Commit Graph

692 Commits

Author SHA1 Message Date
can1357 db2659297a Merge PR #7143: fix(natives): prevent deep HTML crashes and silent truncation (@br411)
# Conflicts:
#	MODULE.bazel.lock
2026-07-31 19:17:47 +02:00
can1357 80a46c2d4c fix(coding-agent): avoid splitting parameter expansions 2026-07-31 19:07:18 +02:00
can1357 969b4a34a5 Merge PR #7176: fix(coding-agent): inspect compound Bash commands in interceptor (@Vincent-Huang-2000) 2026-07-31 19:07:18 +02:00
can1357 f3ae071bb7 docs: clarify kitty placeholder opt-out precedence 2026-07-31 19:07:17 +02:00
can1357 3a3a65c639 Merge PR #7173: docs: document Kitty placeholder environment controls (@roboomp) 2026-07-31 19:07:17 +02:00
roboomp f52ec15a5d docs: documented kitty placeholder environment controls
Added the active Kitty Unicode placeholder overrides to the canonical environment-variable reference, including tmux placement behavior and the unsupported-terminal caveat.

Fixes #7172
2026-07-31 11:47:15 +00:00
Vincent Huang edb0deebb4 fix(coding-agent): inspect compound Bash commands in interceptor rules
Match interceptor regexes against conservative, raw shell command segments
in addition to the complete command, so anchored rules can detect commands
after &&, ||, ;, |, &, and newlines without treating quoted or escaped text
as commands.

Add extractFlatShellCommandSegments() to preserve source text for
user-configured regexes, unlike the token-based approval matcher.
Add skipShellWord() and environment-assignment stripping so rules can match
commands prefixed with NAME=value assignments. Preserve the original command
in interception errors after extracting a leading cd command.
2026-07-31 23:26:43 +12:00
br411 c1c162225b fix(natives): prevent deep HTML crashes and silent truncation
html-to-markdown-rs 2.30 could recurse through pathological HTML until
a native stack overflow aborted the entire OMP process. Upstream 3.9.2
bounds those traversals and reports omitted subtrees as a
machine-readable DepthLimitExceeded warning.

Upgrade html-to-markdown-rs to 3.9.2. Upstream treats a depth-limited
conversion as a successful partial Markdown result plus a warning;
deliberately promote that warning to a rejected `htmlToMarkdown`
promise, allowing the Read tool to fall back without terminating OMP.
Normal conversions and unrelated warnings keep their existing behavior.

Add a rejection-contract test plus a child-process regression proving
OMP survives deeply nested and malformed input.
2026-07-31 00:33:06 +02:00
can1357 652647770e feat(coding-agent): added app.live.toggle keybinding and map display reset to alt+l
- Add the `app.live.toggle` keybinding defaulted to `Ctrl+L` to start or stop live voice mode.
- Remap the default display-reset action (`app.display.reset`) from `Ctrl+L` to `Alt+L`.
- Update the live visualizer to listen for stop keys so the toggle chord terminates active sessions.
2026-07-31 00:20:04 +02:00
can1357 ab572106cd Merge PR #7048: feat(security): add OMP-native security scan subsystem (@kmccleary3301) 2026-07-30 17:11:06 +02:00
roboomp b059550f0b fix(natives): failed fast on uncapturable rootless xwayland root
Under a rootless XWayland session (the GNOME/KDE/sway default) the X11
root window has no backing pixmap, so core `GetImage` on the root returns
`BadMatch`. The computer tool advertised Wayland support yet failed every
screenshot with a raw X11 protocol dump, and coordinate actions stayed
gated behind a capture that could never succeed.

- `Monitor::all` now probes a 1x1 root `GetImage` at initialization and,
  on a `Match`/`Drawable` error, fails fast with an actionable
  `DESKTOP_BACKEND_UNAVAILABLE` message naming the rootless-XWayland
  constraint via the new `root_capture_error` classifier.
- `capture_image` routes its `GetImage` failure through the same
  classifier so any surviving path yields the actionable message rather
  than a raw protocol dump; unrelated errors stay verbatim.
- Corrected the module doc premise and `docs/computer-use.md` to list
  rootless XWayland as unsupported (capture needs a rooted/rootful X
  server, which only exposes X11 clients).

Fixes #7085
2026-07-30 12:38:43 +00:00
Kyle McCleary 4337797565 Merge remote-tracking branch 'origin/main' into feat/security-native
# Conflicts:
#	packages/coding-agent/src/tools/index.ts
2026-07-29 23:26:22 -07:00
can1357 38ebd30337 chore: update stale tests 2026-07-30 07:49:43 +02:00
Kyle McCleary dba303e2e0 Merge remote-tracking branch 'origin/main' into feat/security-native 2026-07-29 20:31:08 -07:00
can1357 d562e53b83 refactor: extracted audio and voice engine into a standalone library crate
- Extracted audio capture and playback implementations, along with the WebRTC peer engine, from `pi-natives` into a new `pi-voice` library crate.
- Updated `pi-natives` bindings to consume the extracted `pi_voice` audio streams and live peer core.
- Added release validation gate jobs, parallelized Linux binary builds, and introduced a concurrent macOS release build job in the CI workflow.
- Updated Bazel workspace configurations, Cargo manifests, and documentation to include the new `pi-voice` crate and its dependencies.
2026-07-30 05:12:40 +02:00
can1357 a38a2f25cf ci: optimized github actions caching and workflows
- Updated GitHub Actions workflows and custom actions to optimize caching strategies and runners.
- Configured separate restore and save steps for bun store caching with non-PR restrictions.
- Added darwin release bazel cache seeding and fallback keys for cache restore.
- Removed native-inputs workflow action and disabled PR-side Rust validation.
2026-07-30 04:56:47 +02:00
Kyle McCleary 089a9963f8 feat(security): OMP-native security subsystem (planner handoff) 2026-07-29 18:47:51 -07:00
can1357 020af06099 Merge PR #6535: feat(mcp): expose server-initiated notifications to extensions via mcp_notification event (@asteriskSF) 2026-07-30 01:48:51 +02:00
can1357 70e6d2c7dc Merge PR #6680: feat(coding-agent): add opt-in max ceiling for auto thinking (@everton-dgn) 2026-07-30 01:48:51 +02:00
can1357 27cb968359 Merge PR #7007: feat(tools): add a browser.cdpUrl setting for the default automation target (@terrxo) 2026-07-30 01:48:50 +02:00
can1357 857b70fe99 Merge remote-tracking branch 'refs/remotes/pr/6535' into prep/6535
# Conflicts:
#	packages/coding-agent/src/extensibility/extensions/runner.ts
2026-07-30 01:42:24 +02:00
can1357 55ac64679e Merge PR #6652: feat(ai): add Exa API key login (@will-bogusz) 2026-07-30 01:26:50 +02:00
can1357 5486c8fd1d Merge PR #6939: feat(extensions): expose session async job snapshots (@usr-bin-roygbiv) 2026-07-30 01:26:50 +02:00
can1357 0249fa4715 Merge PR #7036: feat(rpc): expose live fast-mode control and token throughput (@fredluz) 2026-07-30 01:26:49 +02:00
can1357 5711b763e0 docs(auth): align remaining credential ladders
(cherry picked from commit c606fe3a106611be413f140310ee47a88324cded)
2026-07-29 23:09:09 +02:00
can1357 5c79f5bc4a Merge PR #7023: docs(auth): correct credential precedence (@wolfiesch) 2026-07-29 23:09:09 +02:00
Wolfgang Schoenberger 031beb1751 docs(auth): correct credential precedence
(cherry picked from commit 33ede5efbc52cedc9819cb65c642cfeab82c337c)
2026-07-29 23:09:09 +02:00
can1357 b5ad903788 fix(ttsr): exclude deleted patch text from matcher digest
(cherry picked from commit b4812365368368a5706131c3ff1ecd52fd64662d)
2026-07-29 23:08:24 +02:00
can1357 b98a6853b3 Merge PR #6886: docs: clarify ttsr edit/write matcherDigest is introduced lines (@roboomp) 2026-07-29 23:08:23 +02:00
Éverton Toffanetto e94442b694 fix(ai): preserve legacy Codex SQLite compatibility
(cherry picked from commit 3e5e7b6ea910c56765b4707f617e20b056f3d342)
2026-07-29 23:08:11 +02:00
Éverton Toffanetto db9aa4af1c fix(ai): preserve Codex broker block compatibility
(cherry picked from commit 7de50a84c3d46279e0249617e22ba22222ff8174)
2026-07-29 23:08:10 +02:00
Frederico Luz 1e96750437 fix(rpc): report Anthropic fast fallback honestly
Anthropic's provider-scoped fastModeDisabled state was omitted from the session active predicate, and the unchanged-tier guard prevented explicit retries.
2026-07-29 20:58:01 +01:00
Frederico Luz 07f0ba8a42 fix(rpc): report actual Fireworks fast-mode state 2026-07-29 20:00:11 +01:00
Frederico Luz 7b8001e5c4 fix(rpc): address fast-mode review feedback 2026-07-29 19:47:56 +01:00
Nik Divjak 408f0d352f feat(tools): add a browser.cdpUrl setting for the default automation target
Attaching to a long-running browser (a signed-in profile, an Electron app kept
open for a session) meant repeating app.cdp_url on every browser call, and any
call that omitted it silently launched a fresh headless Chromium instead.

browser.cdpUrl supplies that endpoint once. It is a default rather than an
override: app.cdp_url and app.path still win, and an unset or blank value leaves
cmux and headless resolution exactly as before.
2026-07-29 11:28:26 +02:00
usr-bin-roygbiv 085f870faa feat(extensions): expose session async job snapshots 2026-07-28 23:12:28 +00:00
can1357 b550858265 ci: upgraded continuous integration workflows and migrated bazel dependency locking
- Updated CI workflows and GitHub actions to enhance Bazel cache keying, credential masking, and validation checks.
- Migrated dependency locking from Cargo.Bazel.lock to MODULE.bazel.lock using rules_rust crate_universe.
- Updated build configuration, documentation, and tooling scripts to reflect the lockfile and cache changes.
2026-07-28 12:53:23 +02:00
roboomp e7f26be1af docs: clarify ttsr edit/write matcherDigest is introduced lines
The TTSR lifecycle doc called the edit/write match target the
"reconstructed source snapshot", which reads as the whole prospective
file. For edit that is wrong: every mode's matcherDigest returns only
the lines the call introduces (new_text / + body rows / added diff
lines). Only write passes whole content. Reworded lines 57 and 78 to
match the code contract in streaming.ts.

Fixes #6885
2026-07-28 10:27:00 +00:00
can1357 ac6cd57bd4 Merge PR #6820: fix(coding-agent): preserve parent todos in vibe mode (@Iron-Ham) 2026-07-28 10:59:37 +02:00
can1357 0e556ee32a docs(marketplace): document plugin mcpServers manifest pointer and correct stale extensions note 2026-07-28 10:59:35 +02:00
can1357 b6bd241943 Merge PR #6873: fix(discovery): honor plugin MCP manifest pointers (@roboomp) 2026-07-28 10:59:35 +02:00
roboomp 8f31a123d6 fix(discovery): honored plugin MCP manifest pointers
Resolved mcpServers file pointers from OMP and Claude plugin manifests before the conventional root config fallback.

Updated marketplace installer documentation for runtime symlink and lockfile registration.

Fixes #6871
2026-07-28 07:12:46 +00:00
can1357 e7009452b4 feat(coding-agent/tools): simplified browser screenshot persistence and return paths
- Remove the per-call `save` option from `tab.screenshot()` to simplify usage.
- Update `tab.screenshot()` to return the saved file path as a promise string.
- Configure screenshot persistence to use daemon path or custom `browser.screenshotDir`.
- Add comprehensive tests verifying temp path return and custom directory saving.
2026-07-28 06:40:31 +02:00
can1357 1bba24f191 Merge PR #6830: feat(coding-agent): capability-aware inspect_image with tri-state mode and /vision toggle (@epsilver) 2026-07-27 23:07:26 +02:00
can1357 da6d11de0e feat(agent): introduced prepareToolCall phase supporting argument replacement
- Added a prepareToolCall phase to the agent loop running before tool scheduling for validation and hooks.
- Updated BeforeToolCallContext and result types to support argument replacement instead of in-place mutation.
- Updated coding-agent extension handling and runner to track emitted tool calls and re-evaluate approvals on input revisions.
- Added comprehensive test coverage for argument replacement, concurrency resolution, and schema validation.
2026-07-27 22:55:20 +02:00
can1357 46707e3e36 Merge PR #6681: feat(extensions): let tool_call handlers revise tool input (@psyrendust) 2026-07-27 22:27:09 +02:00
alexis@epsilver.xyz c33b98e260 feat(coding-agent): capability-aware inspect_image with tri-state mode and /vision toggle
Replace the inspect_image.enabled boolean with inspect_image.mode
(auto|on|off, default auto). In auto the tool is registered only when
the active model lacks native image input, so vision-capable models
(e.g. kimi-code/k3) read images inline with their own capabilities
instead of delegating to a separate vision model. on/off force
registration regardless of model capability.

- New utils/inspect-image-mode.ts resolves the effective state from the
  /vision session override, the persisted setting, and model capability
- read tool re-evaluates the effective state per image read and
  re-renders its description, so it returns decoded image blocks again
  whenever inspect_image is hidden
- /vision [on|off|auto|status] slash command (modeled on /computer)
  overrides the mode for the current session only
- Tool set is reconciled on model switch with a status notice when
  inspect_image appears/disappears
- Legacy inspect_image.enabled true/false migrates to mode on/off
2026-07-27 16:24:02 -04:00
Hesham Salman 7f7e742db6 fix(coding-agent): preserve parent todos in vibe mode 2026-07-27 13:52:25 -04:00
can1357 fae0e5df31 Merge PR #6765: feat(catalog,ai): add SiliconFlow providers with dynamic-only model discovery (@iacore) 2026-07-27 15:57:47 +02:00
can1357 da044f33ef Merge PR #6784: fix(tui): route editor word delete through keybindings registry (@roboomp) 2026-07-27 15:57:45 +02:00