- Added Tavily web search provider with API key authentication and credential discovery from environment or database.
- Integrated Tavily as highest-priority search provider in fallback chain with structured response mapping and error handling.
- Added Tavily OAuth login flow in CLI and auth-storage with manual API key input and validation.
- Added comprehensive test suite for Tavily provider covering registration, response mapping, error handling, and credential validation.
Fixes#313
- Removed Kagi Universal Summarizer integration from fetch tool and YouTube scraper.
- Removed `fetch.useKagiSummarizer` configuration setting from settings schema.
- Simplified renderHtmlToText() and renderUrl() functions by removing Kagi summarization fallback logic.
- Fixed indentation inconsistencies in test files from tabs to spaces.
findAnthropicAuth() only checked OAuth credentials in agent.db, missing
api_key type credentials entirely. Users authenticated via stored API key
(not env var, not OAuth) got null from isAvailable(), causing the provider
chain to skip Anthropic.
Added tier 4 (api_key in agent.db) between OAuth check and env var
fallback. Refactored store lifecycle so tiers 3-4 share one instance.
Also fixed ExaProvider.isAvailable() which unconditionally returned true,
ignoring exa.enabled/exa.enableSearch settings and never checking for
credentials. It now respects both settings and requires an actual API key.
* fix(session): bypass user-prompt pipeline in handoff
handoff() was calling #promptWithMessage, which gates on an API key
check before reaching this.agent.prompt(). That gate is appropriate for
user-facing prompts but has no place in an internal document-generation
call: it blocked the test spy on agent.prompt and required callers to
carry real credentials just to run the handoff path.
Fix: call #promptAgentWithIdleRetry directly (preserving the
busy-wait behaviour and #promptInFlightCount tracking) and skip the
user-prompt pipeline (API key validation, bash/python flushes, file
mention expansion, plan messages, extension events) entirely. handoff
creates a fresh session immediately after, so none of that setup
applies.
Tests now reach agent.prompt with no stub on modelRegistry.getApiKey.
* fix(patch): HASHLINE_PREFIX_RE strips comment lines with word: pattern
The regex used [0-9a-zA-Z]{1,16} for the hash ID segment, which matched
common comment patterns like '# Note:', '# TODO:', '# FIXME:'. When a
single-line replacement contained such a comment, nonEmpty===1 and
hashPrefixCount===1, triggering stripping and eating the comment prefix.
Actual hashline IDs are always exactly 2 chars from ZPMQVRWSNKTXJBYH.
Constrain the regex to that exact alphabet so no English word can match.
Also update tests that used fake IDs (AB, CD, EF) not in the real alphabet.
* Revert "fix(patch): HASHLINE_PREFIX_RE strips comment lines with word: pattern"
This reverts commit 112ad083de956d4ed8b78a7e6e9af2c061befbd5.
---------
Co-authored-by: Miroslav Drbal <miroslav.drbal@gendigital.com>
- Resolved symlinked paths before passing to brush shell to keep `pwd` output aligned with canonical Git worktree paths.
- Added `resolveShellCwd` helper that safely resolves symlinks and falls back to original path on error.
- Added test case verifying symlinked directories are canonicalized before execution.
* fix: strip invalid thinking signatures from aborted/errored messages
When a stream is interrupted mid-response, thinking blocks may have
empty or partial cryptographic signatures. These get persisted to
session history and sent on the next API call, causing:
'Invalid signature in thinking block'
transformMessages() now detects aborted/errored assistant messages and
clears thinkingSignature fields so they are treated as unsigned thinking
(converted to text by the serializer).
Also protect truncateForPersistence from corrupting signatures — clear
them entirely instead of truncating, since a partial signature is always
invalid.
* fix: disable thinking when tool_choice forces tool use on Bedrock
Bedrock rejects requests that combine extended thinking with forced
tool_choice (any or specific tool). The Anthropic provider already had
a guard (disableThinkingIfToolChoiceForced) but the Bedrock provider
was missing the equivalent check.
Also fix thinking block serialization: when a thinking block has no
valid signature (e.g., from an aborted stream), convert it to plain
text instead of sending it as reasoningContent without a signature.
The API requires the signature field on all reasoning blocks for models
that support it.
Add thinking block diagnostics to error messages for signature/thinking
related failures to aid debugging.
* fix(patch): HASHLINE_PREFIX_RE strips comment lines with word: pattern
The regex used [0-9a-zA-Z]{1,16} for the hash ID segment, which matched
common comment patterns like '# Note:', '# TODO:', '# FIXME:'. When a
single-line replacement contained such a comment, nonEmpty===1 and
hashPrefixCount===1, triggering stripping and eating the comment prefix.
Actual hashline IDs are always exactly 2 chars from ZPMQVRWSNKTXJBYH.
Constrain the regex to that exact alphabet so no English word can match.
Also update tests that used fake IDs (AB, CD, EF) not in the real alphabet.
* test(patch): add regression tests for comment line prefix stripping bug
Three new tests in hashlineParseContent describe block:
- hashlineParseText preserves '# Word:' comment lines (unit)
- full pipeline: replacing '# Note:' comment line preserves prefix
- full pipeline: replacing '# TODO:' comment line preserves prefix
These would have caught the HASHLINE_PREFIX_RE bug where [0-9a-zA-Z]{1,16}
matched comment words, causing stripNewLinePrefixes to eat the '# Note:'
prefix when a single comment line was the sole replacement entry.
---------
Co-authored-by: Miroslav Drbal <miroslav.drbal@gendigital.com>
#applyHardcodedModelPolicies forced contextWindow=1_000_000 on any model
with id 'gpt-5.4' regardless of provider. This was wrong in every case:
- github-copilot/gpt-5.4: inflated from bundled 400K (and overwrote the
~274K that Copilot's live /models discovery returns via capabilities.limits)
- openai/gpt-5.4: deflated from bundled 1_050_000 to 1_000_000
- openai-codex, opencode, opencode-zen: same downgrade from 1_050_000
The method was called twice — after static load and after runtime discovery —
so it reliably clobbered the correct provider-specific value both times.
No documented rationale exists for the override. The bundled models.json
values are already correct. Remove the method and its two call sites.
fixes#332
Co-authored-by: Miroslav Drbal <miroslav.drbal@gendigital.com>
- Extracted OAuth identifier logic into public functions extractOAuthCredentialIdentifiers and extractOAuthTokenIdentifiers.
- Replaced single credentialIdentity string with multi-identifier resolveCredentialIdentifiers returning string[] for flexible matching.
- Changed credential deduplication from email-based to accountId-based matching in replaceAuthCredentialsForProvider.
- Updated auth-storage tests to verify accountId-prioritized deduplication behavior across soft-disable and hard-delete scenarios.
- Added documentation comments in coding-agent modules explaining partial JSON preservation for streaming tool previews.
- Documented streaming tool preview requirements and render paths in AGENTS.md.
- Added `env` parameter to bash tool for safe environment variable passing without shell re-parsing.
- Added support for rendering partial environment variable assignments in command preview during streaming.
- Updated bash tool prompt to recommend `env` parameter for multiline, quote-heavy, and untrusted values.
- Refactored tool execution component to conditionally merge partial JSON arguments during streaming.
- Added helper functions for environment variable normalization, escaping, and formatting.
- Fixed WebSocket stream fallback logic to safely replay buffered output over SSE when WebSocket fails after partial content has been streamed.
- Added tracking flag to prevent unsafe replays of tool calls and terminal events during fallback transitions.
- Enhanced error recovery to reset output state when replaying buffered content over SSE connection.
- Added docs.rs scraper for extracting Rust crate documentation from rustdoc JSON, supporting modules, functions, structs, traits, enums, and other Rust items with intelligent caching.
- Implemented rustdoc JSON parsing with type rendering for complex Rust types including generics, lifetimes, trait bounds, and qualified paths.
- Added caching layer for rustdoc JSON with date-based versioning for 'latest' releases to reduce repeated fetches.
- Added fallback search strategies in librarian and explore agent prompts for handling empty results.
- Clarified task completion priority in system prompt by prohibiting premature tool call cessation.
- Consolidated and simplified 'Giving Up' guidance in subagent prompt with clearer uncertainty handling.
- Removed duplicate instructions and redundant phrasing to improve prompt clarity and conciseness.
- Added skipPostPromptRecoveryWait option to HandoffOptions for deferring recovery work in handoff operations.
- Added deferred auto-compaction scheduling for threshold-triggered handoffs via post-prompt task queue.
- Extracted handoff document template to dedicated system prompt file for improved maintainability and reusability.
- Changed handoff prompt generation to use template rendering with custom focus instructions support.
- Refactored prompt-in-flight tracking from boolean flag to counter for proper nested operation handling.
- Moved llms.txt endpoint discovery to fallback strategy when rendered page content is low quality, prioritizing page-specific content over site-wide files.
- Enhanced llms.txt endpoint detection to scope candidates to the requested URL path, searching section-specific files before site-wide ones.
- Replaced getOrigin() with buildLlmEndpointCandidates() to generate path-scoped endpoint candidates with depth-based fallback strategy.
- Updated tryLlmEndpoints() to accept full URL and return endpoint metadata alongside content for better fallback tracking.
- Added 2 integration tests validating section-scoped llms.txt discovery and preference for rendered content over site-wide files.
- Clarified contextual pattern mode behavior in ast-grep and ast-edit documentation to explain that results target the selected node, not the outer wrapper.
- Enhanced TypeScript pattern examples to include class method matching syntax with `class $_ { method(...) }` wrapper pattern.
- Removed redundant class method examples that were superseded by improved documentation of contextual pattern mode.
- Renamed parameter names in ast-grep and ast-edit tools from `patterns`/`selector` to `pat`/`sel` for brevity across schema, implementation, and tests.
- Expanded ast-grep and ast-edit tool documentation with 12+ new usage guidelines, examples, and critical notes on pattern syntax, metavariable placement, and error handling.
- Updated CHANGELOG.md to document parameter renames and expanded tool guidance for AST pattern syntax and metavariable usage.
- Reformatted test assertions and type annotations across ast-edit and ast-grep test files for improved readability.
- Added `glob` parameter to `ast_grep`, `ast_edit`, and `grep` tools for filtering files relative to `path`.
- Implemented `combineSearchGlobs()` utility to merge glob patterns from multiple sources instead of throwing errors.
- Changed `grep` tool to combine glob patterns when both `path` and `glob` parameters are provided.
- Updated tool documentation to recommend pairing `path`, `glob`, and `lang` for language-scoped search in mixed repositories.
- Added comprehensive test coverage for combined path and glob parameter handling across grep, ast_grep, and ast_edit tools.
- Added automatic Ollama model capability detection via /api/show endpoint to discover reasoning and input modality support.
- Improved Kagi API error handling with structured error parsing for JSON and plain text response formats.
- Fixed Cerebras streaming compatibility by omitting stream_options.include_usage parameter.
- Simplified API key credential storage to always replace credentials instead of merging for non-minimax providers.
- Updated Kagi Search API key format from 'kagi_...' to 'KG_...' and clarified beta access requirement in provider description.
Fixes#326.
Fixes#321.
Fixes#298.
The context fullness gauge was driven by output token count, causing
erratic jumps between turns (e.g. 84% -> 64%) with no compaction.
Status bar and estimateContextTokens now use calculatePromptTokens()
which returns input + cacheRead + cacheWrite — the actual input context
size. Previously both used a formula that included the final output token
count, which fluctuates with response length and is not part of the
context window for the current request.
isContextOverflow's usage-based fallback (z.ai silent overflow) was
also missing cacheWrite (cache_creation_input_tokens). Per Anthropic
docs the threshold is input + cache_read + cache_creation — all three.
Ref: https://platform.claude.com/docs/en/about-claude/pricing#long-context-pricing
google.ts and google-vertex.ts were double-counting cached tokens.
Gemini's promptTokenCount already includes cachedContentTokenCount, so
assigning input = promptTokenCount and cacheRead = cachedContentTokenCount
overcounted by cachedContentTokenCount on every cached request. Fixed
by subtracting first, matching the OpenAI convention:
input = promptTokenCount - cachedContentTokenCount
cacheRead = cachedContentTokenCount
=> input + cacheRead = promptTokenCount (total prompt, no double-count)
Ref: https://ai.google.dev/api/generate-content#v1beta.GenerateContentResponse.UsageMetadata
All other providers validated: amazon-bedrock (inputTokens is uncached
by API contract), openai-completions/responses/azure (already subtract
cached), kimi/gitlab-duo (delegate to correct implementations), cursor
(API exposes output tokens only — input stays 0 by design).
Co-authored-by: Miroslav Drbal <miroslav.drbal@gendigital.com>
* Add PUPPETEER_PROXY and PUPPETEER_PROXY_IGNORE_CERT_ERRORS env vars
- PUPPETEER_PROXY: routes browser traffic through specified proxy
- PUPPETEER_PROXY_IGNORE_CERT_ERRORS: ignore HTTPS cert errors when set
Made-with: Cursor
* fix(browser): gate PUPPETEER_PROXY_IGNORE_CERT_ERRORS on explicit truthy parse
Previously any non-empty value (including 'false', '0') enabled
--ignore-certificate-errors, silently disabling TLS verification when
operators intended to keep it on. Now only 'true', '1', 'yes', 'on'
(case-insensitive) enable the flag.
Made-with: Cursor
- Added `disabledCause` parameter to credential deletion methods to track reason credentials are disabled.
- Changed credential disabling mechanism from boolean `disabled` flag to `disabled_cause` text field for better auditability.
- Fixed credential purging to respect disabled credentials during email deduplication operations.
- Refactored `replaceAuthCredentialsForProvider()` to update matching credentials instead of deleting all, preserving credential history.
- Added incremental history mode to OpenAI responses .
- Changed OpenAI Codex to exclusively use websockets v2 protocol with fatal error detection for automatic SSE fallback.
- Fixed Gemini model parsing to strip `-preview` suffix for consistent model identification across API calls.
- Improved websocket error handling to extract and report detailed error messages from error events.
- Removed deprecated BETA_RESPONSES_WEBSOCKETS constant and websocket v2 feature flag branching logic.
- Introduced Effort enum and ThinkingConfig metadata for per-model reasoning capabilities with min/max effort levels.
- Migrated thinking level API from string-based ThinkingLevel to structured Effort enum across agent and AI packages.
- Added model-thinking module with effort mapping, policy application, and semantic versioning utilities for provider-specific thinking modes.
- Removed supportsXhigh() function and replaced effort clamping with model-aware validation using ThinkingConfig metadata.
- Expanded models.json with thinking configuration objects for 50+ models including Claude, Gemini, and OpenAI variants.
- Added Python analysis scripts for edit tool usage patterns and tool invocation stream processing.
- Added serviceTier option to OpenAI providers for controlling processing priority and cost across agent, completions, responses, and codex APIs.
- Added providerPayload field to messages for transport-native history reconstruction in OpenAI Responses and Codex APIs.
- Added /fast slash command and serviceTier setting to coding-agent for toggling OpenAI priority mode with fast mode indicator.
- Added remote compaction support with encrypted reasoning preservation for OpenAI models in coding-agent.
- Removed usage caching layer across all providers and refactored UsageFetchContext to eliminate cache and now dependencies.
- Fixed OpenAI Codex streaming service_tier inclusion, provider retry logic with exponential backoff, and email-based credential deduplication.
* idiomatic rust fixes
* idiomatic rust fixes
* display an image if we are fetching an image
* MIME type strictness
* codex nagging me
* codex nagging
* handoff instead of compaction as context filled strategy and surfacing
* handoff instead of compaction as context filled strategy and surfacing p2
* handoff instead of compaction as context filled strategy and surfacing p3
* handoff instead of compaction as context filled strategy and surfacing p4
* handoff instead of compaction as context filled strategy and surfacing p5
* handoff instead of compaction as context filled strategy and surfacing, fixes
* failing fetch test from the fetch tool updates
* handoff focus prompt skeleton
* handoff focus prompt skeleton p2
* fetch bugs
* further codex improvements
* further codex improvements
---------
Co-authored-by: Brit <lol@no.com>
- Added auto-correction logic for off-by-one range start errors in hashline edits.
- Added safety check to prevent false-positive auto-correction when position already includes boundary.
- Added test coverage for off-by-one range correction and duplicate leading line handling.
- Extracted turn-aborted-guidance prompt to external markdown file for better maintainability.
- Corrected provider selection case labels from flat names to namespaced keys (webSearchProvider -> providers.webSearch, imageProvider -> providers.image).
- Expanded web search provider options to include brave, kimi, kagi, and synthetic providers.
- Added RedactedThinkingContent type to support secure encrypted reasoning blocks in Anthropic messages.
- Updated message transformation logic to preserve signed thinking blocks and redacted thinking for latest assistant messages in Anthropic conversations.
- Added handling for redacted_thinking events in Anthropic stream processing with type, data, and index fields.
- Added comprehensive tests validating redacted thinking block preservation and Anthropic thinking immutability during message transformation.
- Removed static thinking mode constant exports (THINKING_LEVELS, ALL_THINKING_LEVELS, ALL_THINKING_MODES, THINKING_MODE_DESCRIPTIONS, THINKING_MODE_LABELS) in favor of dynamic function-based API.
- Renamed formatThinking() to getThinkingMetadata() with return type changed from string to structured ThinkingMetadata object containing value, label, and description.
- Renamed getAvailableThinkingLevel() to getAvailableThinkingLevels() and getAvailableThinkingEffort() to getAvailableThinkingEfforts() with added default parameters for runtime flexibility.
- Updated all consumer modules to use new function-based API instead of static constants, enabling dynamic thinking mode configuration.
- Added `read.defaultLimit` setting to configure default line count for read tool output (default 300 lines).
- Added preset options (200, 300, 500, 1000, 5000 lines) for read default limit in settings UI.
- Updated read tool to distinguish between default and maximum limits per call in prompt documentation.
- Refactored read tool limit logic to use configurable default limit with bounds validation.
- Fixed provider session state not being cleared when branching or navigating tree history, preventing resource leaks with codex provider sessions.
- Added calls to `#closeCodexProviderSessionsForHistoryRewrite()` in branch and navigateTree methods to ensure proper cleanup.
- Added test coverage for provider session cleanup during history branching and tree navigation.
- Removed complex fuzzy matching logic including Levenshtein distance calculation and similarity scoring in favor of a simpler glob-based suffix pattern approach. Replaced findReadPathSuggestions with findUniqueSuffixMatch that returns a path only when exactly one candidate matches, eliminating ambiguous suggestions. Removed legacy ttsr_trigger and ttsrTrigger fields from RuleFrontmatter interface.
- Added fallback to parse the legacy 'thinking' field when 'thinkingLevel' is not provided. The 'thinkingLevel' field takes precedence when both are present. Added tests to verify backward compatibility and field precedence.
- Added kebabToCamel and normalizeKeys utility functions to convert kebab-case keys to camelCase recursively. Updated parseFrontmatter to normalize all parsed keys, ensuring consistent camelCase property access throughout the codebase. Updated all frontmatter key accesses to use camelCase notation (e.g., thinkingLevel, spdxId).
- Updated option interfaces, param builders, and stream functions to use unified `reasoning` field.
- Added `resolveOpenAiReasoningEffort()` to centralize xhigh clamping logic.
- Replaced type casts with `castApi()` helper and fixed test option names.
- Updated coding-agent and benchmark references for consistency.
- Extracted thinking module with ThinkingEffort, ThinkingLevel, and ThinkingMode types to centralize reasoning configuration across packages.
- Migrated ThinkingLevel type from pi-agent-core to pi-ai package with new validation functions parseThinkingLevel() and getAvailableThinkingLevel().
- Consolidated thinking level constants and descriptions into reusable exports (ALL_THINKING_LEVELS, THINKING_MODE_DESCRIPTIONS) for consistent UI display.
- Removed local thinking-effort-label utility and replaced formatThinkingEffortLabel() with centralized formatThinking() function from pi-ai.
- Refactored thinking mode handling to distinguish ThinkingSelector (user-facing with 'off' option) from ThinkingEffort (provider-level).