Commit Graph
606 Commits
Author SHA1 Message Date
can1357 a92d2ce989 feat(coding-agent): removed context argument from eval agent() spawn
Shared background now flows through a '/Users/can/.omp/agent/sessions/-Projects-.tree-pi-commit/2026-06-10T15-36-32-782Z_019eb22d-970e-7000-8964-72c98becf3e8/local' file referenced in each prompt instead of a context string forwarded into the subagent's system prompt. The JS and Python preludes drop the context kwarg from agent(), the subagent system prompt drops the {{#if context}} block and the conversation-context file pointer, and runEvalAgent no longer writes a per-call conversation context file. AgentSession sheds the now-unused formatCompactContext() helper that supplied the file's body, and ToolSession.getCompactContext is removed alongside it.
2026-06-10 17:49:01 +02:00
can1357 fcb8663de8 feat(coding-agent): reworked irc to a send/wait/inbox/list mailbox bus
Replaces the blocking auto-reply IRC turn with a process-global IrcBus and a four-op tool (send/wait/inbox/list). send is fire-and-forget with per-recipient delivery receipts (injected/woken/revived/failed); replies become real turns by the recipient, observed via wait (or the send await:true sugar). Bounded per-agent mailboxes (cap 100) drop oldest on overflow; AgentSession.deliverIrcMessage folds an in-flight delivery in as a non-interrupting aside at the next step boundary, or starts a real wake turn when idle. AgentRegistry/lifecycle handle the idle→woken / parked→revived transitions, so messaging a non-running peer brings it back. Adds a dedicated TUI renderer (directional headers, delivery-outcome coloring, quoted bodies, per-recipient receipt trees, status-badged peer lists with unread counts). irc.timeoutMs is now the default timeout for wait / send await:true. AgentSession sheds the agentRegistry config field, the dedupeIrcReply → dedupeEphemeralReply rename (now used by /btw and /omfg), and the background-channel exchange queue / forwardIrcRelayToMain plumbing the auto-reply model needed.
2026-06-10 17:47:47 +02:00
can1357 316722397a Merge pull request #1896: fix(coding-agent): respect user shell for ! shortcuts 2026-06-10 09:52:28 +02:00
can1357 c08e6f8a19 ux(coding-agent): default artifact captures back to unbounded with opt-in capping 2026-06-10 09:51:47 +02:00
can1357 1821e167f4 fix(coding-agent): deobfuscate secrets in ephemeral turns and obfuscate via provider-context hook 2026-06-10 09:51:47 +02:00
can1357 730e9c8e0c fix(acp): honor the explicit autoApprove session flag when skipping the permission gate 2026-06-10 09:51:47 +02:00
roboomp cafd957f5d fix(providers): disabled ollama thinking for off turns
Propagated explicit thinking-off state through the agent loop so provider requests receive disableReasoning instead of an undefined effort. Added Ollama and agent-session regressions for the :off path.\n\nFixes #2239
2026-06-10 07:41:58 +00:00
handlecusion 2d7d717029 fix(coding-agent): tighten user shell routing 2026-06-10 16:07:59 +09:00
handlecusion 8b9c4fa1b9 fix(coding-agent): respect user shell for shortcuts 2026-06-10 16:07:59 +09:00
can1357 11c53051bf Merge pull request #2097: fix(acp): skip permission gate when yolo mode is explicitly enabled 2026-06-10 08:32:09 +02:00
can1357 d30dca302f Merge pull request #2044: fix(coding-agent): apply enabledModels filter to ACP model list 2026-06-10 08:32:09 +02:00
can1357 3fd09d5770 fix(acp): require explicit yolo opt-in before skipping the client permission gate
The schema default for tools.approvalMode is already "yolo", so checking the
resolved setting alone disabled the ACP permission gate for every
default-config session (17 existing tests in
agent-session-acp-permission.test.ts fail). The skip now requires an
explicitly configured approval mode — the --yolo/--auto-approve runtime
override or a user-set tools.approvalMode — via the new
Settings.isConfigured(), keeping default ACP sessions gated.

Addresses review feedback on #2097.
2026-06-10 08:31:31 +02:00
Theo Mathieuandcan1357 fbb48faf81 fix: reflect --auto-approve flag in settings override so #wrapToolForAcpPermission sees yolo mode 2026-06-10 08:31:30 +02:00
Theo Mathieuandcan1357 c110a624c3 fix(acp): skip permission gate in yolo mode when effective policy is allow 2026-06-10 08:31:30 +02:00
Theoandcan1357 9e28ec4b7e fix: apply enabledModels filter to ACP model list
getAvailableModels() was calling modelRegistry.getAvailable() directly,
which skips the enabledModels setting. The setting was only applied
during session init to pick the starting model, not to the list
advertised to ACP clients (Zed, etc.).

Add filterAvailableModelsByEnabledPatterns() to model-resolver.ts - a
synchronous subset of resolveAllowedModels() that handles the patterns
used in real configs (exact provider/modelId, canonical ids, bare model
ids, thinking-level suffixes). Glob patterns fall back to showing all
models rather than accidentally emptying the picker.

Update getAvailableModels() to call it, so the ACP model dropdown in
Zed (and any other ACP client) respects the users enabledModels config.
2026-06-10 08:31:30 +02:00
can1357 7ce58fe95c Merge pull request #2204: feat(eval): add python interpreter setting 2026-06-10 08:26:59 +02:00
can1357 62ad6e73ae Merge pull request #2200: fix(ai): rotate antigravity credentials on Individual quota reached 429s 2026-06-10 08:26:59 +02:00
can1357 e19f2f689c Merge pull request #2147: fix(coding-agent): hide secrets in provider requests 2026-06-10 08:26:58 +02:00
can1357 c03075c9ae Merge pull request #2083: fix(coding-agent): broke runaway edit loops and capped bash artifact spew 2026-06-10 08:26:57 +02:00
416c9947bd fix(acp): finish prompt turn when extension/custom command is handled locally
Extension commands (e.g. /sonnet) and TypeScript custom commands that
consume the input without calling the LLM return early from
session.prompt() with no agent turn. In ACP mode this left the pending
prompt promise unresolved, hanging the client forever.

Change session.prompt() to return Promise<boolean>: true when the LLM
was invoked, false when the command was fully handled locally.
#runPromptOrCommand calls #finishPrompt immediately on a false return so
the ACP turn completes.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-10 08:26:07 +02:00
can1357 ec81b927fa fix(coding-agent): redact ephemeral side-channel context and preserved remote compaction history
runEphemeralTurn (IRC//btw) called streamSimple directly with the raw
system prompt, bypassing the SDK-level obfuscateProviderContext wrapper;
and #obfuscatePreparationForProvider skipped previousPreserveData, so a
pre-fix openaiRemoteCompaction.replacementHistory could resend raw
secrets on the next remote compaction.

Addresses review feedback on #2147.
2026-06-10 08:26:02 +02:00
roboompandcan1357 d39e4b0d38 fix(coding-agent): hid previous compaction summary
Obfuscated preparation.previousSummary, hook prompt/context, before forwarding to compact() so prior pi- or extension-supplied summaries do not leak verbatim secrets on subsequent compactions.

Fixes #2146
2026-06-10 08:26:02 +02:00
roboompandcan1357 5517115f1a fix(coding-agent): hid handoff instructions
Obfuscated custom instructions before handoff and related side-request provider calls, then deobfuscated generated handoff output before persistence.

Fixes #2146
2026-06-10 08:26:02 +02:00
roboompandcan1357 aa4cd0ab2d fix(coding-agent): preserved tool schemas while redacting
Converted provider-facing tool parameters to wire JSON Schema before redaction so live Zod instances are not deep-cloned into plain objects.

Fixes #2146
2026-06-10 08:26:02 +02:00
roboompandcan1357 2a90108893 fix(coding-agent): hid secrets in provider requests
Redacted configured secrets across provider-facing system prompts, tool definitions, developer reminders, and assistant tool-call payloads before LLM requests.

Fixes #2146
2026-06-10 08:26:01 +02:00
can1357 24cbc93913 fix(eval): thread python.interpreter from session settings and expand ~
Resolve the explicit interpreter from the session's Settings instance
(ToolSession.settings / AgentSession.settings) instead of re-reading the
process-global Settings.init() singleton, so project-scoped and cloned
session settings take effect. The availability cache is now keyed by
cwd + interpreter, and PythonKernel.start/executePython accept the
resolved interpreter as an option. Also expand home-relative paths
(~/...) before resolving against cwd, and document the contract of
resolveExplicitPythonRuntime.

Addresses review feedback on #2204.
2026-06-10 08:26:00 +02:00
roboompandcan1357 8c3149e5a9 fix(ai): scoped antigravity quota blocks by model family
- Added CredentialRankingStrategy scope hooks so providers can rank and block only the limits relevant to the requested model.
- Scoped Antigravity usage reports by model family: Gemini/Gemma use Google counters, Claude uses Anthropic counters, and GPT/OpenAI models use OpenAI counters.
- Added scoped backoff keys so a Gemini quota block no longer suppresses healthy Claude/OpenAI Antigravity sessions on the same OAuth credential.
- Threaded modelId through coding-agent API-key resolvers and usage-limit rotation paths.
- Added regression coverage proving a Google/Gemini exhaustion block still allows Claude selection on the same credential.

Fixes #2198
2026-06-10 08:26:00 +02:00
can1357 dbf1be2096 fix(coding-agent): count head-retained bytes against the artifact cap
After rebasing onto a13e9827f, #createFileSink's head-retention flush
wrote directly to the sink, bypassing #emitToSink's budget accounting —
the on-disk artifact could grow past artifactMaxBytes by up to the head
window. Route the flush through #emitToSink and pin it with a
regression test (fails 24B vs 16B cap without the fix).

Addresses review feedback on #2083.
2026-06-10 08:26:00 +02:00
roboompandcan1357 e18a8649f0 fix(coding-agent): suppressed artifact truncation notice when nothing was elided
Codex review on PR #2083 caught a corruption case in `OutputSink`:
when a stream exceeds `artifactHeadBytes` but still fits below
`artifactMaxBytes`, post-head bytes flow into the tail ring without any
eviction (`droppedBytes === 0`) — yet `#flushArtifactTailIfCapped`
unconditionally injected `[ARTIFACT TRUNCATED: kept first … + last … of
…; 0 B elided from the middle]` between head and tail. The resulting
artifact-on-disk is then no longer verbatim and falsely advertises
truncation for outputs that actually fit. With the default 4 MiB / 3 MiB
split, every ~3–4 MiB bash capture in this band tripped the bug.

The notice is now gated on `droppedBytes > 0`. The tail ring is still
flushed unconditionally so head + tail still equal the verbatim stream
in this band. Regression pinned by a new test in
`test/streaming-output.test.ts` that pushes 24 bytes into a 16-head /
16-tail cap and asserts the file equals the payload byte-for-byte with
no `[ARTIFACT TRUNCATED:` marker.

Refs #2081
2026-06-10 08:26:00 +02:00
roboompandcan1357 77a68b1070 fix(coding-agent): broke runaway edit loops and capped bash artifact spew
Two pathologies surfaced in the same captured failure (#2081): a subagent
spent 16 minutes hammering 205 `edit` calls (182 byte-identical no-ops)
against a file that already matched its payload, while a sibling bash
invocation persisted 7.6MB of PowerShell rich-object metadata to
`~/.omp/agent/artifacts/<id>.bash.log` from what was intended as a small
tail. Both are addressed independently here:

- Hashline executor now consults a per-ToolSession `noopLoopGuard` that
  hashes the raw patch input and tracks consecutive no-ops per canonical
  path. After NOOP_HARD_LIMIT (3) repeats of the same payload the soft
  "byte-identical" hint escalates to a thrown ToolError, which the agent
  loop surfaces as a tool failure rather than success-with-text — far
  more effective at breaking the loop than the soft hint alone. A
  non-noop commit (or any variant payload) resets the counter; state is
  isolated per ToolSession so subagents cannot inherit each other's
  history.
- OutputSink artifact-on-disk writes are now bounded by
  `artifactMaxBytes` (default 4 MiB = 3 MiB head + 1 MiB rolling tail).
  Once the head budget is exhausted, subsequent chunks divert into a
  fixed-size tail ring; `dump()` replays the ring behind a single
  `[ARTIFACT TRUNCATED: kept first … + last … of …; … elided from the
  middle]` notice before closing the sink. Setting `artifactMaxBytes: 0`
  restores the historical unbounded behavior. Sized comfortably above
  anything a model would reasonably scroll through via the artifact URL
  scheme while preventing the captured 7.6MB spray from sitting on disk.

The terminal-typing lag the reporter observed has multiple compounding
causes (transcript-render freezing is disabled on win32; the bash result
renderer lacks the per-render cache that the eval renderer already has).
Those land in a follow-up — the loop guard + artifact cap address the
root pathologies that turned the session into a multi-MB transcript in
the first place.

Fixes #2081
2026-06-10 08:26:00 +02:00
can1357 661587e110 feat(coding-agent): raised retry limits to ten with capped exponential backoff
- Raised Anthropic provider retries to 10 attempts and used a shared jittered exponential backoff for each retry.
- Updated coding-agent retry defaults and session delay calculation to a 500ms base with an 8,000ms jittered cap.
- Added tests that verify capped ten-step backoff sequences and recovery after repeated 502 errors.
2026-06-10 07:49:12 +02:00
can1357 b0fec42218 feat(coding-agent): surfaced lazy LSP servers as available in welcome screen
- Added "available" status so recognized servers show under lazy mode without warmup.
- Rendered full welcome box as pre-TUI splash with fixed slot heights to avoid layout shift.
- Reported lazy servers as available in /status instead of omitting the section.
2026-06-10 07:22:22 +02:00
can1357 1b9d9d0851 refactor(catalog)!: split model catalog from pi-ai
Move bundled models, model cache/manager, thinking metadata, effort helpers,
provider descriptors/discovery, wire constants, and model identity utilities
into the new @oh-my-pi/pi-catalog package.

Update pi-ai to keep provider runtime/auth concerns, move catalog provider
metadata into CATALOG_PROVIDERS, and migrate coding-agent, agent, stats, docs,
and tests to import catalog values from pi-catalog.

Split coding-agent model registry helpers into discovery, roles, and models
config modules while preserving registry orchestration.

BREAKING CHANGE: @oh-my-pi/pi-ai no longer exports catalog subpaths such as
/models, /model-cache, /model-manager, /model-thinking, /effort,
/provider-models*, discovery helpers, and provider wire constants; use the
matching @oh-my-pi/pi-catalog subpaths instead.
2026-06-10 04:06:57 +02:00
can1357 7124c74067 fix(ai): waited for sibling unblock over provider retry window
- Returned earliest sibling block expiry from markUsageLimitReached.
- Capped usage-limit retry to whichever frees up first, avoiding multi-hour waits.
- Added 1s buffer so retry lands after the block actually lapses.
2026-06-10 02:44:40 +02:00
can1357 f2137becb8 fix: fixed prompt parsing, startup tracing, and help-command behavior
- Fixed help rendering so `--help` no longer triggers unrelated command loaders.
- Fixed startup span logging to emit markers only with PI_DEBUG_STARTUP set.
- Fixed logger startup trace behavior for `:start`, `:done`, and `:fail` phases.
- Fixed prompt template processing with cached raw-template compilation and safer formatting.
- Optimized symbol and tag parsing in prompt templates via manual parsers.
2026-06-10 02:17:35 +02:00
can1357 a13e9827f4 fix(coding-agent): fixed bash output integrity, job lifecycle, and interception
artifact spill now includes the head-retained bytes (full capture was missing first ~20KB); chunk throttle coalesces instead of dropping; cd-prefix extraction defers shell-expanded paths; interceptor rule is quote-aware and catches clobber and variable targets; completed async jobs release their Shell; at job cap commands degrade to foreground; PTY mode drops the non-interactive env and notes silent downgrades; timeout/abort annotations always appended; removed dead idle-timeout-watchdog.
2026-06-10 01:27:17 +02:00
Can BölükandGitHub 15f597b71d Merge branch 'main' into farm/44203ced/shake-fallback-when-threshold-stays-above 2026-06-08 22:36:14 +02:00
roboomp a190298414 fix(coding-agent): fell back to context-full when shake cannot drop below threshold
Threshold-driven auto-compaction with strategy=shake auto-continued even when
the shake reclaimed nothing material, and the next agent turn re-triggered the
same shake (which had nothing new to drop on a second pass), spinning forever.
After shake completes, recompute the post-shake context estimate; when it
still exceeds the auto-compact threshold (or shake reclaimed nothing on overflow
recovery), emit a one-shot fallback warning and hand off to the summarization
driven context-full path so progress actually resumes. Idle is exempt — its
60s+ timer self-throttles and cannot dead-loop on its own.

Fixes #2119
2026-06-08 20:34:16 +00:00
roboomp ef49122afe fix(coding-agent): honored skill prompt magic keywords
Skill prompt custom messages now scan user-authored skill args for magic keywords and turn budgets, matching normal prompt steering behavior without scanning skill body text.

Added a regression test for workflowz and hard turn-budget args on skill prompts.

Fixes #2128
2026-06-08 20:32:22 +00:00
can1357 9edf773b81 feat(coding-agent): centralized tool filtering for discovery mode with forced tool activation
- Introduced filterInitialToolsForDiscoveryAll() to centralize tool filtering when discovery mode is "all", replacing inline logic in createAgentSession.
- Added forceActive parameter to ensure tools required by forced tool_choice features (e.g., eager todo) remain active in the request, preventing provider 400 errors.
- Updated eager todo enforcement to check active tool set instead of registry, ensuring it respects tool discovery hiding.
2026-06-08 19:08:31 +02:00
can1357 522a7d0f5d fix(ai): scoped Claude device_id to install id and account
- Derived device_id from both install id and account UUID via v2 hash domain.
- Fell back to v1 install-only hash when no account UUID is present.
- Threaded account UUID through Anthropic metadata user_id resolution.
2026-06-08 18:28:07 +02:00
can1357 eae8b932ef fix: fixed incomplete tool-call abort handling and image content guards
- Normalized image-content preprocessing in agent sessions now returns early when `content` is missing or not a string/array, avoiding invalid normalization paths.
- Updated agent-loop tests to verify partial tool calls are dropped when an assistant aborts before `toolcall_end`, with run completion reported via an assistant `stopReason` of `aborted`.
- Adjusted Anthropic alignment expectations to reflect a single trailing cache-control breakpoint on the final system block.
2026-06-08 15:07:26 +02:00
can1357 a84da2a61e feat(coding-agent): added AST-condition matching for interrupt flow rule handling
- Added astCondition to rule frontmatter parsing and rule metadata, with AST-grep normalization.
- Updated TTSR bucketing so astCondition-only rules are treated as interruptible matches.
- Added ts-redundant-clear-guard as a built-in JS/TS tool rule for guarded clear* calls.
- Added AST snapshot matching in agent sessions with per-stream cache throttling and cleanup.
2026-06-08 14:57:17 +02:00
can1357 0890b2be61 fix: fixed tool-call recovery, stream parsing, and image normalization flows
- Fixed tool result validation to reject invalid blocks and append explicit error diagnostics.
- Handled aborted and leaked tool calls by returning abort results and dropping partial leaked output.
- Fixed Anthropic streaming by enforcing strict SSE parsing and content-block lifecycle checks.
- Fixed image handling by normalizing model-context inputs and preserving images on resize failure.
2026-06-08 14:40:18 +02:00
can1357 462c2b749c fix(coding-agent/task): show agent type in task result header
Append the dispatched agent type to the task result frame header so it reads `Task 16 agents: Reviewer` instead of just `Task 16 agents`.
2026-06-08 14:22:49 +02:00
can1357 0753a7a433 feat(agent): removed max tool-call caps from agent loop and session flow
- Removed `maxToolCallsPerTurn` from `AgentOptions`, `AgentLoopConfig`, and config serialization.
- Removed stream-loop cap enforcement, including the `toolcall_end` abort path and capped assistant messages.
- Removed Anthropic Opus 4.8 batch-cap resolver and agent-session sync logic from coding-agent.
- Updated tests and changelogs to align with uncapped tool-call behavior and dropped cap-specific cases.
2026-06-08 14:15:46 +02:00
can1357 2de70263d8 refactor(coding-agent/session): switched session relocation notice to structured logging
- Replaced the moved-session stderr write with a structured logger.info call.
- Logged relocation metadata as `{ from, to }` fields for the re-rooting path.
2026-06-08 14:00:17 +02:00
can1357 28dade85c3 fix(agent): resolved deferred asides at injection to drop stale messages
- Introduced `AsideMessage` as a message-or-thunk union so aside providers can defer injection decisions.
- Updated agent loop handling to resolve aside thunks at injection time and skip entries that returned `null`, then switched the session yield queue to `drainLazy` for deferred message building.
- Added tests validating lazy aside evaluation and staleness-aware dropping when everything becomes stale after dequeueing.
2026-06-08 06:46:41 +02:00
can1357 de03d7f3d1 feat(agent): added non-interrupting aside message support
- Added a new aside-message source on `Agent` and exposed it in `AgentLoopConfig` as `getAsideMessages`.
- Updated the agent loop to poll aside messages after tool batches and before yielding, merging them with follow-up messages before continuing.
- Changed coding-agent session and yield queue handling to pull queued background messages via `drainMessages` at step boundaries instead of streaming-only injection.
2026-06-08 06:08:43 +02:00
can1357 02dc03d03f fix(coding-agent): updated late diagnostics to batch messages and drop stale results
- Added per-path edit versioning in `EditTool` to drop stale late diagnostics after later edits.
- Added deferred diagnostics queueing through `queueDeferredDiagnostics` and late-diagnostic yield batching.
- Updated `UiHelpers` to render late diagnostic file path and summary lines in the chat transcript.
2026-06-08 05:46:43 +02:00