Commit Graph

711 Commits

Author SHA1 Message Date
can1357 3dd4b6b226 Merge PR #7197: feat(coding-agent): configure web search timeout (@will-bogusz) 2026-08-02 21:21:37 +02:00
can1357 31d20a8ef8 Merge PR #7371: docs: document role-backed task agents (@fatihaziz) 2026-08-02 20:54:38 +02:00
can1357 7c3b24ddf2 feat: implemented cross-platform window discovery and targeting capabilities
- Added window discovery, targeting, and frame validation for macOS, Windows, and Linux platforms.
- Updated computer tool and protocol definitions to support listing and targeting specific application windows.
- Refactored native computer tool exposure to function-only representation across models.
- Updated documentation and test suites to reflect window-scoped computer control capabilities.
2026-08-02 17:35:29 +02:00
Fatih Al-Aziz dc0664c5b8 docs: clarify role and task examples 2026-08-02 17:50:15 +07:00
Fatih Al-Aziz 4ba49fac72 docs: use bundled role model selectors 2026-08-02 17:39:59 +07:00
Fatih Al-Aziz 6bf0332834 docs: explain vibe tier role overrides 2026-08-02 17:37:28 +07:00
Fatih Al-Aziz 2f0e7772a7 docs: document role-backed task agents 2026-08-02 17:15:09 +07:00
can1357 72c66c87c1 fix(xdg): adopted legacy secret-placeholder.key and marketplaces.json at XDG paths 2026-08-01 20:46:25 +02:00
can1357 890dc0c55d Merge PR #7195: fix(coding-agent): omit unsupported Anthropic search temperature (@will-bogusz) 2026-08-01 20:13:38 +02:00
Sunil Srivatsa 8a7edb3f3d fix(coding-agent): preserve explicit extensions in isolation 2026-08-01 12:32:19 -04:00
can1357 ad78b6a84e feat(coding-agent/tools): implemented shared browser daemon management
- Added `ensureSharedBrowser` and shared browser acquisition to manage project-shared broker-owned Chromium instances.
- Implemented concurrent duplicate daemon start prevention and single-flight `pendingOpens` deduplication.
- Updated browser handle disposal to disconnect from shared daemons rather than closing them.
- Updated browser documentation and launch specifications to support shared and local headless runs.
2026-08-01 08:30:05 +02:00
Will e68266405f fix(coding-agent): cap web search timeout 2026-07-31 16:53:39 -04:00
Will e3f66975e9 fix(coding-agent): omit unsupported search temperature 2026-07-31 16:38:02 -04:00
Will 30087124dc feat(coding-agent): configure web search timeout 2026-07-31 16:37:22 -04:00
can1357 f76ce86966 Merge PR #6840: feat(extensions): add ctx.invokeTool for native built-in delegation (@psyrendust) 2026-07-31 20:17:32 +02:00
can1357 977b5d4281 Merge PR #7079: acp: wire ctx.ui.editor through elicitFromAcpClient (@marton78) 2026-07-31 19:28:41 +02:00
can1357 db2659297a Merge PR #7143: fix(natives): prevent deep HTML crashes and silent truncation (@br411)
# Conflicts:
#	MODULE.bazel.lock
2026-07-31 19:17:47 +02:00
can1357 80a46c2d4c fix(coding-agent): avoid splitting parameter expansions 2026-07-31 19:07:18 +02:00
can1357 969b4a34a5 Merge PR #7176: fix(coding-agent): inspect compound Bash commands in interceptor (@Vincent-Huang-2000) 2026-07-31 19:07:18 +02:00
can1357 f3ae071bb7 docs: clarify kitty placeholder opt-out precedence 2026-07-31 19:07:17 +02:00
can1357 3a3a65c639 Merge PR #7173: docs: document Kitty placeholder environment controls (@roboomp) 2026-07-31 19:07:17 +02:00
roboomp f52ec15a5d docs: documented kitty placeholder environment controls
Added the active Kitty Unicode placeholder overrides to the canonical environment-variable reference, including tmux placement behavior and the unsupported-terminal caveat.

Fixes #7172
2026-07-31 11:47:15 +00:00
Vincent Huang edb0deebb4 fix(coding-agent): inspect compound Bash commands in interceptor rules
Match interceptor regexes against conservative, raw shell command segments
in addition to the complete command, so anchored rules can detect commands
after &&, ||, ;, |, &, and newlines without treating quoted or escaped text
as commands.

Add extractFlatShellCommandSegments() to preserve source text for
user-configured regexes, unlike the token-based approval matcher.
Add skipShellWord() and environment-assignment stripping so rules can match
commands prefixed with NAME=value assignments. Preserve the original command
in interception errors after extracting a leading cd command.
2026-07-31 23:26:43 +12:00
br411 c1c162225b fix(natives): prevent deep HTML crashes and silent truncation
html-to-markdown-rs 2.30 could recurse through pathological HTML until
a native stack overflow aborted the entire OMP process. Upstream 3.9.2
bounds those traversals and reports omitted subtrees as a
machine-readable DepthLimitExceeded warning.

Upgrade html-to-markdown-rs to 3.9.2. Upstream treats a depth-limited
conversion as a successful partial Markdown result plus a warning;
deliberately promote that warning to a rejected `htmlToMarkdown`
promise, allowing the Read tool to fall back without terminating OMP.
Normal conversions and unrelated warnings keep their existing behavior.

Add a rejection-contract test plus a child-process regression proving
OMP survives deeply nested and malformed input.
2026-07-31 00:33:06 +02:00
can1357 652647770e feat(coding-agent): added app.live.toggle keybinding and map display reset to alt+l
- Add the `app.live.toggle` keybinding defaulted to `Ctrl+L` to start or stop live voice mode.
- Remap the default display-reset action (`app.display.reset`) from `Ctrl+L` to `Alt+L`.
- Update the live visualizer to listen for stop keys so the toggle chord terminates active sessions.
2026-07-31 00:20:04 +02:00
Márton Danóczy 5ee4712638 docs: addressed PR #7079 review — changelog entry + stale editor-stub note
- Added the coding-agent changelog entry the review flagged as missing.
- Updated docs/extensions.md: the ACP UI-context surface note still listed
  editor among the stubbed no-op methods after it was wired through
  elicitFromAcpClient.
2026-07-30 22:53:54 +02:00
Larry Gordon a50bcd5fed fix(extensions): wire invokeTool to the extension path as same-tool delegation
Addresses PR review. The initial version put invokeTool on AgentToolContext
via ToolContextStore, but the extension execute path (RegisteredToolAdapter)
builds its own ExtensionContext and never saw it, so the documented
registerTool wrapper use case did not work. It also allowed arbitrary
cross-tool targets (bypassing the target's approval policy), used a
session-global recursion counter that tripped on concurrent independent
delegations, and missed discoverable built-ins that xdev partitioning moves
out of the tool array.

Rework:
- Move invokeTool onto ExtensionContext, and bind it in RegisteredToolAdapter
  to the tool's own name, so a re-registered built-in actually receives it.
- Make delegation same-tool only: invokeTool takes just (params, options) and
  runs the native built-in of the caller's own name. It cannot reach an
  arbitrary target, so it cannot escalate past the approval already granted
  for the call, and the native call is not re-gated.
- Track recursion depth per call chain (threaded through invokeNativeTool and
  createContext) instead of session-global state, so concurrent delegations
  do not interfere.
- Seed the native resolver from the xdev registry when present (it retains
  discoverable built-ins like browser), else the built-in registry.

Replaces the ToolContextStore-level unit test with an end-to-end test that
registers a built-in wrapper through the extension/session path and asserts
the native tool runs the wrapper's delegated input.
2026-07-30 10:35:12 -07:00
Larry Gordon 6acf957dd8 feat(extensions): add ctx.invokeTool for native built-in delegation
A tool's execute context now carries invokeTool(name, params, options?),
which runs the native built-in of `name` and returns its result. A tool
that re-registers a built-in (e.g. wrapping write to add logging or a
policy check) can delegate to the original instead of reimplementing it.

The native implementation is captured before extension re-registration
replaces the registry entry and before the ExtensionToolWrapper pass, so
invokeTool reaches the unwrapped native execute: it does not recurse into
the caller's own wrapper, and it inherits the caller's already-granted
approval rather than re-running the gate. Delegation depth is guarded
against accidental self-recursion, and it resolves to undefined when no
native tool of that name exists.

Wired through ToolContextStore with a lazy native-tool resolver, so it is
coding-agent-only (no agent-loop change) and sees the fully-assembled
built-in set at call time.
2026-07-30 10:35:09 -07:00
can1357 ab572106cd Merge PR #7048: feat(security): add OMP-native security scan subsystem (@kmccleary3301) 2026-07-30 17:11:06 +02:00
roboomp b059550f0b fix(natives): failed fast on uncapturable rootless xwayland root
Under a rootless XWayland session (the GNOME/KDE/sway default) the X11
root window has no backing pixmap, so core `GetImage` on the root returns
`BadMatch`. The computer tool advertised Wayland support yet failed every
screenshot with a raw X11 protocol dump, and coordinate actions stayed
gated behind a capture that could never succeed.

- `Monitor::all` now probes a 1x1 root `GetImage` at initialization and,
  on a `Match`/`Drawable` error, fails fast with an actionable
  `DESKTOP_BACKEND_UNAVAILABLE` message naming the rootless-XWayland
  constraint via the new `root_capture_error` classifier.
- `capture_image` routes its `GetImage` failure through the same
  classifier so any surviving path yields the actionable message rather
  than a raw protocol dump; unrelated errors stay verbatim.
- Corrected the module doc premise and `docs/computer-use.md` to list
  rootless XWayland as unsupported (capture needs a rooted/rootful X
  server, which only exposes X11 clients).

Fixes #7085
2026-07-30 12:38:43 +00:00
Kyle McCleary 4337797565 Merge remote-tracking branch 'origin/main' into feat/security-native
# Conflicts:
#	packages/coding-agent/src/tools/index.ts
2026-07-29 23:26:22 -07:00
can1357 38ebd30337 chore: update stale tests 2026-07-30 07:49:43 +02:00
Kyle McCleary dba303e2e0 Merge remote-tracking branch 'origin/main' into feat/security-native 2026-07-29 20:31:08 -07:00
can1357 d562e53b83 refactor: extracted audio and voice engine into a standalone library crate
- Extracted audio capture and playback implementations, along with the WebRTC peer engine, from `pi-natives` into a new `pi-voice` library crate.
- Updated `pi-natives` bindings to consume the extracted `pi_voice` audio streams and live peer core.
- Added release validation gate jobs, parallelized Linux binary builds, and introduced a concurrent macOS release build job in the CI workflow.
- Updated Bazel workspace configurations, Cargo manifests, and documentation to include the new `pi-voice` crate and its dependencies.
2026-07-30 05:12:40 +02:00
can1357 a38a2f25cf ci: optimized github actions caching and workflows
- Updated GitHub Actions workflows and custom actions to optimize caching strategies and runners.
- Configured separate restore and save steps for bun store caching with non-PR restrictions.
- Added darwin release bazel cache seeding and fallback keys for cache restore.
- Removed native-inputs workflow action and disabled PR-side Rust validation.
2026-07-30 04:56:47 +02:00
Kyle McCleary 089a9963f8 feat(security): OMP-native security subsystem (planner handoff) 2026-07-29 18:47:51 -07:00
can1357 020af06099 Merge PR #6535: feat(mcp): expose server-initiated notifications to extensions via mcp_notification event (@asteriskSF) 2026-07-30 01:48:51 +02:00
can1357 70e6d2c7dc Merge PR #6680: feat(coding-agent): add opt-in max ceiling for auto thinking (@everton-dgn) 2026-07-30 01:48:51 +02:00
can1357 27cb968359 Merge PR #7007: feat(tools): add a browser.cdpUrl setting for the default automation target (@terrxo) 2026-07-30 01:48:50 +02:00
can1357 857b70fe99 Merge remote-tracking branch 'refs/remotes/pr/6535' into prep/6535
# Conflicts:
#	packages/coding-agent/src/extensibility/extensions/runner.ts
2026-07-30 01:42:24 +02:00
can1357 55ac64679e Merge PR #6652: feat(ai): add Exa API key login (@will-bogusz) 2026-07-30 01:26:50 +02:00
can1357 5486c8fd1d Merge PR #6939: feat(extensions): expose session async job snapshots (@usr-bin-roygbiv) 2026-07-30 01:26:50 +02:00
can1357 0249fa4715 Merge PR #7036: feat(rpc): expose live fast-mode control and token throughput (@fredluz) 2026-07-30 01:26:49 +02:00
can1357 5711b763e0 docs(auth): align remaining credential ladders
(cherry picked from commit c606fe3a106611be413f140310ee47a88324cded)
2026-07-29 23:09:09 +02:00
can1357 5c79f5bc4a Merge PR #7023: docs(auth): correct credential precedence (@wolfiesch) 2026-07-29 23:09:09 +02:00
Wolfgang Schoenberger 031beb1751 docs(auth): correct credential precedence
(cherry picked from commit 33ede5efbc52cedc9819cb65c642cfeab82c337c)
2026-07-29 23:09:09 +02:00
can1357 b5ad903788 fix(ttsr): exclude deleted patch text from matcher digest
(cherry picked from commit b4812365368368a5706131c3ff1ecd52fd64662d)
2026-07-29 23:08:24 +02:00
can1357 b98a6853b3 Merge PR #6886: docs: clarify ttsr edit/write matcherDigest is introduced lines (@roboomp) 2026-07-29 23:08:23 +02:00
Éverton Toffanetto e94442b694 fix(ai): preserve legacy Codex SQLite compatibility
(cherry picked from commit 3e5e7b6ea910c56765b4707f617e20b056f3d342)
2026-07-29 23:08:11 +02:00
Éverton Toffanetto db9aa4af1c fix(ai): preserve Codex broker block compatibility
(cherry picked from commit 7de50a84c3d46279e0249617e22ba22222ff8174)
2026-07-29 23:08:10 +02:00