Commit Graph

4727 Commits

Author SHA1 Message Date
roboomp b60dc669ea fix(auth): fenced oauth refresh writes
- Fenced final OAuth refresh update and terminal-disable CAS statements by row id, serialized credential data, active lease owner, and unexpired lease time.
- Passed an AbortSignal through MCP OAuth token refresh and bounded owned refresh operations below the lease TTL while awaiting the aborted fetch to settle.
- Added regressions for stolen-lease update/disable attempts and timed-out MCP token fetch abort behavior.

Fixes #5081
2026-07-10 21:49:18 +00:00
roboomp cb32853130 fix(auth): renewed oauth refresh leases
- Renewed durable OAuth refresh leases while token refreshes are in flight so slow endpoints cannot let a peer steal the row and replay a rotating refresh token.
- Let CAS update and disable storage errors propagate instead of collapsing them into peer-win misses.
- Added regressions for lease renewal and CAS storage failure propagation.

Fixes #5081
2026-07-10 21:15:04 +00:00
roboomp cf021ad393 fix(auth): serialized mcp oauth refreshes
- Added durable SQLite refresh ownership for stored OAuth rows, with canonical re-read before refresh and compare-and-set persistence.
- Routed MCP proactive and forced OAuth refresh through the shared owner so waiters reuse the winner's rotated credential.
- Added MCP regression tests for shared SQLite refresh ownership and stale invalid_grant losers.

Fixes #5081
2026-07-10 20:25:49 +00:00
can1357 68bc6ba605 test(coding-agent): updated thinking model metadata expectations
- Update Ollama discovery tests to reflect the wire effort vocabulary.
- Adjust model registry test expectations to treat adaptive effort ladders as verbatim, removing the legacy effortMap backfilling behavior.
2026-07-10 14:10:41 +02:00
can1357 e8add61016 fix(debug): stopped native fallback for missing delve
- Kept missing language-specific adapters from falling through to native debuggers.
- Resolved nested launch roots before session-local binaries and PATH, including explicit adapters and go.work workspaces.
- Added actionable install/configuration errors and deterministic regression coverage.

Fixes #5037
2026-07-10 14:06:57 +02:00
can1357 d435385ab1 feat: introduced max reasoning effort tier across model and rpc systems
- Introduced `Max` as a first-class reasoning effort tier across all packages, including AI providers, coding agent configurations, and RPC protocols.
- Refactored model effort ladders to use wire-exact mappings and removed legacy effort aliasing (e.g., `max-to-xhigh` mapping).
- Updated model registry and provider configurations to support `Max` tier routing, color themes, and UI icon associations.
- Expanded test suites to provide end-to-end coverage for the new reasoning tier, including updated compatibility and fallback scenarios.
2026-07-10 13:39:42 +02:00
can1357 6813fa128f test: aligned ai and tui test contracts with recent stream and paint changes
- Asserted the terminal [DONE] sentinel frame in raw SSE capture since onSseEvent observers receive every wire frame as it arrives.
- Included updatedAtMs in credential block persistence expectations per the broker snapshot contract from issue #4980.
- Taught VirtualTerminal the no-ED2 destructive paint bytes: ED3 history clears now invalidate the offset-keyed text cache instead of bypassing emulation, keeping legacy full-clear recreation only for the WASM trap workaround.
- Refreshed the advisor parity comment for UUIDv7 provider session ids.
2026-07-10 13:21:06 +02:00
can1357 558e0bd085 test(coding-agent): aligned advisor and reload tests with uuidv7 session ids
- Updated advisor provider-options parity assertions to the UUIDv7 provider session identity introduced for issue #5040 instead of the retired -advisor suffix.
- Disabled codex websocket prewarm in the responses-replay harness so seeded provider-state stubs are not replaced before reload closes them.
2026-07-10 12:58:54 +02:00
can1357 6dbbfbe1e0 feat(coding-agent): renamed explore agent to scout
- Renamed the `explore` agent to `scout` throughout prompt templates, agent definitions, and configuration schemas.
- Updated documentation and internal tool references to reflect the new agent identity.
2026-07-10 12:51:50 +02:00
can1357 390a4ae927 fix(coding-agent): reconcile late MCP discovery 2026-07-10 12:37:46 +02:00
can1357 2bf8f43b67 fix(agent): keep incremental yields budget-bound 2026-07-10 12:37:46 +02:00
can1357 a3c0d536cc Merge PR #4971: fix(agent): stop terminal yield loops after IRC wake 2026-07-10 12:37:38 +02:00
can1357 3862e0c945 Merge PR #5016: fix(cli): preserve MCP tools when --tools filters built-ins 2026-07-10 12:37:37 +02:00
can1357 cec1639242 Merge PR #5014: fix(agent): commit yield before budget abort 2026-07-10 12:37:37 +02:00
can1357 09977ac0ad Merge PR #5023: fix(bash): avoid aborting native timeout signals 2026-07-10 12:37:36 +02:00
can1357 f4283e035a Merge PR #4994: fix(auth): decouple login success from model refresh 2026-07-10 12:37:36 +02:00
can1357 f8a927e5cb Merge PR #5043: fix(lsp): handle go.work workspace diagnostics 2026-07-10 12:37:36 +02:00
can1357 5d6e9a92d7 Merge PR #4999: fix(coding-agent): restore ask tool timeout fallback 2026-07-10 12:37:36 +02:00
can1357 70754dfa01 fix(coding-agent): hardened same-realm runtime guards from PR review
- setCwd now updates the saved __omp_session__ stack entry so a deferred
  cross-runtime setCwd is visible to the runtime's next run (review should-fix)
- JsRuntime installation asserts realm ownership before mutating globals;
  a first init during another runtime's live run fails via init-failed
  instead of clobbering the active run's globals
- cmux runCmuxCode marks the armed cancel rejection as handled so a sync
  setup throw under an already-aborted signal cannot become an unhandled
  rejection (review P2)
- credited #4907 in the changelog entry
2026-07-10 12:33:53 +02:00
can1357 674c7a252a Merge branch 'main' into pr-4907 2026-07-10 12:22:24 +02:00
can1357 b9bb0cc1d6 Merge branch 'main' into pr-5030 2026-07-10 12:14:52 +02:00
can1357 1dfbc2caf6 Merge remote-tracking branch 'origin/farm/e42ff742/fork-prompt-cache-affinity' 2026-07-10 12:09:25 +02:00
can1357 2dafa7ac79 feat: further codex metadata 2026-07-10 11:35:09 +02:00
roboomp b2b1708d88 fix(coding-agent): guarded fork cache on scoped models
- Treated startup scoped model selection as a prompt-cache shape override before inheriting fork cache keys.

- Covered the --models fork path so a scoped startup model cannot reuse the parent prompt_cache_key.

Fixes #5035
2026-07-10 07:41:59 +00:00
roboomp 7fa2c3f42d fix(coding-agent): preserved fork prompt cache affinity
- Persisted an inherited provider prompt-cache key on full session forks while keeping the child OMP session id independent.

- Added --prompt-cache-key and SDK startup inheritance so explicit cache affinity is separate from provider session routing.

- Cleared automatic inherited keys when model, thinking, system prompt, or tool schema inputs change.

Fixes #5035
2026-07-10 07:22:28 +00:00
roboomp 993b21204e fix(lsp): handled go.work workspace diagnostics
Detected go.work before go.mod for workspace diagnostics and expanded go build package patterns from go.work use entries.

Added regression coverage for go.work-only roots and mixed go.work/go.mod workspaces.

Fixes #5038
2026-07-10 07:14:49 +00:00
usr_bin_roygbiv cdecf65f8b fix(compaction): retry after AWS credential failures 2026-07-10 00:42:31 -05:00
roboomp bc9f4c4be6 fix(coding-agent): armed ask timeout for legacy ui
Added an explicit timeout presentation capability so interactive queued dialogs defer the fallback while older UI implementations still get an immediate tool-owned timeout.

Refs #4995
2026-07-10 04:13:18 +00:00
roboomp 9002f4ff0a fix(bash): avoided aborting native timeout signal
Prevented explicit bash timeouts from also aborting the AbortSignal passed to pi-natives while streamed output is still draining. Native timeout_ms now owns cancellation, and the JavaScript timer only reports the fallback timeout result.

Added regression coverage for streamed output before an explicit timeout.

Fixes #5021
2026-07-10 03:48:40 +00:00
roboomp 2c838e9622 Merge remote-tracking branch 'origin/main' into farm/8134d5cd/fix-revived-yield-loop 2026-07-10 03:38:00 +00:00
roboomp 095353ed43 fix(coding-agent): preserved multi-question timeout defaults
Applied the timeout auto-selection before multi-question single-choice prompts auto-advance, and replaced pending test promises with Promise.withResolvers().

Refs #4995
2026-07-10 03:05:54 +00:00
roboomp fcf389ae72 fix(coding-agent): deferred ask timeout until display
Started the ask tool fallback timeout from the selector presentation callback so queued dialogs do not consume the user's response window.

Refs #4995
2026-07-10 02:49:33 +00:00
roboomp 4f689c0b1b fix(agent): validated pending yield commits
Keep assistant yield tool calls pending until YieldTool.execute returns a successful tool result.

Prevent invalid pre-execution yield arguments from bypassing schema retry handling while still suppressing the soft budget abort during validation.

Fixes #5006
2026-07-10 01:47:08 +00:00
roboomp 0d606f2f30 fix(cli): preserved mcp tools with tools filter
Interactive sessions defer MCP discovery, so CLI --tools produced an initial built-in-only active set and later MCP refreshes respected that filtered set.

Force-activate deferred MCP tools when MCP discovery mode is disabled, matching the blocking startup path while leaving discovery-mode selection intact.

Fixes #5013
2026-07-10 01:21:33 +00:00
roboomp 1bb97efec8 fix(agent): committed yield before budget abort
Persist yield tool-call arguments as soon as an assistant turn commits the yield call, before the soft request budget guard can abort the session.

Add a regression covering a yielding turn that crosses the budget threshold without a tool result event.

Fixes #5006
2026-07-10 01:16:06 +00:00
roboomp facfb3c35a fix(coding-agent): synced ask fallback timeout resets
Reset the ask tool fallback timeout whenever the interactive selector resets its UI countdown, preventing late keypresses from falling back to the original recommended option.

Refs #4995
2026-07-09 23:37:50 +00:00
roboomp 4f4f852ad6 fix(coding-agent): restored ask tool timeout
Ensured ask tool timeouts abort stalled UI selectors and return the recommended option instead of hanging. Added regression coverage for selectors that never settle.

Fixes #4995
2026-07-09 23:17:41 +00:00
roboomp 497d385ce0 fix(auth): decoupled login success from model refresh
Switched interactive OAuth login to start model discovery in the background after credentials are saved.

Added a regression test that keeps model refresh pending and asserts the success transcript appears immediately.

Fixes #4989
2026-07-09 22:12:17 +00:00
roboomp 92307e11d8 test(agent): updated terminal yield expectations
- Updated stale yield-empty-stop regressions for the new terminal-yield contract.
- Kept coverage for clearing yield termination before the next prompt and IRC wake.

Fixes #4963
2026-07-09 19:24:39 +00:00
roboomp 0f3cf73a85 fix(agent): stopped terminal yield wake loops
- Aborted the active agent loop synchronously when a terminal yield tool result finishes, so IRC-wake turns stop before another provider call.
- Added a regression covering idle IRC wake handling after a terminal yield.

Fixes #4963
2026-07-09 19:13:29 +00:00
can1357 4a20b51ca8 feat: implemented auto-sealing for transcript blocks and TUI row emission
- Added auto-sealing logic to `FinalizableBlock` to finalize displaceable snapshots when they enter the scrollback area.
- Updated TUI frame emission to publish committed rows and clamp them to segment bounds, ensuring accurate component updates.
- Introduced component tracking and cleanup in event controller tests to prevent resource leaks during finalization.
- Validated state transitions and post-emit synchronization through comprehensive new test suites for transcript and TUI components.
2026-07-09 20:37:09 +02:00
can1357 7c560c7151 fix(acp): flushed final assistant text lost to agent_end race
The assistant message_end fan-out is fire-and-forget in the session layer
and can be parked on extension delivery while agent_end is flushed through
#endInFlight, so agent_end can overtake it. #finishPrompt then unsubscribes
the prompt turn and the mapAssistantMessageEnd fallback never runs: an ACP
client that only received agent_thought_chunk updates (thinking streamed,
text arrived only on the trailing message) stays stuck on the thinking
block with no visible answer. On agent_end, emit the last assistant
message's text before resolving the prompt when live-message progress shows
no text was ever delivered, and defer the live-state reset past that flush
so a late message_end cannot resurrect fresh progress and double-emit.

Fixes #4902
2026-07-09 18:36:39 +02:00
can1357 efc90d26b8 style: applied biome fixes to integrated issue fixes 2026-07-09 18:34:06 +02:00
can1357 cab5c4b62a test(coding-agent): covered PowerShell fallback when native read throws
Adopted the dispatch regression test from PR #3427: a native Windows
image conversion failure must fall through to the PowerShell GetImage()
bridge. The dispatch behavior itself already landed in d718d54a33.

Refs #3426
2026-07-09 18:33:44 +02:00
can1357 cde9ee7501 fix(tui): repainted write first partial result over pending tail preview
The first-result viewport-repaint gate assumed only streamed
__partialJson placeholder shapes (SSH) could re-anchor; the write
renderer's collapsed pending preview paints a tail window from decoded
content, so its first partial result re-anchored to the top of the file
and left the committed tail rows stale above the new frame.

Resolve forceFirstResultViewportRepaint per renderer as a boolean or an
(args, options) predicate evaluated at paint time: write opts in when a
collapsed preview outgrew the streaming tail window, SSH stays scoped to
the streamed-placeholder shape it always covered.

Adopted from PR #4478 (roboomp) with an allocation-free line-count scan
and terminal-buffer regression coverage.

Fixes #4477
2026-07-09 18:30:48 +02:00
roboomp 894cf489ff fix(tui): canceled streaming prompts on first escape
Esc during an active streaming turn required a second press within 2s
(two-step arm from #3493). In the no-input-waiter submit path the turn
starts with isStreaming=true but no working loader, so Esc fell into
the two-step branch and the agent_start subscription then wiped the
arm — repeated presses kept re-arming and never aborted. The loader-up
path already aborted on a single press, so the confirmation guarded no
coherent state. First Esc now aborts the streaming turn directly.

Adopted from PR #4938 (test + input-controller + changelog hunks only;
unrelated workflow-notice.md churn dropped).

Fixes #4921
2026-07-09 18:30:48 +02:00
can1357 ca68daa81c fix(mnemopi): made recall fact ids resolvable via memory reads
recall (includeFacts) surfaces facts.fact_id as a result id, but
store.get only searched working_memory + episodic_memory, so every
surfaced fact id was a dead end for 'read memory://<id>' and
memory_edit ('not found in any scoped bank').

- store.get now falls back to the facts table (visibility mirrors
  factRecall: same-session or scope='global'), returning a read-only
  row with memory_store 'fact' and the full triple as content.
- coding-agent labels the store honestly ('fact') in memory:// reads
  and reports not_editable (instead of not_found) for memory_edit ops
  on fact ids; the facts table stays immutable.

Fixes #4725
2026-07-09 18:27:23 +02:00
can1357 898643f9a9 fix(coding-agent): refreshed expired OAuth in built-in discovery
Built-in model discovery admitted providers via peekApiKey, which
deliberately never refreshes OAuth rows, so a provider whose only stored
credential was an expired OAuth token was silently dropped from online
discovery and its token was never rotated (model selector 'refresh'
stayed empty for logged-in users).

Resolve built-in discovery keys through an online-only preflight that
refreshes an expired stored OAuth credential, applying the disabled/
configured/targeted provider filters before the side-effecting
resolution so refreshProvider(x) cannot rotate unrelated credentials.
Offline discovery stays peek-only. Under online-if-uncached the
preflight consults the same cache freshness the model manager uses
(2h default TTL, 5min non-authoritative retry) so tokens refresh
exactly when the manager will fetch — a fresh cache never triggers a
token-endpoint call.

Adopted from PR #4896 with two amendments: dropped an unrelated
workflow-notice.md prompt edit, and aligned the preflight cache TTL
with the manager's real 2h default (was 24h, which skipped the refresh
on the common startup path for caches aged 2-24h; regression covered
by the new online-if-uncached tests). Also corrected the stale
'Default: 24h' doc on cacheTtlMs in the catalog.

Fixes #4893

Co-authored-by: roboomp <omp@can.ac>
2026-07-09 18:27:23 +02:00
roboomp 3a9bcc9ed4 fix(agent): let role agents inherit configured effort
- Removed bundled reviewer and plan thinking-level hard pins so their model roles can supply configured effort.
- Added regression coverage for bundled reviewer and plan parsing.
- Updated the coding-agent changelog.

Fixes #4761
2026-07-09 18:27:23 +02:00
can1357 c944870566 fix(coding-agent): implemented pi's ui.addAutocompleteProvider API
Extensions calling ctx.ui.addAutocompleteProvider (e.g. @ff-labs/pi-fff)
crashed at load with 'TypeError: ... is not a function' because omp's
ExtensionAPI.ui omitted pi's autocomplete-provider API; the throw also
aborted the rest of a try/catch-guarded session_start init.

ExtensionUIContext now declares addAutocompleteProvider(factory).
Interactive mode stacks each factory on the built-in editor provider in
registration order, re-applies the stack on every slash-command refresh,
and skips throwing/malformed factories; RPC, ACP, and headless contexts
accept the factory as a no-op, matching upstream pi's RPC behavior.

Fixes #4919
2026-07-09 18:27:23 +02:00