Commit Graph

135 Commits

Author SHA1 Message Date
re2zero 9d0699e070 fix(coding-agent): resolve xd:// device dispatches against device user policy first
When an xd:// device is dispatched through the write tool, the outer
approval gate now consults tools.approval.<deviceName> before falling
back to tools.approval.write. This lets users scope allow/deny/prompt
to a single device mount without changing the blanket write tool policy.

The write tool's approval function returns { tier, policyKey: deviceName }
for xd:// device dispatches. resolveApproval uses the policyKey to look
up the user override on the device name, falling back to the invoking
tool's own policy when the device has none configured.

Adds:
- ToolApprovalDecision.policyKey field (optional, additive)
- policyKey-aware lookup in resolveApproval and requiresApproval
- Updated error messages naming the correct config key
- Unit tests for policyKey resolution and WriteTool integration

Fixes can1357/oh-my-pi#7923
2026-08-08 02:45:19 +08:00
can1357 bc39ffa265 feat: introduced omptype validation package and migrated workspace dependencies
- Introduce `@oh-my-pi/omptype` as a new ArkType-compatible schema validation package featuring a lazy JIT runtime, JSON Schema emission, and compatibility adapters.
- Replace `arktype` across workspace packages and test utilities with `@oh-my-pi/omptype`.
- Add benchmark suites, tests, and documentation for the new validation engine and adapters.
- Update workspace build, test runner, and release configurations to include the new package.
2026-08-03 21:56:48 +02:00
Márton Danóczy 7708f372b5 fix(hashline,coding-agent): key snapshot tag on actually-persisted content after ACP bridge writes
Root cause of the reported "edit tool silently reformats the whole
file" corruption: fs/write_text_file has no verbatim guarantee. When
an ACP client (e.g. Zed with format_on_save: on) reformats a buffer
on save, routeWriteThroughBridge reported the pre-write content as
successfully written, and Patcher.commit keyed the returned snapshot
tag on that same pre-write text instead of what actually landed on
disk. The next edit anchored on that tag then resolved hunks against
a baseline the file had already drifted away from, which is what
produced whole-file "corruption" from single-line hunks -- reproduced
live in this session against real Swift/JSON/TypeScript files with
Zed as the ACP client.

- routeWriteThroughBridge reads the file back after the bridge write
  and returns the verified content plus a drift flag (best-effort:
  ACP defines no ordering between the client acking the write and its
  own async format-on-save settling, so this degrades gracefully to
  the old stale-tag-on-next-read failure mode, never to corruption).
- HashlineFilesystem.writeText propagates that verified content in
  view-space (the same space readText returns -- e.g. a notebook's
  editable cell text, not its raw JSON), not storage-space, so tag
  validation on the next edit compares like with like.
- Patcher.commit keys fileHash/header/snapshot on the verified
  post-write content (normalized, so BOM/line-ending restoration never
  produces a false "drift") when it diverges from what was sent, and
  appends a warning naming the drift -- but deliberately leaves the
  returned `after` (and therefore the model-visible diff) scoped to
  the intended hunk. Diffing against the full drifted file would
  balloon the tool response to span every reformatted line (measured
  ~6.8x inflation on a 245-line file with one touched line); the
  warning is the correct O(1) channel for "your editor reformatted
  this," not an O(file-size) diff.
- write.ts keys its own snapshot header on the verified bridge content
  too (no diff-size concern there since write always replaces the
  whole file).

Caught via code review (dispatched against the first pass of this
fix): a naive "just use the verified content everywhere" fix broke
.ipynb editing outright (write-space vs read-space content mismatch,
tag invalid on every notebook edit) and would have inflated every
drifted edit response by ~6.8x. Both are now covered by regression
tests that fail against the pre-fix code and pass against this one.

(cherry picked from commit 35ab80e43be5800b2f48728e4400eb9fd7f7f7d2)
2026-07-29 23:08:38 +02:00
can1357 84a7937325 docs(tools): note the literal-path escape in the selector-list guard
The guard now probes the full target before refusing, so an existing file
named like a selector list stays writable. Say so in the CHANGELOG entry
and the readSelectorListMisfire doc comment.
2026-07-28 10:59:36 +02:00
can1357 c66fac2ddd fix(tools): let an existing literal selector-list filename stay writable
Probe the full target with probeLiteralPathExists before classifying it as a
mis-dispatched read-selector list, matching the single-selector guard, so an
existing POSIX file like 'report:1-2;archive:3-4' can still be overwritten.
2026-07-28 10:59:36 +02:00
can1357 fefccc4acb Merge PR #6811: fix(tools): refuse write targets shaped as a read-selector list (@roboomp) 2026-07-28 10:59:36 +02:00
can1357 21b3764b08 refactor(coding-agent): replaced xdevregistry with state interface and helpers
- Replaced the `XdevRegistry` class with the `XdevState` interface and pure helper functions across core and session tools.
- Updated session configurations, tool execution, and renderers to utilize canonical tool map initialization and sharing.
- Adapted unit tests and mocks to use `XdevState` and associated helper functions for permission and dispatch verification.
2026-07-28 03:34:36 +02:00
roboomp 4ac322db93 fix(tools): refuse write targets shaped as a read-selector list
The read-selector-misfire guard (#6123/#6387) short-circuited whenever
`content` was non-empty, so a semicolon-joined list of read selectors
(`a.txt:1-2;b/c.txt:3-4`) passed as a write path with content fell through
to ordinary filesystem creation and silently built a nested directory tree
in the workspace. `read` accepts no such list, so this shape is always a
mis-dispatched multi-file read.

Refuse any target that splits on `;` into 2+ segments each carrying its own
read selector, regardless of `content` — the non-empty-content escape hatch
covers a lone selector-shaped filename, never a `;`-list.

Fixes #6809
2026-07-27 14:20:33 +00:00
roboomp 144043ad48 fix(coding-agent): used session settings in file guards
Passed session-scoped settings through Edit and Write generated-file checks and fell back to schema defaults when no global singleton exists.

Guarded inline image sizing against an uninitialized global settings proxy and added isolated-session regression coverage.

Fixes #6549
2026-07-24 22:42:38 +00:00
roboomp 75668387db fix(write): guarded selector-shaped archive members
Applied the read-selector misfire check to archive members after loading
the archive entry map and before mutation. Missing empty selector-shaped
members now fail closed, while existing literal members remain writable.

Added regression coverage proving rejected writes leave archives unchanged.
2026-07-23 20:07:07 +00:00
roboomp c232c3af76 fix(write): reject local read-selector-shaped write targets
A read-only step that mis-dispatches read as write passes the full read
expression (src/foo.tsx:1-260:raw) as the target. Because a literal colon
filename is legal on POSIX (#4618), write resolved it to filesystem creation
and reported success, leaving a stray zero-byte file the model could not
recover from - the local analogue of the xd:// near-miss guard (#6123).

assertNotReadSelectorMisfire now fails closed when the tail parses as a
read-tool selector, the literal target is missing, and content is empty,
pointing at the equivalent read(...). Non-empty content stays the escape
hatch and existing literal colon filenames remain writable.

Fixes #6387
2026-07-23 18:39:36 +00:00
roboomp b2e7e34567 fix(write): let conflict:// writes reach the resolver
- Exempted the handler-less conflict:// scheme from the URI-like guard so parseConflictUri still splices registered blocks.
- Extended the near-miss regression to assert conflict://1 reaches the resolver.

Fixes #6123
2026-07-21 22:33:33 +00:00
roboomp ea5c816e65 fix(write): rejected unknown uri-like targets
- Blocked malformed and unregistered URI-like paths before filesystem resolution.
- Suggested canonical xd:// spelling while preserving explicitly escaped local paths.
- Added regression coverage for xdt://, xd:/, and xd/ near misses.

Fixes #6123
2026-07-21 21:19:53 +00:00
roboomp 912dd44068 fix(write): guarded xd approval evaluation failures
Schema-invalid JSON objects can reach mounted approval functions before xdev dispatch validates their arguments. Fall back to the exec tier when an approval function throws, preserving fail-closed prompting and allowing dispatch to surface its normal schema error.

Added regression coverage for ast_edit payloads containing null paths.

Fixes #5727
2026-07-16 17:29:17 +00:00
roboomp 5445beb6f5 fix(write): evaluate function-valued xd:// device approvals
The write approval gate discarded a mounted tool's function-valued
approval and never decoded the device JSON payload, defaulting the tier
to exec. Read/write xd:// operations then prompted in non-yolo modes
that permit them.

Now decode valid object payloads and resolve the mounted tool's normal
approval decision via resolveToolTier; malformed JSON, non-object
payloads, and unknown devices still fall back to exec and prompt.

Fixes #5727
2026-07-16 17:24:22 +00:00
can1357 9afedb591e feat(coding-agent): added opt-in task prewalk and tightened --tools and xdev behavior
- Added a `task.prewalk` option (default `false`), removed default task `prewalk` flags, and updated prewalk resolution so bunded generic task execution only prewalks when explicitly enabled.
- Enforced strict `--tools` validation in CLI parsing, making unknown tool names fail fast with `CliUsageError` instead of being silently filtered.
- Migrated legacy discovery settings (`tools.discoveryMode`, `tools.essentialOverride`, MCP discovery keys) into updated `tools.xdev` handling with preserved explicit override behavior.
- Hardened xdev/ACP execution flow by capping `docsAll` payloads with overflow listing and remapping `xd://` dispatches/approval gating for correct execute/read behavior and reduced duplicate prompts.
2026-07-15 18:39:36 +02:00
can1357 5ff277349c refactor(coding-agent): consolidated tool surface onto xd:// devices and hub
- Added the `xd://` virtual device protocol (`internal-urls/xd-protocol.ts`, `tools/xdev.ts`): tools declaring `loadMode: "discoverable"` are unmounted from the request tools array and driven via `read xd://` (list/docs+schema) and `write xd://<tool>` (execute), gated by the `tools.xdev` setting (default on) and inlined into the system prompt.
- Merged the `irc`, `job`, and `launch` tools into a single `hub` tool (`tools/hub/`, `async/job-manager.ts`): messaging keeps `send`/`inbox`/`list`, job control maps to `wait`/`cancel`/`jobs`, process supervision keeps `start`/`logs`/`stop`/`restart`/`describe` with `ps`, and the unified `wait` races background jobs against peer messages; SDK `IrcTool`/`JobTool`/`LaunchTool` are replaced by `HubTool`.
- Removed the hidden `resolve` tool in favor of the `xd://resolve`/`xd://reject`/`xd://propose` resolution devices, auto-including `write` whenever a deferrable tool or plan mode is present.
- Removed the BM25 tool-discovery system: the `search_tool_bm25` tool, the `tool-discovery` module, the `tools.discoveryMode`/`mcp.discoveryMode`/`mcp.discoveryDefaultServers`/`tools.essentialOverride` settings, per-tool MCP selection, and the `mcp_tool_selection` message type.
- Unified tool presentation on `ToolLoadMode` (`essential`|`discoverable`), replacing the custom-tool `xdev?: boolean` opt-out; custom, extension, MCP, RPC host, image-generation, and TTS tools now default to `discoverable`, and added a `satisfies` predicate to `SoftToolRequirement`.
- Removed the standalone `ssh` command tool and `ssh/ssh-executor` (the `ssh://` read/write/search protocol stays), and made `--tools` address hidden built-ins.
- Updated collab-web to render `xd://` dispatches and `hub` op families, dropped the `search_tool_bm25`/`ssh`/`report-finding` renderers, refreshed tool docs and prompts, and migrated the affected tests and changelogs.
2026-07-15 15:16:29 +02:00
can1357 946ba4bcea Merge PR #5044: fix(cli): parse max-time duration suffixes (@roboomp)
# Conflicts:
#	packages/coding-agent/src/cli/flag-tables.ts
2026-07-14 18:46:14 +02:00
can1357 1dfec0d161 Merge PR #5090: fix(advisor): reduce stale advisories via delta coalescing, WIP markers, and delivery annotation (@apoc)
# Conflicts:
#	packages/coding-agent/src/advisor/__tests__/advisor.test.ts
#	packages/coding-agent/src/advisor/runtime.ts
#	packages/coding-agent/src/session/agent-session.ts
2026-07-14 18:44:57 +02:00
can1357 a011e07d18 Merge PR #5078: fix(coding-agent): prevent memory URL writes from leaking to cwd (@roboomp) 2026-07-14 18:41:17 +02:00
can1357 7a0ae70313 feat(coding-agent/tools): implemented bulk conflict resolution via conflict://*
- Added `conflict://*` support to the `write` tool, allowing resolution of multiple conflicts in a single call using per-id directives.
- Implemented `parseBulkDirectives` to interpret `ID: @side` mappings from the raw input content.
- Enabled partial bulk resolution where unlisted conflict IDs remain registered for subsequent operations.
- Updated conflict documentation and tool summaries to reflect the new bulk resolution capability.
2026-07-11 18:23:57 +02:00
can1357 7e5e7e864d feat(coding-agent-tools): implemented auto-trimming for echo lines
- Implemented logic to automatically detect and trim redundant lines duplicating adjacent file content within conflict markers.
- Added delimiter balancing and boundary tracking to ensure accurate removal of echoed text while preserving EOL formatting.
- Updated user feedback to report the number of trimmed echo lines during write and conflict resolution operations.
- Expanded test coverage to include multi-line echo scenarios and integration validation of the repair process.
2026-07-11 17:04:23 +02:00
can1357 b0d98d9e2b fix(coding-agent): decoupled lsp diagnostics from tool execution
- Offloaded slow LSP diagnostics to a deferred channel in the `write` tool to prevent blocking agent execution for the full 3-second poll window.
- Abstracted deferred diagnostic logic into a reusable `DeferredDiagnostics` class to standardize tracking and deduplication across tools.
- Updated `WriteTool` to support `beginDeferredDiagnosticsForPath` callbacks, surfacing diagnostics as an aside instead of stalling the tool result.
- Added a regression test validating that `write` completes immediately while diagnostics arrive asynchronously.
2026-07-11 07:33:19 +02:00
roboomp a4f43be040 fix(coding-agent): rejected read-only internal url writes
Blocked write tool filesystem fallback for read-only internal URL schemes so memory:// targets cannot be materialized as project-relative paths.

Added a regression test covering memory://root/memory_summary.md writes and the leaked memory:/root path.

Fixes #5075
2026-07-10 14:18:53 +00:00
can1357 cde9ee7501 fix(tui): repainted write first partial result over pending tail preview
The first-result viewport-repaint gate assumed only streamed
__partialJson placeholder shapes (SSH) could re-anchor; the write
renderer's collapsed pending preview paints a tail window from decoded
content, so its first partial result re-anchored to the top of the file
and left the committed tail rows stale above the new frame.

Resolve forceFirstResultViewportRepaint per renderer as a boolean or an
(args, options) predicate evaluated at paint time: write opts in when a
collapsed preview outgrew the streaming tail window, SSH stays scoped to
the streamed-placeholder shape it always covered.

Adopted from PR #4478 (roboomp) with an allocation-free line-count scan
and terminal-buffer regression coverage.

Fixes #4477
2026-07-09 18:30:48 +02:00
can1357 9a319b8a89 Merge PR #4462: fix(lsp): notify servers about harness file writes (@roboomp) 2026-07-05 13:10:26 +02:00
roboomp 0b7f4865a7 fix(tui): handled invalid path render args
Validated path-like renderer inputs before calling path helpers so provider-supplied arrays or objects cannot crash TUI rendering before schema validation reports the bad tool call.

Added renderer regression coverage for read, write, and edit call/result components with array and object path arguments.

Fixes #4525
2026-07-04 15:47:52 +00:00
roboomp 74a8289404 fix(coding-agent): guarded write renderer content
Coerced runtime write content before preview rendering so truthy non-string transcript values cannot crash CR normalization, line counting, or highlighting.

Added regression coverage for pending write calls and merged write results with non-string runtime content.

Fixes #4495
2026-07-04 05:22:21 +00:00
roboomp 065f0da7c2 fix(lsp): threaded tool abort signal through ACP-bridge notify
Bridge-backed writes now respect tool timeout/cancel: routeWriteThroughBridge takes an optional AbortSignal and forwards it to notifyWorkspaceWatchedFiles, so a wedged LSP server no longer hangs the bridge path.

Updated write, replace, patch, and hashline callers to pass the tool signal.

Refs #4459
2026-07-03 15:57:42 +00:00
can1357 db8c79cc93 style: apply formatter and fix devin test enum
biome + cargo fmt over merge-sweep eval-fix commits; correct StopReason.END_TURN (nonexistent) to StopReason.FUNCTION_CALL in devin streaming test
2026-07-01 04:45:28 +02:00
can1357 23e0512e7a fix(coding-agent): sanitize write progress preview 2026-07-01 04:40:55 +02:00
roboomp 58c84e4c94 fix(coding-agent): streamed write progress
Emitted partial write-tool updates before filesystem, archive, SQLite, internal URL, and conflict writes so the TUI can render execution-phase progress instead of waiting for the final result.

Updated the write renderer to keep partial results pending, show the progress snapshot, and suppress diagnostics until the final result.

Fixes #3960
2026-07-01 01:57:14 +00:00
Tommaso Fontana f9ece90853 fix(omp): harden ssh:// URL handler per PR review
- buildSshTarget rejects destinations beginning with "-" (SSH argument-injection / local RCE guard)
- gate ssh:// read/search/write at the exec approval tier; substring scan covers search's pre-expansion delimited paths and write's hashline-wrapped paths
- validate the entire materialized buffer as UTF-8 instead of only the first 8 KiB prefix
- write peels read selectors (raw/conflicts) so it targets the same file read does, and rejects line-range/malformed selectors instead of silently stripping them
- write to a uniquely named remote temp; document symlink-replacement on write as a v1 limit
2026-06-26 20:41:35 +02:00
can1357 a796c22101 Merge PR #2244: fix: route edit/patch/replace writes through ACP client bridge (@Mokto)
# Conflicts:
#	packages/coding-agent/src/edit/modes/replace.ts
#	packages/coding-agent/src/tools/write.ts
2026-06-21 16:31:12 +02:00
can1357 2eef88978b feat(coding-agent): made write and find tools essential
- Promoted `write` and `find` tools to `essential` status to ensure they are always available regardless of discovery mode.
- Updated `DEFAULT_ESSENTIAL_TOOL_NAMES` to include these tools by default.
- Updated documentation and tests to reflect the change in default essential tool availability.

Fixes #3165
2026-06-21 07:02:44 +02:00
can1357 66d9df6e1f ux(coding-agent): removed static pending icons from edit headers
- Remove the static "pending" hourglass icon from edit and write tool headers to reduce visual noise.
- Update multi-file status lines to use the active spinner icon directly instead of replacing a static icon, ensuring consistent liveness cues.
2026-06-20 22:46:12 +02:00
can1357 021d82ac1f feat(coding-agent): consolidated and optimize archive handling
- Centralized archive operations into a new `utils/zip.ts` module with unified support for ZIP, tar, and tar.gz formats.
- Optimized ZIP reading using lazy, ranged central-directory access and implemented ZIP64 support for large files.
- Hardened archive extraction with directory traversal protection and configured memory limits for loading and extraction.
- Refactored tool-specific logic to utilize the new centralized utility and deleted the redundant `archive-reader.ts`.
2026-06-18 19:21:37 +02:00
can1357 38d1d3a2f5 feat(coding-agent): vendor relevant parts of markit 2026-06-18 19:11:22 +02:00
can1357 e92db73ec6 feat(coding-agent/tools): added explicit ArkType schema descriptions to agent tools
- Added explicit ArkType schema descriptions across all coding agent tool definitions.
- Updated schema definitions in autoresearch and commit tools with descriptive wrappers.
- Documented tool schema enhancements in the packages/coding-agent CHANGELOG.
2026-06-18 00:59:55 +02:00
can1357 a050474af7 feat: migrated validation schemas and tool definitions from Zod to ArkType
- Migrated all wire protocol, schema definitions, and tools validation from Zod to ArkType across multiple packages.
- Updated extension runtimes, custom tools loader, and TypeBox compatibility shim to expose and use ArkType instances.
- Added a comprehensive ArkType migration guide, validation parity tests, and helper utilities.
- Removed redundant PDF asset routing and parsing implementations from the read tool.
2026-06-18 00:59:53 +02:00
roboomp 285ed3c47d fix(plan-mode): normalize write target before bridge routing
Unwrap bracketed [path#TAG] headers at the top of WriteTool.execute() so internal-URL detection, plan-mode guard, plan path resolution, and ACP bridge routing all see the same filesystem target. Without this, ['/data/workspaces/can1357__oh-my-pi__2472/.omp-session/2026-06-13T20-19-47-341Z_019ec2a3-fc0d-7000-b1e6-25831d3c3ec5/local/scratch.md' slipped past isInternalUrlPath() and was bridged to the editor instead of staying on disk as a session-local artifact.\n\nFixes #2472
2026-06-14 07:36:24 +00:00
can1357 dc50969c15 ux(coding-agent/tools): added executable notices to write tool output
- Added a reusable notice constant for executable write operations.
- Appended the executable notice to write-result output whenever a file was made executable.
2026-06-13 21:20:06 +02:00
can1357 64aa558e62 chore: consistency 2026-06-13 00:03:27 +02:00
can1357 ae84502b82 fix(coding-agent): bypass LSP for individual conflict resolution
Individual conflict resolution now bypasses the LSP writethrough to prevent formatting from corrupting other unresolved marker blocks and to avoid noisy diagnostics in partially resolved files.
2026-06-12 11:29:38 +02:00
can1357 b25b7cc7c2 fix(coding-agent): fixed committed transcript rerendering after block finalization
- Added transcript and assistant block version tracking for finalized segments.
- Changed committed block reuse logic to require prior finalization and same version.
- Fixed rerendering of committed finalized blocks when version values changed.
2026-06-11 16:21:44 +02:00
ben 745c9a9df4 Fix render CPU thrash in long transcripts 2026-06-11 20:27:52 +08:00
Theo Mathieu 0420990d8f fix(lint): organize imports per biome rules 2026-06-10 11:37:04 +02:00
Theo Mathieu d283d5c2db fix: lift bridge guard+hygiene into shared helper; add parity tests
Addresses all three review concerns from @roboomp and @chatgpt-codex-connector:

1. **Contract regression fixed**:  guard
   (extracted from ) is now called by all four write sites.
   Internal-URL paths (e.g. ) and the active plan file
   in plan mode are never routed to the editor bridge.

2. **Bridge call hygiene**: bridge calls are now wrapped in ,
    is called, and
   is bumped — matching the contract  already had.

3. **Tests**:  adds 6 parity tests
   (2 per write site) mirroring :
   - routes plain workspace writes through the bridge, skips writethrough
   - writes local plan artifacts to disk instead of the ACP bridge

**Shared module**:  exports
 and  (guard +
bridge call + ToolError wrap + invalidateFsScanAfterWrite +
bumpFileMutationVersion). All four write sites call it; the duplicated
6-line pattern is gone.  is simplified to use the same helper
instead of its private  method.
2026-06-10 11:31:52 +02:00
can1357 61a57c1d21 fix(coding-agent): stabilized streaming TUI rendering with readonly rows and memoized reuse
- Changed render methods to return component-owned `readonly string[]` rows.
- Added `RenderStablePrefix` row reuse to avoid repainting unchanged streaming content.
- Stabilized streaming gutters and spinner placement to reduce preview jitter and flicker.
- Finalized commit-safe transcript behavior for tool-call previews and added streaming edge-case tests.
2026-06-10 07:26:02 +02:00
can1357 82225e4444 fix(coding-agent): closed vault write approval bypass and fixed interaction tools
vault writes now rated write-tier and plan-mode enforced; .tar.gz rewrites keep gzip, are atomic, and write through symlinks; CRLF conflict detection works; conflict twins only invalidated when truly stale; ask discloses timeout auto-selection in result and transcript; todo rejects duplicate ids and stops persisting half-applied batches; auto-generated guard validates against mtime+size; ACP writes run post-write bookkeeping; irc errors set isError.
2026-06-10 01:27:17 +02:00