Commit Graph
9801 Commits
Author SHA1 Message Date
roboomp f3fda5139d fix(session): fence flushSync during session moves
A fenced append followed by a Ctrl+C flushSync in the post-rename, pre-repoint window rewrote the full body to the old path, recreating the orphan. Sync rewrites now defer while the session file is relocating.

Fixes #7270
2026-08-01 13:47:58 +00:00
roboomp ea265df009 fix(session): fenced appends during session moves
Prevented synchronous session appends from reopening the vacated source path while moveTo relocates and repoints the journal.

Fixes #7270
2026-08-01 13:39:51 +00:00
roboomp 55115f4bfd fix(coding-agent): refresh advisor context prompt on reload
Rebuilt advisor runtimes with the rediscovered context files so advisor turns stop evaluating against stale AGENTS.md instructions after /reload-plugins.

Fixes #7258
2026-08-01 11:46:55 +00:00
roboomp 08c80f7da0 fix(coding-agent): scope context rediscovery to session settings
Threaded the session's disabledExtensions into context-file rediscovery so a concurrently-created session's global settings cannot toggle another session's context entries.

Fixes #7258
2026-08-01 11:36:34 +00:00
roboomp 2b268b4d2c fix(coding-agent): refreshed context files on plugin reload
Rediscovered context files from the active session cwd whenever plugin prompt sources refresh, while preserving explicitly preloaded SDK context.

Covered edited and disabled context files in the current system prompt.

Fixes #7258
2026-08-01 11:27:03 +00:00
Kenneth Hoff c3a72e026e fix(memory): mirror off-backend message in ACP /memory stats|diagnose
The TUI's CommandController special-cased backend.id === "off" for
/memory stats|diagnose, but the ACP/RPC slash-command handler in
builtin-registry.ts still fell back to the generic "not available for
the off backend" template — non-TUI users with memory.backend=off saw
the self-contradictory wording this PR was meant to remove.

Extract the shared fallback into memoryStatsUnavailableMessage()
(memory-backend/messages.ts) and use it from both CommandController
and the ACP builtin-registry handler, so the two surfaces can't drift
again.

Addresses review comment:
https://github.com/can1357/oh-my-pi/pull/7251#discussion_r3695383090
2026-08-01 12:12:57 +02:00
Kenneth Hoff 7d0b8cf8dc fix(memory): clarify /memory stats and /memory diagnose message when memory is off
/memory stats and /memory diagnose fall back to a generic
'Memory <action> is not available for the <backend.id> backend.'
message whenever the active backend's stats/diagnose hook is
undefined. For every real backend (hindsight, mnemopi, local) this
reads fine, but the off backend isn't a backend a user picked among
several stats-capable options - it's the no-op state memory falls
back to by default - so the same template renders as 'Memory stats
is not available for the off backend.', which reads as an odd,
almost self-contradictory warning.

Special-case backend.id === "off" with wording that matches the
phrasing offBackend.status() already uses elsewhere ('Memory backend
is off.'), and add a unit test covering both the off-backend wording
and the unchanged generic fallback for a real backend (local) that
simply has no stats hook.

The regression test only asserts on a mocked showWarning call and
never renders Markdown, so it doesn't need a real theme instance;
drop the global dark-theme setup/teardown to avoid leaving the
process-wide theme singleton mutated for later suites in the same
Bun process.
2026-08-01 11:58:50 +02:00
roboomp 52a0af8625 fix(coding-agent): blocked stale revivals after hard kill
A parked revive holds the same AgentRef while constructing a new session.
If the Hub tombstoned that ref before revive completed, the reviver could
still attach its session and set the terminal ref back to idle because
identity alone remained unchanged.

- Made aborted registry refs terminal: reject revival claims, late session
  attachment, and status transitions out of aborted.
- Made lifecycle revival accept only an untouched detached parked ref or the
  exact running session already claimed by createAgentSession; dispose and
  reject every terminal/stale result.
- Added a delayed-revival regression test and claim-before-kill CAS checks.

Fixes #7250
2026-08-01 09:52:09 +00:00
roboomp 57732e9dcd fix(coding-agent): detach hard-aborted refs so ensureLive can't route into a dead session
Preserving aborted refs on dispose exposed a latent invariant break: the
executor's hard-abort path (finalizeSubagentLifecycle) set status `aborted`
and disposed the session without detaching it. With the ref now retained, it
kept a dangling pointer to the disposed session, and ensureLive returns any
non-null ref.session before its revivability check — so hub focus / transcript
chat could route into a dead session.

- finalizeSubagentLifecycle: detach the session before disposing on the
  terminal hard-abort path, upholding the AgentRef invariant (session === null
  when aborted).
- release(tombstone): detach before dispose too (capture the live session
  first), same invariant.
- unregisterUnlessParked: preserve `aborted` refs only when already detached;
  an aborted ref still holding a live session is a bug and is unregistered
  rather than kept reachable.
- Regression test now asserts ensureLive rejects a tombstoned id as terminal.

Fixes #7250
2026-08-01 09:42:41 +00:00
roboomp d350dd8f84 fix(coding-agent): preserve aborted tombstone across live-session dispose
A live-session hub kill did not stick: release(tombstone) awaited the
wrapped session dispose first, and createAgentSession's unregisterUnlessParked
removed any non-parked ref, so the subsequent detach/setStatus no-oped and the
ref was gone — leaving the reopen resurrection for idle/running agents.

- release(tombstone) now marks the ref `aborted` BEFORE disposing, so the
  dispose guard preserves it; the session is detached afterward.
- unregisterUnlessParked now also spares terminal `aborted` refs (matching
  the documented "hard-killed, terminal" retention and finalizeSubagentLifecycle).
- Regression test now uses a session stub that mirrors the real wrapped
  dispose (unregister unless parked/aborted), so it fails if the tombstone is
  set after dispose.

Fixes #7250
2026-08-01 09:34:43 +00:00
Anatoli Tsinovoy e5541a577a fix(ai): address Bedrock Mantle review feedback 2026-08-01 12:29:07 +03:00
roboomp 65fd8cb0e8 fix(coding-agent): keep hub-killed subagent from resurrecting as parked
The Agent Hub kill path called AgentLifecycleManager.release(), which
disposes the session and then unregisters the ref while leaving the
on-disk <id>.jsonl intact. On the next hub open, registerPersistedSubagents
rescans the transcript tree and its `if (!registry.get(id))` guard cannot
distinguish an explicit kill from a normally-parked agent, so it re-adopts
the killed id as a fresh `parked` row.

Add a `tombstone` option to release() that mirrors finalizeSubagentLifecycle's
genuine-kill path: dispose and detach the session but keep the ref registered
as terminal `aborted` instead of removing it. The kept-registered id makes the
rescan guard skip it, and the transcript stays on disk (still reachable via
history://<id>, per #5261). The hub kill button now passes tombstone: true.

Fixes #7250
2026-08-01 09:26:26 +00:00
zhang17-24 1596d9231e fix(coding-agent): let customDirectories skills win over default-path duplicates
When a skill name exists both in a default discovery path (e.g.
~/.claude/skills/<name>) and in an explicitly configured
skills.customDirectories entry, the default-path copy loaded first and the
custom-directory skill was silently dropped on the name collision. As a
result skill://<name> resolved to the default path and reported "File not
found" when the user's skill lived only in the custom directory.

Custom-directory skills now override same-named default-path skills (the
user's explicit configuration is the higher-priority source); duplicates
within customDirectories keep first-wins.
2026-08-01 16:05:31 +08:00
Parsifa1 ea437745a3 fix(xdg): move secret-placeholder.key, marketplaces.json, and run/ out of config root
These four paths bypassed DirResolver's XDG-aware rootSubdir/agentSubdir
hooks, resolving directly against getConfigRootDir()/getAgentDir() and
ignoring XDG state/data layout. Add XDG-aware path helpers in dirs.ts
and route all four through them:

- secret-placeholder.key → $XDG_STATE_HOME/omp/ (state, agent flattened)
- marketplaces.json      → $XDG_DATA_HOME/omp/  (data)
- run/daemons/<hash>/    → $XDG_STATE_HOME/omp/run/ (state)
- run/provider-inflight/ → $XDG_STATE_HOME/omp/run/ (state)

omp config init-xdg migrates secret-placeholder.key and marketplaces.json
from their legacy locations; run/ is ephemeral and rebuilds on restart.
2026-08-01 06:40:48 +00:00
can1357 f94c8809e5 Merge remote-tracking branch 'origin/farm/101aa6fd/codex-search-preserve-sse-error' 2026-08-01 08:33:48 +02:00
can1357 126c3804e3 Merge remote-tracking branch 'origin/farm/41d773e1/ask-dialog-question-undefined-crash' 2026-08-01 08:33:30 +02:00
can1357 03f5eb7acf Merge remote-tracking branch 'origin/farm/c5198f90/fix-effective-prompt-cache-key' 2026-08-01 08:33:25 +02:00
can1357 2b8546faa0 Merge remote-tracking branch 'origin/farm/8f2adac9/bash-auto-background-clearable-timer' 2026-08-01 08:33:11 +02:00
can1357 ad78b6a84e feat(coding-agent/tools): implemented shared browser daemon management
- Added `ensureSharedBrowser` and shared browser acquisition to manage project-shared broker-owned Chromium instances.
- Implemented concurrent duplicate daemon start prevention and single-flight `pendingOpens` deduplication.
- Updated browser handle disposal to disconnect from shared daemons rather than closing them.
- Updated browser documentation and launch specifications to support shared and local headless runs.
2026-08-01 08:30:05 +02:00
pi3123 4a9350963f Hoist interactive-host flag above settings load; add changelog entries
Settings.init opens agent.db/stats.db before setInteractiveHost ran, so
interactive hosts received the 1000ms headless busy timeout on those
databases (issue #2421 class). Declare the flag before settings load and
add [Unreleased] changelog entries per repo conventions.
2026-07-31 23:27:15 -07:00
roboomp fe4e553be3 fix(coding-agent): clear bash auto-background threshold timer
waitForManagedBashJob raced job completion against a bare
Bun.sleep(thresholdMs), which cannot be cancelled. When completion,
abort, or steering won the race, the losing Bun.sleep timer stayed
scheduled and ref'd, keeping Bun's event loop alive until the threshold
expired — delaying SDK/headless shutdown and accumulating timers under
fast command rates.

Replace the Bun.sleep with a Promise.withResolvers settled by a
cancellable setTimeout, and route every outcome (including the former
no-signal early return) through one try/finally that clears the timer
and removes the abort/steer listeners.

Add a child-process regression test that runs the real auto-background
path for a fast command against a 30s threshold and asserts the process
exits promptly instead of being held for the full threshold.

Fixes #7235
2026-08-01 05:14:43 +00:00
roboomp 838d120249 fix(coding-agent): reused effective prompt cache key
- Reused the agent's explicit or inherited cache identity for ephemeral side turns.
- Forwarded the same effective key through manual and automatic native compaction.
- Added regression coverage for all three secondary request paths.

Fixes #7218
2026-08-01 03:44:59 +00:00
pi3123 edb3feda9b Bound synchronous SQLite busy-waits in headless hosts
Headless hosts (print/RPC/ACP/eval/SDK) run the agent loop on the same
thread as bun:sqlite, so a lock-contention busy-wait of the interactive
5s timeout freezes the protocol loop for seconds at a time with no
liveness signal. Use a 1s busy_timeout for session-critical databases
(agent.db, history.db, stats.db) when the host is not interactive, and
let the existing asynchronous open/retry paths recover from contention.
2026-07-31 19:59:48 -07:00
Brent dc4d15e59d fix(cli): centralize command help metadata 2026-08-01 00:29:57 +00:00
roboomp 8a059e3027 fix(coding-agent): normalize ask dialog questions to prevent render crash
The live AskDialog trusted question.question while its render helpers
(replaceTabs, renderQuestionTitle, questionTabLabel) assume a string. A
question reaching AskDialogComponent without a string question field threw
an uncaught TypeError that escaped the TUI render loop and killed the
session. The transcript renderer already normalizes the same malformed
data via normalizeRenderQuestions; the live path did not.

Normalize the questions array at dialog entry (new normalizeDialogQuestions),
coercing question/id/label to strings and options to a well-formed array,
matching the transcript path.

Fixes #7211
2026-08-01 00:11:21 +00:00
Brent c8871419e2 fix(cli): statically link help environment setup 2026-07-31 22:49:04 +00:00
Brent a572fcb9be fix(cli): preserve help metadata contracts 2026-07-31 22:01:19 +00:00
Brent 9df3067930 perf(cli): keep root help off runtime graph 2026-07-31 21:28:41 +00:00
roboomp af343f70d0 fix(agent): distinguished started steering aborts
Track entry into tool.execute separately from tool event emission. Never-started skips retain SyntheticToolResultDetails with executed:false; in-flight aborts now use distinct interrupted metadata with execution:started so consumers do not assume no partial work occurred.

Keep both interrupt states neutral in the TUI and cover the agent metadata boundary plus rendering behavior.

Fixes #7199
2026-07-31 21:16:28 +00:00
roboomp ebd84d4f85 fix(tui): render mid-turn steering skips as info, not errors
A tool call aborted mid-batch to service queued steering/peer input emits a synthetic placeholder result with isError:true so the model retries it. The TUI keyed all error styling (red ✘, red frame/text) off that flag, so a normal steering skip rendered identically to a real tool failure.

Mark the skip placeholder with the existing SyntheticToolResultDetails discriminator (source: "interrupt_skipped", executed:false) and render benign skips through the neutral generic card (info glyph, dim text, neutral background), bypassing any bespoke error frame. Genuine failures keep their error styling.

Fixes #7199
2026-07-31 21:06:07 +00:00
roboomp 5283c4c99b fix(agent): routed codex v2 compaction through websockets
- Reused the live Codex provider session for WebSocket-first V2 compaction.
- Fell back to SSE V2 on WebSocket transport failure before the existing V1 fallback.
- Propagated the configured WebSocket preference through manual, automatic, and advisor compaction paths.
- Added transport reuse and fallback regression coverage.

Fixes #7198
2026-07-31 21:00:15 +00:00
roboomp d4cb024b57 fix(coding-agent): preserve codex web search backend error diagnostics
The Codex SSE `type:"error"` branch read only top-level `code`/`message`,
so backend rejections emitted under a nested `error` or `response.error`
object collapsed to `Codex error (): Unknown error`, hiding the cause
(e.g. a regional/model-snapshot rejection). `response.failed` similarly
dropped the error code.

Add a shared `extractCodexSseError` that reads top-level, nested `error`,
and `response.error` envelopes, and wire both error paths through it so
the backend code and message survive in `SearchProviderError`. The
existing `web_search_call` requirement is untouched.

Fixes #7200
2026-07-31 20:56:54 +00:00
Will e68266405f fix(coding-agent): cap web search timeout 2026-07-31 16:53:39 -04:00
Will e3f66975e9 fix(coding-agent): omit unsupported search temperature 2026-07-31 16:38:02 -04:00
Will 30087124dc feat(coding-agent): configure web search timeout 2026-07-31 16:37:22 -04:00
Jérémy Marchand 4476940a4a docs(mcp): document requestIdFormat as OMP-specific
The option only exists in OMP's own config format, so the OMP-owned discovery
providers are the only ones that parse it. Say so in the schema description, the
MCPServerConfigBase doc, and the changelog, and name the config paths where
setting it actually takes effect, so nobody expects a server imported from
another tool's config to honor it.
2026-07-31 21:04:02 +02:00
Jérémy Marchand c676bbb81b fix(mcp): honor requestIdFormat in OMP plugin MCP configs
OMP plugins ship their own .mcp.json, and that provider whitelists fields into
the canonical MCPServer shape the same way the other loaders do, so a plugin
bundling an integer-only server could set requestIdFormat and still have it
dropped before it reached a transport.

Extract the value parsing into parseRequestIdFormat() next to parseBoolean() in
discovery/helpers.ts and use it from all three OMP-owned loaders (native,
standalone mcp.json, omp-plugins), replacing the two hand-rolled copies.

Vendor providers (claude, claude-plugins, cursor, vscode, gemini, opencode,
windsurf) are deliberately untouched: they translate another tool's own server
list, where an OMP-specific key has no meaning.
2026-07-31 21:03:06 +02:00
Jérémy Marchand 0a1b8e35b8 fix(mcp): include requestIdFormat in connection-equivalence dedup
Discovery collapses differently-named MCP entries that point at the same
command/args/env/cwd (or url/headers) into one connection, keeping whichever
loaded first and dropping the rest as aliases. requestIdFormat changes the bytes
sent on the wire, same as auth/oauth which the comparator already covers, so a
higher-priority alias lacking the field could shadow a lower-priority entry that
set it, silently falling back to string ids for a server that needs numbers.

Add requestIdFormat to isSameMCPConnection, normalized against its own default so
an explicit "string" is not treated as a different connection than leaving it
unset. timeout stays excluded, since it is a client-side knob that never touches
the wire.
2026-07-31 21:03:06 +02:00
Jérémy Marchand 3cb6e5df9c fix(mcp): carry requestIdFormat through MCP config discovery
The option was only present on the transport-facing `MCPServerConfig`, so a
value written in `.omp/mcp.json` or a standalone `.mcp.json` never reached the
transports: discovery normalizes config into the canonical `MCPServer` shape and
`convertToLegacyConfig()` rebuilds the transport config from it, and neither step
knew about the field. Setting `"number"` in the documented config path silently
kept the snowflake-string default, which is the hang the option exists to avoid.

Wire it through the same four places `timeout` already uses: the canonical
`MCPServer` shape, the two OMP-native loaders (with validate-and-warn on an
unrecognized value), and the legacy conversion. Foreign-format providers are
untouched, since the key is OMP-specific.

Also point the `MCPServerConfigBase` doc comment at `RequestIdAllocator` rather
than a helper name that never existed.
2026-07-31 21:03:06 +02:00
Jérémy Marchand 8560188314 feat(mcp): let a server opt into integer JSON-RPC request ids
Apple's `xcrun mcpbridge` decodes JSON-RPC `id` as an integer only. OMP
mints collision-resistant snowflake strings, so the bridge logs
`mcpbridge.DecodeError Code=1`, never replies, and every request hangs
until it times out (#7053). JSON-RPC 2.0 permits String and Number ids
equally, so both shapes are legal and the string default stays.

Add `requestIdFormat: "string" | "number"` to the shared server config
and honor it in all three transports through one allocator. The string
default is unchanged, so this is inert unless a server opts in.

Verified against Xcode 26.3's bridge: with `"number"`, `initialize`
succeeds and `tools/list` returns all 21 tools; with the default, the
same request times out.
2026-07-31 21:03:05 +02:00
can1357 b3e0bde7b7 refactor(coding-agent): adjusted block resolution formatting and update tests
- Update hashline block resolution formatting to correctly incorporate anchor lines within operation labels.
- Fix and update test assertions and mock contexts across coding agent tests.
2026-07-31 20:55:37 +02:00
can1357 06649b7407 feat(coding-agent): rewrote codex saved-reset trigger algorithm
- Replaced the reactive weekly-only auto-redeem predicate with a pool-wide
  planner: an expiry-salvage sweep piggybacks on the 5-minute usage
  heartbeat and spends any account's reset that would otherwise expire
  within codexResets.salvageHorizonHours, and the blocked-turn path scans
  all stored accounts with eligibility built from the exact exhausted
  5h/weekly windows (openai/codex#28525), unblocking at the latest reset
  among them.
- Made the live 429's parsed unblock timestamp authoritative for the
  active account (pre-block snapshots survive cache invalidation via
  in-flight adoption and last-good fallback), synthesizing the candidate
  when no usable report exists, and overlaying live credit counts from
  the dedicated credits route since a stale /wham/usage zero is never
  corrected upstream.
- Treated nothing_to_reset, credit_list_failed, and thrown consumes as
  non-terminal: the episode key is released and deferred 30 minutes
  instead of burying a banked credit; redeemResetCredit now spends the
  soonest-expiring credit.
- Added planner unit fixtures plus integration regressions driving the
  real triggers end to end, with an injectable per-session coordinator
  seam and a sweep settlement handle.
2026-07-31 20:39:12 +02:00
can1357 f76ce86966 Merge PR #6840: feat(extensions): add ctx.invokeTool for native built-in delegation (@psyrendust) 2026-07-31 20:17:32 +02:00
can1357 4d45e8154a fix(eval): consulted starting sessions when scoping kernel resets
- resolveOwnerScopedSessionKey's getOwners in the Python and JS executors
  only read live sessions, so a subagent reset issued while the shared
  kernel was still starting resolved to the base key, awaited the
  parent's startup, and shut its brand-new kernel down.
- Python and JS starting sessions are now owner-bearing records like
  Ruby/Julia's: owners attach synchronously before startup resolves,
  getOwners and per-owner disposal consult them, and the final
  sessions.set is identity-guarded so a disposed starting record cannot
  resurrect its kernel.
- Regression: deferred PythonKernel.start proves a concurrent subagent
  reset forks immediately and never reaps the parent's starting kernel
  (fails with the previous getOwners).
2026-07-31 20:15:07 +02:00
can1357 ccc9b900cf fix(eval): forked subagent kernel resets away from shared sessions
- Subagents inherit the parent's eval session id, so a child's
  reset: true destroyed the co-owned kernel and every sibling's
  interpreter state mid-session.
- resolveOwnerScopedSessionKey now routes a reset from a non-exclusive
  owner onto a deterministic per-owner fork key: the requester gets a
  fresh private kernel, co-owners keep the shared one, and the fork
  stays sticky for that owner until its teardown reaps it.
- Applied across Python, JavaScript, Ruby, and Julia executors; JS
  contexts gained an owner registry plus disposeVmContextsByOwner,
  wired into EvalRunner.disposeKernels and SDK session teardown.
- Covered by pure key-resolution contracts and an end-to-end JS test:
  co-owner reset forks, shared state survives, fork is sticky, and
  per-owner dispose reaps only the fork.
2026-07-31 20:13:23 +02:00
can1357 a6c6257574 chore: applied formatter and deduplicated observer stubs in task fixtures 2026-07-31 19:51:52 +02:00
can1357 63d6bd3064 Merge PR #7060: fix(browser): own headless Chromium profile dir to survive Windows EBUSY cleanup (@roboomp) 2026-07-31 19:42:43 +02:00
can1357 a91fa13116 Merge PR #7055: fix(tui): preserve literal code block rows (@GratefulDave) 2026-07-31 19:42:43 +02:00
can1357 f46af54f9c fix(browser): preserve screenshot correctness when attached 2026-07-31 19:42:42 +02:00
can1357 ce1ec2103f Merge PR #7006: fix(tools): stop browser automation from stealing focus in an attached browser (@terrxo)
# Conflicts:
#	packages/coding-agent/src/tools/browser/tab-supervisor.ts
2026-07-31 19:42:12 +02:00