Commit Graph

8702 Commits

Author SHA1 Message Date
can1357 b76c07ece2 feat(pi-natives): added LiveWebRtcPeer and deviceCheckGenerateToken bindings
- Replaced puppeteer-based WebRTC with native LiveWebRtcPeer for cross-platform live audio delivery.
- Added cross-platform microphone capture via miniaudio and Opus codec integration for live encoding/decoding.
- Added Apple DeviceCheck attestation token generation via raw Objective-C FFI for macOS.
- Updated live session model to "gpt-live-1-codex" and default voice to "sol" across protocol and controller.
- Added LiveWebRtcPeer and deviceCheckGenerateToken to the public native bindings API.
2026-07-24 08:22:22 +02:00
can1357 75cc0a054f feat(coding-agent/tools): added default card fallback for tool rendering
- Extracted #formatToolExecution into a standalone formatDefaultToolExecution module.
- Updated xdev renderXdevCall and renderXdevResult to use the default card when no mounted renderer exists.
- Added fallback rendering that shows tool label, args, and output with appropriate theming.
- Added integration test verifying generic card renders for mounted tools without bespoke renderers.
2026-07-24 08:19:13 +02:00
can1357 024f49220e fix(coding-agent): handled xdev execution errors with mounted tool renderer
- Catch execution errors in XdevRegistry and render them using the mounted tool's error handling.
- Preserve xdev dispatch context when device execution fails.
2026-07-24 08:03:17 +02:00
can1357 af9e8546a9 feat: implemented session account selection and pinning via slash command
- Add `pinSessionOAuthAccount` storage method and active account flag to the auth storage API.
- Introduce session account selector component, controller logic, and interactive mode delegation.
- Implement the `/session pin` builtin slash command with text listing and account pinning capabilities.
- Add unit tests covering session account selection, component navigation, and command handling.
2026-07-24 07:57:55 +02:00
can1357 38ad7e71c4 Merge PR #6472: fix(coding-agent): restored legacy keyText export (@roboomp) 2026-07-24 06:51:37 +02:00
can1357 189a3b51f0 fix: defer tiny-title prewarm past the scheduled first paint
requestRender(true) only queues the paint via setImmediate; calling
prewarm() synchronously afterwards put the worker spawn syscall ahead
of the render callback in the same loop turn. Schedule the prewarm
with its own setImmediate (FIFO after the render callback) so the
first startup frame paints before the subprocess spawns.
2026-07-24 06:51:37 +02:00
can1357 02ad4c3376 Merge PR #6469: fix(tui): prewarmed tiny-title worker off the first-submit hot path (@roboomp) 2026-07-24 06:51:37 +02:00
can1357 4f97aea2db Merge PR #6468: fix(tools): closed spilled output descriptors on error/abort paths (@roboomp) 2026-07-24 06:51:36 +02:00
can1357 1343dea49d fix(coding-agent/utils): guarded AppleScript file-url coercion to prevent URL text mangling
- Fixed a macOS clipboard bug where copied URL text like `https://i.can.ac/x.png` was coerced into a bogus HFS path (`/https/::i.can.ac:x.png`) and dead-ended with "Image not found" instead of falling through to text paste.
- The AppleScript now checks `clipboard info for "class furl"` before coercing so plain text/URL clipboards paste as text rather than file paths.
- Extracted the script to its own `.applescript` file and added TypeScript declarations for `.applescript` imports.
2026-07-24 06:49:03 +02:00
roboomp fbd8382edb fix(coding-agent): restored legacy keyText export
- Added the upstream keyText helper to the legacy package-root shim.
- Covered active keybinding formatting and documented the compatibility fix.

Fixes #6470
2026-07-24 03:59:10 +00:00
roboomp a39dbc9b44 fix(tools): guarantee spill sink close when tail replay fails
#finalizeFile marked the sink finalized then ran the capped-artifact tail
replay before closing. A write error during that replay threw before
sink.end(), and because #finalized was already set the executor finally
paths calling dispose() could not retry the close, leaking the descriptor
and masking the original tool error.

Moved sink.end() into a finally around the tail replay and swallowed both
the replay and close errors so the descriptor is always released and
dispose() never throws.
2026-07-24 03:53:21 +00:00
roboomp 3cdb93cd01 fix(tui): prewarm tiny-title worker off the first-submit hot path
The first interactive submit fired session.generateTitle() before
startPendingSubmission() painted the optimistic user row, and
tinyTitleClient.generate() spawned the local tiny-title subprocess
synchronously in #ensureWorker() before its first await. With a local
providers.tinyModel configured, subprocess-spawn latency therefore landed
ahead of the first frame, stalling the first prompt.

Paint the pending row before starting titling, and prewarm an idle,
unref'd worker at TUI startup via a no-op ping (no model load) so the
first submit reuses a live subprocess.

Fixes #6462
2026-07-24 03:48:43 +00:00
roboomp 31098f9248 fix(tools): closed spilled output descriptors on error/abort paths
OutputSink.dump() was the only path that closed the spill Bun.FileSink.
The bash and Python executors re-throw on failure and their finally
blocks never closed the sink, so any large-output command that errored
leaked the artifact descriptor until an unrelated read (e.g. a SKILL.md
load) hit EMFILE.

Added an idempotent OutputSink.dispose() that closes the sink exactly
once (awaiting any in-flight sink creation, guarding post-finalize
resurrection) and wired it into every executor's finally block.

Fixes #6463
2026-07-24 03:44:12 +00:00
usr-bin-roygbiv 68ac163e2c fix(computer): harden native desktop execution 2026-07-24 01:40:05 +00:00
can1357 681d7daf65 feat(computer): unified native addon, /computer toggle, function tool
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
  a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
  XTest input with keysym mapping) compiled into the core addon on every
  published target; Linux arm64 and musl are now supported and headless
  hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
  lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
  build dependencies, and the now-unreferenced vendored libspa crate;
  reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
  XTest layouts reject negative origins and coordinates beyond 0..=32767,
  batch coordinates stay bound to the frame last returned to JS with
  intermediate screenshots deferred, coordinate input requires a
  previously returned frame, and failed chord releases still release
  every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
  no input is emitted after expiry and wait-heavy batches are rejected
  upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
  scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
  a regular function tool with a typed GA action schema across OpenAI,
  Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
  session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
2026-07-24 01:40:05 +00:00
usr-bin-roygbiv 4fe03e25cb fix(coding-agent): align computer session ownership 2026-07-24 01:40:05 +00:00
usr-bin-roygbiv 57f8acdd18 fix(native): harden desktop input and compatibility 2026-07-24 01:40:05 +00:00
usr-bin-roygbiv b9504f65e7 feat: add native Codex computer use 2026-07-24 01:40:04 +00:00
can1357 0868861abd test(eval): matched allowed-agents wording in tool description 2026-07-24 02:41:35 +02:00
can1357 6cf5b25399 chore: update changelogs 2026-07-24 02:38:32 +02:00
can1357 1e1d2e91ea style: applied biome formatting 2026-07-24 02:27:35 +02:00
can1357 f1875dc45a style: applied biome fixes to live module 2026-07-24 02:27:08 +02:00
can1357 fc3e9970c7 style: organized imports in session modules after fallback merge 2026-07-24 02:26:26 +02:00
can1357 366bd6203e Merge PR #6392: feat(coding-agent): add usage-aware model fallback (@eggpeat) 2026-07-24 02:25:35 +02:00
can1357 77669aed54 Merge PR #6395: feat: configure xdev prompt docs (@joeshull) 2026-07-24 02:25:35 +02:00
can1357 5ded27b0b1 fix(cli): stopped $-pattern expansion when injecting cache prefix 2026-07-24 02:25:25 +02:00
can1357 3f2ef2cea1 Merge PR #6413: feat(cli): benchmark prompt cache reuse (@riverpilot)
# Conflicts:
#	packages/ai/src/providers/pi-native-server.ts
#	packages/ai/src/stream.ts
#	packages/ai/src/types.ts
2026-07-24 02:25:24 +02:00
can1357 b33e705aef Merge PR #6416: feat(ai): add process-scoped OAuth account pools (@atyrode) 2026-07-24 02:24:30 +02:00
can1357 0689092866 Merge PR #6445: feat(extensions): expose session service tiers (@atyrode) 2026-07-24 02:24:29 +02:00
can1357 aff775ecfb Merge PR #6443: fix(coding-agent): make mixed-agent task batches atomic and inspectable (@TechDufus) 2026-07-24 02:24:17 +02:00
can1357 fe2ddc94aa Merge PR #6430: fix(dap): reject and bound the unix socket connect on Linux (@roboomp) 2026-07-24 02:24:16 +02:00
can1357 9d2456415e fix(acp): propagated initial MCP refresh failure, drained stale chain 2026-07-24 02:24:16 +02:00
can1357 802ca5258c Merge PR #6437: fix(acp): pick up MCP tools that connect after the startup race (@barisdemirdelen) 2026-07-24 02:24:16 +02:00
can1357 2e3fbbbd2a Merge PR #6432: fix(session): clear session-scoped tool state (@roboomp) 2026-07-24 02:24:15 +02:00
can1357 e2a986c6b6 Merge PR #6429: fix(session): preserve compaction data for rewinds (@roboomp) 2026-07-24 02:24:05 +02:00
can1357 9c0ad16b8a Merge PR #6431: fix(agent): commit plan-reference flag on delivery, not construction (@roboomp) 2026-07-24 02:24:05 +02:00
can1357 32f79dbb48 Merge PR #6444: fix(plan): preserve and line-anchor review annotations (@anatoli-tsinovoy) 2026-07-24 02:24:05 +02:00
can1357 d2db3a9cad Merge PR #6442: fix(coding-agent): return from cancelled /omfg amendments (@anatoli-tsinovoy) 2026-07-24 02:24:04 +02:00
can1357 ca8c9eb69f Merge PR #6396: fix(tts): preserve playback across internal turns (@roboomp) 2026-07-24 02:24:04 +02:00
can1357 0abc977d98 Merge PR #6397: fix(write): reject local read-selector-shaped write targets (@roboomp) 2026-07-24 02:24:04 +02:00
can1357 3890f5b97b Merge PR #6450: fix(extensibility): guard legacy-pi-compat commonjs registration first-wins (@roboomp) 2026-07-24 02:24:04 +02:00
Brent 8a9630c031 fix(coding-agent): reselect fallback account by health 2026-07-24 02:23:51 +02:00
Brent 6d4a345d69 fix(coding-agent): defer ACP reserve confirmation 2026-07-24 02:23:51 +02:00
Brent 93af91b7f5 fix(coding-agent): preserve fallback CI contracts 2026-07-24 02:23:51 +02:00
Brent 0bfb0bd1e3 feat(coding-agent): add usage-aware model fallback 2026-07-24 02:23:51 +02:00
can1357 041adb2b1f fix(xdev): tolerated malformed inline-device allowlist config
Settings.get returns raw merged config without element validation, so a
scalar or non-string tools.xdevInlineDevices entry reached Bun.Glob and
threw while building the system prompt. Normalized the allowlist to
string patterns and compiled globs once per render.
2026-07-24 02:23:22 +02:00
Joe Shull f4641c165e feat: allowlist xdev prompt docs 2026-07-24 02:23:22 +02:00
Joe Shull f15191c37d feat: configure xdev prompt docs 2026-07-24 02:23:22 +02:00
can1357 9687818228 fix(session): cleared branch-scoped tool state
Applied the session-scoped tool reset after /branch and /btw create their
branched logical sessions, closing the same stale-state leak as /new,
handoff, and cross-session switches.

Added a branch transition to the staged-preview regression matrix.
2026-07-24 02:23:15 +02:00
roboomp 55d18e89a5 fix(session): cleared handoff-scoped tool state
Applied the session-scoped tool reset after handoff creates its replacement session.

Added regression coverage for stale staged preview directives across handoff.

Fixes #4093
2026-07-24 02:23:15 +02:00