Commit Graph
6725 Commits
Author SHA1 Message Date
can1357 ae89b3ff08 fix(tui): merged scrollback offer boundary repair
Merged PR #4330 and fixed the remaining offered-boundary regression by stopping offer promotion at intervening live blocks.

Verified with targeted transcript/native scrollback regressions: 40 pass.
2026-07-02 23:41:53 +02:00
can1357 5de45fa975 Merge remote-tracking branch 'origin/farm/61175132/fix-windows-session-tail-loss' 2026-07-02 23:33:20 +02:00
can1357 2c8daf0578 feat: implemented dynamic coercion for legacy tool argument aliases
- Added `normalizeSingleStringField` to dynamically map misplaced string inputs to required schema fields for single-argument tools.
- Integrated argument normalization into `validateToolArguments` to handle model-specific variations in JSON payloads during validation passes.
- Updated `coding-agent` streaming and rendering components to recognize `_input` as a legacy alias for `input` across various UI paths and logic flows.
- Refactored `hashlineEditParamsSchema` to strictly enforce the `input` field while maintaining support for legacy aliases via runtime coercion rather than schema definition.
- Corrected unit tests to reflect that `_input` is rejected by the strict schema but handled gracefully by the validation layer.
2026-07-02 23:32:35 +02:00
can1357 ae2da8b8bc Merge remote-tracking branch 'origin/farm/1ca78b3d/capture-tts-worker-stderr' 2026-07-02 23:28:45 +02:00
can1357 718eefcdf5 Merge remote-tracking branch 'origin/farm/fd1e45ae/fix-acp-terminal-shell-wrap' 2026-07-02 23:28:06 +02:00
roboomp 01ab7e26d7 fix(session): kept newer fence owner on stale rewrite unwind
SessionManager.#runFencedAtomicRewrite's finally now only clears #atomicRewriteFenceEpoch when it still matches the unwinding task's epoch. When flushSync supersedes an in-flight rewrite (bumping #diskEpoch and resetting #diskTail), a fresh atomic task scheduled at the new epoch can take ownership of the fence before the stale rewrite finally settles; the previous unconditional clear stranded the newer rewrite's bookkeeping so subsequent sync appends took the hot writer path and were then detached by the newer publish.

Regression: SequencedRewriteStorage pauses the first N writeTextAtomic calls on per-call gates. Test schedules a stale rewrite, forces flushSync to bump the epoch via a fenced append, schedules a newer rewrite that parks at pauses[1], releases the stale gate (stale unwinds and guard-rejects), then appends a custom entry — asserts writerOpens does not grow (fence preserved) and the fenced entry lands in the newer publish's body. Without the fix, writerOpens grows from 1 to 2.

Fixes #4338
2026-07-02 21:20:53 +00:00
can1357 234a46fa3f feat(session): delayed session termination for pending async background jobs
- Added `#hasPendingAsyncWake` to detect running or pending background jobs owned by the agent.
- Deferred todo reminders and `session_stop` hook passes until all agent-owned background async jobs complete.
- Ensured scheduling pauses caused by async jobs do not trigger terminal session stops or premature todo nags.
2026-07-02 23:14:22 +02:00
roboomp 549b4c13a8 fix(session): relaxed fence once flushSync superseded the atomic
Replaced the boolean #atomicRewriteActive flag with #atomicRewriteFenceEpoch: number | null. The fence branch in #appendToSessionFile now applies only while the pending atomic rewrite's epoch still matches #diskEpoch. Once flushSync -> #rewriteSynchronously bumps the epoch, the in-flight writeTextAtomic is guaranteed to abandon via its commitGuard, so subsequent sync appends can (and must) take the hot path against the freshly-published body instead of being stranded in memory when close() returns without another rewrite.

New regression: pauses writeTextAtomic mid-flight, appends a fenced custom entry, calls flushSync (which captures it into the durable body), then appends a message + custom entry after the epoch bump. Reads the current JSONL BEFORE releasing the paused atomic and asserts both post-flushSync entries are already on disk; then releases the atomic (commitGuard rejects) and closes the session and asserts nothing is lost.

Fixes #4338
2026-07-02 20:54:24 +00:00
can1357 0059aed4f0 feat(hashline): enabled content hash matching to resolve tag collisions
- Simplified match logic to rely exclusively on content hash equality.
- Removed strict validation that rejected colliding snapshot tags.
- Updated recovery behavior to resolve collisions to the most-recently recorded snapshot.
- Refactored tests to expect successful preview and patching despite tag ambiguity.
2026-07-02 22:45:29 +02:00
can1357 d82b9bdc5f feat(agent): allowed dynamic model resolution per LLM call
- Added `getModel` to `AgentLoopConfig` to allow runtime model resolution.
- Updated `streamAssistantResponse` to resolve the model dynamically per provider call instead of using the stale configuration snapshot.
- Enabled mid-run model switches to take effect immediately for context promotion and retry fallbacks.
2026-07-02 22:43:11 +02:00
roboomp babb731cf5 fix(session): looped title fallback + drained backend on close
SessionManager.#persistTitleChangeEntry's catch fallback previously did a single-shot atomic rewrite: any prompt/tool appended while it awaited was fenced with #atomicRewriteDirty=true but never re-serialized. Extracted the fenced-rewrite do-while loop into #runFencedAtomicRewrite and used it from both #rewriteAtomically and #persistTitleChangeEntry, so fenced entries during either path are captured before the task resolves.

Added SessionStorage.drain(): for FileSessionStorage and MemorySessionStorage it is a no-op; IndexedSessionStorage already had one and now conforms to the interface. SessionManager.flush() and close() await it so a graceful shutdown does not exit while a fire-and-forget writeTextSync publish (queued by flushSync on an indexed backend) is still on the wire — reducing the residual publish-window race for Redis/SQL where the backend cannot be aborted mid-flight.

Regression covers the title fallback loop: TitleFallbackPausingStorage forces updateSessionTitle to throw, pauses the fallback's writeTextAtomic, appends a message and a custom entry during the pause, and asserts (a) both fenced entries land on the current JSONL, (b) the final title is applied, and (c) writeTextAtomicCalls >= 2 proving the loop iterated.

Fixes #4338
2026-07-02 20:32:27 +00:00
roboomp f614ec1537 fix(session): honored commitGuard at indexed publish time
IndexedSessionStorage.writeTextAtomic no longer delegates directly to writeText, which yielded on #awaitPath between the guard check and the backend publish. The new impl consults the guard three times — up front, again after #awaitPath resolves, and finally inside the enqueued task immediately before #backend.writeFull — so a flushSync that bumps #diskEpoch while the atomic rewrite is suspended cannot land stale content on Redis/SQL backends. When the enqueue-time guard rejects, the optimistic index update is restored only when nothing has advanced it past our mtime, so a concurrent writer's state is preserved.

Added a PausableWriteFullBackend regression: the first writeTextAtomic parks inside backend.writeFull holding the per-path tail; the second queues with a guard that flips after the first is released. The backend records only the first content, confirming the guard is honored at publish time.

Fixes #4338
2026-07-02 19:17:45 +00:00
roboomp 23d9f7c898 fix(session): discarded temp on EPERM guard-reject branches
FileSessionStorage.#replaceSessionFileAfterEpermSync now unlinks the staged temp file when commitGuard returns false in both fallback branches: the ENOENT-vanished-target path and the post-move-aside path (where the moved-aside backup is also restored). Honors the writeTextAtomic contract that a guard-rejected stage is discarded.

Regressions cover all three guard-reject exits: the direct rename pre-check, the ENOENT branch inside the EPERM fallback, and the move-aside branch that also restores the backup. Each asserts no orphan .tmp remains in the session dir.

Fixes #4338
2026-07-02 19:11:25 +00:00
roboomp 24c6b3a9f9 fix(session): fenced writer close-yield inside atomic rewrite
SessionManager.#rewriteAtomically now enables #atomicRewriteActive before #closeWriterHandle() and keeps it set until the rewrite task exits, so a sync append landing in the close-yield window is fenced and cannot open a fresh writer that the pending writeTextAtomic would then detach from the current JSONL path. Same pattern applied to the #persistTitleChangeEntry atomic fallback.

Added a regression that pauses the fake storage's writer.close() gate, appends a message and a custom entry during the pause, and asserts (1) no new writer opens (writerOpens counter unchanged) and (2) the fenced entries land on the current JSONL path after the rewrite completes.

Fixes #4338
2026-07-02 19:07:36 +00:00
roboomp 326a3406a8 fix(session): guarded atomic rewrite against flushSync overwrites
SessionStorage.writeTextAtomic now accepts a commitGuard the backend calls synchronously immediately before publishing the staged body. FileSessionStorage performs the guard check and rename in the same tick via fs.renameSync (both on the direct path and the EPERM move-aside fallback), so a concurrent #rewriteSynchronously (flushSync -> Ctrl+C / session exit) that bumps the disk epoch cannot be overwritten by the stale body serialized before it ran. MemorySessionStorage and IndexedSessionStorage honor the same guard.

SessionManager.#rewriteAtomically threads a guard that returns false when the disk epoch changes, and re-checks the epoch after every writeTextAtomic before touching #fileIsCurrent / #rewriteRequired. #persistTitleChangeEntry's atomic fallback wires the same guard.

Added a regression that pauses the fake storage's writeTextAtomic mid-flight, appends a session_exit custom entry (which the fence records in memory), calls flushSync, releases the paused rewrite, and asserts the exit record is still on the JSONL path and the atomic publish was rejected by the guard.

Fixes #4338
2026-07-02 19:00:27 +00:00
roboomp 69db80fbe7 fix(session): preserved tail after atomic compaction rewrites
Fenced synchronous session appends while an atomic full-file replacement is active so Windows EPERM fallback cannot detach the append writer from the current JSONL path.

Added a deterministic storage fake regression covering superseded compaction rewrites, title changes, session-exit diagnostics, resume, and post-rewrite tool/assistant tail persistence.

Fixes #4338
2026-07-02 18:36:56 +00:00
roboomp 157c1d1c7d fix(acp): reuse resolved bash shell for terminal/create wrap
Addresses codex review on #4335: the previous wrap dropped to cmd.exe on Windows, which broke bash tool semantics for $VAR, $(...), source, and POSIX quoting even when the local executor would have resolved Git Bash / bash.exe. The wrap now takes the resolved ShellConfig (shell binary + login/-c args + optional prefix) from settings.getShellConfig() and reuses it for the ACP terminal/create shape, so the ACP path matches the local path on both platforms. Tests updated to stub getShellConfig and assert the resolved-shell shape deterministically.
2026-07-02 17:59:56 +00:00
roboomp 7b52f64680 fix(acp): wrap bash tool shell line in /bin/sh -c for terminal/create
The bash tool routes commands through the ACP client's terminal/create when the client advertises the terminal capability. It was passing the full shell line as the ACP command field with no args, which relies on the client interpreting command through a shell. Per the ACP protocol docs, command is the executable and args is its argv tail; a spec-conformant client spawns them directly (no implicit shell), so any bash line with a space, pipe, &&, redirect, or $(...) failed with ENOENT and the agent silently degraded to read-only tools.

The bash tool now wraps the shell line before the createTerminal call: { command: /bin/sh, args: [-c, line] } on POSIX and { command: cmd.exe, args: [/d, /s, /c, line] } on Windows. /d/s/c matches Node's spawn({ shell: true }) convention (/s preserves the whole shell line as one argv element on the receiving end). process.platform on the agent side proxies the client's platform, which matches the near-universal ACP shape of an editor spawning omp as a co-hosted subprocess.

Fixes #4333
2026-07-02 17:53:58 +00:00
Vlad Toie d064563c55 feat(ai): track Claude Fable weekly usage separately in omp usage
Anthropic's OAuth usage endpoint now ships a generic limits[] array;
model-scoped weekly caps (Fable) exist only there while the legacy
seven_day_opus/seven_day_sonnet buckets are permanently null. Parse
weekly_scoped entries into anthropic:7d:<slug> tier rows (Claude 7 Day
(Fable)), backfill shared 5h/7d from session/weekly_all when legacy
buckets are absent, and accept limits[]-only payloads in hasUsageData.

Add scopeLimits/blockScope to claudeRankingStrategy so an exhausted
Fable/Mythos cap gates only matching-model requests instead of cooling
down the whole OAuth credential (mirrors the Antigravity per-counter
precedent). Dedupe the ACP /usage tier suffix when the label already
names the tier.
2026-07-02 19:55:00 +03:00
roboomp b0e52a13ac fix(subprocess): avoided stderr capture handles for idle workers
Bun keeps the parent event loop alive when an unref'd child has a piped
stderr stream. The first #4324 fix started with stderr: "pipe", so a
long-lived idle TTS/STT/tiny/mnemopi worker could keep short CLI commands
alive even after proc.unref().

Switch worker stderr capture to a temp-file fd target instead of a Bun
ReadableStream pipe. The parent does not start any JS read while the
worker is alive; after onExit it reads the bounded tail from the file,
logs captured lines, appends the tail to the surfaced worker Error, then
closes and removes the temp capture.

Add a regression that spawns a non-test wrapper process with an idle
unref'd worker and asserts the wrapper exits immediately. Existing stderr
capture, truncation, and intentional SIGKILL behavior remain covered.

Fixes #4324
2026-07-02 16:25:41 +00:00
roboomp 49b4ef50f8 fix(tui): fixed audited scrollback tail rows
Separated audited offerable transcript rows from durable snapshot rows so lower finalized content below a live block can be repaired instead of duplicated when the live block grows.

Added transcript and virtual-terminal regressions for the lower finalized tail case.

Fixes #4326
2026-07-02 16:24:11 +00:00
roboomp 4cca96c5bf fix(subprocess): captured worker stderr and surfaced it on unexpected exit
Inference worker subprocesses (TTS, STT, tiny-model, mnemopi embeddings)
were spawned with stderr: "ignore", so a native crash inside the child
was completely discarded. The parent only ever logged the bare exit code
(e.g. Kokoro TTS's recurring "tts subprocess exited with code 7"),
leaving the recurring crash loop undiagnosable.

createWorkerSubprocess now pipes stderr and drains it in the parent:

- Each decoded stderr line is forwarded to logger.debug under
  "<exitLabel> stderr" so operators get live visibility on chatty native
  runtimes without touching the chat scrollback.
- A bounded 16 KiB ring keeps the tail of stderr so the eventual exit
  Error carries the actual crash reason (ONNX Runtime traceback, glibc
  assertion, etc.) instead of "code 7" alone. The prefix is preserved so
  existing log grepping keeps working.
- The exit event and the stderr pipe are independent, so a synchronous
  read in onExit would race the drain. SpawnedSubprocess grew a
  stderrDrained: Promise<void>, and onExit chains the error surface off
  it so callers see the whole tail. Tests can await stderrDrained
  deterministically instead of racing wall-clock timers.
- Intentional terminate() SIGKILLs still stay silent — signal-exit
  gating on intentionalExit is unchanged.

Fixes #4324
2026-07-02 16:09:15 +00:00
can1357 e73a25489c feat(coding-agent/tools): migrated path input from array to semicolon-delimited string
- Changed the `path` property from an array of strings to a single semicolon-delimited string across tool definitions and tests.
- Updated validation error messages to reflect the new `path` input format.
- Adjusted all relevant test cases to provide path targets as semicolon-separated strings.
2026-07-02 17:48:46 +02:00
can1357 88f0aab994 style: formatted eval fix commits with biome 2026-07-02 10:34:53 +02:00
can1357 3830ad353e merge PR #3843 (surviving delta): perf: streaming-reveal/render throughput + core hot-path optimizations (@oldschoola)
# Conflicts:
#	packages/coding-agent/src/config/model-resolver.ts
2026-07-02 10:31:45 +02:00
can1357 12bbf4a090 merge PR #1706 (+exit-guard port): fix(coding-agent): guard custom tool process exits during load (@roboomp) 2026-07-02 10:30:58 +02:00
can1357 eeeab97db0 fix(session): auto-reply awaited IRC sends to an idle plan-mode session
Plan mode records idle IRC deliveries into context without waking a turn,
so an 'irc send await:true' sender was stranded until its wait timeout:
delivery reported injected but no reply could ever be generated. Extend the
existing ephemeral side-channel auto-reply (previously only for mid-turn
recipients with async execution disabled) to the idle plan-mode case — the
second situation where a real reply turn cannot happen in time. No primary
turn is woken; plan-mode convergence stays user-driven.

The deliverIrcMessage eligibility change itself rode in the previous commit
(same-file hunks); this commit carries the bus doc and the regression test:
an awaited idle IRC message in plan mode resolves the sender's bus waiter
via the side-channel reply while the primary loop stays asleep.
2026-07-02 10:30:51 +02:00
can1357 71209f025d fix(session): drop stale plan-mode-decision tool choice on skip/exit
The settle-time reminder queues a hard 'required' tool choice paired with a
scheduled continuation. If that continuation never runs (user prompt bumps
the generation, dispose, compaction/handoff) or plan mode is exited first,
the queued directive leaked onto the next unrelated turn as a forced tool
call. Remove it by label on continuation skip, on user-initiated prompts,
and when plan mode is disabled.
2026-07-02 10:30:51 +02:00
can1357 2875dd3349 merge PR #3911: fix(session): converge plan mode on ask/resolve across continuation paths (@metaphorics)
# Conflicts:
#	packages/coding-agent/src/session/agent-session.ts
2026-07-02 10:30:51 +02:00
can1357 727bcf1401 fix: drop superseded /btw todo-reminder HUD clear
Main removed the floating todoReminderContainer in 112317bc8 (todo
reminders are now anchored inside the scrollback transcript and reset
by renderInitialMessages({clearTerminalHistory: true})), so the added
this.todoReminderContainer.clear() references a property that no longer
exists post-merge, failing typecheck and throwing on every /btw branch.
Revert the interactive-mode hunk and its test, and reword the changelog
entry to cover only the goal-mode todo context fixes.
2026-07-02 10:30:12 +02:00
can1357 4940a053ad merge PR #3777: Fix todo HUD and goal context follow-ups (@jeffscottward) 2026-07-02 10:30:12 +02:00
can1357 23d16a4c5e merge PR #3922: fix(task): scan OMP extension agents/ dirs in discoverAgents (@roboomp) 2026-07-02 10:30:06 +02:00
can1357 a23d1d6554 merge PR #4140: fix(coding-agent): stopped isolated task merges failing when working tree carries WIP for files the agent also modifies (@roboomp) 2026-07-02 10:30:06 +02:00
can1357 ebf41281e7 fix(tui): stop spinner ticks for frozen pending previews
The github renderer materializes plain Text per display rebuild, so its
animatedPendingPreview opt-in requested 30fps repaints with a frozen
glyph for the whole run_watch wait; drop the flag. Custom tools with
only one of renderCall/renderResult never route to the animated generic
fallback, so gate the unregistered-renderer spinner on both being
absent. Regression tests for both no-tick contracts.
2026-07-02 10:30:06 +02:00
can1357 6429de3e83 merge PR #4172: fix(tui): animate live tool spinners (@roboomp) 2026-07-02 10:30:06 +02:00
can1357 278056025b merge PR #4200: fix(tui): stop /move overlay from statting every entry per keystroke (@roboomp) 2026-07-02 10:30:06 +02:00
can1357 4e12e5bf76 fix(extensibility): read lazy graph modules from disk at import time
The consume-once source map kept entries for graph modules the initial
import never loaded (modules only reached via lazy dynamic imports).
Their first import - possibly long after load, and after an on-disk
edit - was served the boot-time snapshot instead of current file
content, and the unconsumed sources stayed in the plugin closure for
the process lifetime.

Clear the map once the entry import settles: everything Bun loaded at
startup was already consumed (keeping the read-once win), and anything
left must be read at its actual import time, matching pre-dedup
behavior for lazy modules. The new regression test passes on the
pre-dedup baseline and fails on the unfixed dedup.
2026-07-02 10:29:57 +02:00
can1357 64e4bd89d1 merge PR #4205: perf(extensibility): read extension source graph once per load (@metaphorics) 2026-07-02 10:29:57 +02:00
can1357 2a7a7ec15c merge PR #4202: fix(coding-agent): scope discoverExtensionPaths to native extension-module provider (@roboomp) 2026-07-02 10:29:57 +02:00
can1357 c8fcf7a3c7 merge PR #4209: fix(coding-agent): cache plugin extension resolution (@roboomp) 2026-07-02 10:29:56 +02:00
can1357 a7ff81e0f6 merge PR #4217: fix(providers): hydrate runtime model cache before selection (@roboomp) 2026-07-02 10:29:47 +02:00
can1357 a5043b11ec merge PR #4221: fix(session): keep model switches active after rate limits (@roboomp) 2026-07-02 10:29:47 +02:00
can1357 c2a9f97c41 fix(title): don't treat caseless scripts as shouting
isAllCapsWord matched any multi-letter token without a lowercase letter,
so CJK tokens registered as ALL-CAPS words: two adjacent ones marked the
whole source shouty and silently disabled acronym restoration for every
non-Latin-script message (e.g. '修复 CNPG 集群故障' kept 'Cnpg'). Require an
actual uppercase letter; cased-script shout detection is unchanged.
2026-07-02 10:29:38 +02:00
can1357 289c7b357d fix(title): allowlist ETL so acronym restoration matches the documented contract
The PR's changelog, doc comment, and prompt examples all name ETL as a
restored acronym, but the review-response narrowing (vowel heuristic +
allowlist) silently dropped it: ETL bears a vowel and was not listed.
Add it to COMMON_TITLE_ACRONYMS and pin it in the allowlist test.
2026-07-02 10:29:37 +02:00
can1357 7be66da1ef merge PR #4222: fix(title): preserve ALL-CAPS acronyms in auto-generated session titles (@roboomp) 2026-07-02 10:29:37 +02:00
can1357 a6bd317af6 style: bun run fix 2026-07-02 10:26:33 +02:00
PR Evaluator a76a33476a fix(coding-agent): guard custom tool loads with the shared exit guard
Replaces the bespoke batch-scoped process.exit interceptor with the
withExitGuard convention main established for extension/hook/plugin
loaders (500c39aa2): guard the module import and factory invocation so
a synchronous process.exit()/process.reallyExit() from a custom tool
becomes an ExtensionExitError handled as a recoverable load error,
while host exit paths stay untouched outside the guarded windows.
Tests cover the import-time exit (issue #1704 repro) and factory-time
exit; both would kill the test process without the guard.
2026-07-02 10:24:21 +02:00
can1357 fca39e8ede perf: reconcile with main — drop superseded streaming/patch/session work, port resolver context reuse
main independently absorbed batch-1 (incremental grapheme slice 718c7cea2, markdown
stream-prefix cache 705426548 + 3822a83b4) and the pathTo/patch.ts items; restore
main's refined versions wholesale. Port the model-resolver optimization onto main's
resolver shape: hoist per-candidate case folds in matchModel and build the
preference context once per role resolution (matchPatternWithContext) instead of
per fallback pattern. Rewrite changelog entries to the surviving items only.
2026-07-02 10:22:48 +02:00
PR Evaluator 6ad4db58a5 fix(coding-agent): backport shared extension exit guard from main
Byte-identical copy of the withExitGuard/ExtensionExitError block from
main (500c39aa2) so the custom-tool loader can reuse the established
guard convention; merges as an identical change against main.
2026-07-02 10:21:13 +02:00
roboomp bc5fbb4eb6 fix(title): avoid restoring emphasized words as acronyms
Narrow acronym restoration so plain all-caps English words such as FIX
and WORK do not get restored when the model naturally capitalizes the
first title word. Restorable all-caps source tokens now need a stronger
acronym signal: a common technical acronym allowlist, digits, or a
consonant-only shape.

This keeps CNPG, ETL, JWT, SQL, and API restoration while preserving the
anti-shout behavior for single emphatic words.

Fixes #4220
2026-07-02 07:02:26 +00:00