Commit Graph
7799 Commits
Author SHA1 Message Date
Mathews-Tom b9b5ee45d5 Merge remote-tracking branch 'upstream/main' into fix/mcp-stdio-process-group-kill 2026-07-18 00:26:51 +05:30
can1357 261ce6c370 fix(prompting): preserved direct tools sharing xd names
Kept top-level custom tool descriptors when a retained xd device uses the same name. Added compact and inline inventory coverage for mounted-only and dual-presentation tools.
2026-07-17 20:44:34 +02:00
can1357 e1e2a868b1 merge pull request #5799 2026-07-17 20:40:39 +02:00
can1357 248421fdf9 fix(coding-agent): fixed xd:// mount notices triggering unsolicited model turns
- Fixed xd:// mount notices forcing their own model turn by deferring them until the next user prompt instead.
- Added `#pendingXdevMountDelta` field and `#takePendingXdevMountNotice()` to coalesce mount/unmount events and ride along with prompts.
- Mount and unmount events that cancel each other out before the next prompt are now dropped from the coalesced delta.
- Notices remain buffered during quiet startup mode (`startup.quiet`) and are delivered on the subsequent user prompt.
2026-07-17 20:36:11 +02:00
Mathews-Tom 224796b13a fix(mcp): sweep group SIGKILL after a cooperative detached leader exit
terminateStdioProcess() treated a detached leader's cooperative SIGTERM
exit as proof the whole process group was gone, so close() skipped the
group SIGKILL and left a SIGTERM-trapping/ignoring grandchild running as
an orphan — exactly the process tree this change set out to reap. A
detached transport now always sweeps the group SIGKILL after SIGTERM,
even when the leader itself already exited.

waitForProcessExit() also left its losing Bun.sleep() timer running
after Promise.race settled from the other side, holding the event loop
open for up to the full grace window on every close(). It now uses a
cancellable setTimeout cleared in a finally block.

Adds a regression test spawning a non-trapping leader with a
SIGTERM-trapping grandchild to cover the gap the first fix closes.
2026-07-18 00:02:21 +05:30
Mathews-Tom c30c3ab0fb fix(mcp): process-group kill and SIGKILL escalate on stdio transport close
Before: StdioTransport.close() did a bare `this.#process.kill()` — a single
direct SIGTERM to the immediate child, with no wait and no escalation. On
Linux (and other non-Windows/non-macOS POSIX hosts), the MCP server is
spawned detached (setsid, its own session leader) so terminal job-control
signals can't stop it. A detached server that traps/ignores SIGTERM — or a
grandchild it spawns inside that session — survived omp process exit and
was orphaned, re-parented to PID 1.

After: close() runs a bounded, idempotent teardown:
  1. End stdin first (cooperative EOF) so a well-behaved server can exit on
     its own before any signal is sent.
  2. Send SIGTERM: to the whole process group (negative-pid `process.kill`)
     when this transport actually spawned detached on a POSIX host, else to
     the direct child only. A negative-pid signal is never attempted for a
     non-detached transport, since it could hit an unrelated group. ESRCH
     from the group signal means the group is already gone (treated as
     success); any other group-signal failure falls back to a direct-child
     signal.
  3. Wait up to ~1s for the direct child to exit; if it hasn't, escalate to
     SIGKILL (group-or-direct, same rule as step 2) and wait a further
     bounded ~0.5s before returning. Total worst case (~1.5s) stays well
     inside the ~3s MCP disconnect-all budget in agent-session.ts dispose().

`#process` is captured into a local and nulled before the first `await`, so
repeat/concurrent close() calls see it already cleared and skip re-signaling
— idempotent per the existing contract documented above close().

Extracted the signal/escalate logic into an exported `terminateStdioProcess`
(plus a `KillableSubprocess` structural type, decoupled from the stdio pipe
generics) so tests can drive group-signal escalation with an explicit
`detached` flag — `StdioTransport.connect()` ties `detached` to the host's
real `process.platform` via `resolveStdioSpawnCommand()`, so a POSIX
detached session can't be reproduced end-to-end through `connect()` on a
non-Linux dev/CI host, but a real detached process group can still be
spawned directly on any POSIX host to exercise it.

Tests added to stdio.test.ts: detached child trapping SIGTERM escalates to
SIGKILL; a detached parent's SIGTERM-trapping grandchild is only reached by
the group SIGKILL (proves group, not direct-child-only, signaling); a
well-behaved child closes promptly without escalating; a non-detached
transport never attempts a group signal. Extended
test/mcp-stdio-transport.test.ts's existing close() idempotency coverage
with a case where the first close() had to run the full escalation path.

Fixes #5578.
2026-07-17 23:22:06 +05:30
vmcall 131d06075d fix(task): preserved essential load mode 2026-07-17 17:46:07 +02:00
vmcall 4121c19781 test(eval): aligned allowed-agent prompt expectation 2026-07-17 17:38:12 +02:00
vmcall d53cf023b0 fix(task): reconciled structured subagents with upstream
- Preserved the plan-mode capability clamp after upstream removed report_finding.
- Updated persisted-revival coverage for mounted xdev tool activation.
- Applied current formatter output to conflicted runtime files.
2026-07-17 17:38:12 +02:00
vmcall b4952e27c4 refactor(eval): removed dead isolation recovery formatter 2026-07-17 17:38:12 +02:00
vmcall 1dbedbedf5 fix(task): restored restricted spawn policy description 2026-07-17 17:38:12 +02:00
vmcall 2aaa639b69 fix(task): marked dynamic task schema non-strict
Caller-provided output schemas are free-form JSON and cannot be represented by OpenAI strict tool schemas. Keep todo strict while explicitly sending task as non-strict.
2026-07-17 17:38:12 +02:00
vmcall 414ef80c41 fix(task): restored goal activation outside restricted sessions
- Preserved goal-mode tool injection for ordinary explicit tool lists.
- Kept plan-mode LSP and IRC unavailable under the host capability clamp.
- Added regressions for both capability boundaries.
2026-07-17 17:36:59 +02:00
vmcall d944879f21 feat(task): unified structured subagent execution
- Added per-invocation task schemas with strict and permissive validation.
- Shared task and eval agent policy, artifacts, isolation, and lifecycle handling.
- Enabled host-restricted plan-mode eval agents and persisted their capability clamp.

Fixes #5279
2026-07-17 17:36:59 +02:00
roboomp 6b88e69057 fix(prompting): hid xd tools from direct inventory
- Filtered xd-mounted names from compact and inline tool inventories.

- Added regression coverage for both inventory rendering modes.

Fixes #5797
2026-07-17 07:09:23 +00:00
can1357 eac51b6a04 Merge: darkphilosophy/feat/advisor-per-agent-toggle
Brings the per-advisor toggle, status-line glyphs, quota display, and the
failing-advisor stall/abort fix (f4c8143) onto main's rewritten advisor
runtime. Conflict reconciliation kept main's architecture (fingerprint
prefix reconciliation, host-level onTurnError recovery + fallback chains,
terminal-failure classification) and ported the branch semantics onto it:

- #failing latch: waitForCatchup resolves immediately while an advisor is
  mid-failure; parked waiters wake the moment a turn fails, before any
  async hook or retry sleep.
- Turn-end render containment: a formatter bug restores the cursor/prefix/
  dedup snapshot and never propagates into the primary's turn-end callback
  (per-advisor try/catch boundary in AgentSession).
- Quota pause: when host recovery declines a usage-limit failure, the
  runtime latches quotaExhausted, requeues the batch, and notifies —
  cleared only by an explicit reset.
- Hard halt after a permanent rejection or three backlog-drop cycles.
- #recoverAdvisorTurn also marks usage limits for structural errors thrown
  before any assistant turn is recorded.
2026-07-17 07:37:29 +02:00
DarkPhilosophy f4c81434d0 fix(advisor): never let a failing advisor stall or abort the primary agent
A broken advisor could hold the primary agent on the per-turn catch-up
gate for its full 30s budget while retrying, and an exception thrown from
onTurnEnd propagated into the primary's turn-end callback.

- waitForCatchup resolves immediately while the advisor is mid-failure
  (new #failing latch, set at the failure catch BEFORE any async hook,
  cleared on the next successful turn or reset/seed).
- Every parked waiter is woken the moment an advisor turn fails.
- The turn-end boundary isolates advisor exceptions per advisor: a
  throwing advisor loses its delta, the primary and sibling advisors
  continue untouched.
- A failed render (poisoned message, formatter bug) restores the delta
  cursor and dedup state, so the delta is re-rendered next turn instead
  of silently lost; the size probe itself is guarded and falls back to
  the deferred renderer.
2026-07-17 07:24:30 +03:00
can1357 2a6d551063 revert(status-line): restored single-row status bar with priority drop
- Reverted PR #5751 (issue #5749): continuation rows wrapped the editor
  top border onto extra lines, which is unacceptable for the input frame.
- EditorTopBorder is back to a single content/width pair; narrow widths
  drop right segments, shrink the path, then drop left segments.
2026-07-17 05:49:13 +02:00
can1357 adb2a3c7e2 style: formatted files from owner-approved merges 2026-07-17 05:33:19 +02:00
can1357 fcb368263b merge PR #5507 via eval/pr-5507: feat(telemetry): support full OTel — log and metric export 2026-07-17 05:32:51 +02:00
can1357 450bea6cc7 feat(coding-agent): disabled generate_image by default
Lands the intent of #5318 on the established generate_image.enabled
gate instead of introducing a parallel imagegen.enabled key; sessions
must opt in before the tool registers top-level or as an xd:// device.
2026-07-17 05:32:51 +02:00
can1357 e00eb7cfbc fix telemetry export signals 2026-07-17 05:29:46 +02:00
can1357 4e0e53c183 merge PR #5321 via eval/pr-5321: feat(coding-agent): generate_image per-request provider + Codex-subscription images 2026-07-17 05:29:29 +02:00
can1357 ac3d779fad merge PR #5592 via eval/pr-5592: feat(warp): emit native CLI-agent events 2026-07-17 05:29:29 +02:00
can1357 dee89ed5ae fix(warp): settle deferred handoffs 2026-07-17 05:25:05 +02:00
can1357 92d63050c0 merge sweep/2026-07-17 2026-07-17 05:24:45 +02:00
can1357 039497a167 merge PR #5546 via eval/pr-5546: fix: render bash timeout with warning border instead of error 2026-07-17 05:23:50 +02:00
can1357 a7eadcae46 merge PR #5635 via eval/pr-5635: fix(coding-agent): disable thinking on local llama.cpp Qwen models 2026-07-17 05:23:49 +02:00
can1357 8bdb69254b merge PR #5596 via eval/pr-5596: feat(coding-agent): support per-project model roles
Combined #5586's role-tag precedence with #5596's scope labels in the
selector status messages.
2026-07-17 05:23:49 +02:00
can1357 87bd6c7b94 Merge branch 'sweep/2026-07-17' into eval/pr-5321
# Conflicts:
#	packages/coding-agent/src/config/settings-schema.ts
#	packages/coding-agent/src/tools/image-gen.ts
#	packages/coding-agent/test/tools/image-gen.test.ts
2026-07-17 05:23:41 +02:00
can1357 b4e46f8fc6 fix(session): tolerated partial extension runners in dispose
Managed-timer cleanup from #5667 is now optional-called so host or test
facades implementing only the dispatch surface do not throw during
dispose; aligned the selector fallback status expectation with #5586's
role-tag casing.
2026-07-17 05:23:00 +02:00
can1357 86b6265ef5 Merge branch 'sweep/2026-07-17' into eval/pr-5592
# Conflicts:
#	packages/coding-agent/test/agent-session-checkpoint-rewind-branch.test.ts
2026-07-17 05:22:52 +02:00
can1357 ab39a4b18b Merge branch 'sweep/2026-07-17' into eval/pr-5546 2026-07-17 05:22:13 +02:00
can1357 a4c9ffb434 fix: preserve bash timeout and abort semantics 2026-07-17 05:18:39 +02:00
can1357 f36394ef55 style: fixed formatting in merged test and session files 2026-07-17 05:02:31 +02:00
can1357 2594ae352b style: formatted conflict-resolved files with biome 2026-07-17 05:01:19 +02:00
can1357 dd84ec57ce apply PR #5468: fix(advisor): stop retrying terminal failures
Grafted the evaluator's port (ec2c1e632) onto the merged advisor
runtime: terminal provider failures classified non-retriable (and not
context overflow) drop the bounded batch after one attempt with a
single notification; fallback-chain recovery and overflow recovery
retain precedence. Includes the one-prompt regression test and tags the
rollback-retry fixture's synthetic failure as transient.
2026-07-17 05:00:06 +02:00
can1357 11a879e993 merge PR #5463 via eval/pr-5463: fix(advisor): anchor context maintenance on provider usage
Semantic merge with #5734 (delivered-prefix reconciliation) and #5748
(fallback chains): kept the coalescing round cap and wip threading,
adopted bounded cursor-preserving maintenance resets and overflow
recovery, and gated late-arrival consumption on coalescing rounds so
both suites' backlog and preserved-updates contracts hold.
2026-07-17 04:55:49 +02:00
DarkPhilosophy 1b4c292f8f Merge remote-tracking branch 'can1357/main' into feat/advisor-per-agent-toggle 2026-07-17 05:47:09 +03:00
DarkPhilosophy 3be0663bf2 fix(advisor): halt permanently rejected advisors and chunk large delta renders
Two shared failure modes with a single misbehaving advisor:

- A permanently rejected request (invalid_request_error, e.g. a model the
  account no longer supports) retried forever: one notice, then silent
  re-attempts on every turn, rebuilding heavy context each cycle. Quota
  exhaustion already paused with a notice; this class now hard-stops the
  runtime after a permanent rejection or three consecutive backlog-drop
  cycles, with a visible notice. An explicit reset (/new, config rebuild,
  restart) re-enables it, and waitForCatchup resolves while halted so the
  primary agent never parks on a runtime that cannot drain.

- The delta render ran synchronously on the event loop; replaying a
  multi-MB transcript after a reset blocked it for 600ms+ per render
  (measured 675ms at ~54MB). Large deltas now render in size- and
  count-bounded chunks that yield between slices (675ms -> single-digit
  ms stalls). Tool call/result pairing survives chunk boundaries via a
  shared whole-delta result index in formatSessionHistoryMarkdown; small
  per-turn deltas keep the synchronous fast path.
2026-07-17 05:47:01 +03:00
can1357 6f42a4375f merge PR #5748 via eval/pr-5748: fix(advisor): apply configured fallback chains 2026-07-17 04:45:46 +02:00
can1357 b28dd5e50a merge PR #5734 via eval/pr-5734: fix(advisor): reconcile rewritten transcript prefixes 2026-07-17 04:45:38 +02:00
can1357 4e85f6acee apply PR #5490: fix(tui): refresh dark/light appearance on explicit ctrl+l reset
Cherry-picked 69c9fe8d4; resolved terminal.ts against the newer
onPrivateModeReport signature and unioned appearance tests with the
Windows Terminal polling regression.
2026-07-17 04:45:22 +02:00
can1357 06d11d11a1 apply PR #5480: fix(slash-commands): added /q alias for /quit
Cherry-picked b6b376987 from the PR head; the branch's unrelated
prompt/test drive-bys were already present via other merged PRs.
2026-07-17 04:44:03 +02:00
can1357 1f9a5d5299 merge PR #5442 via eval/pr-5442: fix(rpc): tolerate malformed stdin lines instead of crashing
Resolved against the newer RpcInputDispatcher loop: kept serial dispatch
and shutdown coordination, replaced only the readJsonl generator with
line-based reads and a per-line parse-error response frame.
2026-07-17 04:43:41 +02:00
can1357 22ae8045f2 merge PR #5768 via eval/pr-5768: fix(tools): keep essential built-ins top-level when re-registered without loadMo 2026-07-17 04:42:10 +02:00
can1357 c1fc297f3f merge PR #5763 via eval/pr-5763: fix(web-search): scoped kimi search to kimi code credentials 2026-07-17 04:42:10 +02:00
can1357 05e1314bd9 merge PR #5760 via eval/pr-5760: fix(coding-agent): restored xdev for explicit tool sessions
Resolved plan-mode exit overlap with #5662 (kept restore/rollback
structure, routed pending-switch clearing through
clearPendingPlanModelSwitch) and unioned additive test blocks with
#5672/#5662.
2026-07-17 04:42:10 +02:00
can1357 348b8e99e0 merge PR #5754 via eval/pr-5754: fix(cli): bounded print-mode memory teardown 2026-07-17 04:40:05 +02:00
can1357 cef2708f87 merge PR #5752 via eval/pr-5752: fix(discovery): isolated Claude local plugins 2026-07-17 04:40:05 +02:00