Commit Graph

7179 Commits

Author SHA1 Message Date
can1357 1082b6316a Merge remote-tracking branch 'origin/farm/5ce2a200/hide-secrets-blocks-advisor' 2026-06-22 17:44:48 +02:00
can1357 3e345a50a1 Merge remote-tracking branch 'origin/farm/8689c858/model-discovery-cache-ttl' 2026-06-22 17:44:39 +02:00
can1357 d025803cb6 Merge remote-tracking branch 'origin/farm/923f93e8/perplexity-isavailable-openrouter-leak' 2026-06-22 17:44:31 +02:00
can1357 3c98cc556c Merge remote-tracking branch 'origin/farm/0008d917/png-string-paste-image' 2026-06-22 17:44:01 +02:00
can1357 75acaa40f1 Merge remote-tracking branch 'origin/farm/4801c6f1/stdio-transport-merge-process-env' 2026-06-22 17:43:52 +02:00
can1357 beb61b1831 Merge remote-tracking branch 'origin/farm/f3af36ee/clear-openai-completions-on-switch' 2026-06-22 17:43:34 +02:00
can1357 0fbcb63539 fix: preserved shells with running background jobs
- Added `Shell.liveBackgroundJobCount` to query active background processes.
- Retained per-call `:async:` shells if background jobs are still running upon turn completion.
- Reaped shells automatically once their last background process exits to prevent lingering processes.
2026-06-22 17:25:19 +02:00
can1357 26c72689c2 feat(coding-agent): added share.store setting for session uploads
- Added a `share.store` configuration option (`blob` | `gist`) that allows users to choose between the default share server or a GitHub gist for storing exported session data.
- Changed the default upload target from secret GitHub gists to the share server to avoid GitHub API rate limits for shared sessions.
- Enabled fallback to the share server when a gist upload fails or the GitHub CLI is unavailable.
2026-06-22 17:25:05 +02:00
roboomp 45b200cd09 fix(coding-agent): evicted resolved completions session URLs
The completions provider stores session state under the request-time resolved base URL, which can differ from the catalog baseUrl for Moonshot, Alibaba Coding Plan, Azure deployments, and similar provider overrides. The model-switch cleanup now evicts the previous provider prefix whenever the switch leaves that completions backend, so those resolved-url keys cannot survive the switch.
2026-06-22 13:39:48 +00:00
roboomp 596a2d1317 style: bun run fix 2026-06-22 13:30:10 +00:00
roboomp 8cebe98d2f fix(coding-agent): evicted openai-completions provider session state on backend switch
`AgentSession.#closeProviderSessionsForModelSwitch` only handled
`openai-codex-responses` and `openai-responses:<provider>` keys. The
`openai-completions:<provider>:<baseUrl>:<modelId>` entries — which cache
strict-tools disable scopes and reasoning-effort fallbacks tied to the
upstream backend — survived /model switches between different providers or
base URLs, so the next request to that backend (e.g. on /model toggle
back) replayed stale decisions made against an entirely different
transport.

Switching to a model whose `(provider, baseUrl)` differs from the current
openai-completions model now evicts every cached entry sharing the old
prefix. Same-backend model toggles keep their cached state, matching the
existing codex/responses semantics.

Fixes #3260
2026-06-22 13:30:01 +00:00
roboomp 0b88ab32f8 fix(mcp): wrap unresolvable Windows commands in cmd.exe for PATHEXT lookup
Bun.spawn -> CreateProcess only appends `.exe` to extensionless names; `.cmd`/`.bat` are never tried. Bare MCP commands like `npx` (which exists only as `npx.cmd` on Windows) crashed the subprocess ~140ms after spawn with ENOENT/EINVAL whenever our own PATH walk couldn't pin the file down (empty `Bun.env.PATH` under a restricted parent process, UNC mounts that reject `fs.access`, locked-down shells).

`resolveStdioSpawnCommand` now routes any unresolved bare command through `cmd.exe /d /s /c` so Windows's PATHEXT search runs Windows-native. Direct-spawn fast path is preserved for resolved `.exe`/`.com` files; the existing `.cmd`/`.bat` wrap is unchanged. The reporter's stated cause ("process.env not merged") was incorrect — the merge has been in place at `transports/stdio.ts:316-319` since well before 16.1.14 — but the symptom they hit is real.

Fixes #3250
2026-06-22 10:49:42 +00:00
roboomp fe9ffc7912 fix(tui): preserved bare png filename pastes
Require bracketed image-path paste detection to see an explicit local path separator or file URI before routing .png-like text to image attachment handling.\n\nFixes #3253
2026-06-22 10:46:24 +00:00
roboomp 5258c5d6e3 fix(coding-agent): stop perplexity auto-chain from hijacking openrouter auth
PerplexityProvider.isAvailable() accepted authStorage.hasAuth("openrouter")
as a valid credential, so any user with an OpenRouter key configured (for
LLM access) had every webSearch: auto request silently routed through
OpenRouter's perplexity/sonar-pro endpoint. Since Perplexity sits first in
SEARCH_PROVIDER_ORDER, downstream providers like Gemini were never reached
and users saw unexpected charges on their OpenRouter billing.

Auto-chain admission now requires a direct Perplexity credential
(PERPLEXITY_COOKIES, Perplexity OAuth, or PERPLEXITY_API_KEY).
isExplicitlyAvailable still returns true, so users who want the
OpenRouter-backed perplexity/sonar-pro path can opt in by setting
webSearch: perplexity explicitly — the existing OpenRouter fallback in
getApiConfigs handles that case unchanged.

Fixes #3251
2026-06-22 10:42:37 +00:00
roboomp c2339cd477 fix(providers): refreshed discovery cache after config edits
Configured provider discovery now treats models.yml/models.json edits as a cache staleness boundary, forcing online-if-uncached refreshes instead of reusing fresh rows written before the config change.

Added regression coverage for Ollama metadata overrides with a pre-existing models.db row.

Fixes #3242
2026-06-22 08:04:17 +00:00
roboomp 426ca4bf03 fix(coding-agent): redacted nested advisor custom details
Walked custom/hook `details` recursively through the obfuscator so nested renderer fields (e.g. async-result `jobs[].label`) cannot leak configured secrets into the advisor prompt.

Fixes #3237
2026-06-22 07:24:51 +00:00
roboomp df71f9bc18 fix(coding-agent): redacted advisor file mentions
Rewrote file-mention path and content through the configured obfuscator before the advisor delta is formatted, matching the primary provider's hide-secrets behavior.

Fixes #3237
2026-06-22 07:20:11 +00:00
roboomp 2d65f29d90 fix(coding-agent): redacted advisor context before formatting
Redacted structured advisor delta messages before markdown/XML formatting so secrets containing XML-significant characters still match configured hide-secrets entries.

Added regression coverage for expanded primary-context redaction.

Fixes #3237
2026-06-22 07:14:05 +00:00
roboomp a7ee69ffff style: bun run fix 2026-06-22 07:05:46 +00:00
roboomp 7dadeab331 fix(coding-agent): hid secrets from advisor prompts
Stopped restoring placeholders inside opaque assistant thinking blocks and threaded the configured secret obfuscator into advisor session-update prompts.

Added regression coverage for thinking preservation and advisor prompt redaction.

Fixes #3237
2026-06-22 07:05:23 +00:00
can1357 eb8ed9c6bd feat(coding-agent/prompts): enforced specialized tool usage over bash commands
- Updated system and tool prompts to explicitly forbid using shell utilities like grep, rg, awk, and find for tasks better suited to specialized tools.
- Clarified that bash should be reserved for terminal operations and computational pipelines that produce facts not available through existing specialized tool outputs.
2026-06-22 08:07:40 +02:00
can1357 4e54e557bc feat: improved context usage display and update model configurations
- Updated status line to display token usage with an unknown context marker (" 5K/? ") when the model context window is unavailable.
- Updated `fugu` model specifications in `models.json` and catalog constants with corrected pricing, increased context windows, and disabled stream idle timeouts.
- Corrected OpenAI usage accounting by excluding redundant orchestration input tokens in `openai-shared` logic.
2026-06-22 08:04:42 +02:00
can1357 320261fca9 chore: bump version to 16.1.14 2026-06-22 07:23:40 +02:00
can1357 a94cadf723 refactor(coding-agent): standardized evaluation kernel and executor architecture
- Extracted common kernel and executor logic into `BaseKernel` and `executor-base` to eliminate duplicated implementations for Julia, Python, and Ruby.
- Migrated shared operational workflows--including session namespacing, environment filtering, and result mapping--to centralized backend helpers.
- Consolidated runtime discovery and resolution logic into a unified `runtime-env` utility module.
- Simplified language-specific modules by delegating subprocess lifecycle, IPC, and configuration management to the newly established base classes.
2026-06-22 07:22:10 +02:00
can1357 92bae8ab91 refactor(coding-agent): consolidated parallel API logic
- Centralized Parallel API utilities and parsing logic into a single module.
- Exported constants and helper functions from `parallel.ts` to replace duplicated definitions in the search provider.
- Updated the search provider to leverage the unified `parseParallelSearchPayload` function with metadata parsing toggled off.
2026-06-22 07:20:35 +02:00
can1357 6bdba2d3c9 test(coding-agent): cover opt-in eval backend schema gating
- Assert the eval tool hides disabled backends from the model-facing wire
  schema (language enum + field descriptions), summary, and description by
  default (rb/jl off), and advertises them once enabled — including the
  enabled-subset case.
- Update the env-flag fallback test for the new rb/jl opt-in defaults and
  extend the env guard to PI_RB/PI_JL so the suite is shell-independent.
- Note the opt-in default and dynamic advertising in the changelog.
2026-06-22 06:22:29 +02:00
can1357 c926eb381d feat(coding-agent/tools): made ruby and julia backends opt-in
- Changed default evaluation backend configuration to only enable Python and JavaScript by default.
- Implemented dynamic tool parameter generation to hide Ruby and Julia from the model's schema when they are disabled in settings.
- Updated tool summary and field descriptions to reflect the currently enabled runtime backends.
2026-06-22 06:13:01 +02:00
can1357 33e2594f03 feat(coding-agent): added support for Julia and display language icons in code cells
- Added Julia language support to the theme symbol maps.
- Enabled language icons in code cell headers for the eval tool renderer.
2026-06-22 06:13:01 +02:00
can1357 1f3f3cf5d1 feat: added ruby and julia language support to coding-agent
- Implemented persistent execution backends for Ruby and Julia using dedicated kernel processes and NDJSON-based IPC.
- Integrated language-specific prelude environments, runtime path resolution, and security-focused environment variable filtering.
- Exposed configuration options, tool schema updates, and lifecycle management for seamless agent interaction with both languages.
- Added comprehensive integration tests and updated prompt documentation to support the new evaluation capabilities.
2026-06-22 06:13:01 +02:00
can1357 93db34b0d5 refactor(coding-agent): consolidated editor state and unify transcript rendering
- Centralized draft state and image management by migrating fields from context to the CustomEditor component.
- Standardized transcript row construction by introducing shared helpers for background jobs, IRC traffic, and file mentions.
- Refactored redundant UI logic and helper functions into reusable utility modules to streamline message submission and component rendering.
- Standardized event handler types by consolidating lifecycle definitions into a shared module while maintaining public API stability.
2026-06-22 06:11:57 +02:00
can1357 c204d1b30c refactor(coding-agent): removed redundant readHashLines setting
- Removed the `readHashLines` setting to consolidate hashline display logic.
- Simplified `resolveFileDisplayMode` to derive hashline visibility solely from the active edit mode.
- Added automatic cleanup of the `readHashLines` key from existing configuration files.
2026-06-22 06:11:28 +02:00
can1357 be3687a5f1 feat(tui): improved settings list wheel interaction handling
- Implement `handleWheelAt` to restrict wheel scrolling to the settings pane.
- Update selection movement to support clamping when scrolling at boundaries.
- Add tests to verify boundary behavior and spatial constraints.
2026-06-22 06:10:17 +02:00
can1357 1750973503 refactor(coding-agent): established shared subprocess infrastructure to
- Established shared `subprocess` infrastructure to standardize worker IPC, environment resolution, and error handling.
- Migrated mnemopi, speech-to-text, tiny-model, and TTS clients to utilize consolidated worker-client utilities.
- Implemented common runtime helpers for ONNX model loading, logging, and process readiness probing.
- Eliminated redundant local spawn logic and environment mapping across all inference worker clients.
2026-06-22 05:50:07 +02:00
can1357 7e247eac46 refactor(coding-agent/prompts): updated system and tool prompts to present
- Updated system and tool prompts to present dedicated tools as preferred defaults rather than absolute prohibitions.
- Relaxed the hard-forbidding of shell equivalents for file operations, searching, and editing.
- Retained guidance on prioritizing tools for their gitignore semantics, structure, and line-anchoring capabilities.
2026-06-22 05:44:10 +02:00
can1357 2361775e9f refactor(coding-agent): consolidated TUI component shared logic
- Introduced `selector-helpers.ts` to centralize reusable list, dashboard, and selection utilities.
- Refactored `AgentDashboard`, `ExtensionList`, `HistoryResultsList`, and `TreeList` to use standardized rendering and navigation helpers.
- Encapsulated viewport padding, scrolling logic, and key matching to reduce code duplication across TUI components.
- Maintained consistent scrollbar themes and keyboard behaviors while simplifying component-specific implementations.
2026-06-22 05:41:32 +02:00
can1357 fe33b372f9 refactor(coding-agent): consolidated message framing logic
- Extracted incremental byte-stream framing logic into a shared `MessageFramer` class.
- Replaced redundant, per-client implementations in `dap/client.ts` and `lsp/client.ts`.
- Centralized buffer management to avoid O(n^2) allocation patterns during large message bursts.
2026-06-22 05:29:00 +02:00
can1357 cc0c67beb1 chore: bump version to 16.1.13 2026-06-22 04:47:47 +02:00
can1357 fc01e3b6cb feat: added devin provider support
- Implemented the Devin inference provider, including OAuth flow with PKCE, Connect protocol integration, and streaming support for chat requests.
- Integrated comprehensive Protobuf-based service definitions and generated TypeScript clients for Devin's API infrastructure, including model management and workspace operations.
- Updated the AI and Catalog modules to support dynamic model discovery, provider-specific configuration, and authentication.
- Standardized tool call arguments as `Record<string, unknown>` across provider implementations to ensure type safety.
2026-06-22 04:45:17 +02:00
can1357 0a1323ae80 chore: bump version to 16.1.12 2026-06-22 01:14:32 +02:00
can1357 7302a7ae96 feat(coding-agent): improved secret obfuscation and data protection
- Refined obfuscation logic to use granular, typed transformations instead of generic object traversal.
- Enforced an 8-character minimum for secret patterns and restricted redaction to user-authored content to prevent false positives.
- Preserved system prompts, tool schemas, and opaque remote replay data to maintain provider context and data integrity.
- Integrated protected snapshot exports with targeted redaction to safeguard sensitive information in shared sessions.
2026-06-22 01:13:52 +02:00
can1357 aa1dbde498 Merge remote-tracking branch 'origin/farm/a2703356/enforced-rpc-behavior-left-over' 2026-06-21 23:29:39 +02:00
can1357 7315059812 Revert "fix(coding-agent): prevented WebP encoding for Codex-bound images"
This reverts commit 2e6e0ea3b3.
2026-06-21 23:29:10 +02:00
roboomp 816f47540a fix(rpc): preserved explicit caller config across host-defaulted paths
Re-added the isConfigured guard inside applyDefaultSettingOverrides so the
runtime override applied at RPC/ACP startup only fills holes — explicit
embedder/project/--config/global values now survive for task.isolation.{mode,
merge,commits}, task.{eager,batch,maxConcurrency,maxRecursionDepth,disabledAgents,
agentModelOverrides}, memory.backend, memories.enabled, advisor.{enabled,
subagents,syncBacklog,immuneTurns}, plus the RPC-only async.{enabled,maxJobs}
and bash.autoBackground.{enabled,thresholdMs}. The guard was originally added
for #2598 and had quietly regressed, so the override re-asserted the schema
default and clobbered every explicit value — matching the contract problem
#2828 already fixed for the todo paths.

Replaced the prior 'default-disables advisor' test (which codified the
clobbering as the contract) with a comprehensive 'honors explicit
host-defaulted settings' regression covering every contested path across
rpc/rpc-ui/acp.

Fixes #3207
2026-06-21 19:58:28 +00:00
can1357 7962a39f86 chore: bump version to 16.1.11 2026-06-21 18:34:15 +02:00
can1357 816f4d060d chore: update changelogs 2026-06-21 18:33:57 +02:00
can1357 266723a870 Merge remote-tracking branch 'origin/farm/fb97f79d/fix-prompt-template-optimistic-render' 2026-06-21 18:31:42 +02:00
can1357 838b5162bc feat(coding-agent): standardized html export styling with brand palette
- Introduced `web-palette.ts` to implement the collab-web pink/purple brand identity for HTML exports.
- Updated `generateThemeVars` to support a `palette` option, allowing users to choose between the brand-web aesthetic and a specific TUI theme.
- Configured public exports and the share-viewer script to default to the brand-web palette rather than inheriting the user's terminal theme.
- Refactored `AgentSession.exportToHtml` to align with the new branding defaults while allowing for per-export theme overrides.
- Adjusted `dark.json` background values to ensure better visual consistency across internal surfaces.
2026-06-21 18:31:03 +02:00
can1357 1cb433cbde feat(coding-agent): added browser navigation helpers and improved timeout management
- Implemented `waitForSelector` and `waitForNavigation` methods in the browser tool API.
- Introduced per-operation fail-fast budget management with dynamic timeout clamping.
- Added validation for selector engines to reject unsupported Playwright-only platform features.
- Standardized error handling to provide descriptive, named timeouts for stalled browser operations.
2026-06-21 18:10:10 +02:00
can1357 2e6e0ea3b3 fix(coding-agent): prevented WebP encoding for Codex-bound images
- Updated model detection to exclude WebP format for Codex-based providers, which do not support it.
- Forced the image resize pipeline to encode to PNG or JPEG for incompatible models to resolve transmission errors.
- Added test coverage to verify that WebP images are re-encoded when using the Codex Responses backend.
2026-06-21 18:00:18 +02:00
roboomp 1c22d32640 test(tui): restored event-controller optimistic stubs
Added clearOptimisticUserMessage and replaceOptimisticUserMessage stubs to the EventController message_start test double so the optimistic-submission case no longer throws when the controller reconciles the signature.

Fixes #3199
2026-06-21 15:49:58 +00:00