Commit Graph

79 Commits

Author SHA1 Message Date
can1357 38b61ae342 fix(session): honored explicit retry-after over reason backoff
- A provider-supplied retry-after now bypasses the transient rate/concurrency
  heuristic window instead of being overridden by it (regression from the
  subscription-cap retry change).
- Updated event-controller/ui-helpers test doubles for provenance-gated
  renderer selection (hasBuiltInTool), aggregated retryErrors on
  auto_retry_end, and Bedrock override compat gaining streamIdleTimeoutMs.
2026-08-07 23:38:25 +02:00
roboomp 7d4b2e7998 fix(agent): re-check context on cooldown-expiry revert in auto-continue path
A cooldown-expiry model revert runs at a turn boundary. The user-prompt
path reverts then re-checks accumulated context against the restored
model via runPrePromptCompactionIfNeeded, but the automatic
agent.continue() path (#scheduleAgentContinue) reverted and issued the
next request with no such check. When a transient failure had fallen
back to a larger-window model and the conversation then grew past the
original model's window, restoring the primary once its cooldown expired
sent a predictably oversized request to the smaller model.

maybeRestoreRetryFallbackPrimary now reports whether it actually
switched, and the auto-continue path runs the same post-revert
context-fit maintenance (compaction/promotion) the prompt path already
runs, but only when a revert occurred.

Fixes #7952
2026-08-07 23:38:24 +02:00
can1357 e9888367d1 refactor: migrated packages to internal utility modules and removed external dependencies
- Implemented in-house, zero-dependency utility modules in `pi-utils` covering DOM manipulation, markdown parsing, templating, browser automation helpers, and terminal buffers.
- Migrated packages across the repository to consume the new internal utilities and `omptype` schema validators instead of external dependencies.
- Removed multiple external runtime and development dependencies including Zod, Marked, LRU cache, Turndown, and Puppeteer browser packages.
2026-08-05 13:39:09 +02:00
Brent 2da96d77a7 fix(coding-agent): close fallback lifecycle races 2026-08-03 17:51:32 +00:00
Brent 353bbc034b fix(coding-agent): harden usage fallback review races 2026-08-03 17:15:57 +00:00
Brent db97103c32 fix(coding-agent): complete usage-aware fallback integration 2026-08-03 16:34:35 +00:00
can1357 832d4f1506 Merge PR #6987: fix(coding-agent): treat streamed visible text as replay-unsafe in turn recovery (@metaphorics) 2026-07-29 23:08:51 +02:00
metaphorics 93819dbec4 fix(coding-agent): gate refusal retries on replay safety
(cherry picked from commit 531b25beffa2096c76adff6692f3697e649f0e95)
2026-07-29 23:08:51 +02:00
metaphorics 9733d13827 fix(coding-agent): make replay safety authoritative
(cherry picked from commit 118ecabb22f406afbd56864ff0fbafc8f4f1fa4c)
2026-07-29 23:08:50 +02:00
metaphorics b5602ddfc1 fix(coding-agent): treat streamed visible text as replay-unsafe in turn recovery
(cherry picked from commit 3aeac1a4afa756e9c7d579246d8f334cd0731cda)
2026-07-29 23:08:50 +02:00
Paolo Mazzitti 3c7233af44 fix(coding-agent): scope advisor cost to active session 2026-07-29 07:18:48 +00:00
can1357 8c5dc16344 fix(task): enforced per-spawn effort ceiling across retry fallbacks
- task.maxEffort only clamped the initial thinking level; a retry
  fallback candidate could clamp back up to its model floor and run a
  low-capped spawn at high.
- The ceiling now rides the session as thinkingLevelCeiling: clamped in
  ModelControls (constructor, setThinkingLevel, auto classifier,
  restore) and in applyRetryFallbackCandidate; fallback candidates whose
  floor exceeds the ceiling are skipped.
- Effort value import moved to @oh-my-pi/pi-catalog/effort; changelog
  attribution added.
- Review follow-up for PR #6794.
2026-07-27 16:09:28 +02:00
can1357 12a2b13e93 fix(session): unwedged auto-retry after assistant-tail removal miss
A context rebuild that recreated the failed turn's message object made the
identity-keyed active-context removal miss, so the scheduled retry
continuation rejected the terminal assistant error message locally
("Cannot continue from message role: assistant") before any provider
request. auto_retry_end never fired, retryPromise stayed pending, and the
in-flight prompt() plus the TUI retry indicator hung until a manual
follow-up.

The retry path now strips a still-failed assistant tail positionally after
the backoff (generation-guarded, never in preserveFailedTurn mode), and a
continuation that still fails locally closes the retry saga with a failed
auto_retry_end via the new scheduleAgentContinue onError hook.

Fixes #5382
2026-07-27 04:59:31 +02:00
Brent 8a9630c031 fix(coding-agent): reselect fallback account by health 2026-07-24 02:23:51 +02:00
Brent 0bfb0bd1e3 feat(coding-agent): add usage-aware model fallback 2026-07-24 02:23:51 +02:00
can1357 3829bff31a Merge PR #4637: feat(notifications): add error turn notifications (@Mathews-Tom)
# Conflicts:
#	packages/coding-agent/src/modes/controllers/event-controller.ts
#	packages/coding-agent/src/prompts/tools/eval.md
#	packages/coding-agent/src/session/agent-session.ts
#	packages/coding-agent/src/task/index.ts
2026-07-23 17:49:06 +02:00
can1357 db3a6a1407 Merge PR #6318: fix(tui): show fallback models in Agent Hub (@roboomp) 2026-07-23 11:37:13 +02:00
can1357 e4de9509c7 test: adapt catalog-pinned tests to regenerated model catalog
- Repointed tests off removed gpt-5.2/5.3 codex variants and devin models (e06ac0b787): context-promotion and TTSR tests pin gpt-5.5 -> gpt-5.6-sol via per-test modelOverrides since no bundled codex model has a runtime-effective promotion target anymore; replay-boundary and history-payload suites use gpt-5.5; advisor quota fallback uses devin/swe-1-6-slow with suffix-less selectors per #4579 devin-agent semantics; gateway-reference pins kilo/giga-potato and now asserts the reference carries effortRouting so the cross-provider no-inherit contract stays meaningful.
- Verified cross-provider gateway references do not inherit wire routing after variant collapse (identity/reference.ts:145-154) - stale test, no product bug.
2026-07-22 22:26:10 +02:00
roboomp f9a56ff94f fix(tui): showed fallback models in agent hub
- Exposed the active retry fallback selector from live agent sessions.
- Rendered fallback rows with an explicit marker and resolved provider/model.
- Added an end-to-end fallback-to-Agent-Hub regression assertion.

Fixes #6316
2026-07-22 19:08:32 +00:00
roboomp b257a6dcbf fix(session): preserved startup fallback ownership
- Carried startup-selected fallback role and primary selector into AgentSession.
- Continued remaining role fallback entries after the startup fallback fails.
- Added regression coverage for chained startup failover.

Fixes #6283
2026-07-22 11:11:30 +00:00
can1357 c655db4e3c fix(session): added #prunedTerminalRefusal field to store the
- Added `#prunedTerminalRefusal` field to store the pruned refusal for post-settle consumers.
- Modified `getLastAssistantMessage()` to return the pruned refusal before active-context lookup.
- Reset `#prunedTerminalRefusal` on `agent_start` so a fresh run supersedes the settled refusal.
- Updated test mock helpers to include `getLastAssistantMessage` for consistency.
2026-07-18 17:51:48 +02:00
can1357 eac51b6a04 Merge: darkphilosophy/feat/advisor-per-agent-toggle
Brings the per-advisor toggle, status-line glyphs, quota display, and the
failing-advisor stall/abort fix (f4c8143) onto main's rewritten advisor
runtime. Conflict reconciliation kept main's architecture (fingerprint
prefix reconciliation, host-level onTurnError recovery + fallback chains,
terminal-failure classification) and ported the branch semantics onto it:

- #failing latch: waitForCatchup resolves immediately while an advisor is
  mid-failure; parked waiters wake the moment a turn fails, before any
  async hook or retry sleep.
- Turn-end render containment: a formatter bug restores the cursor/prefix/
  dedup snapshot and never propagates into the primary's turn-end callback
  (per-advisor try/catch boundary in AgentSession).
- Quota pause: when host recovery declines a usage-limit failure, the
  runtime latches quotaExhausted, requeues the batch, and notifies —
  cleared only by an explicit reset.
- Hard halt after a permanent rejection or three backlog-drop cycles.
- #recoverAdvisorTurn also marks usage limits for structural errors thrown
  before any assistant turn is recorded.
2026-07-17 07:37:29 +02:00
can1357 6f42a4375f merge PR #5748 via eval/pr-5748: fix(advisor): apply configured fallback chains 2026-07-17 04:45:46 +02:00
can1357 1424cae066 feat(coding-agent): added id-prefixed wildcard support to retry fallback chains
- Implemented parsing of id-prefixed wildcard keys and entries, allowing provider-specific prefixes in retry fallback configuration.
- Added logic to re-prefix failing model IDs and to match id-prefixed keys, with validation of provider existence.
- Updated settings schema description and changelog, and added tests covering the new behavior.
2026-07-17 03:49:43 +02:00
roboomp 203b959056 fix(advisor): restored primary after fallback cooldown
- Retained the advisor's original selector and thinking level while progressing through fallback candidates.
- Restored the configured primary before later advisor turns once its selector cooldown expired.
- Covered quota fallback restoration under the default cooldown-expiry policy.
2026-07-16 20:08:51 +00:00
roboomp 777e5e0982 fix(advisor): applied configured fallback chains
- Switched advisor turns to the next configured model after provider quota or rate-limit failures.
- Emitted fallback applied and succeeded lifecycle events without reporting advisor unavailability after recovery.
- Added an end-to-end advisor quota fallback regression test.

Fixes #5740
2026-07-16 19:56:24 +00:00
Mathews-Tom ea3882f8a3 fix(coding-agent): close terminal retry lifecycle 2026-07-15 22:53:47 +05:30
Mathews-Tom 4452465f57 Merge remote-tracking branch 'upstream/main' into feat/error-notify 2026-07-15 04:47:26 +05:30
roboomp 5e71fac653 fix(session): retried bare Request was aborted error-stop turns
A stalled or dropped provider stream that surfaces as stopReason:"error"
carrying the bare "Request was aborted" sentinel fell through both retry
gates: #isRetryableReasonlessAbort required stopReason:"aborted", and
#isRetryableError's classifier returns no retriable kinds for the generic
sentinel. The turn died immediately despite retry.enabled.

- Relaxed #isRetryableReasonlessAbort to accept an empty generic-abort
  sentinel turn under stopReason "aborted" or "error", tagging it Abort so
  #handleRetryableError retries it without model fallback.
- Kept the deliberate-abort guards intact: user interrupts and silent aborts
  carry their own markers (not the generic sentinel), and #abortInProgress /
  #isDisposed / #streamingEditAbortTriggered still settle without retry.
- Rewrote the stale fallback test that froze the buggy no-retry behavior to
  assert retry-and-recover for the error-stop sentinel.

Fixes #5375
2026-07-14 19:39:24 +00:00
Mathews-Tom b72a320d2d Merge remote-tracking branch 'upstream/main' into feat/error-notify
# Conflicts:
#	packages/coding-agent/src/session/agent-session.ts
2026-07-14 03:12:29 +05:30
can1357 ac16253613 wip: rslide (experimental) 2026-07-13 04:21:54 +02:00
can1357 58d6130b50 feat(coding-agent): enabled model fallback for hard errors
- Extended `AgentSession` to consult `retry.fallbackChains` on non-retryable (hard) model errors.
- Implemented `#isHardErrorFallbackEligible` to validate eligibility for model switching before surfacing terminal errors.
- Updated `#handleRetryableError` to orchestrate immediate model switching for hard errors, bypassing backoff-retries for the failing model.
- Ensured hard errors propagate to the user if no fallback candidates are available or if no credential can be resolved for the fallback model.
2026-07-13 00:59:43 +02:00
Mathews-Tom 328f8cd85b Merge remote-tracking branch 'upstream/main' into feat/error-notify 2026-07-12 06:58:41 +05:30
can1357 d54dcc2224 feat(coding-agent): allowed model fallback after retry budget exhaustion
- Permit model fallback even if the retry budget is exhausted when the current provider is locked by credential rotation or usage limits.
- Reset the retry budget when successfully switching to a fallback model to ensure the new model has a full allowance of retries.
- Added a regression test to verify that credential rotation failure triggers model fallback.
2026-07-12 01:35:50 +02:00
Mathews-Tom f9e481baad fix(coding-agent): preserve final retry error toasts
AgentSession defers and coalesces the wire-level agent_end while a
prompt is in flight (#emitSessionEvent), so a multi-attempt retry saga
often surfaces only ONE agent_end to EventController — which can be
the final settle, not an intermediate attempt. Consuming #retryPending
against whichever agent_end arrived first (previous commit) could
therefore discard the real final failure notification.

Switch to gating purely on the retry lifecycle: #retryPending is set
by auto_retry_start and cleared only by auto_retry_end (both
outcomes), never consumed by sendErrorNotification itself. Those
lifecycle events are never deferred, so they reliably bracket the
window a retry is actually outstanding regardless of how agent_end
coalescing lands.

Close the residual gap this creates: #handleRetryableError's
classifier-refusal and Fireworks-fallback-ineligible branches could
short-circuit a saga that already announced auto_retry_start without
ever emitting auto_retry_end, latching #retryPending open forever.
Both branches now emit a final auto_retry_end(false) when a prior
attempt already started the saga. #handleAgentStart also clears
#retryPending defensively so a saga that still somehow never resolves
cannot suppress a later, unrelated turn's notification.
2026-07-12 04:17:11 +05:30
can1357 54bafa1cce feat(coding-agent): implemented interactive fallback chain configuration
- Implemented model-specific keys and provider wildcards for `retry.fallbackChains` with updated resolution logic.
- Added interactive fallback chain management in the model roles UI, including support for reordering and editing.
- Improved fallback chain specificity rules and added comprehensive validation with startup warnings.
- Fixed mouse interaction alignment and hover state coordinate mapping in the roles view.
2026-07-11 22:03:35 +02:00
can1357 d435385ab1 feat: introduced max reasoning effort tier across model and rpc systems
- Introduced `Max` as a first-class reasoning effort tier across all packages, including AI providers, coding agent configurations, and RPC protocols.
- Refactored model effort ladders to use wire-exact mappings and removed legacy effort aliasing (e.g., `max-to-xhigh` mapping).
- Updated model registry and provider configurations to support `Max` tier routing, color themes, and UI icon associations.
- Expanded test suites to provide end-to-end coverage for the new reasoning tier, including updated compatibility and fallback scenarios.
2026-07-10 13:39:42 +02:00
roboomp b2f7238a03 fix(coding-agent): allowed mixed fallback chains
- Allowed implicit default fallback resolution when other role fallback chains are configured.
- Covered the mixed-role first-run fallback case.

Fixes #4533
2026-07-05 19:21:08 +00:00
roboomp ed7d1cb982 fix(coding-agent): honored implicit fallback primary
- Treated the active model as the default retry primary when only retry.fallbackChains.default is configured.
- Covered the first-run case where modelRoles.default is unset but a default fallback chain exists.

Fixes #4533
2026-07-04 16:54:40 +00:00
roboomp 11c96c9ae3 fix(session): preserved refusal stop payloads
Passed the settled assistant message into session_stop emission so refusal-as-error turns can be pruned from replay context without hiding their stop details from extension hooks.

Expanded the refusal regression test to assert the session_stop payload still exposes the refusal as last_assistant_message.

Fixes #3591
2026-06-26 18:06:09 +00:00
roboomp db61ca0274 fix(session): kept session_stop hooks on classifier refusals
Removed the early return after refusal pruning so the agent_end tail still reaches `#emitSessionStopEvent`, restoring `session_stop` extension hooks (block/continue/telemetry) for refusal-as-error stops.

Regression test wires an extensionRunner with a session_stop handler and asserts it fires for both the refusal turn and the following clean turn.

Fixes #3591
2026-06-26 17:59:26 +00:00
roboomp fbcc157b75 fix(session): pruned classifier refusals from context
Stopped API-level classifier refusal messages from being persisted or replayed as assistant dialogue after the failed turn settles.

Fixes #3591
2026-06-26 17:53:48 +00:00
can1357 5d72ce1237 Merge PR #2729: fix(coding-agent): accept max thinking alias (@roboomp)
# Conflicts:
#	packages/coding-agent/test/model-resolver.test.ts
#	packages/coding-agent/test/sdk-model-selection.test.ts
2026-06-19 00:58:52 +02:00
usr_bin_roygbiv 2634bbf1d2 fix(coding-agent): bypass stream-interrupted guard for Gemini malformed function calls 2026-06-18 00:42:22 -05:00
can1357 17ce678468 fix(coding-agent): handled provider error finish reasons and preserve subprocess failure codes
- Added detection for provider error finish reasons occurring before tool calls to identify fatal messages.
- Prevented subprocess tool execution finalization from resetting a non-zero exit code when yield items exist.
- Ensured a default error message is set in stderr when a subprocess fails after yielding a result.
2026-06-18 01:11:10 +02:00
can1357 a0cffe4814 feat: updated model-aware API-key resolution and antigravity endpoint failover
- Updated getApiKey signatures to accept a Model and return ApiKey or ApiKeyResolver.
- Updated stream key handling to resolve credentials per model and use seedApiKeyResolver for retries.
- Added antigravityEndpointMode setting with auto/production/sandbox endpoint selection.
- Added 429/5xx endpoint failover for Gemini stream, usage, search, and image calls.
2026-06-17 12:24:21 +02:00
roboomp 7b62bffb34 fix(agent): matched routed retry primaries
Matched retry fallback roles against the plain model selector as well as the routed in-flight selector, preserving configured chains for compat-routed OpenRouter and Vercel models.

Added regression coverage for a compat-routed OpenRouter primary using a plain role selector.
2026-06-16 09:01:58 +00:00
roboomp 3d3cdb42d4 fix(agent): kept at-suffixed fallback ids
Stopped retry fallback selector parsing from treating every @ suffix as upstream routing, preserving exact model ids like google-vertex Claude @default variants.

Resolved fallback candidates from raw selectors during preflight so routed selectors still work without corrupting exact at-suffixed ids.
2026-06-16 08:37:49 +00:00
roboomp ad58175946 fix(agent): restored routed retry primaries
Resolved retry fallback primaries from the raw selector during cooldown restore so OpenRouter and Vercel upstream pins survive fallback recovery.

Added regression coverage for routed OpenRouter primaries reverting after cooldown expiry.
2026-06-16 08:16:49 +00:00
roboomp d3259ac33d fix(coding-agent): normalized max cooldown selectors
Normalized max thinking aliases when recording and checking retry fallback cooldown suppressions while preserving live literal :max model IDs.\n\nFixes #2727
2026-06-16 03:55:45 +00:00