Commit Graph

1137 Commits

Author SHA1 Message Date
can1357 af2e2bf05c Merge PR #7121: fix(search): paginate DuckDuckGo HTML results (@roboomp) 2026-07-31 19:14:47 +02:00
can1357 80a46c2d4c fix(coding-agent): avoid splitting parameter expansions 2026-07-31 19:07:18 +02:00
can1357 969b4a34a5 Merge PR #7176: fix(coding-agent): inspect compound Bash commands in interceptor (@Vincent-Huang-2000) 2026-07-31 19:07:18 +02:00
Vincent Huang 296ece7ea5 fix(coding-agent): handle input fd redirects in interceptor 2026-08-01 00:34:19 +12:00
Vincent Huang 270590c225 fix(coding-agent): avoid splitting Bash redirection operators 2026-07-31 23:51:18 +12:00
Vincent Huang edb0deebb4 fix(coding-agent): inspect compound Bash commands in interceptor rules
Match interceptor regexes against conservative, raw shell command segments
in addition to the complete command, so anchored rules can detect commands
after &&, ||, ;, |, &, and newlines without treating quoted or escaped text
as commands.

Add extractFlatShellCommandSegments() to preserve source text for
user-configured regexes, unlike the token-based approval matcher.
Add skipShellWord() and environment-assignment stripping so rules can match
commands prefixed with NAME=value assignments. Preserve the original command
in interception errors after extracting a leading cd command.
2026-07-31 23:26:43 +12:00
can1357 5ea583e413 feat: replaced legacy editing commands with unified put and cut syntax
- Replaced legacy `SWAP`, `INS`, and `PASTE` commands with unified `PUT` and `CUT` hunks across parser, grammar, tokenizer, and test suites.
- Added support for named registers and span paste operations in clipboard and block execution logic.
- Implemented indentation repair and enhanced gap locator formatting for improved patch resilience.
- Updated documentation, system prompts, and session analysis scripts to reflect the new syntax and header shapes.
2026-07-31 00:19:52 +02:00
roboomp a07d782058 fix(search): paginated duckduckgo results
Followed DuckDuckGo's returned continuation form until the requested result limit is satisfied, preserving deduplication across pages and the existing search deadline.

Added regression coverage for continuation field submission and 20-result collection.

Fixes #7116
2026-07-30 22:09:44 +00:00
can1357 ccd3bb9565 chore: reformat 2026-07-30 04:25:32 +02:00
can1357 091f670ea0 style: apply biome formatting to merged changes 2026-07-30 01:28:07 +02:00
can1357 da794ebb24 Merge PR #6938: feat(coding-agent): allow checkpoint/rewind/learn/manage_skill in subagents when explicitly requested (@szavadsky) 2026-07-30 01:26:49 +02:00
can1357 f2251b7d59 chore: normalize changelogs and formatting after merging open fixes 2026-07-29 23:09:40 +02:00
can1357 6527671c3a fix(lsp): sanitize expanded generic output
(cherry picked from commit 1260d0633a5fb533c492f272ee500fec60c46e22)
2026-07-29 23:09:14 +02:00
can1357 2adf484ef1 Merge PR #7042: fix(lsp): handle quick exits before reader teardown (@roboomp) 2026-07-29 23:09:13 +02:00
roboomp dca8f44b73 fix(lsp): handled quick exits before reader teardown
Waited briefly for process exit publication after clean stdout EOF so the process handler preserves the real exit code and stderr, while genuine reader errors still tear down immediately.

Cleared only the matching initialization failure for explicit reloads and added regressions for quick exits, reader errors, ordinary backoff, and immediate reload retries.

Fixes #7041

(cherry picked from commit a76522b759f14421202d4cc437ec611b78be20d1)
2026-07-29 23:09:13 +02:00
can1357 eb8f3e6c2c Merge PR #6993: fix(coding-agent): require web_search_call in codex search (@roboomp) 2026-07-29 23:08:55 +02:00
roboomp e5ea31b22c fix(coding-agent): require web_search_call in codex search
GPT-5.6 Responses-Lite models receive tool_choice "auto" (the forced
hosted choice is invalid under the lite shape, #5771/#5772), so the model
may answer without invoking the hosted web_search tool. The codex search
parser accepted any non-empty answer, returning a stale completion with
zero sources as a successful search.

callCodexSearch now tracks response.web_search_call.* events (and
web_search_call output items) and throws CodexNoWebSearchError when none
occurred. The candidate chain treats that error as retryable, advancing
default lite models to a non-lite model that forces web_search, and
surfaces a clear failure when the model was explicitly configured.

Fixes #6988

(cherry picked from commit a276cd0b3df1d0d041faf0a63fabcbb884e36a91)
2026-07-29 23:08:54 +02:00
can1357 7338be4d67 Merge PR #6845: fix(launch): isolate legacy xterm replay (@usr-bin-roygbiv) 2026-07-29 23:08:22 +02:00
usr-bin-roygbiv 197fd2df02 test: restore complete Worker descriptors
(cherry picked from commit a7d227e6227b2c1d20ae4a9d5107be57980463a1)
2026-07-29 23:08:22 +02:00
can1357 2c99f2f2e8 fix(git): preserve effective character locale
(cherry picked from commit ef7abf60ad1b80642ba1731e043f8eeb82c6a6aa)
2026-07-29 23:08:21 +02:00
usr-bin-roygbiv 8b81b1c0a0 fix(launch): preserve logs on replay failure
(cherry picked from commit 2bebc32a05553e75edef16f71218fa2bfbfc1f77)
2026-07-29 23:08:21 +02:00
Rolando Diaz e8bfd67d28 test(gh): bypass cached binary lookup
(cherry picked from commit 85d0ddca05640e95e7d750218c6533d6f936957d)
2026-07-29 23:08:20 +02:00
Rolando Diaz b1c3ba8b8e fix(git): preserve UTF-8 locale for gh subprocesses
(cherry picked from commit e703aa00892b4589baa6c9dcb5f3ab2a3afb1662)
2026-07-29 23:08:20 +02:00
Rolando Diaz 62cffde87a fix(git): treat empty LC_CTYPE as unset
(cherry picked from commit 02364899ad23031d0ffe47be574ed547e249efa5)
2026-07-29 23:08:20 +02:00
Rolando Diaz 6ddea85d07 fix(git): preserve inherited UTF-8 character locale
(cherry picked from commit 4d51427cf144dd6415ee3b61158b5650011a796e)
2026-07-29 23:08:19 +02:00
Rolando Diaz a38160e245 fix(git): preserve UTF-8 locale for child processes
(cherry picked from commit f7c46ea55fb016daf6c34ecadf87443dadc61047)
2026-07-29 23:08:19 +02:00
Slava Zavadsky fdd46bd971 fix(coding-agent): pair checkpoint/rewind for restricted sessions too
The !restrictToolNames guard on the pairing blocks was wrong: a restricted
session with tools:[checkpoint] passes isToolAllowed (requestedTools is
defined) but the pairing is skipped, stranding the agent without rewind.
Remove the guard — this is a safety pairing, not a convenience widening.
Added restricted-session tests in both createTools and SDK active-set paths.
2026-07-28 21:18:43 -04:00
Slava Zavadsky abef08116e fix(coding-agent): auto-pair checkpoint/rewind and add changelog
Address review feedback on PR #6938:
- One-sided tools: list checkpoint without rewind (or vice versa) now
  auto-includes the sister tool, preventing a stuck subagent
- Add changelog entry under [Unreleased]
2026-07-28 18:12:01 -04:00
Slava Zavadsky afa76546a6 feat(coding-agent): allow checkpoint/rewind/learn/manage_skill in subagents when explicitly requested
Closes #3762

When an agent definition's frontmatter  list explicitly includes
checkpoint, rewind, learn, or manage_skill, allow them in subagents.
Previously all four were hard-gated to top-level sessions.

- Relax taskDepth gates in isToolAllowed using the already-captured
  requestedTools variable (no signature change needed)
- Remove isTopLevelSession function and its 4 guard sites from checkpoint.ts
- Update checkpoint prompt with enablement docs
- Add tests for subagent explicit-request, no-request, disabled-setting,
  and top-level paths
2026-07-28 17:57:02 -04:00
can1357 e7009452b4 feat(coding-agent/tools): simplified browser screenshot persistence and return paths
- Remove the per-call `save` option from `tab.screenshot()` to simplify usage.
- Update `tab.screenshot()` to return the saved file path as a promise string.
- Configure screenshot persistence to use daemon path or custom `browser.screenshotDir`.
- Add comprehensive tests verifying temp path return and custom directory saving.
2026-07-28 06:40:31 +02:00
can1357 21b3764b08 refactor(coding-agent): replaced xdevregistry with state interface and helpers
- Replaced the `XdevRegistry` class with the `XdevState` interface and pure helper functions across core and session tools.
- Updated session configurations, tool execution, and renderers to utilize canonical tool map initialization and sharing.
- Adapted unit tests and mocks to use `XdevState` and associated helper functions for permission and dispatch verification.
2026-07-28 03:34:36 +02:00
can1357 e54757f307 fix(coding-agent): declared restricted slate in local image read test
- The inspect_image availability contract treats a session with neither
  isToolActive nor xdevRegistry as mode-resolved (auto + unknown model =>
  metadata-only reads); the local:// image stub must report the tool
  inactive so the read keeps inlining image blocks.
2026-07-27 23:53:47 +02:00
can1357 da6d11de0e feat(agent): introduced prepareToolCall phase supporting argument replacement
- Added a prepareToolCall phase to the agent loop running before tool scheduling for validation and hooks.
- Updated BeforeToolCallContext and result types to support argument replacement instead of in-place mutation.
- Updated coding-agent extension handling and runner to track emitted tool calls and re-evaluate approvals on input revisions.
- Added comprehensive test coverage for argument replacement, concurrency resolution, and schema validation.
2026-07-27 22:55:20 +02:00
can1357 d16a251777 chore: reorg tests 2026-07-27 16:43:53 +02:00
roboomp cb55edd60e fix(lsp): honored custom server language ids
Added an optional per-server languageId override and used it for both disk-backed and in-memory didOpen notifications.

Covered config loading and both document-open paths with a fake custom GDScript server.

Fixes #6800
2026-07-27 11:54:29 +00:00
can1357 e2ed58d4d5 Merge PR #4168: fix(inspect-image): bounded per-request timeout on the vision-model call (@roboomp)
# Conflicts:
#	packages/coding-agent/src/config/settings-schema.ts
2026-07-27 04:59:19 +02:00
can1357 dccf0d3c8a Merge PR #6748: perf(launch): isolate PTY replay in broker (@usr-bin-roygbiv) 2026-07-27 04:58:28 +02:00
usr-bin-roygbiv 403f90783e perf(launch): isolate PTY replay in broker 2026-07-27 01:17:19 +00:00
shoucandanghehe 62e24ffc16 test(coding-agent): follow promise fixture convention 2026-07-26 23:56:27 +08:00
shoucandanghehe cdf373b77d fix(coding-agent): handle asynchronous LSP pipe failures 2026-07-26 23:37:12 +08:00
can1357 d1dc436d1e Merge PR #6596: fix(coding-agent): preserve Claude computer coordinates (@wolfiesch)
# Conflicts:
#	docs/computer-use.md
#	packages/coding-agent/src/tools/computer.ts
#	packages/coding-agent/test/tools/computer.test.ts
2026-07-26 15:44:51 +02:00
can1357 56a8ab1413 Merge PR #6697: fix(coding-agent): match bash deny/prompt patterns per command segment (@roboomp) 2026-07-26 15:41:28 +02:00
can1357 9b651f2869 Merge PR #6616: fix(cursor): sync native todo list from server-resolved tool calls (@quantmind-br) 2026-07-26 15:41:27 +02:00
Diogo Soares Rodrigues 9088fe821b fix(cursor): await error-drain transforms and sanitize mirrored todo labels
Two boundary defects on the mirrored-todo path.

1. The Agent error drain snapshotted #cursorToolResultBuffer without
   awaiting entry.pending, unlike #emitCursorSplitAssistantMessage. An
   async cursorOnToolResult still running when the provider errored
   patched an entry the catch path had already detached, so the
   pre-transform payload was persisted. A provider error is exactly when
   a transform is most likely to be in flight.

2. The todo renderer interpolated mirrored provider text straight into
   terminal output. A Cursor snapshot carries model-authored task
   content, phase names and summary text verbatim, so a label holding
   ANSI/C0 sequences rewrote the terminal on every render and replay.
   sanitizeText alone is not enough - it preserves tabs, which punch
   holes in bordered output - so every display path now funnels through
   one forDisplay() helper: task labels, blocker notes, phase headers,
   the zero-task fallback, and the streaming renderCall preview. Raw
   values are untouched; content and phase name are the identity keys
   the local list is looked up by and what gets persisted.
2026-07-26 09:29:13 -03:00
roboomp e650607cad fix(coding-agent): segment bash approval commands with shell-aware tokenizer
The regex splitter only recognized `&&`, `||`, `;`, `|` and newlines, so a
single `&` (background operator) — also a command terminator — slipped a
dangerous command past a deny rule (`sleep 1 & rm -rf /tmp/x`), which under
approvalMode: yolo executed with no prompt.

Extract the shell-aware tokenizer from gh-cache-invalidation into a shared
tools/shell-tokenize.ts and reuse it for deny/prompt segmentation. It honors
every command boundary (`&&`, `||`, `;`, `|`, single `&`, subshells,
newlines) plus quoting and escapes, so both callers share one implementation.

Fixes #6695
2026-07-26 11:36:19 +00:00
roboomp 85110c366c fix(coding-agent): match bash deny/prompt patterns per command segment
bashApprovalPatternToRegExp anchors globs with ^...$ against the whole
normalized command, so a bash.patterns deny rule only fired when the
dangerous command was first in the line. A compound command such as
`cd /tmp && rm -rf /tmp/x` bypassed the rule and, under approvalMode:
yolo, executed with no prompt -- deny is the guard that outranks yolo.

deny/prompt rules now match the whole command or any single segment
(split on &&, ||, ;, |, newlines). allow rules still require the entire
command to match and never apply to compound lines, so a narrow allow
cannot vouch for a smuggled unsafe segment.

Fixes #6695
2026-07-26 11:28:48 +00:00
Wolfgang Schoenberger 0c5fa60c77 fix(coding-agent): cap captures for resizing transports
Use the resolved supportsImageDetailOriginal capability to constrain native computer frames whenever a Responses transport clamps screenshot detail to auto. Preserve the established Claude-family fallback for transports that do not expose this capability.

Cover Copilot GPT-5 Responses through real catalog model resolution and the controller's observable capture options.
2026-07-26 02:53:01 -07:00
Wolfgang Schoenberger fc68288477 fix(coding-agent): scope computer capture limits 2026-07-26 02:53:01 -07:00
Wolfgang Schoenberger 25dc887fb2 fix(coding-agent): preserve computer coordinates across providers 2026-07-26 02:53:00 -07:00
usr-bin-roygbiv 9bab62ee55 fix(computer-use): address routing review gaps 2026-07-25 02:14:36 +00:00