Commit Graph

80 Commits

Author SHA1 Message Date
usr-bin-roygbiv 9ceebb2a4d fix(workers): isolate compiled host selectors 2026-07-25 08:31:54 +00:00
usr-bin-roygbiv 237692deab fix(computer-use): re-enter single worker host 2026-07-25 07:45:56 +00:00
usr-bin-roygbiv a7e988b604 fix(computer-use): isolate worker process entry 2026-07-25 07:13:12 +00:00
usr-bin-roygbiv f1fb05df80 fix(eval): statically link rejection interceptor 2026-07-25 04:24:25 +00:00
usr-bin-roygbiv fe985551c5 fix(eval): preserve process bootstrap boundary 2026-07-25 01:30:04 +00:00
usr-bin-roygbiv c34e3ae819 fix(computer-use): preserve lazy native pairing 2026-07-25 00:53:58 +00:00
usr-bin-roygbiv 8e2d654880 fix(computer-use): route enabled desktop control 2026-07-25 00:42:23 +00:00
usr-bin-roygbiv 8af48840fe fix(coding-agent): statically dispatch computer worker 2026-07-25 00:42:23 +00:00
usr-bin-roygbiv b9504f65e7 feat: add native Codex computer use 2026-07-24 01:40:04 +00:00
roboomp 30953d3bfe fix(cli): errored on unknown __omp_worker_ selectors
Unknown reserved __omp_worker_* selectors hit the worker-host re-entry
seam, runWorkerEntrypoint returned false, and the ignored result let the
process exit 0 with empty stdout/stderr. A stale or mistyped selector
looked healthy to parent processes and install smoke paths.

Check runWorkerEntrypoint's return at the dispatch seam: an unrecognized
selector now writes "Error: unknown worker selector: <arg>" to stderr and
sets a nonzero exit code without starting a worker. Known selectors and
normal CLI arguments are unchanged.

Fixes #5712
2026-07-16 14:15:44 +00:00
Colin Mason a83f461b35 lazy load js eval process entry in cli 2026-07-13 09:57:20 -04:00
Colin Mason 640d7c83b9 propagate ipc clone errors to eval cells 2026-07-13 09:57:20 -04:00
Colin Mason 9c9da2387d harden js eval subprocess 2026-07-13 09:57:19 -04:00
Colin Mason c40ccdc684 isolate eval runtimes from terminal 2026-07-13 09:57:19 -04:00
can1357 4cfec93458 feat(coding-agent/launch): introduced persistent project service tool
- Introduced a project-scoped `launch` tool to orchestrate long-running services, debuggers, and watchers with persistent execution capabilities.
- Implemented a robust daemon broker with Unix/Windows IPC transport that manages process lifecycles, readiness monitoring, and automatic log rotation.
- Added detached process support to ensure services persist independently of the main application lifecycle, including recovery and cleanup mechanisms.
- Updated the `bash` interceptor to prioritize the new `launch` tool for background processes and provided comprehensive documentation for lifecycle and signal handling.
2026-07-13 04:21:55 +02:00
can1357 3d2568060a fix(coding-agent): dispatched CLI entry in Bun.build-compiled windows binaries
- Bun.build-API compiled Windows executables report import.meta.main === false
  (standalone loader keys the entry module with backslashes but registers the
  main path with forward slashes), so cli.ts never dispatched: the binary
  exited silently with code 0 and omp update rolled back after failing to
  verify the new version.
- Entry dispatch and worker-host declaration now also honor the define-folded
  PI_COMPILED marker, which is only true inside compiled binaries where the
  entry module is by definition the process entry.
- Verified on a Windows VM: --version prints omp/16.4.3 and --smoke-test
  passes (stats sync worker + tiny-model subprocess) on a cross-compiled
  binary; v16.4.3 release binary reproduces the silent exit.
2026-07-11 11:08:55 +02:00
can1357 41cc57c238 feat(coding-agent/tts): redesigned streaming speech vocalization
- Added `SpeakableStream` to strip markdown noise, silence code blocks and tables, normalize links and paths, and emit sentence/clause segments.
- Reworked `Vocalizer` to segment assistant deltas in the parent process, lazily open TTS streams, idle-flush partial thoughts, and chain playback sessions.
- Added gapless streaming playback with ffmpeg/sox backends, ducking-aware pacing, fallback file playback, and immediate stop handling.
- Added IPC `sendAndFlush` support and used it in the TTS worker so audio chunks drain before blocking ONNX inference resumes.
- Added speakable-stream coverage for markdown filtering, segmentation latency, idle flushing, and forced long-segment splits.
2026-07-02 08:30:58 +02:00
roboomp bf56a76e59 fix(mnemopi): isolated local embeddings worker in subprocess to skip onnxruntime napi crash
Moved mnemopi's local embedding provider out of the main agent process by
spawning a dedicated `Bun.spawn` child for fastembed + onnxruntime-node. The
agent CLI gains a hidden `__omp_worker_mnemopi_embed` dispatch; `loadMnemopi`
/ `loadMnemopiCore` install the subprocess-backed initializer through the
newly-exposed `setLocalModelInitializer` seam so every `embed()` call
round-trips through IPC instead of loading the NAPI module. The parent
SIGKILLs the child on dispose so the destructor that segfaults Bun on
Windows shutdown (NAPI finalizer at exit on npm installs, `process.dlopen`
constructor at session start on standalone binaries) never runs in any
address space the agent owns. Mirrors the tiny-model fix from #1607.

Adds `smokeTestMnemopiEmbedWorker` to `omp --smoke-test`, a new
`test/issue-3031-repro.test.ts` that pins the spawn/dispatch/signal-exit
contract and forbids re-importing `fastembed-runtime` from the agent surface,
and changelog entries.

Fixes #3031
2026-06-19 08:09:50 +00:00
can1357 d182db3973 feat(coding-agent): implemented gitignore-aware scan command to ttsr cli
- Added the `scan` action to `ttsr` CLI with support for gitignore-aware file globbing.
- Integrated AST pre-filtering and optimized AST/regex matching to evaluate scan rules.
- Implemented file size limits, binary file detection, and custom `--no-gitignore` and `--max-bytes` flags.
- Introduced comprehensive test suites validating directory mapping, exclusions, and size-limit enforcement.
2026-06-18 01:57:23 +02:00
can1357 db58a163b2 fix(coding-agent): isolated JS eval runtime globals across runtime lifetimes
- Made `JsRuntime` track the realm globals it installs (`#globalOwner`, `#ownedGlobalKeys`, `PRELUDE_GLOBAL_KEYS`) and reclaim them in `dispose()`, re-binding ownership through `#activateGlobals()` on cwd/run-scope/run; disposing an older inline/direct runtime no longer deletes a newer runtime's helper globals, and overlapping same-realm runs are serialized via `enterGlobalRun`.
- Added `WorkerCore.dispose()` (rejects pending tool calls with `ToolError` and disposes the runtime) and invoked it from `spawnInlineWorker` teardown in `context-manager.ts`.
- Updated the `js-static-import-rewrite` test to snapshot and restore any pre-existing `__omp_import__` global instead of unconditionally deleting it.
- Added `runtime-global-dispose.test.ts` covering newer-runtime global survival, older-runtime reactivation, and cross-runtime mutation rejection.
- Clarified the `runWorkerEntrypoint` comment in `cli.ts` about `parentPort` sync-prefix buffering for tab/eval workers.
2026-06-17 01:21:33 +02:00
can1357 3ab675a83b fix: added buffered worker inboxing and standardized worker selectors
- Added `WorkerInbox` and `installWorkerInbox(port)` to queue worker messages before bind.
- Added `consumeWorkerInbox()` to replay buffered messages and clear one active inbox.
- Added buffered inbox consumption in JS and tab worker transports before direct message handlers.
- Normalized worker selector arguments to the `__omp_worker_*` naming across workers and tests.
2026-06-15 11:59:44 +02:00
Ogrodev f9bc96e96c fix(coding-agent): harden profile auth shipping gaps 2026-06-14 20:30:50 -03:00
Ogrodev 0123a46f83 Merge remote-tracking branch 'upstream/main' into feat/profiles-and-alias
# Conflicts:
#	packages/coding-agent/src/cli/args.ts
2026-06-14 19:10:31 -03:00
can1357 b830f7912b feat: unified speech setup and introduced local STT/TTS capabilities
- Added unified `omp setup speech` flow with JSON/check modes and model picker.
- Added local STT pipeline with sherpa workers, recorder/download flow, and streaming inference.
- Added local TTS pipeline with `omp say`, backend selection, and streaming vocalization.
- Replaced legacy speech settings with unified `speech`/`speechgen` configuration keys.
2026-06-14 16:07:44 +02:00
Ogrodev 75694dc49c Merge upstream/main (15.11.0) into feat/profiles-and-alias
Conciliated changelogs: branch entries kept under [Unreleased] above
upstream's new 15.11.0 release section in coding-agent and utils.
2026-06-10 19:08:49 -03:00
Ogrodev 4d4c745bb9 Merge upstream/main (force-rewritten) into feat/profiles-and-alias
Upstream force-rewrote history; this branch carried old-SHA twins of the
rewritten commits. All non-goal conflicts resolved to upstream (verified
ours == old upstream tip). Goal-side reconciliation:
- cli.ts: profile bootstrap woven into the new lazy-import/resolveCliArgv
  structure; worker-host entry declaration deferred until after profile
  selection (pi-utils/env eagerly snapshots the agent dir .env); the
  floating runCli call guarded with import.meta.main || !Bun.isMainThread
  so importing runCli stays side-effect free while Worker re-entry works.
- args.ts/flag-tables.ts: kept profile/alias branches; upstream's new
  repeatable --config overlay flag moved into STRING_SETTERS.
- Changelogs: upstream-released bullets deduped out of Unreleased; profile
  entries restored under Unreleased.
- task/index.ts: removed duplicated validateTaskIds block from auto-merge.
2026-06-10 08:17:40 -03:00
can1357 6b76463941 fix: fixed stats dashboard asset serving for bundled CLI distributions
- Fixed npm CLI bundling by invoking `generate-client-bundle.ts --generate` before build and `--reset` after.
- Added `PI_BUNDLED` handling in `packages/stats/src/server.ts` and switched bundled distributions to embedded assets.
- Decoded embedded archives via `decodeEmbeddedClientArchive` and treated legacy placeholder content as missing.
- Handled missing dashboard source/build directories as ENOENT during mtime scans to avoid startup crashes.
- Extended `--smoke-test` to start the stats server and validate dashboard HTML contains expected asset markers.
2026-06-10 10:45:31 +02:00
danzaio e2c7c45ff8 fix(cli): limit extensions guard to bare command 2026-06-10 08:31:37 +02:00
danzaio da1ad85dbe fix(cli): reject ambiguous extensions command 2026-06-10 08:31:37 +02:00
can1357 dc5c93462f feat: rerouted worker subprocesses through the bundled CLI host entrypoint
- Rerouted sync, tab, js-eval, and tiny workers to re-enter CLI modes via `__omp_*` selectors.
- Adjusted `cli.ts` startup to dispatch worker entrypoints before parsing and exit 1 on uncaught errors.
- Bundled CLI as `dist/cli.js` in prepack, switching `omp` binary and published files.
- Removed explicit Bun `--compile` worker entrypoints from build/release scripts in favor of host-entry dispatch.
- Added `declareWorkerHostEntry()` and `workerHostEntry()` environment helpers and `PI_COMPILED` binary detection.
2026-06-10 03:57:31 +02:00
Ogrodev b99039ded2 fix(coding-agent): profile-scope native config discovery and load symlinked extension dirs
Native user-level config discovery (MCP, skills, rules, slash commands, prompts, instructions, hooks, tools, settings, extensions, and the top-level SYSTEM.md/RULES.md/AGENTS.md) now resolves the user scope through getAgentDir() in builtin.ts, omp-extension-roots.ts, and the discovery-layer getUserPath() helper. A named profile sees only its own ~/.omp/profiles/<name>/agent config instead of the default profile's ~/.omp/agent leaking into every profile, matching the /mcp config writer and getMCPConfigPath("user").

discoverExtensionModulePaths now detects top-level symlinked directories that the native glob skips (follow_links=false) and synthesizes their index/package.json entry-point matches, so an extension shared across profiles via a symlink loads like a real directory. Symlinked extension files were already handled.

cli: check --tiny-worker on the profile-flag-stripped resolvedArgv, matching the adjacent --smoke-test check and launch routing.
2026-06-04 15:07:55 -03:00
Ogrodev fc6ed84c26 Merge upstream/main into feat/profiles-and-alias 2026-06-01 11:31:15 -03:00
roboomp 5843a78dbf fix(tiny): isolated tiny model worker in subprocess to skip onnxruntime napi crash
Moved the tiny title/memory worker from a Bun Worker thread into a child process spawned via Bun.spawn IPC. The agent CLI gains a hidden --tiny-worker dispatch the parent invokes through process.execPath; the parent SIGKILLs the child on dispose so onnxruntime-node's NAPI finalizer never runs in any address space the agent owns. On Windows that finalizer was segfaulting Bun at shutdown after the tiny title model loaded (issue #1606). Drops the now-dead 'close'/'closed' handshake and the unused parentPort bootstrap, and removes tiny/worker.ts from --compile worker entries in both build scripts plus the regression test that pinned them.

Fixes #1606
2026-05-31 21:02:25 +00:00
Ogrodev cff1358559 Merge branch 'main' of https://github.com/can1357/oh-my-pi into feat/profiles-and-alias
# Conflicts:
#	packages/utils/src/dirs.ts
2026-05-31 14:12:13 -03:00
Ogrodev 1f67c58034 Merge branch 'main' of https://github.com/can1357/oh-my-pi into feat/profiles-and-alias
# Conflicts:
#	packages/coding-agent/src/cli.ts
#	packages/coding-agent/src/cli/args.ts
#	packages/coding-agent/src/main.ts
#	packages/utils/src/dirs.ts
2026-05-31 12:00:00 -03:00
can1357 20c019fccb refactor(cli): moved MallocStackLogging cleanup to cli entrypoint
- Removed env var deletion from utils/dirs.ts (wrong layer).
- Placed it in the CLI entrypoint so it runs before any subprocess inherits the env.
2026-05-31 16:57:22 +02:00
can1357 0986a9e605 refactor(dirs): moved malloc env scrubbing into dirs module import
- Removed `scrubProcessEnv` from procmgr and its explicit call in cli.ts.
- Scrubbing now happens automatically when `dirs.ts` is imported, eliminating the need for a manual call at startup.
2026-05-30 22:26:52 +02:00
can1357 826c3b932d refactor(packages/coding-agent): reorganized tiny-title runtime stack
- Added tiny-title protocol contracts, including progress-state unions, message payloads, and transport interfaces.
- Added title text utilities to truncate long inputs, wrap `<user-message>` blocks, and normalize generated titles.
- Added tiny-title model registry and helpers with type-safe keys and runtime optional loading via optionalDependencies.
- Added client-side worker orchestration with spawn fallback, request queueing, progress/error routing, and smoke-test APIs.
- Added worker runtime for model resolution, prompt-based inference, lock-based install retries, and close-time cache clear.
2026-05-30 17:40:18 +02:00
can1357 b890345808 feat: added tiny-title worker to CLI/release entrypoints plus cleanup
- Added usage tips content and rendered one random tip in the welcome component.
- Implemented tip rendering rules to skip narrow boxes, truncate long text, and style output.
- Added tiny-title worker to binary and release entrypoints, including repro test coverage.
- Added tiny-title worker smoke-test execution and shutdown cleanup in the session disposal path.
2026-05-30 16:55:54 +02:00
Ogrodev 2e4f258050 fix(profiles): harden alias upsert, env precedence, and bootstrap flag handling
- profile-alias: refuse to rewrite a managed block whose start marker lacks a
  matching end marker instead of appending, which on the next install would
  splice from the stale start through the new end and delete intervening user
  shell config (data loss in dotfiles).
- dirs/cli: add resolveProfileEnv so OMP_PROFILE takes precedence and an
  explicitly-empty OMP_PROFILE selects the default profile instead of falling
  through to PI_PROFILE; share the rule across both env-read sites.
- dirs: reject uppercase profile names so profile identity/isolation is stable
  across case-sensitive and case-insensitive filesystems.
- profile-bootstrap: treat an unclassified bare long option as a possible
  extension string flag and forward its successor untouched (never as a global
  --profile/--alias), while exempting known value-less launch flags via
  VALUELESS_FLAGS so 'omp --print --profile work' still selects a profile.
- tests: cover all four contracts.
2026-05-30 11:05:30 -03:00
Ogrodev db8e090f91 fix(coding-agent): surface invalid inherited profile env as clean CLI error
- Revalidate OMP/PI profile env in runCli when no explicit --profile is passed
- Convert module-load profile parse failures into CLI error reporting path
- Preserve successful execution flow for valid profile selection paths
- Add integration test ensuring invalid env emits clear error and non-zero exit
2026-05-30 09:08:16 -03:00
Ogrodev bf15496d5a fix(coding-agent): avoid eager env side effects during CLI bootstrap
- Use @oh-my-pi/pi-utils/dirs as the CLI import surface instead of the broader pi-utils entry.
- Replace procmgr.scrubProcessEnv usage with direct removal of MallocStackLogging env vars before subprocesses.
- Move installProfileAlias to a static top-level import to avoid deferred module loading during bootstrap.
2026-05-29 22:33:30 -03:00
Ogrodev 203b5275a7 Restore native Hashline exports 2026-05-29 22:12:43 -03:00
Ogrodev c800e1524a Merge remote-tracking branch 'upstream/main' into feat/profiles-and-alias
# Conflicts:
#	packages/coding-agent/src/cli.ts
2026-05-29 21:55:39 -03:00
roboomp db525316ab fix(discovery): wire extension package sub-dirs into discovery + add top-level install command
Bug 1: capability loaders in src/discovery/builtin.ts only walked
.omp/ and ~/.omp/agent/, so extension packages registered via
extensions: in settings or --extension on the CLI shipped their
skills/, hooks/pre|post/, tools/, commands/, rules/, prompts/, and
.mcp.json silently — the docs at omp.sh/docs/extension-authoring
advertise the opposite. Add a new omp-plugins discovery provider that
scans every configured extension package directory for those
sub-trees, plus a small omp-extension-roots helper that resolves the
union of settings-driven and CLI-injected roots. main.ts injects CLI
extension paths via injectOmpExtensionCliRoots before any capability
load.

Bug 2: install was never registered as a top-level subcommand, so
`omp install ./my-extension` was rewritten to `launch install
./my-extension` and forwarded to the LLM as an initial prompt. Add a
top-level install command that routes local paths to plugin link and
remote specs to plugin install. Extract the command table into
src/cli-commands.ts so tests can introspect registered subcommands
without triggering cli.ts's top-level await.

Fixes #1496
2026-05-29 06:16:32 +00:00
Ogrodev 680917f02a feat: added isolated profiles with --profile and --alias
Added named OMP profiles that isolate agent state (auth credentials,
sessions, settings, model cache, history, memories, blobs, plus
config root subdirs) under `~/.omp/profiles/<name>/agent/`. Activated
via `--profile <name>` or `OMP_PROFILE=<name>`; `default` maps back to
the regular `~/.omp/agent/` tree.

Added `--alias <command>` to generate a shell shortcut (e.g.
`omp-work`) that forwards `omp --profile <name>`. Detects the active
shell (bash, zsh, fish, PowerShell, pwsh), writes a wrapper into the
correct rc file, and preserves subcommands like `update`, `--version`,
and `--model` because the wrapper passes through argv unchanged.

The `--profile`/`--alias` bootstrap pre-parser lives in
`packages/coding-agent/src/cli/profile-bootstrap.ts` and runs before
any module that touches `getAgentDir()` (notably `@oh-my-pi/pi-utils/env`,
which eagerly loads `.env` from the agent directory at its own import
time). The pre-parser mirrors `parseArgs` value-consumption rules and
honors `--`, so commands like `omp --system-prompt --profile foo` pass
the literal `--profile` through as the prompt body instead of silently
activating profile `foo`.

XDG resolution for named profiles is keyed on the profile-specific
XDG path (`$XDG_*_HOME/omp/profiles/<name>`), never the base app root,
so a profile's location is decided once at first activation and stays
stable even after `omp config init-xdg` materializes the base later.
The default profile keeps its existing base-app-root check.

`setProfile(undefined)` (and `setProfile("default")`) restores the
pre-profile `PI_CODING_AGENT_DIR` snapshot taken at first activation
instead of unconditionally deleting it. `setAgentDir` refreshes the
snapshot since that call is the user explicitly redefining the
baseline.

Validation rejects profile names that match `.`/`..`, fail
`/^[A-Za-z0-9][A-Za-z0-9._-]{0,63}$/`, or hit a Windows reserved
device name (`CON`, `PRN`, `AUX`, `NUL`, `COM0-9`, `LPT0-9`, including
dotted variants like `CON.txt`) — those would let `setProfile` accept
the input only for directory creation to fail later with confusing
errors on Windows.
2026-05-27 07:50:45 -03:00
can1357 ebae144ad9 refactor(ai): removed HTTP/2 fetch patching bootstrap
- Deleted the `packages/ai/src/utils/h2-fetch.ts` HTTP/2 retry wrapper and removed its public export from `packages/ai/src/index.ts`.
- Removed the `installH2Fetch` import and invocation from `packages/coding-agent/src/cli.ts`, so the CLI no longer patches `fetch` for HTTP/2 negotiation.
- Updated `packages/coding-agent/CHANGELOG.md` to align the vim-mode removal notes with the code changes.
2026-05-26 13:16:59 +02:00
can1357 1228c96959 feat(coding-agent): added worktree list/clear CLI with orphan pruning
- Added the new `omp worktree` (`wt`) command with `list|clear`, `all/dry-run/json` options, and CLI registration.
- Added `listWorktrees`/`clearWorktrees` flows that scan worktrees, classify orphaned entries, emit JSON, and call `worktree.prune`.
- Replaced legacy path encoding with `hashPath` via `getWorktreeDir`, updating task isolation, storage keys, and PR checkout paths.
- Added bounded PR worktree path retries before `git worktree add` and updated checkout-path tests for hashed names.
2026-05-22 12:47:13 +09:00
can1357 df1c1a6ba8 feat(auth): added auth-gateway forward-proxy and broker usage/migrate endpoints
- Added `omp auth-gateway serve/token/status` — a forward-proxy injecting broker credentials for OpenAI Chat, Anthropic Messages, and OpenAI Responses wire formats.
- Added `GET /v1/usage` to auth-broker and auth-gateway; usage cache switched to 5-min per-credential TTL with jitter and last-good fallback on failure.
- Added `AuthStorage.setConfigApiKey/removeConfigApiKey/clearConfigApiKeys` so `models.yml` `apiKey` beats OAuth tokens without overriding `--api-key`.
- Added `omp auth-broker migrate --from-local` for idempotent upload of local SQLite/env credentials to the broker.
2026-05-16 23:25:10 +02:00
can1357 c3f5a60c22 feat(auth): added auth-broker for remote credential vault
- Added `AuthBrokerClient`, `RemoteAuthCredentialStore`, `AuthBrokerRefresher`, and `startAuthBroker` server in `packages/ai/src/auth-broker`.
- Renamed `AuthCredentialStore` class to `SqliteAuthCredentialStore`; extracted `AuthCredentialStore` as a persistence interface.
- Added `exportSnapshot`, `forceRefreshCredentialById`, `disableCredentialById`, and `upsertCredential` to `AuthStorage` for broker wire protocol.
- Added `omp auth-broker` CLI subcommand (serve, token, login, logout, import, status) and `discoverAuthStorage` broker-mode path keyed on `OMP_AUTH_BROKER_URL`.
2026-05-16 20:44:07 +02:00