Commit Graph

729 Commits

Author SHA1 Message Date
can1357 ee026fa2e3 Merge PR #7704: fix(natives): gate wayland capture capability on pipewire feature (@roboomp)
# Conflicts:
#	crates/pi-natives/src/desktop/linux/wayland/mod.rs
2026-08-05 22:16:16 +02:00
can1357 65132b3373 fix(computer): correct Wayland recovery guidance 2026-08-05 22:15:47 +02:00
can1357 307ba8b9f3 Merge PR #7711: fix(computer): correct Wayland foreground delivery (@roboomp) 2026-08-05 22:15:47 +02:00
can1357 e9888367d1 refactor: migrated packages to internal utility modules and removed external dependencies
- Implemented in-house, zero-dependency utility modules in `pi-utils` covering DOM manipulation, markdown parsing, templating, browser automation helpers, and terminal buffers.
- Migrated packages across the repository to consume the new internal utilities and `omptype` schema validators instead of external dependencies.
- Removed multiple external runtime and development dependencies including Zod, Marked, LRU cache, Turndown, and Puppeteer browser packages.
2026-08-05 13:39:09 +02:00
roboomp ea887b00a9 fix(computer): corrected Wayland foreground delivery
Reported compositor-limited per-window input before reaching the AT-SPI focus path and stopped advertising foreground delivery on Wayland.

Removed the obsolete AT-SPI window-raise helper and updated public recovery guidance.

Fixes #7702
2026-08-05 10:57:25 +00:00
roboomp dc4725e626 fix(natives): gate wayland capture capability on pipewire feature
WaylandBackend::capabilities() hardcoded capture:true, but the PipeWire
screencast path is compiled only under the wayland-pipewire feature, which
is off by default and excluded from shipped Bazel addons (crate_features=[]).
Released builds therefore advertised capture the binary could never do:
every capture() call returned CaptureFailed, and callers trusting
capabilities() retried into a guaranteed failure.

Gate the capture flag and capture_permission on cfg!(feature =
"wayland-pipewire") so the report matches the compiled-in path, and align
docs/computer-use.md with what shipped builds actually support.

Fixes #7700
2026-08-05 10:45:57 +00:00
can1357 b0a94a8fc0 chore: cleanup 2026-08-05 03:07:16 +02:00
can1357 18e6df18a6 Merge PR #7621: fix(coding-agent/eval): remove per-call model override from agent() (@szavadsky) 2026-08-05 01:12:01 +02:00
can1357 5073602977 docs(mcp): clarify translated config precedence 2026-08-05 01:11:58 +02:00
can1357 e50b989e45 Merge PR #7654: fix(mcp): propagate enabled flag from translated tool configs (@roboomp) 2026-08-05 01:11:57 +02:00
can1357 ca71858545 Merge PR #7497: fix(tool): exempt piped-stdin stages from bash interceptor (@roboomp) 2026-08-05 01:11:55 +02:00
roboomp 9f92d36425 fix(mcp): ordered project entries before user in translated importers
The Claude/Cursor/Gemini/Windsurf importers appended user entries before
project entries, so a project `enabled: false` could not claim its dedupe key
ahead of a same-named user server and the disable was silently ignored. Load
project entries first, matching the native/Codex loaders, so a project disable
suppresses a same-named user server.

Updated docs/mcp-config.md to reflect the project-first precedence and added
compound regression coverage.

Fixes #7652
2026-08-04 21:14:11 +00:00
Slava Zavadsky b8779dae63 fix(coding-agent/eval): remove per-call model override from agent() (#6438)
Completes the maintainer's removal of per-call model selection from
subagent spawns (9f8aa87dbf removed it from the task tool and the
model-facing agent() docs/prompt, but the eval agent() runtime and all
four preludes still accepted and forwarded a per-call model).

Subagents now always resolve through the selected agent's frontmatter
model and settings, so an explicit model: "default" can no longer
silently route children onto the parent session model.

- agent-bridge: drops "model?" from agentArgsSchema and the request
  forward; adds "+": "delete" so a legacy model argument is stripped
  (same contract as the task wire schemas).
- JS/Python/Ruby/Julia preludes: remove the model parameter from
  agent(); completion()'s tier selector is unchanged.
- docs (tools/eval.md, python-repl.md) updated to the removed surface.

Refs #6438
2026-08-04 08:35:01 -04:00
can1357 bc39ffa265 feat: introduced omptype validation package and migrated workspace dependencies
- Introduce `@oh-my-pi/omptype` as a new ArkType-compatible schema validation package featuring a lazy JIT runtime, JSON Schema emission, and compatibility adapters.
- Replace `arktype` across workspace packages and test utilities with `@oh-my-pi/omptype`.
- Add benchmark suites, tests, and documentation for the new validation engine and adapters.
- Update workspace build, test runner, and release configurations to include the new package.
2026-08-03 21:56:48 +02:00
can1357 1a8caad23e chore: update docs + rename reset to clear 2026-08-03 18:37:23 +02:00
can1357 ebd5e3f86f chore: update stale docs 2026-08-03 16:39:23 +02:00
roboomp 430e4e386b fix(tool): preserved piped stdin across continuations
Retained pending pipeline state across blank and comment-only continuation
lines, and parsed Bash's |& operator as a single pipe boundary. Added
regression coverage for both forms and aligned the Bash interceptor docs.

Fixes #7496
2026-08-03 12:45:50 +00:00
roboomp cbfbcd865e fix(tool): exempt piped-stdin stages from bash interceptor
The 17.2.2 compound-fragment matching splits commands on every unquoted
operator including `|`, so a downstream pipe stage like `grep x` in
`printf 'x\n' | grep x` became a standalone interception candidate and was
routed to the `grep` tool, which searches paths and cannot consume the
previous stage's stdout.

`extractFlatShellCommandSegments` now flags each segment that receives piped
stdin from a single unquoted `|`, and `interceptionCandidates` skips those:
a stdin-consuming stage cannot be replaced by a path-based dedicated tool.
Standalone (`grep pattern path`), first-stage (`grep x file | wc`), and
`&&`/`||`/`;`-sequenced commands still match.

Fixes #7496
2026-08-03 12:36:36 +00:00
can1357 3dd4b6b226 Merge PR #7197: feat(coding-agent): configure web search timeout (@will-bogusz) 2026-08-02 21:21:37 +02:00
can1357 31d20a8ef8 Merge PR #7371: docs: document role-backed task agents (@fatihaziz) 2026-08-02 20:54:38 +02:00
can1357 7c3b24ddf2 feat: implemented cross-platform window discovery and targeting capabilities
- Added window discovery, targeting, and frame validation for macOS, Windows, and Linux platforms.
- Updated computer tool and protocol definitions to support listing and targeting specific application windows.
- Refactored native computer tool exposure to function-only representation across models.
- Updated documentation and test suites to reflect window-scoped computer control capabilities.
2026-08-02 17:35:29 +02:00
Fatih Al-Aziz dc0664c5b8 docs: clarify role and task examples 2026-08-02 17:50:15 +07:00
Fatih Al-Aziz 4ba49fac72 docs: use bundled role model selectors 2026-08-02 17:39:59 +07:00
Fatih Al-Aziz 6bf0332834 docs: explain vibe tier role overrides 2026-08-02 17:37:28 +07:00
Fatih Al-Aziz 2f0e7772a7 docs: document role-backed task agents 2026-08-02 17:15:09 +07:00
can1357 72c66c87c1 fix(xdg): adopted legacy secret-placeholder.key and marketplaces.json at XDG paths 2026-08-01 20:46:25 +02:00
can1357 890dc0c55d Merge PR #7195: fix(coding-agent): omit unsupported Anthropic search temperature (@will-bogusz) 2026-08-01 20:13:38 +02:00
Sunil Srivatsa 8a7edb3f3d fix(coding-agent): preserve explicit extensions in isolation 2026-08-01 12:32:19 -04:00
can1357 ad78b6a84e feat(coding-agent/tools): implemented shared browser daemon management
- Added `ensureSharedBrowser` and shared browser acquisition to manage project-shared broker-owned Chromium instances.
- Implemented concurrent duplicate daemon start prevention and single-flight `pendingOpens` deduplication.
- Updated browser handle disposal to disconnect from shared daemons rather than closing them.
- Updated browser documentation and launch specifications to support shared and local headless runs.
2026-08-01 08:30:05 +02:00
Will e68266405f fix(coding-agent): cap web search timeout 2026-07-31 16:53:39 -04:00
Will e3f66975e9 fix(coding-agent): omit unsupported search temperature 2026-07-31 16:38:02 -04:00
Will 30087124dc feat(coding-agent): configure web search timeout 2026-07-31 16:37:22 -04:00
can1357 f76ce86966 Merge PR #6840: feat(extensions): add ctx.invokeTool for native built-in delegation (@psyrendust) 2026-07-31 20:17:32 +02:00
can1357 977b5d4281 Merge PR #7079: acp: wire ctx.ui.editor through elicitFromAcpClient (@marton78) 2026-07-31 19:28:41 +02:00
can1357 db2659297a Merge PR #7143: fix(natives): prevent deep HTML crashes and silent truncation (@br411)
# Conflicts:
#	MODULE.bazel.lock
2026-07-31 19:17:47 +02:00
can1357 80a46c2d4c fix(coding-agent): avoid splitting parameter expansions 2026-07-31 19:07:18 +02:00
can1357 969b4a34a5 Merge PR #7176: fix(coding-agent): inspect compound Bash commands in interceptor (@Vincent-Huang-2000) 2026-07-31 19:07:18 +02:00
can1357 f3ae071bb7 docs: clarify kitty placeholder opt-out precedence 2026-07-31 19:07:17 +02:00
can1357 3a3a65c639 Merge PR #7173: docs: document Kitty placeholder environment controls (@roboomp) 2026-07-31 19:07:17 +02:00
roboomp f52ec15a5d docs: documented kitty placeholder environment controls
Added the active Kitty Unicode placeholder overrides to the canonical environment-variable reference, including tmux placement behavior and the unsupported-terminal caveat.

Fixes #7172
2026-07-31 11:47:15 +00:00
Vincent Huang edb0deebb4 fix(coding-agent): inspect compound Bash commands in interceptor rules
Match interceptor regexes against conservative, raw shell command segments
in addition to the complete command, so anchored rules can detect commands
after &&, ||, ;, |, &, and newlines without treating quoted or escaped text
as commands.

Add extractFlatShellCommandSegments() to preserve source text for
user-configured regexes, unlike the token-based approval matcher.
Add skipShellWord() and environment-assignment stripping so rules can match
commands prefixed with NAME=value assignments. Preserve the original command
in interception errors after extracting a leading cd command.
2026-07-31 23:26:43 +12:00
br411 c1c162225b fix(natives): prevent deep HTML crashes and silent truncation
html-to-markdown-rs 2.30 could recurse through pathological HTML until
a native stack overflow aborted the entire OMP process. Upstream 3.9.2
bounds those traversals and reports omitted subtrees as a
machine-readable DepthLimitExceeded warning.

Upgrade html-to-markdown-rs to 3.9.2. Upstream treats a depth-limited
conversion as a successful partial Markdown result plus a warning;
deliberately promote that warning to a rejected `htmlToMarkdown`
promise, allowing the Read tool to fall back without terminating OMP.
Normal conversions and unrelated warnings keep their existing behavior.

Add a rejection-contract test plus a child-process regression proving
OMP survives deeply nested and malformed input.
2026-07-31 00:33:06 +02:00
can1357 652647770e feat(coding-agent): added app.live.toggle keybinding and map display reset to alt+l
- Add the `app.live.toggle` keybinding defaulted to `Ctrl+L` to start or stop live voice mode.
- Remap the default display-reset action (`app.display.reset`) from `Ctrl+L` to `Alt+L`.
- Update the live visualizer to listen for stop keys so the toggle chord terminates active sessions.
2026-07-31 00:20:04 +02:00
Márton Danóczy 5ee4712638 docs: addressed PR #7079 review — changelog entry + stale editor-stub note
- Added the coding-agent changelog entry the review flagged as missing.
- Updated docs/extensions.md: the ACP UI-context surface note still listed
  editor among the stubbed no-op methods after it was wired through
  elicitFromAcpClient.
2026-07-30 22:53:54 +02:00
Larry Gordon a50bcd5fed fix(extensions): wire invokeTool to the extension path as same-tool delegation
Addresses PR review. The initial version put invokeTool on AgentToolContext
via ToolContextStore, but the extension execute path (RegisteredToolAdapter)
builds its own ExtensionContext and never saw it, so the documented
registerTool wrapper use case did not work. It also allowed arbitrary
cross-tool targets (bypassing the target's approval policy), used a
session-global recursion counter that tripped on concurrent independent
delegations, and missed discoverable built-ins that xdev partitioning moves
out of the tool array.

Rework:
- Move invokeTool onto ExtensionContext, and bind it in RegisteredToolAdapter
  to the tool's own name, so a re-registered built-in actually receives it.
- Make delegation same-tool only: invokeTool takes just (params, options) and
  runs the native built-in of the caller's own name. It cannot reach an
  arbitrary target, so it cannot escalate past the approval already granted
  for the call, and the native call is not re-gated.
- Track recursion depth per call chain (threaded through invokeNativeTool and
  createContext) instead of session-global state, so concurrent delegations
  do not interfere.
- Seed the native resolver from the xdev registry when present (it retains
  discoverable built-ins like browser), else the built-in registry.

Replaces the ToolContextStore-level unit test with an end-to-end test that
registers a built-in wrapper through the extension/session path and asserts
the native tool runs the wrapper's delegated input.
2026-07-30 10:35:12 -07:00
Larry Gordon 6acf957dd8 feat(extensions): add ctx.invokeTool for native built-in delegation
A tool's execute context now carries invokeTool(name, params, options?),
which runs the native built-in of `name` and returns its result. A tool
that re-registers a built-in (e.g. wrapping write to add logging or a
policy check) can delegate to the original instead of reimplementing it.

The native implementation is captured before extension re-registration
replaces the registry entry and before the ExtensionToolWrapper pass, so
invokeTool reaches the unwrapped native execute: it does not recurse into
the caller's own wrapper, and it inherits the caller's already-granted
approval rather than re-running the gate. Delegation depth is guarded
against accidental self-recursion, and it resolves to undefined when no
native tool of that name exists.

Wired through ToolContextStore with a lazy native-tool resolver, so it is
coding-agent-only (no agent-loop change) and sees the fully-assembled
built-in set at call time.
2026-07-30 10:35:09 -07:00
can1357 ab572106cd Merge PR #7048: feat(security): add OMP-native security scan subsystem (@kmccleary3301) 2026-07-30 17:11:06 +02:00
roboomp b059550f0b fix(natives): failed fast on uncapturable rootless xwayland root
Under a rootless XWayland session (the GNOME/KDE/sway default) the X11
root window has no backing pixmap, so core `GetImage` on the root returns
`BadMatch`. The computer tool advertised Wayland support yet failed every
screenshot with a raw X11 protocol dump, and coordinate actions stayed
gated behind a capture that could never succeed.

- `Monitor::all` now probes a 1x1 root `GetImage` at initialization and,
  on a `Match`/`Drawable` error, fails fast with an actionable
  `DESKTOP_BACKEND_UNAVAILABLE` message naming the rootless-XWayland
  constraint via the new `root_capture_error` classifier.
- `capture_image` routes its `GetImage` failure through the same
  classifier so any surviving path yields the actionable message rather
  than a raw protocol dump; unrelated errors stay verbatim.
- Corrected the module doc premise and `docs/computer-use.md` to list
  rootless XWayland as unsupported (capture needs a rooted/rootful X
  server, which only exposes X11 clients).

Fixes #7085
2026-07-30 12:38:43 +00:00
Kyle McCleary 4337797565 Merge remote-tracking branch 'origin/main' into feat/security-native
# Conflicts:
#	packages/coding-agent/src/tools/index.ts
2026-07-29 23:26:22 -07:00
can1357 38ebd30337 chore: update stale tests 2026-07-30 07:49:43 +02:00