Commit Graph
12189 Commits
Author SHA1 Message Date
zero 82436b0e93 fix(natives): make Windows-host builds and addon loading work end to end
Runtime: the loader's AVX2 probe used [System.Runtime.Intrinsics.X86.Avx2]
via powershell.exe, which only exists on .NET Core — stock Windows PowerShell
5.1 raised TypeNotFound, so every Windows host silently loaded the baseline
addon and paid ~270ms for the spawn on the startup path. Ask the kernel via
bun:ffi (IsProcessorFeaturePresent(PF_AVX2_INSTRUCTIONS_AVAILABLE), ~0.5ms)
and fall back to pwsh-then-powershell for Node embeds. scripts/host-detect.ts
shared the same broken probe for build-time variant selection.

Build: `bun run build:native` on a win32 host died deep inside the bazel msvc
repo rules (linux/mac exec hosts only, by design). The `host` pseudo-target
now delegates to the local napi build against real VS Build Tools, and other
targets fail fast with guidance. build-bindings.ts resolves the @napi-rs/cli
JS entry from its manifest (the node_modules/.bin shim is a PE launcher Bun
cannot parse) and auto-appends VS Build Tools' bundled CMake/Ninja to PATH
via vswhere so a vcvars prompt is no longer required. Cap maudio at
opt-level=1 to dodge a rustc ICE codegenning MaybeUninit<ma_fence> for
x86_64-pc-windows-msvc under the pinned nightly (Bazel's older pin is
unaffected).

Compile: Bun.Glob.scan yields backslash paths on Windows; the legacy Pi
virtual module used them verbatim for export keys and generated identifiers,
producing invalid JavaScript in compiled-binary builds.

Tests: strip ConPTY negotiation escapes in the pty argv test; ignore the
bazel-oh-my-pi convenience symlink.
2026-08-07 16:54:02 +08:00
roboomp 2597244b00 fix(bash): constrain leading cd extraction to a single path token
The `cd <path> && ...` extractor matched everything up to the first `&&`
with a greedy regex, so a redirect or extra argument before the `&&` was
swallowed into the structured cwd. `cd /tmp 2>/dev/null && echo ok` became
cwd `/tmp 2>/dev/null`, which failed fs.stat and killed the command before
the shell ran.

Replace the regex with `extractLeadingCdTarget`, a quote/escape-aware
scanner in shell-tokenize.ts that captures exactly one path token and
bails (leaving the command for the shell) when anything else — a redirect,
extra argument, shell expansion, or a non-`&&` separator — precedes the
top-level `&&`.

Fixes #7883
2026-08-07 06:43:55 +00:00
Caelum d1ed93d8a2 fix(status-line): carry effective sessionAccent into SegmentContext and honor it for session_name
Address review feedback: the segment previously read the setting from ctx.session.settings, a second source of truth that could disagree with the component's effectiveSettings.sessionAccent and crashed lightweight test fixtures lacking a settings manager. Resolve the value once in #buildSegmentContext from the effective settings and pass it through SegmentContext.sessionAccent so the name segment and the gap-fill divider consume the same value. Add regression assertions for the enabled and disabled branches and a changelog entry.
2026-08-07 12:23:19 +08:00
Caelum 844e1fda33 fix(status-line): honor sessionAccent toggle for session_name segment
The session_name segment rendered the session name text with getSessionAccentHex unconditionally, ignoring the statusLine.sessionAccent setting. The adjacent gap-fill divider (component.ts) already gated on sessionAccent !== false, so disabling the setting only removed the accent-colored divider line while the session name itself stayed hash-colored - an inconsistent half-off state.

Read the setting via ctx.session.settings.get (same pattern already used by the goal segment in this file at line 206) and fall back to the theme accent color when disabled, matching the divider behavior.
2026-08-07 12:23:19 +08:00
can1357 102eaa4543 feat(cli): added omp share command for saved sessions
Shares a saved session by id prefix or .jsonl path without launching the
agent - same encrypted upload, store selection, and share.redactSecrets
handling as the /share slash command.
2026-08-07 06:00:07 +02:00
can1357 35ab3ece48 refactor(secrets): extracted buildSecretObfuscator from sdk session setup
Moved the obfuscator assembly (secrets.yml + env entries + built-in
credential patterns, placeholder-key minting rules, redaction-only
fallback) from createAgentSessionScoped into the secrets module so other
entrypoints can build the same obfuscator.
2026-08-07 05:59:58 +02:00
can1357 2ad61c7b92 feat(discovery): added Agent Plugins 1.0.0 standard support
- New agent-plugins provider discovers packages with a root plugin.json
  targeting the canonical schema (agent-plugins.org) from marketplace
  installs, --plugin-dir, and configured extension roots; skills/ and
  mcp.json load per spec with closed-schema validation,
  ${PLUGIN_ROOT}/${PLUGIN_DATA} expansion, reserved subprocess
  environment, instance-keyed data dirs, and per-component isolation.
- Package-boundary containment (spec §4.1) is enforced before every
  read via the new contained-path helpers, including skill:// resource
  access from the read tool and bash; plugin skill files must
  realpath-resolve inside the plugin root (skills carry containRoot).
- Legacy claude-plugins/omp-plugins providers yield skills and MCP
  surfaces of standard-targeting roots to the new provider and skip
  fatally invalid packages.
2026-08-07 05:59:52 +02:00
can1357 b94bfba025 feat(mcp): enforced header precedence and origin policy on remote transports
- Client-generated HTTP/MCP/authorization headers win over configured
  headers case-insensitively (Agent Plugins §7.2.1) via the new
  header-policy fetch wrapper used by the HTTP and legacy SSE transports.
- headerPolicy: "origin-locked" pins configured headers to the configured
  URL's origin: never forwarded across cross-origin redirects, and
  method-changing redirects of JSON-RPC POSTs are refused.
- envPolicy: "literal" exempts stdio env values (and origin-locked
  headers) from config-value resolution: no ambient env-name lookup, no
  __omp_shell("command execution, empty values preserved.")
2026-08-07 05:59:36 +02:00
Brent 564b983286 ci: retry flaky timeout checks 2026-08-06 21:50:21 +00:00
Mustaqeem66 24a334376e fix(extensions): roll back provider registrations on load failure 2026-08-06 20:00:29 +00:00
Brent 67e154912a test(coding-agent): cover prewalk review regressions 2026-08-06 19:57:10 +00:00
Brent 2efe8896ea fix(coding-agent): make prewalk lifecycle one-shot 2026-08-06 19:57:10 +00:00
roboomp 2fe1d1991a feat(coding-agent): marked child processes as agent-driven
- Set AGENT=1 through the shared non-interactive child environment.

- Covered the marker through the bash executor integration path.

Fixes #7847
2026-08-06 18:45:58 +00:00
kimp 3ba60e31d0 chore(coding-agent): separate changelog release sections 2026-08-07 00:18:37 +07:00
kimp cde7f7f30b chore: merge upstream main into strict schema fix 2026-08-07 00:17:51 +07:00
kimp 7dcfd9422a fix(coding-agent/tools): deduplicate JTD primitive detection 2026-08-07 00:17:38 +07:00
zhang17-24 ec0253effd fix(coding-agent): signalled fallback commits with a non-zero exit code 2026-08-06 23:03:25 +08:00
Vinh Nguyen ed4cfeec99 fix(coding-agent): prefer proxy-reported model name over bundled catalog name 2026-08-06 21:57:03 +07:00
roboomp 42322041c4 fix(tui): make ctrl+o expand tool output regardless of focus
app.tools.expand (Ctrl+O) was wired only through the editor's input path,
so when a tool-approval prompt or other selection dialog took keyboard
focus the key was delivered to that component and never reached the expand
handler — a large truncated edit could not be expanded while the user was
deciding whether to approve or deny it.

Promote the shortcut to a global TUI input listener (matching the existing
debug and branch/copy shortcuts) so it fires regardless of focus. It defers
when the main transcript is not the active surface (a fullscreen/anchored
overlay: agent hub, transcript viewer, log viewer, model picker) or when the
focused component rebinds Ctrl+O for its own use (the tree selector's filter
cycle). The editor-scoped handler is removed as a clean cutover.

Fixes #7837
2026-08-06 13:55:34 +00:00
roboomp 8ca2230675 fix(commit): report hook refusals cleanly and honor --push on a clean tree
git.commit() was awaited without a try in both agentic commit routes and the legacy pipeline, so a refusing pre-commit/commit-msg hook escaped as an uncaught GitCommandError. In a bundled build Bun renders that as kilobytes of minified source. The split loop also threw out of its order loop, reporting no progress.

The empty-staged-tree early return fired before args.push was read, so 'omp commit --push' on a clean tree exited 0 without pushing.

Route commit/push failures through a shared execute helper: abortOnGitFailure prints the hook's own message (plus split-plan progress) and throws a CommitAbortedError the command maps to exit 1; pushOrAbort pushes existing commits when the tree is clean and reports refused pushes cleanly.

Fixes #7834
2026-08-06 13:26:58 +00:00
can1357 d9d911a58d fix(coding-agent): kept mid-turn command deferral silent
- Reverted the status-line acknowledgment added for deferred panel
  commands: showStatus mounts a Spacer+Text into the transcript, and any
  mid-turn transcript mount re-renders rows below the growing live block,
  duplicating them in native scrollback (issues #4806/#6767).
- The queue still flushes at every settle, terminal or not.
2026-08-06 14:18:50 +02:00
can1357 43c1b245e7 chore: bump version to 17.2.10 2026-08-06 13:32:34 +02:00
can1357 9e738dc880 chore: reformat + rewrite changelogs 2026-08-06 13:30:08 +02:00
can1357 52ec788afb fix(coding-agent): enforce exact trusted extension paths 2026-08-06 13:24:29 +02:00
can1357 9628c2e2e6 Merge PR #7754: feat(omp): load only explicitly trusted extensions (@oleksoleksoleks) 2026-08-06 13:24:29 +02:00
kimp 103791f14b fix(coding-agent/tools): preserve native JSON Schema containers 2026-08-06 15:50:22 +07:00
Chess Luo 54bd5cd452 fix(coding-agent): clean up legacy Exa and computer settings 2026-08-06 16:36:04 +08:00
Chess Luo 32d6421e84 test(tui): isolate Herdr env in direct-terminal fixtures 2026-08-06 16:06:40 +08:00
roboomp 181f63ebc0 fix(coding-agent): detect non-English questions in todo reminder guard
The isAwaitingUserAnswer guard that suppresses the todo completion reminder while the agent waits on a user question only recognized English question words and pronouns. A '?'/'?'-terminated Chinese, Japanese, Korean, or Spanish prompt went undetected, so the <system-reminder> interrupted the pause and the model misread it as the user's answer.

isQuestionPromptLine now also treats a question-mark-terminated line containing any non-ASCII character as a pending user question.

Fixes #7803
2026-08-06 06:47:27 +00:00
roboomp bfd1e64bf6 fix(read): normalized recovery paths
Used the resolved cwd-relative path in summary recovery selectors, PDF image handles, and notebook diagnostics.

Fixes #7788
2026-08-06 03:40:10 +00:00
ParadaCarleton ecaefd54d7 fix(tree): stop rendering bookkeeping entries as empty rows
Seven session entry types — title_change, credential_pin, mode_change,
service_tier_change, ttsr_injection, reset_boundary and session_init —
fell through #getEntryDisplayText's default branch to the empty string,
and none of them were in the default view's hidden set. Each one drew as
a bare bullet: a row you cannot read, cannot identify and cannot explain
the gap it leaves in the thread.

Hide them in the default and no-tools views, alongside the settings
entries they resemble, and give every one of them a label for `all`
mode. The default branch now falls back to the entry type rather than
the empty string, so a type added later degrades to a dull row instead
of an invisible one. Service tier renders its per-family map, and says
"(default)" when the tier was cleared instead of printing null.
2026-08-05 19:08:54 -07:00
roboomp 07bb0ac51f fix(acp): resolve session/load across legacy session directories
session/load and session/resume resolved a session only within the
directory re-derived from cwd (SessionManager.list(cwd)), so sessions
stored under the legacy/hashed project-directory scheme (17.2.5+,
reverted in #7656) were unreachable and threw "ACP session not found"
despite existing on disk.

#findStoredSession now falls back to a global by-id scan (listAll,
already used by the fork path) when the cwd-scoped lookup misses. The
session id is globally unique and #openStoredSession reopens the file
with the request cwd, so no directory-scheme knowledge is needed.

Fixes #7779
2026-08-06 02:08:49 +00:00
roboomp 931f61867c fix(tui): gated built-in renderers by tool provenance
- Routed session tool provenance through live and rebuilt transcript render paths.
- Kept same-named extension tools on the generic renderer while preserving native tool rendering.
- Added regression coverage for an external recall result collision.

Fixes #7770
2026-08-06 01:36:25 +00:00
roboomp f5f7b09dd7 fix(vault): pass vault= as top-level obsidian cli option
The vault=<name> argument was appended after the subcommand
(obsidian bases vault=Work), but the Obsidian CLI only honors it as a
top-level option before the subcommand. Placed after, the subcommand
consumed/ignored it and the command bound to whichever vault had window
focus, so vault://<name>?op=... silently queried the wrong vault.

Prepend the vault arg in #runCli and #vaultInfo so it precedes the
subcommand (obsidian vault=Work bases), matching the CLI's documented
top-level-option semantics.

Fixes #7771
2026-08-06 01:36:01 +00:00
roboomp f6c5a43a1f fix(session): handled subscription-cap retry exhaustion
- Classified subscription and plan rate caps as credential-rotatable usage limits while preserving transient per-minute throttles.

- Applied reason-specific backoff to transient rate limits and collapsed exhausted retry attempts behind one budget-labeled terminal error.

- Covered classification, delay selection, persisted transcript aggregation, and retry event propagation.

Fixes #7767
2026-08-06 01:31:22 +00:00
Franklin Castillo 3381b4305a docs(coding-agent): correct js-debug runtime + extraction path per review
Two wording fixes for PR #7759 review:
- debug.md no longer requires `node` on PATH; documents that the adapter
  runs under node if available, else the omp Bun host, matching
  resolveDefaultJsDebugAdapter()'s process.execPath fallback.
- The unavailable message and CHANGELOG now say "extract under
  ~/.local/opt" (not "to ~/.local/opt/js-debug/"), so the archive's
  js-debug/src/dapDebugServer.js lands at the auto-discovered path
  instead of one directory too deep.

Refs #7757.
2026-08-05 18:28:28 -04:00
Franklin Castillo 3afc87926b docs(coding-agent): clarify js-debug-adapter install is not an npm package
The "js-debug-adapter not available" message and the debug doc only
mentioned Mason and JS_DEBUG_DAP_SERVER, leaving users to try
`npm i -g js-debug-adapter`, which 404s: js-debug-adapter is the omp
adapter id, not an installable package. Surface the supported installs
(Mason; the standalone vscode-js-debug release tarball extracted to
~/.local/opt/js-debug/, which resolveJsDebugServerPath already
auto-discovers; or JS_DEBUG_DAP_SERVER) in both the error message and
docs/tools/debug.md.

Refs #7757.
2026-08-05 17:59:59 -04:00
roboomp 3df56506c7 fix(coding-agent): preserve before_agent_start prompt override across base rebuilds
The per-turn systemPrompt returned by before_agent_start was applied only to the agent state, so any base-prompt rebuild firing in the prompt window (context-overflow compaction/promotion, memory promotion, MCP/RPC tool refresh, hindsight MM-TTL refresh) re-pushed the rebuilt base via setSystemPrompt and silently dropped the override before the request.

SessionTools now tracks the active per-turn override and re-applies it on every base rebuild during the turn, clearing it when the turn ends.

Fixes #7755
2026-08-05 21:28:37 +00:00
Alexander KirilinandEric Singer 9154c56a69 feat(omp): load only explicitly trusted extensions
Co-authored-by: Eric Singer <singer.ericm@gmail.com>
2026-08-05 16:32:45 -04:00
can1357 1d181161b0 style: formatted legacy-pi shim changes with biome 2026-08-05 22:18:05 +02:00
can1357 c5cce0f325 chore: normalized changelogs after merging 14 pull requests 2026-08-05 22:17:01 +02:00
can1357 ccd5a5c988 Merge PR #7697: test: fix Windows portability of bash ACP, Warp capability, and logger closure tests (@metaphorics)
# Conflicts:
#	packages/utils/test/logger-runtime-closure.test.ts
2026-08-05 22:16:53 +02:00
can1357 cac0887fee Merge PR #7708: fix(coding-agent): preserve shell quoting in POSIX $EDITOR commands (@metaphorics) 2026-08-05 22:16:29 +02:00
can1357 a6918d3397 Merge PR #7669: fix(catalog): exposed low effort tier for deepseek-v4-flash (@roboomp) 2026-08-05 22:16:29 +02:00
can1357 ae84aff853 Merge PR #7675: fix(memory): hide disabled memory protocol (@roboomp) 2026-08-05 22:16:28 +02:00
can1357 ca3884039b test(session): canonicalize hashed migration cwd 2026-08-05 22:16:28 +02:00
can1357 0474e797da Merge PR #7678: fix(session): migrate hashed session dirs back to legacy names (@roboomp) 2026-08-05 22:16:28 +02:00
can1357 1e3419ebac Merge PR #7688: fix(tui): detach plan approval dispatch from serialized event chain (@roboomp) 2026-08-05 22:16:28 +02:00
can1357 65132b3373 fix(computer): correct Wayland recovery guidance 2026-08-05 22:15:47 +02:00
can1357 307ba8b9f3 Merge PR #7711: fix(computer): correct Wayland foreground delivery (@roboomp) 2026-08-05 22:15:47 +02:00