes the
stripped-PATH spawn throw, but rundll32 exits 0 unconditionally, so the
delayed-failure telemetry added there can never observe a Windows launch
failure. Replace it with %SystemRoot%-resolved PowerShell Start-Process
via -EncodedCommand:

- failures ShellExecute itself reports (missing target, no handler
  executable, access denied) surface as exit code 1 and reach the
  existing non-zero-exit logging (verified live on Windows 11: missing
  file exits 1; unregistered schemes exit 0 on any opener because the
  OS hands them to the app-picker — documented limitation);
- the UTF-16LE/base64 payload keeps OAuth query strings opaque to
  cmd/PowerShell metacharacter parsing; embedded single quotes are
  doubled into a PS literal;
- %SystemRoot% anchoring with a bare-name PATH fallback preserves the
  stripped-PATH resilience from #4420.

Also pins the WSL-mount test's path.resolve against Windows dev hosts
so the mocked linux platform stays deterministic.

Refs #4418
2026-07-05 15:53:36 -06:00
Mathews-Tom 79d1658703 Merge remote-tracking branch 'upstream/main' into feat/secret-friendly-names 2026-07-06 03:03:55 +05:30
Mathews-Tom b95155423a Merge remote-tracking branch 'upstream/main' into feat/error-notify 2026-07-06 03:03:47 +05:30
roboomp d5d849f48c fix(commit): capture split-executor staged diff with binary contents
Without --binary, `git diff --cached` writes `Binary files ... differ` stubs
for staged binary files. runSplitCommit reset the index and then fed those
stubs to `git apply --cached --binary`, which cannot reconstruct the content,
so a split plan that included `bun.lockb` (or any other staged binary) would
crash the apply step after the reset had already cleared the index.

Pass `binary: true` when capturing `stagedDiff` so the patch text carries the
real binary payload and the executor can re-stage it per commit group.

Refs #4632, #4634 review
2026-07-05 21:32:40 +00:00
roboomp 7945c1e8eb fix(commit): pair staged lock files with the split-plan commit that owns them
git_overview hides EXCLUDED_LOCK_FILES from the model so lock files never drive
split decisions, but runSplitCommit then re-fetched the raw staged set and
rejected any plan that failed to enumerate them, aborting `omp commit` with
"Split commit plan missing staged files: <lockfile>". Skipping the validator
would have masked a real drop — the executor resets the index and only
re-stages files listed in each commit group.

Introduce packages/coding-agent/src/commit/agentic/lock-files.ts with a
LOCK_FILE_MANIFESTS map and an assignLockFilesToPlan helper that attaches each
orphaned lock file to (1) the commit group touching a sibling manifest in the
same directory, (2) any commit group touching a matching manifest, or (3) the
last commit group. git-overview.ts imports EXCLUDED_LOCK_FILES from the shared
module so the filter and the pairing table stay in sync.

Fixes #4632
2026-07-05 21:21:41 +00:00
roboomp a2e055fa9c fix(tools): closed two open literal-wins gaps flagged by codex
Two Codex bot findings from earlier PR reviews were still open.

1. local:// URL selector shadow (read.ts): the local:// branch resolved
   `local://foo:1-2` and rewrote readPath to `${localFile.path}:${sel}`,
   then let splitPathAndSelPreferringLiteral run on the synthesized
   string. A sibling literal `${localFile.path}:${sel}` file would win
   over the intended URL selector semantics. The branch now promotes the
   URL selector into the explicit-selector state and sets
   readPath = localFile.path, so downstream literal-preferring routing
   never re-splits the concatenation.

2. Delimited expansion before literal probe (path-utils.ts): grep called
   expandDelimitedPathEntries before parsePathSpecs, and
   splitDelimitedPathEntry only checked whether the peeled base of the
   entry resolved. A real POSIX file whose name contained a delimiter
   plus a selector-shaped tail (a;b:1-2) got split into ["a", "b:1-2"]
   and never reached the literal-preferring probe. splitDelimitedPathEntry
   now short-circuits on probeLiteralPathExists — "missing" is the only
   outcome that lets delimiter expansion run.

Added regressions: `read local://notes.md:1-2` still slices the base file
when a sibling `notes.md:1-2` literal exists, and grep searches a real
`a;b:1-2` file without semicolon-splitting.
2026-07-05 19:24:21 +00:00
roboomp b2f7238a03 fix(coding-agent): allowed mixed fallback chains
- Allowed implicit default fallback resolution when other role fallback chains are configured.
- Covered the mixed-role first-run fallback case.

Fixes #4533
2026-07-05 19:21:08 +00:00
roboomp b0a84847b7 fix(agent): emitted handoff session switch hook
Fixes #4434
2026-07-05 19:19:02 +00:00
Insodimensionandinsodimension 22d949b022 feat(coding-agent): generate_image per-request provider + Codex-subscription images
The generate_image tool gains an optional 'provider' param
(auto|openai|openai-codex|antigravity|xai|gemini|openrouter): say the
provider in chat and the tool uses it for that call; absent, it falls back
to the providers.image setting, then auto-detect. openai-codex now works
INDEPENDENT of the active chat model: a connected Codex (ChatGPT OAuth)
subscription drives OpenAI's hosted image_generation tool (model priority
gpt-5.5 -> gpt-5.4 -> gpt-5.1 -> gpt-5 -> gpt-5-codex), so images ride the
subscription instead of the metered API key. providers.image accepts
openai-codex. (Recovered from parked lane dbf87cd04; oauth.html rebrand
left parked.)
2026-07-06 00:46:01 +05:30
roboomp 6c8e7625a2 fix(tools): tightened literal-path probe against stat ambiguity
resolveExistingReadPath treated any stat failure other than ENOENT/ENOTDIR as
"exists" and any other resolved path was considered a hit. That silently
reinterpreted a real literal path such as test:1-2 as test plus selector 1-2
whenever the raw path was a dangling symlink, sat under an unreadable parent,
or hit a transient I/O error.

The new probeLiteralPathExists returns "exists" / "missing" / "unknown" from
an lstat probe. splitPathAndSelPreferringLiteral now falls back to the strict
selector split only on "missing"; both "exists" and "unknown" keep the raw
path, so an unreachable literal is never reinterpreted. Grep and read use
the same probe: the explicit selector branch keeps the literal path when
existence is uncertain, and only a definitive ENOENT/ENOTDIR lets structured
archive/sqlite/pdf dispatch take over.

Added regressions covering probeLiteralPathExists exists/missing/dangling-
symlink cases and splitPathAndSelPreferringLiteral over a dangling symlink.
2026-07-05 18:17:59 +00:00
roboomp ff3b0c795c fix(tools): added explicit selector fields for read and grep
The literal-path stat fallback made selector-shaped filenames accessible, but it did not give callers a deterministic way to read or grep a range from a literal filename such as test:1-2. Encoding that as test:1-2:1-2 remained recursively ambiguous if a longer literal file later appeared.

Read now accepts an optional selector field that is parsed independently from path. When selector is present, path is treated as the exact path first, so { path: "test:1-2", selector: "1-2" } always means lines 1-2 from the literal file test:1-2. Inline :<sel> remains supported for compatibility.

Grep now accepts an optional line-range selector field with the same literal-path behavior. Explicit selectors bypass path suffix peeling, while archive/internal/URL routing still handles non-literal structured paths.

Updated read/grep tool prompts and added deterministic regressions proving that a longer literal file like test:1-2:5-6 or test:1-2:2-2 does not change the meaning of { path: "test:1-2", selector: ... }.
2026-07-05 18:09:29 +00:00
roboomp c493d12f95 fix(tools): preserved escaped literal selector-shaped paths
splitPathAndSelPreferringLiteral only statted resolveToCwd(rawPath), so shell-escaped paths such as dir/a\ b:1-2 missed the existing dir/a b:1-2 file and fell back to the strict selector peel. That let read target dir/a\ b with a range instead of the literal filename.

The helper now probes resolveReadPath(rawPath, cwd), reusing the read path resolver's existing escaped-space and filesystem variant normalization before deciding whether the literal file exists.

Grep also stores the resolved filesystem path for literal matches so the later search-scope parser does not reinterpret backslashes as path separators. Regression coverage now includes helper, read, and grep cases for dir/a\ b:1-2.
2026-07-05 17:47:06 +00:00
roboomp c40b0ff5da fix(tools): skipped grep archive materialization for literal filesystem matches
parsePathSpecs preserved an existing literal path like data.zip:1-2, but resolveArchiveSearchPaths only received the cleaned path strings and reparsed the same literal as archive data.zip plus member 1-2. If data.zip existed, grep materialized or errored on the archive member before searching the literal file.

GrepPathSpec now carries whether a local entry was kept because the raw filesystem path exists. Archive materialization consumes the specs instead of bare strings and skips those literal matches, while ordinary archive selectors still materialize as before.

Regression coverage adds grep over data.zip:1-2 with a real data.zip alongside, proving the literal file is searched instead of the archive member.
2026-07-05 17:38:20 +00:00
roboomp 48a6e46750 fix(tools): hoisted literal-preferring split ahead of archive/sqlite/pdf dispatch in read
The prior hunk placed the literal-preferring split after resolveArchiveReadPath,
resolveSqliteReadPath, and splitPdfImageMemberReadPath, so a real POSIX file
such as data.zip:1-2 or notes.db:1-2 still got hijacked: the archive/sqlite
resolvers matched the base extension, opened data.zip / notes.db, and errored
on the phantom :1-2 member before the literal file was ever considered.

Now the async splitter runs first. When the strict grammar would have peeled
a suffix but the literal path stats successfully, all three structured
dispatchers decline. Otherwise the ordering is unchanged, so archive/sqlite/
pdf-image reads keep working when the literal file does not exist.

Regression coverage adds `data.zip:1-2` and `notes.db:1-2` cases where the
base archive/sqlite file also exists on disk, exercising the exact ordering
bug the reviewer flagged.
2026-07-05 17:33:21 +00:00
roboomp c8df93ca31 fix(tools): preferred literal filesystem match over trailing :selector peel for read and grep
splitPathAndSel unconditionally peels a trailing :<sel> chunk whenever it
matches the read-tool selector grammar (raw, conflicts, N-M, N+K, ...). On
POSIX, filenames may legitimately contain colons, so a real file named
test:1-2 or log:raw was shredded to test/log before either read.ts or
grep.parsePathSpecs stated anything and both surfaced "Path not found".

Added splitPathAndSelPreferringLiteral(rawPath, cwd) alongside the strict
splitter: it only overrides the peel when fs.stat succeeds against the raw
path. Read (execute) and grep (parsePathSpecs) call the async variant for
non-URL paths; internal-URL splitting stays unchanged. Regression covers
splitter fallbacks, read/grep behavior on literal-colon files, and that
:1-2 selectors still work when the base file is the only real match.

Fixes #4618
2026-07-05 17:23:12 +00:00