Commit Graph
1619 Commits
Author SHA1 Message Date
can1357 b0063dd180 Merge PR #6787: fix(mcp): deduplicate aliased server connections (@roboomp) 2026-07-27 15:57:44 +02:00
can1357 ae01a76136 fix(agent): hardened pre-model-call gate state cleanup and API surface
- Cleared the retained soft-requirement lifecycle alongside the deferred
  hard choice: clearDeferredToolDirectives() owns both, is called from
  clearAllQueues/reset and session-scoped tool-state cleanup, with a
  regression covering reminder re-injection after a queue clear.
- Allowed void-returning pre-model gates via the named AgentBeforeModelCall
  type and normalized gate results in the loop and Agent dispatcher.
- Documented that the first gate installed mid-run applies from the next
  run; corrected the onToolChoiceRejected contract docs; documented the
  cross-run lifetime of ToolChoiceQueue's in-flight claim.
- Removed the unused addBeforeModelContextBuild hook.
- Relocated both packages' changelog entries out of the released 17.1.4
  sections into Unreleased with PR attribution, folding the never-shipped
  Fixed bullet into Added and noting the input-event timing change.
2026-07-27 14:08:53 +02:00
can1357 6bbfc1110a Merge PR #6543: feat(agent): add a pre-model-call gate that can stop the turn (@paralin) 2026-07-27 14:01:11 +02:00
roboomp da11d906ff fix(mcp): unified tool collision handling
Moved first-wins MCP tool-name deduplication and origin-aware warnings into one shared helper used by startup extension registration, SDK custom-tool assembly, and deferred refreshes.

Added an SDK startup regression proving colliding MCP proxy tools keep the first origin instead of silently overwriting it.

Fixes #6786
2026-07-27 10:49:59 +00:00
roboomp ab8fb13eea fix(mcp): deduplicated aliased server connections
Deduplicated semantically identical MCP endpoints across provider-specific names while preserving provider priority and canonical direct names.

Kept the first registration on sanitized tool-name collisions and logged both origins.

Fixes #6786
2026-07-27 10:22:39 +00:00
can1357 733f20d963 style: formatted scheduleAgentContinue signature per biome 2026-07-27 05:00:25 +02:00
can1357 12a2b13e93 fix(session): unwedged auto-retry after assistant-tail removal miss
A context rebuild that recreated the failed turn's message object made the
identity-keyed active-context removal miss, so the scheduled retry
continuation rejected the terminal assistant error message locally
("Cannot continue from message role: assistant") before any provider
request. auto_retry_end never fired, retryPromise stayed pending, and the
in-flight prompt() plus the TUI retry indicator hung until a manual
follow-up.

The retry path now strips a still-failed assistant tail positionally after
the backoff (generation-guarded, never in preserveFailedTurn mode), and a
continuation that still fails locally closes the retry saga with a failed
auto_retry_end via the new scheduleAgentContinue onError hook.

Fixes #5382
2026-07-27 04:59:31 +02:00
can1357 e07db86f2d Merge PR #6670: fix(mcp): map mounted tools to xd routes (@jeffscottward) 2026-07-27 04:58:27 +02:00
can1357 9d76e168ba Merge PR #6706: fix(ai): preserve custom Anthropic web-search history (@roboomp) 2026-07-27 04:58:24 +02:00
Christian Stewart 01ecab6df7 fix(agent): clear deferred choices on branches
A pre-model gate can defer a claimed hard tool choice for the next call. Branch transitions cleared the coding-agent queue but left that agent-owned value alive, allowing an obsolete forced tool to cross into the replacement transcript.

Expose the narrow deferred-choice reset at the Agent owner and invoke it from the shared session-scoped tool-state cleanup used by both branch paths. Failed session switches retain their existing rollback behavior.

Signed-off-by: Christian Stewart <christian@aperture.us>
2026-07-26 12:05:30 -07:00
Christian Stewart e79eabc3b6 feat(agent): add a pre-model-call gate that can stop the turn
The agent loop had no place to refuse a provider request. A host that needs to
act on the assembled context before it is billed, checking that the prompt still
fits the window, that a budget boundary has not been crossed, or that the
session should hand off instead of spending, could only observe the request
after the fact, when the tokens were already committed.

Add `AgentLoopConfig.beforeModelCall`, asked once per turn beside the deadline
check and before `turn_start` is emitted. A `stop` result ends the stream with
no turn open, so nothing has to synthesise a cancellation event and no consumer
is left holding a half-open turn. Placing it there also keeps `turn_end`'s
contract intact: that event carries the assistant message for a completed turn,
and a gated stop has no assistant message to report.

`syncContextBeforeModelCall` keeps its existing void contract and its job of
refreshing prompt and tool state, so implementations typed as returning void are
unaffected.

`Agent.setBeforeModelCall` installs the host's callback, and `addBeforeModelCall`
registers an additional callback without displacing the host's, returning a
disposer so an extension can attach and detach independently. A supplied
`reason` is logged where the loop stops.

Signed-off-by: Christian Stewart <christian@aperture.us>
2026-07-26 12:02:18 -07:00
can1357 b646234c41 Merge PR #6646: fix(secrets): avoid hashline placeholder collisions (@roboomp) 2026-07-26 15:45:09 +02:00
can1357 60b0968e1f Merge PR #6484: fix(coding-agent): resume agent after /tree ask re-answer (@roboomp) 2026-07-26 15:41:31 +02:00
can1357 ca4f0d6c56 Merge PR #6494: fix(session): cancel in-flight session_stop handlers (@roboomp) 2026-07-26 15:41:28 +02:00
can1357 e758f10a96 Merge PR #6660: fix(prewalk): apply same-model effort downgrades instead of skipping (@roboomp) 2026-07-26 15:41:28 +02:00
can1357 c5a819b162 Merge PR #6669: fix(session): retry reasonless tool-call aborts (@roboomp) 2026-07-26 15:41:28 +02:00
can1357 7bbe140914 Merge PR #6626: fix(advisor): propagate advisor provider session id via metadata (@roboomp) 2026-07-26 15:38:52 +02:00
can1357 2cc6b28d98 Merge PR #6537: fix(advisor): bound Codex SSE retries (@jeffscottward) 2026-07-26 15:38:52 +02:00
roboomp 2fb9f888ad fix(ai): preserved custom anthropic web-search history
Retained complete native web-search call/result pairs through leaked-thinking projection at their original source anchors.

Kept opaque server-tool blocks atomic during persistence, stripped them on reparent, and covered custom continuations plus compaction retention.

Fixes #6703
2026-07-26 13:32:08 +00:00
Jeff Scott Ward fcdd33d2fe fix(mcp): map mounted tools to xd routes 2026-07-26 01:02:11 -04:00
roboomp 0988efbce6 fix(session): recover cursor reasonless tool aborts
Scoped the Cursor server-execution marker gate to the stream-stall path so an unmarked client-side Cursor tool call (todo/MCP) followed by a reasonless abort recovers via its synthetic executed:false result instead of settling the turn.

Fixes #6668
2026-07-26 04:33:34 +00:00
roboomp 464eba46b3 fix(session): retried reasonless tool-call aborts
Continued from synthetic unexecuted tool results when a reasonless request abort arrives after a complete streamed tool call. Preserved deliberate user, lifecycle, and streaming-edit guard abort behavior.

Fixes #6668
2026-07-26 04:26:53 +00:00
roboomp 583ff590f2 fix(prewalk): apply same-model effort downgrades instead of skipping
The prewalk arm/switch guard compared model identity only (modelsAreEqual /
provider+id), discarding the resolved thinkingLevel. A legal same-model target
at a cheaper effort (e.g. prewalk: "@task" resolving to the active model at a
lower level) was dropped as a no-op, so the session ran the expensive effort for
the whole run while still paying the plan/continue nudges — silently on the
session path, logger.debug only on the subagent path.

Compare (provider, id, effective thinking level) via a shared prewalkWouldBeNoop
helper. Effort-only deltas on the same model now switch; a genuine no-op emits a
user-visible notice on the session path and never arms on the subagent path.

Fixes #6659
2026-07-26 02:20:03 +00:00
roboomp 431a5509cc fix(secrets): removed hash placeholder fallback
- Removed hash-delimited placeholder parsing and stored-session aliases.
- Simplified replay and display restoration to the double-dollar format.
- Replaced legacy compatibility tests with an inert-token regression.
2026-07-25 23:03:19 +00:00
roboomp 7ca59dc6bd fix(secrets): avoided hashline placeholder collisions
- Switched newly generated secret placeholders to double-dollar delimiters.
- Preserved trusted stored-session restoration for legacy hash-delimited tokens.
- Updated redaction regressions and changelog coverage.

Fixes #6631
2026-07-25 20:24:27 +00:00
roboomp f1f118acd0 fix(advisor): rebind identity on every provider-session change
Advisor provider-identity refresh was only invoked from resetSessionState(), so transitions that update the primary identity without re-priming the advisor (branch with skipConversationRestore, fork) left the advisor emitting the previous session id/metadata/telemetry. Move the refresh into #syncAgentSessionId() via a new SessionAdvisors.refreshProviderIdentity() so it fires on every provider-session change regardless of conversation restore. Add a fork regression test.
2026-07-25 17:55:48 +00:00
roboomp f6a93a34b4 fix(advisor): forwarded session metadata to overflow compaction
The advisor overflow-compaction one-shot calls compact() directly, bypassing the advisor Agent and its metadata resolver, so it omitted metadata.user_id. Resolve the advisor's session metadata per candidate provider (after credential selection) and pass it into the compact() options alongside sessionId/promptCacheKey. Add a regression test asserting the direct compaction request carries the advisor session id.
2026-07-25 17:49:21 +00:00
roboomp 8a998ca429 fix(advisor): refreshed provider identity on session switch
Rebind the live advisor Agent's provider session id, prompt cache key, credential resolver, metadata resolver, and telemetry identity whenever AgentSession crosses a conversation boundary. Add a regression test proving /new preserves the advisor Agent while assigning and emitting a distinct new provider session UUID.
2026-07-25 17:39:12 +00:00
roboomp c5af78d403 fix(advisor): propagate advisor provider session id via metadata
The advisor Agent is constructed separately in session-advisors.ts with
its own advisorProviderSessionId, but unlike AgentSession it never had a
metadata resolver installed. Its outbound requests therefore omitted the
metadata.user_id session identity that main and subagent requests carry,
so custom Anthropic-compatible proxies saw advisor traffic with no stable
session id to route or attribute on.

Extract buildSessionMetadata into session/session-metadata.ts and install
it as the advisor agent's metadata resolver, scoped to the advisor's own
provider session id and resolved live so token refreshes surface the
current account_uuid.

Fixes #6625
2026-07-25 17:30:18 +00:00
usr-bin-roygbiv 8e2d654880 fix(computer-use): route enabled desktop control 2026-07-25 00:42:23 +00:00
roboomp 144043ad48 fix(coding-agent): used session settings in file guards
Passed session-scoped settings through Edit and Write generated-file checks and fell back to schema defaults when no global singleton exists.

Guarded inline image sizing against an uninitialized global settings proxy and added isolated-session regression coverage.

Fixes #6549
2026-07-24 22:42:38 +00:00
Jeff Scott Ward 050388b486 fix(advisor): bound Codex SSE retries 2026-07-24 15:24:14 -04:00
can1357 b0f1b5c0c5 Merge PR #6496: fix(ai): preserve Anthropic server-tool history (@roboomp) 2026-07-24 16:26:52 +02:00
can1357 3676b5d97f feat: implemented client usage tracking and reporting in the auth broker
- Add usage history, reporting, and client summary endpoints to the auth broker.
- Implement SQLite persistence, batching, and periodic flushing for observed client usage.
- Integrate usage reporting into the coding agent session for completed assistant messages.
- Update stats aggregator and dashboard to retrieve usage history snapshots from the broker.
2026-07-24 15:20:46 +02:00
roboomp 07fcec1e68 fix(ai): preserved Anthropic server-tool history
Persisted native server-tool calls and web-search results in assistant content, replayed them only to the issuing Anthropic provider, and retained Umans gateway filtering.

Fixes #6495
2026-07-24 08:49:43 +00:00
roboomp 9506548b21 fix(session): cancelled in-flight stop handlers
Raced session_stop handlers against the active settle signal and discarded cancellation without timeout errors.

Added runner and AgentSession regressions for pre-dispatch and in-flight aborts, timeout preservation, and stale continuation suppression.

Fixes #6489
2026-07-24 07:29:39 +00:00
can1357 c1d4e38aa6 feat(coding-agent): added live session delegation with turn-based transcript display
- Added `LIVE_DELEGATION_MESSAGE_TYPE` constant and delegation message handling for voice sessions.
- Implemented turn-based transcript coalescing with user and assistant turn counters.
- Added transcript display row with normalized rendering in the live visualizer.
- Refactored controller to send delegation messages via `sendCustomMessage` with configurable frame styling.
- Removed microphone permission error reporting from silence detection logic.
2026-07-24 09:16:50 +02:00
can1357 c9c0882724 feat(audio): replaced Chromium browser audio with native audio stack
- Switched from `miniaudio` to `maudio` Rust crate and added `AudioCapture` and `AudioPlayback` native classes.
- Removed browser-side audio infrastructure including Web Audio API, audio worklet processor, and WebRTC runtime.
- Migrated STT recorder and transcriber modules to use native `AudioCapture` with callback-based streaming.
- Replaced streaming audio player with native `AudioPlayback` that writes PCM directly without TypeScript intermediaries.
- Removed ffmpeg, wav, and platform-specific playback commands from the audio toolchain.
2026-07-24 08:54:16 +02:00
can1357 af9e8546a9 feat: implemented session account selection and pinning via slash command
- Add `pinSessionOAuthAccount` storage method and active account flag to the auth storage API.
- Introduce session account selector component, controller logic, and interactive mode delegation.
- Implement the `/session pin` builtin slash command with text listing and account pinning capabilities.
- Add unit tests covering session account selection, component navigation, and command handling.
2026-07-24 07:57:55 +02:00
roboomp 7dee729ef7 fix(coding-agent): defer /tree ask re-answer resume until after ui rebuild
Scheduling agent.continue() inside navigateTree started a post-prompt
task before the interactive /tree handler rebuilt its transcript, so a
fast provider's agent_start/turn_start could render against the stale
pre-rebuild UI and then be clobbered by renderInitialMessages.

navigateTree now reports the commit via askReanswerCommitted instead of
resuming, and SelectorController.showTreeSelector calls the new
AgentSession.resumeAfterAskReanswer() only after renderInitialMessages +
reloadTodos, so the resumed turn always renders against the rebuilt
transcript.

Addresses chatgpt-codex-connector review on #6484.
Fixes #6483
2026-07-24 05:27:00 +00:00
roboomp c2946d0dff fix(coding-agent): resume agent after /tree ask re-answer
Committing a new answer to a past `ask` via `/tree` branched a fresh
sibling toolResult and rebuilt context, but `navigateTree` never
scheduled `agent.continue()`. Unlike a live `ask` — whose continuation
is intrinsic to the streaming run loop — the /tree re-answer mutates the
tree outside any running turn, so the model never consumed the new
answer and the session sat idle until a manual prompt.

Schedule an agent continue at the end of the reanswerAskResult
completion, gated to the ask re-answer branch only so plain leaf moves
and the read-only reopenAsk probe stay idle.

Fixes #6483
2026-07-24 05:12:28 +00:00
can1357 4f97aea2db Merge PR #6468: fix(tools): closed spilled output descriptors on error/abort paths (@roboomp) 2026-07-24 06:51:36 +02:00
roboomp a39dbc9b44 fix(tools): guarantee spill sink close when tail replay fails
#finalizeFile marked the sink finalized then ran the capped-artifact tail
replay before closing. A write error during that replay threw before
sink.end(), and because #finalized was already set the executor finally
paths calling dispose() could not retry the close, leaking the descriptor
and masking the original tool error.

Moved sink.end() into a finally around the tail replay and swallowed both
the replay and close errors so the descriptor is always released and
dispose() never throws.
2026-07-24 03:53:21 +00:00
roboomp 31098f9248 fix(tools): closed spilled output descriptors on error/abort paths
OutputSink.dump() was the only path that closed the spill Bun.FileSink.
The bash and Python executors re-throw on failure and their finally
blocks never closed the sink, so any large-output command that errored
leaked the artifact descriptor until an unrelated read (e.g. a SKILL.md
load) hit EMFILE.

Added an idempotent OutputSink.dispose() that closes the sink exactly
once (awaiting any in-flight sink creation, guarding post-finalize
resurrection) and wired it into every executor's finally block.

Fixes #6463
2026-07-24 03:44:12 +00:00
can1357andusr-bin-roygbiv 681d7daf65 feat(computer): unified native addon, /computer toggle, function tool
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
  a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
  XTest input with keysym mapping) compiled into the core addon on every
  published target; Linux arm64 and musl are now supported and headless
  hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
  lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
  build dependencies, and the now-unreferenced vendored libspa crate;
  reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
  XTest layouts reject negative origins and coordinates beyond 0..=32767,
  batch coordinates stay bound to the frame last returned to JS with
  intermediate screenshots deferred, coordinate input requires a
  previously returned frame, and failed chord releases still release
  every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
  no input is emitted after expiry and wait-heavy batches are rejected
  upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
  scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
  a regular function tool with a typed GA action schema across OpenAI,
  Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
  session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
2026-07-24 01:40:05 +00:00
usr-bin-roygbiv 4fe03e25cb fix(coding-agent): align computer session ownership 2026-07-24 01:40:05 +00:00
usr-bin-roygbiv b9504f65e7 feat: add native Codex computer use 2026-07-24 01:40:04 +00:00
can1357 fc3e9970c7 style: organized imports in session modules after fallback merge 2026-07-24 02:26:26 +02:00
can1357 366bd6203e Merge PR #6392: feat(coding-agent): add usage-aware model fallback (@eggpeat) 2026-07-24 02:25:35 +02:00
can1357 77669aed54 Merge PR #6395: feat: configure xdev prompt docs (@joeshull) 2026-07-24 02:25:35 +02:00