Commit Graph

9345 Commits

Author SHA1 Message Date
can1357 a82e36955f test(agent): cover text-only model image replay 2026-07-14 23:11:09 +02:00
can1357 3a772de879 Merge PR #5518: fix(agent): strip images for non-vision models mid-session (@roboomp) 2026-07-14 23:11:08 +02:00
can1357 a3b4f28078 Merge PR #5506: fix(session): auto-retry bare "Request was aborted" error-stop turns (@roboomp) 2026-07-14 23:11:08 +02:00
can1357 5e8cc40fbe Merge PR #5514: fix(bash): abort isolated shells on cancellation (@roboomp) 2026-07-14 23:11:08 +02:00
can1357 55ad1ff1bc Merge PR #5505: fix(plugins): refresh stale Bun git cache before reinstall (@roboomp) 2026-07-14 23:11:07 +02:00
can1357 6cdefd83e0 Merge PR #5523: fix(coding-agent): accept silent advisor stops with output tokens (@roboomp) 2026-07-14 23:11:07 +02:00
can1357 b76f7aeecf fix(launch): scope batch validation to PTYs 2026-07-14 23:11:07 +02:00
can1357 330744bfeb Merge PR #5520: fix(launch): pass Windows PTY arguments directly (@roboomp) 2026-07-14 23:11:07 +02:00
can1357 69de4b7725 style: formatted history-protocol test imports 2026-07-14 22:59:35 +02:00
can1357 24a441e6b2 chore: normalized changelogs after landing farm fixes 2026-07-14 22:58:49 +02:00
can1357 6b381eb765 Merge PR #5451: fix(eval): honor timeout zero and classify session deadlines (@roboomp) 2026-07-14 22:58:49 +02:00
can1357 3663963b76 Merge PR #5466: fix(tools): gate generate_image behind setting and tool whitelist (@roboomp) 2026-07-14 22:58:48 +02:00
can1357 6f7b2483da fix(internal-urls): ignore non-directory artifact candidates 2026-07-14 22:58:48 +02:00
can1357 ba5c915777 Merge PR #5455: fix(internal-urls): serve history:// transcripts from disk fallback (@roboomp) 2026-07-14 22:58:48 +02:00
can1357 88ab942d9f Merge PR #5478: fix(web-search): stop Perplexity OAuth token leaking to the API-key endpoint (@roboomp) 2026-07-14 22:58:48 +02:00
can1357 1e1569d58e Merge PR #5465: fix(extensions): let tool_result rewrite thrown failure content (@roboomp) 2026-07-14 22:58:48 +02:00
can1357 6f8a3ab94a Merge PR #5458: fix(browser): bound headless browser close to unblock tab cleanup (@roboomp) 2026-07-14 22:58:47 +02:00
can1357 ebe79d6f53 fix(mcp): retain DCR metadata fallback 2026-07-14 22:58:47 +02:00
can1357 80f9329e31 Merge PR #5456: fix(mcp): preserve discovered registration endpoint (@roboomp) 2026-07-14 22:58:47 +02:00
can1357 77cdf1e753 Merge PR #5454: fix(tui): trigger internal-url autocomplete inside slash args (@roboomp) 2026-07-14 22:58:47 +02:00
can1357 413949ccf4 Merge PR #5450: fix(todo): signal removal intent so agent stops rebuilding cleared todos (@roboomp) 2026-07-14 22:58:47 +02:00
can1357 e755fcf983 Merge PR #5469: fix(tui): handle Kitty vim navigation sequences (@roboomp) 2026-07-14 22:58:46 +02:00
can1357 9f17927ee7 Merge PR #5467: fix(cli): flush config JSON output before exit (@roboomp) 2026-07-14 22:58:46 +02:00
can1357 c897f54a07 Merge PR #5459: fix(coding-agent): reject prose thinking session titles (@roboomp) 2026-07-14 22:58:46 +02:00
can1357 c8628d5416 Merge PR #5471: fix(coding-agent): route /guided-goal oneshot through Codex websocket transport (@roboomp) 2026-07-14 22:58:46 +02:00
can1357 52f0d3f9e6 fix(discovery): tolerate malformed plugin cwd 2026-07-14 22:58:46 +02:00
can1357 263eeead04 Merge PR #5481: fix(discovery): resolve relative plugin MCP command/cwd against config dir (@roboomp) 2026-07-14 22:58:45 +02:00
roboomp 1a4c195017 fix(coding-agent): accepted silent advisor stops with output tokens
The advisor runtime rejected every content-less stop completion as a
failed turn, so a deliberate silent review (the documented verifier
behavior) triggered retries and a spurious "unavailable" warning. Only
treat a content-less stop as a failure when it produced no output signal
(zero output and reasoning tokens), so a token-bearing silent stop counts
as a successful silent review.

Fixes #5493
2026-07-14 20:31:21 +00:00
roboomp 9b8ec997b2 fix(coding-agent): reused one codex side session per guided-goal interview
- Minted the guided-goal Codex side session id once per interview in handleGuidedGoalCommand and threaded it through every turn via GuidedGoalTurnOptions.sideSessionId, so a multi-question interview shares a single websocket-only Codex socket instead of opening a fresh one each turn (which could trip websocket_connection_limit_reached and fall back to the rejected SSE path).
- Exported newGuidedGoalSessionId; runGuidedGoalTurn mints its own id only when no side session id is supplied (one-shot callers, tests).
- Added regression coverage asserting the supplied side session id is reused across turns.

Fixes #5304
2026-07-14 20:25:16 +00:00
roboomp 1be025bb72 fix(cursor): propagated returned tool error status
Cursor exec bridges derived failure state only from thrown exceptions, so structured AgentToolResult.isError failures were emitted as successes. Propagate the returned flag through standard and streaming shell execution, with regression coverage for both paths.
2026-07-14 20:20:54 +00:00
roboomp 90c4726bae fix(launch): passed Windows PTY arguments directly
Added a direct-argv PTY entry point and used it for Windows launch sessions so portable-pty no longer re-quotes cmd.exe command text.

Rejected direct .bat and .cmd applications with guidance to use cmd.exe /c.

Fixes #5416
2026-07-14 20:17:03 +00:00
roboomp 00c8e921f6 fix(agent): strip images for non-vision models mid-session
Switching from a vision model to a text-only model kept replaying
historical image content blocks to the new provider, which rejected them
with invalid_argument. The convertToLlm wrapper in sdk.ts only filtered
images when images.blockImages was set, never by model capability, so
the outbound request carried image blocks the active model could not
accept.

Add replaceLlmImagesWithText() to scrub image blocks out of the
already-converted LLM message view, and call it from the sdk wrapper
when the active model's input lacks "image". History on disk keeps its
images; only the provider request is scrubbed, and the check reads the
active model dynamically so a /model switch takes effect next turn.

Fixes #5400
2026-07-14 20:11:25 +00:00
roboomp a9e6e4e67e fix(bash): aborted isolated shells on cancellation
Route overlapping executions through owned Shell instances so timeout and interrupt paths can explicitly abort native child-process cleanup.

Fixes #5389
2026-07-14 19:57:59 +00:00
roboomp 5e71fac653 fix(session): retried bare Request was aborted error-stop turns
A stalled or dropped provider stream that surfaces as stopReason:"error"
carrying the bare "Request was aborted" sentinel fell through both retry
gates: #isRetryableReasonlessAbort required stopReason:"aborted", and
#isRetryableError's classifier returns no retriable kinds for the generic
sentinel. The turn died immediately despite retry.enabled.

- Relaxed #isRetryableReasonlessAbort to accept an empty generic-abort
  sentinel turn under stopReason "aborted" or "error", tagging it Abort so
  #handleRetryableError retries it without model fallback.
- Kept the deliberate-abort guards intact: user interrupts and silent aborts
  carry their own markers (not the generic sentinel), and #abortInProgress /
  #isDisposed / #streamingEditAbortTriggered still settle without retry.
- Rewrote the stale fallback test that froze the buggy no-retry behavior to
  assert retry-and-recover for the error-stop sentinel.

Fixes #5375
2026-07-14 19:39:24 +00:00
roboomp 2439f77e70 fix(plugins): refreshed stale bun git cache before reinstall
Fetched current heads and tags into Bun's matching cached bare clone before running bun update.

Added an isolated HTTP git regression covering a moved branch with a stale cache.

Fixes #5401
2026-07-14 19:37:06 +00:00
can1357 1f619dcf18 feat(ai): enhanced Codex rate-limit header ingestion and usage-based key ranking
- Added a Codex rate-limit parser for `x-codex-*` headers and registered it with the Codex usage provider.
- Updated auth-storage to require parsed usage headers before ingesting usage data, treated exhaustion as non-throttled, and renamed ranked candidate drain fields.
- Reworked key ranking math to use `headroom / remainingHours` with a 1-minute minimum, then applied measured-usage precedence with hot-window demotion behavior.
- Updated session handling and tests to support provider-aware header ingestion with deterministic, exhaustion-aware account selection.
2026-07-14 20:54:03 +02:00
roboomp 6467a3119e fix(discovery): rooted relative plugin mcp command and cwd at config dir
Discovered plugin .mcp.json stdio servers launched relative command/cwd
values against the session cwd instead of the plugin's config directory,
breaking bundled ChatGPT/Codex plugins (e.g. Computer Use) with ENOENT
when spawning ./... from an unrelated cwd.

The claude-plugins and omp-plugins providers now resolve relative cwd and
path-like command (./ or ../) against the .mcp.json directory via a shared
resolvePluginStdioPaths helper; bare executables such as npx are left
untouched so PATH lookup still works.

Fixes #5330
2026-07-14 18:36:21 +00:00
roboomp c97449c51d fix(web-search): stop perplexity oauth token leaking to api-key endpoint
The consumer ask endpoint (/rest/sse/perplexity_ask) intermittently closes
its socket before responding. getApiConfigs emitted the OAuth session JWT
(returned by getApiKey while OAuth is the active origin) as a direct
api.perplexity.ai api-key config, so a transient transport failure on the
ask endpoint fell through and sent the session token as a Bearer to the
direct API, whose 401 masked the real error.

- Suppress the direct api-key config when getCredentialOrigin reports the
  active perplexity credential as oauth.
- Give the OAuth ask request one transport-only retry; HTTP responses
  (including 401/429) are final and never retried.
- Add regression coverage for both legs.

Fixes #5315
2026-07-14 18:28:43 +00:00
roboomp 8b179ffc3b fix(coding-agent): routed guided-goal oneshot through codex websocket transport
- Passed the session provider transport (providerSessionState + preferWebsockets) and an isolated session id to the /guided-goal interview completion so websocket-only Codex models (gpt-5.6-luna/sol/terra) get a websocket session instead of an SSE fallback the Codex /responses endpoint rejects with "Model not found".
- Added regression coverage asserting the guided-goal request inherits the session transport with an isolated session id.

Fixes #5304
2026-07-14 18:09:59 +00:00
roboomp 3fa5ffd0b1 fix(tui): handled Kitty vim navigation sequences
Routed vim-style h/j/k/l navigation through the protocol-aware key matcher across custom coding-agent selectors and overlays.

Fixes #5314
2026-07-14 18:08:23 +00:00
roboomp df7aa6d01f fix(cli): awaited config JSON stdout flush
- Waited for the stdout write callback before the config command exits.
- Covered JSON output larger than the 64 KiB pipe buffer.

Fixes #5309
2026-07-14 18:06:40 +00:00
roboomp 5878ed8f49 fix(tools): gate generate_image behind setting and tool whitelist
generate_image was registered as a custom tool and force-activated via the alwaysInclude list in createAgentSession, so it survived --no-tools (empty toolNames) and any explicit whitelist that omitted it. There was also no generate_image.enabled setting, so /settings had no toggle.

Add a generate_image.enabled setting and only register the tool when enabled and either no whitelist is given or it names generate_image.

Fixes #5305
2026-07-14 18:06:10 +00:00
roboomp 5303c3852e fix(extensions): let tool_result rewrite thrown failure content
ExtensionToolWrapper caught a thrown tool exception, emitted tool_result
with the modifiable result, then rethrew the original executionError whenever
the effective error state stayed true. This discarded any replacement content
or details a handler returned, so an extension could only surface modified
content by returning isError: false, which wrongly converted the failure into
a success.

Return the (possibly modified) result carrying isError instead of rethrowing.
The agent loop already honors AgentToolResult.isError (coerceToolResult) and
surfaces it as a tool error on the wire, so replacement failure content now
reaches the model while the call remains an error. No-modification, error->success, and success->error paths keep their existing semantics.

Fixes #5302
2026-07-14 18:01:02 +00:00
roboomp 33e87d5930 fix(browser): bound headless browser close to unblock tab cleanup
disposeBrowserHandle awaited Puppeteer's browser.close() for the headless
kind with no timeout. browser.close() resolves only once Chromium fully
exits, so a wedged process (a Windows failure mode) left releaseTab stuck
in the "Closing tab" phase forever.

Cap the close at 5s and force-kill the Chromium process tree on timeout so
the tool call always releases.

Fixes #5260
2026-07-14 17:48:18 +00:00
roboomp 3666cb93d2 fix(coding-agent): rejected prose thinking session titles
Rejected markerless prose thinking preambles while preserving marked titles and plain markerless title responses.

Fixes #5252
2026-07-14 17:48:15 +00:00
roboomp fb98465923 fix(mcp): preserved discovered registration endpoint
Threaded the authorization server's advertised registration endpoint through OAuth discovery, add, reauth, and the client flow instead of deriving metadata from the authorization endpoint.

Added pathful-issuer discovery and end-to-end DCR regression coverage.

Fixes #5267
2026-07-14 17:46:24 +00:00
roboomp e29fbce55c fix(internal-urls): serve history:// transcripts from disk fallback
history:// resolve/complete/index queried the in-memory AgentRegistry
exclusively, so transcripts of unregistered one-shot helpers
(keepAlive: false), released agents, or any subagent after a session
resume threw "Unknown agent" despite their .jsonl session file
persisting on disk — unlike agent://, which reads .md outputs off disk.

Added sessionFilesFromDisk() to registry-helpers: a recursive scan of
the artifacts dirs keyed by agent id, excluding advisor transcripts
(__advisor*.jsonl) and EPERM-rewrite backups (.bak). HistoryProtocolHandler
now falls back to it on a registry miss (resolve and the else branch),
merges on-disk agents into the index, and unions them into completions.
Documented history:// in the system prompt's Internal URLs section.

Fixes #5261
2026-07-14 17:41:26 +00:00
roboomp 3abade7256 fix(tui): trigger internal-url autocomplete inside slash args
The allowArgs branch in PromptActionAutocompleteProvider.getSuggestions
returned CombinedAutocompleteProvider's result verbatim, so a null from
the base provider short-circuited before getInternalUrlSuggestions.
Internal URL schemes (agent://, skill://, omp://, ...) never completed
inside slash command arguments.

Fall through to internal-url completion when the base provider yields no
argument match. `#` prompt-action tokens stay literal inside slash args.

Fixes #5263
2026-07-14 17:37:55 +00:00
roboomp 8e6d26b1e8 fix(eval): honored unlimited cell timeouts
- Disabled the eval watchdog when timeout is explicitly zero.
- Classified session deadline aborts as TimeoutError while preserving their message.
- Documented and tested both timeout contracts.

Fixes #5250
2026-07-14 17:33:56 +00:00
roboomp fd3f15c915 fix(todo): signal removal intent so agent stops rebuilding cleared todos
The /todo rm reminder was a generic "user manually modified" message
showing an empty list, so the model read the cleared list as missing and
re-populated it on the next turn. buildSystemReminder now emits an explicit
do-not-recreate / do-not-re-add directive for removals while keeping
status mutations (done/drop) neutral.

Fixes #5258
2026-07-14 17:33:21 +00:00