Commit Graph

6674 Commits

Author SHA1 Message Date
can1357 af2e2bf05c Merge PR #7121: fix(search): paginate DuckDuckGo HTML results (@roboomp) 2026-07-31 19:14:47 +02:00
can1357 8f6305f772 fix(tools): preserve read continuation notice when spilling 2026-07-31 19:14:47 +02:00
can1357 ce6c57acb0 Merge PR #7117: fix(coding-agent): spill oversized read results to artifacts (@wolfiesch) 2026-07-31 19:14:46 +02:00
can1357 78825403ad fix(coding-agent): replay queued appearance changes 2026-07-31 19:08:17 +02:00
can1357 540e8f5797 Merge PR #7188: fix(coding-agent): preserve scrollback on appearance changes (@Sairen777)
# Conflicts:
#	packages/coding-agent/src/modes/controllers/input-controller.ts
2026-07-31 19:08:16 +02:00
can1357 95f5dc8011 Merge PR #7192: fix(coding-agent): reload MCP servers on /reload-plugins (@roboomp) 2026-07-31 19:07:28 +02:00
can1357 3411bc3c8d Merge PR #7177: fix(coding-agent): keep ExtensionContext.cwd live across /move (@KennethHoff) 2026-07-31 19:07:18 +02:00
can1357 80a46c2d4c fix(coding-agent): avoid splitting parameter expansions 2026-07-31 19:07:18 +02:00
can1357 969b4a34a5 Merge PR #7176: fix(coding-agent): inspect compound Bash commands in interceptor (@Vincent-Huang-2000) 2026-07-31 19:07:18 +02:00
can1357 32748807a7 Merge PR #7175: fix(coding-agent): re-export compact from legacy pi shim (@roboomp) 2026-07-31 19:07:17 +02:00
can1357 e13c2918b6 test(coding-agent): provide settings in input context fixture 2026-07-31 19:07:17 +02:00
can1357 3a68ce7eb0 Merge PR #7167: fix(cli): generate titles for positional initial messages (@roboomp) 2026-07-31 19:07:17 +02:00
can1357 21b1d4d4d2 Merge PR #7165: fix(tui): format selector keybinding hints (@roboomp) 2026-07-31 19:07:16 +02:00
can1357 40120fd2b4 fix(context): preserve total-only usage anchors 2026-07-31 19:07:16 +02:00
can1357 bf08e12629 Merge PR #7163: fix(session): reconstruct context without prompt usage (@harshav167) 2026-07-31 19:07:16 +02:00
can1357 71244aec4b Merge PR #7161: fix(tui): contain synchronous image conversion failures (@roboomp) 2026-07-31 19:07:16 +02:00
can1357 da3b5bd65a Merge PR #7153: fix(session): stop repeated mid-turn compaction dead ends (@roboomp) 2026-07-31 19:07:15 +02:00
roboomp b8ab418dd6 test(coding-agent): update MCP reauth fake for reload deps
reloadServers() now reads ctx.settings and session.setMCPPromptCommands, which
the shared /mcp reauth|unauth harness did not provide, so those tests threw
inside reload and failed their showError assertions. Add both members to the
fake context.

Fixes #7189
2026-07-31 16:59:38 +00:00
roboomp 62d7a7c5c9 fix(coding-agent): clear stale MCP prompts on reload
MCPManager.disconnectAll clears connections without notifying the session's
prompt-command consumer, so removed or disabled prompt servers left stale
/server:prompt commands after /reload-plugins and /mcp reload.

Clear the session MCP prompt-command registry immediately after disconnect and
before asynchronous rediscovery. Newly loaded prompts repopulate it through
the existing manager callback. Extend the reload regression coverage.

Fixes #7189
2026-07-31 16:48:36 +00:00
roboomp 95744328ef fix(coding-agent): honor mcp.enableProjectConfig on reload
reloadServers() rediscovered MCP with no options, so loadAllMCPConfigs
defaulted enableProjectConfig to true — /reload-plugins (and /mcp reload)
could start project .mcp.json servers a user opted out of.

Derive discovery filters (enableProjectConfig, filterExa, filterBrowser)
from ctx.settings before reconnecting, matching startup discovery. Added a
regression test asserting the opt-out is forwarded.

Fixes #7189
2026-07-31 16:41:08 +00:00
roboomp c7fb9140fb fix(coding-agent): reload MCP servers on /reload-plugins
/reload-plugins documents MCP in its reload scope but the TUI handler only
reset skill/command/capability caches and never reconnected MCP servers or
refreshed the session MCP tool registry, so .mcp.json edits stayed inactive
until process restart.

Route the TUI reload pipeline through a shared reloadTuiPluginState() helper
that also runs the disconnect/rediscover/refreshMCPTools path used by
/mcp reload, exposed as MCPCommandController.reloadServers().

Fixes #7189
2026-07-31 16:33:28 +00:00
Kenneth Hoff ae08bd57cb fix(coding-agent): keep ExtensionContext.cwd live across /move
ExtensionRunner cached cwd from its constructor argument, which is set
once at session start. /move (SessionManager.moveTo) relocates the
active session's directory, but ExtensionRunner never re-read it, so
every ExtensionContext built afterwards (tool calls, hooks, slash
commands) kept reporting the pre-move directory for the rest of the
session -- observed while building an extension that tracks the
session's git worktree via ctx.cwd.

Turn cwd into a getter over this.sessionManager.getCwd() instead of a
constructor-time snapshot. Session-scoped, not the process-global
project directory: the interactive /move handler happens to also
chdir the process (command-controller.ts -> applyCwdChange ->
setProjectDir), but moveTo() itself never touches that global, so a
programmatic AgentSession.moveSession()/SessionManager.moveTo() call,
a collab guest adopting a host's session cwd without chdir'ing, or an
SDK/ACP session opened via createAgentSession({ cwd }) with a cwd that
differs from the process's own would all still observe a stale
ctx.cwd under a getProjectDir()-based getter. Reading the runner's own
sessionManager -- already held for other purposes -- covers every one
of these instead of just the single-session interactive case.

The constructor parameter is kept (renamed _initialCwd, documented as
ignored) so the two existing call sites don't need touching.

Added a regression test constructing a real ExtensionRunner over an
in-memory SessionManager, relocating it via SessionManager.moveTo(),
and asserting both runner.cwd and createContext().cwd observe the new
directory.
2026-07-31 15:13:37 +02:00
Vincent Huang 296ece7ea5 fix(coding-agent): handle input fd redirects in interceptor 2026-08-01 00:34:19 +12:00
roboomp 922e7a58ef fix(coding-agent): re-export compact from legacy pi shim
Legacy pi extensions import `compact` from the `@earendil-works/pi-coding-agent`
package root (aliased to the legacy shim). It lives in
`@oh-my-pi/pi-agent-core/compaction` (same module as the already-bridged
`estimateTokens`) and the coding-agent barrel does not forward it, so the shim's
`export * from "../index"` left it off the surface and a named import failed
Bun's static export check during plugin validation
(`omp plugin install npm:pi-claude-bridge`).

`keyHint` (also named in the report) already resolves via the modes/components
barrel, so only `compact` needed bridging.

Fixes #7174
2026-07-31 12:07:44 +00:00
Vincent Huang 270590c225 fix(coding-agent): avoid splitting Bash redirection operators 2026-07-31 23:51:18 +12:00
Vincent Huang edb0deebb4 fix(coding-agent): inspect compound Bash commands in interceptor rules
Match interceptor regexes against conservative, raw shell command segments
in addition to the complete command, so anchored rules can detect commands
after &&, ||, ;, |, &, and newlines without treating quoted or escaped text
as commands.

Add extractFlatShellCommandSegments() to preserve source text for
user-configured regexes, unlike the token-based approval matcher.
Add skipShellWord() and environment-assignment stripping so rules can match
commands prefixed with NAME=value assignments. Preserve the original command
in interception errors after extracting a leading cd command.
2026-07-31 23:26:43 +12:00
roboomp 19818fd8fb fix(cli): skipped titles for positional extension commands
Applied the extension-command eligibility check inside the shared AgentSession title gate so editor and CLI bootstrap submissions cannot diverge.

Added direct regression coverage for programmatic startup submissions.

Fixes #7166
2026-07-31 10:34:46 +00:00
roboomp 223122d6b0 fix(cli): generated titles for positional initial messages
Moved automatic title eligibility and persistence into AgentSession so editor and CLI bootstrap submissions share one path.

Added a PTY regression probe covering the positional-message launch flow.

Fixes #7166
2026-07-31 10:28:48 +00:00
Harsha Vardhan 66a7126b5b fix(session): reconstruct context without prompt usage 2026-07-31 20:10:01 +10:00
roboomp a60f1efa96 fix(tui): formatted selector keybinding hints
Routed copy selector and ask dialog hints through the shared human-readable key formatter and covered both rendered surfaces.

Fixes #7164
2026-07-31 10:06:46 +00:00
roboomp b9b60545ab fix(tui): contained synchronous image conversion failures
- Centralized PNG conversion behind an async boundary so constructor and encoder throws become promise rejections.
- Kept live and restored Kitty image rendering interactive by omitting failed conversions.
- Added regressions for both tool-result render paths.

Fixes #7160
2026-07-31 09:44:07 +00:00
roboomp 527c68c72b fix(session): waited for persistence before compaction rearm
Move the dead-end rearm probe below the mid-run turn-persistence barrier so prepareCompaction sees the just-finished assistant and tool result.

Delay message-end persistence in the regression and require compaction at the second tool boundary, before another provider request can be sent.

Fixes #7151
2026-07-31 08:48:25 +00:00
roboomp f6878d3739 fix(session): re-arm mid-turn compaction after new cut points
The dead-end mark parked the live tool-loop context permanently, but the array keeps growing: a later smaller tool result can move the oversized turn to the summarizable side. Recheck prepareCompaction each boundary and re-attempt once a cut point appears, instead of suppressing until provider overflow.

Added a regression proving maintenance re-attempts once a cut point becomes available.

Fixes #7151
2026-07-31 08:37:56 +00:00
roboomp ae7038f9d3 fix(session): stopped repeated mid-turn compaction dead ends
Remember no-progress mid-turn compaction results for the live agent-loop context so later tool boundaries skip identical rescue work. The weak context key naturally resets for the next user turn.

Added a scripted regression covering one warning and one attempt per oversized tool-loop turn.

Fixes #7151
2026-07-31 08:25:00 +00:00
Alex Jaden daa9b99aab fix(coding-agent): preserve scrollback on appearance changes 2026-07-31 10:34:43 +05:00
Wolfgang Schoenberger 5f9558d17a fix(tools): keep truncation metadata when spilling read output
The artifact spill wrapper dropped the read truncation metadata, so a
spilled oversized read lost its next-offset pagination hint, and an
artifact:// read of an already-spilled result was spilled a second time.
Preserve the existing truncation metadata and skip re-spilling artifact
reads.
2026-07-30 16:25:48 -07:00
can1357 652647770e feat(coding-agent): added app.live.toggle keybinding and map display reset to alt+l
- Add the `app.live.toggle` keybinding defaulted to `Ctrl+L` to start or stop live voice mode.
- Remap the default display-reset action (`app.display.reset`) from `Ctrl+L` to `Alt+L`.
- Update the live visualizer to listen for stop keys so the toggle chord terminates active sessions.
2026-07-31 00:20:04 +02:00
can1357 5ea583e413 feat: replaced legacy editing commands with unified put and cut syntax
- Replaced legacy `SWAP`, `INS`, and `PASTE` commands with unified `PUT` and `CUT` hunks across parser, grammar, tokenizer, and test suites.
- Added support for named registers and span paste operations in clipboard and block execution logic.
- Implemented indentation repair and enhanced gap locator formatting for improved patch resilience.
- Updated documentation, system prompts, and session analysis scripts to reflect the new syntax and header shapes.
2026-07-31 00:19:52 +02:00
roboomp a07d782058 fix(search): paginated duckduckgo results
Followed DuckDuckGo's returned continuation form until the requested result limit is satisfied, preserving deduplication across pages and the existing search deadline.

Added regression coverage for continuation field submission and 20-result collection.

Fixes #7116
2026-07-30 22:09:44 +00:00
Wolfgang Schoenberger 9a6a1b40be fix(coding-agent): spill oversized read results to artifacts 2026-07-30 15:04:52 -07:00
can1357 4c1793b9b7 fix(security): hardened cloud import attribution and comparison honesty
- Failed closed when cloud pulls could not verify the project origin.
- Re-verified configuration attribution on every cloud finding detail.
- Rejected non-repository-relative Codex bundle locations.
- Refused lineage comparisons against incomplete after-scans.
- Preserved diff and working-tree targets when adding path scopes.
- Logged post-publication output failures and recovered persisted status.
- Used Bun.SHA256 directly and reused pi-ai JWT decoding.
- Shortened exported paths in interactive output.
2026-07-30 17:24:07 +02:00
can1357 ab572106cd Merge PR #7048: feat(security): add OMP-native security scan subsystem (@kmccleary3301) 2026-07-30 17:11:06 +02:00
can1357 3803219716 Merge PR #7095: fix(coding-agent): add createEditTool/createWriteTool to legacy pi shim (@roboomp) 2026-07-30 17:05:16 +02:00
can1357 fe33685f55 Merge PR #7090: fix(coding-agent): honor remote llama.cpp/ollama discovery base urls (@roboomp) 2026-07-30 17:05:15 +02:00
roboomp 766ccbf24a fix(coding-agent): add createEditTool/createWriteTool to legacy pi shim
The legacy @oh-my-pi/pi-coding-agent shim exported the read/bash/grep/find/ls
tool factories but omitted the edit and write ones. pi extensions importing
createEditTool or createWriteTool (e.g. gentle-pi) failed Bun's static export
check during extension validation, blocking omp install.

Added createEditTool/createEditToolDefinition and createWriteTool/
createWriteToolDefinition, mirroring the upstream pi surface and the existing
sibling factories. The unsupported operations seam throws a descriptive error
like createGrepTool does.

Fixes #7094
2026-07-30 14:36:10 +00:00
can1357 14dc5d4fcc fix(coding-agent/eval): bypassed environment proxies for python bridge calls
- Configure the python eval prelude to use a custom urllib opener that ignores environment proxies.
- Add test coverage verifying parallel tool bridge calls succeed when proxy variables are set.
2026-07-30 16:19:48 +02:00
roboomp fad7e97d53 fix(catalog): scoped Ollama model caches by endpoint
Ollama's online-if-uncached path keyed every endpoint under the same
provider namespace. Changing OLLAMA_BASE_URL or OLLAMA_HOST therefore
reused fresh models routed to the previous endpoint until cache expiry.

Centralize an endpoint-normalized Ollama cache namespace and apply it to
both configured coding-agent discovery and the catalog model manager.
Add coverage proving a default refresh discovers the new endpoint even
while the previous endpoint has a fresh row.

Fixes #7087
2026-07-30 13:31:08 +00:00
roboomp ec2caea840 fix(coding-agent): honor remote llama.cpp/ollama discovery base urls
llama.cpp and Ollama model discovery probed /models and /props with a
250ms timeout tuned for a loopback server. That cap also applied to a
host reached over the network, so a remote or LAN LLAMA_CPP_BASE_URL
(or OLLAMA_BASE_URL/OLLAMA_HOST) with normal round-trip latency timed
out, discovery returned no models, and the picker fell back to stale
127.0.0.1:8080 entries.

Select the probe timeout by host: strictly-loopback base URLs keep the
fast fail so a busy or foreign service on the default port never stalls
startup; every non-loopback host gets a generous discovery budget.

Fixes #7087
2026-07-30 13:19:41 +00:00
Kyle McCleary 4337797565 Merge remote-tracking branch 'origin/main' into feat/security-native
# Conflicts:
#	packages/coding-agent/src/tools/index.ts
2026-07-29 23:26:22 -07:00
Kyle McCleary 0b968bbb49 feat(security): integrate Codex Security cloud scans 2026-07-29 23:24:26 -07:00