Commit Graph
337 Commits
Author SHA1 Message Date
can1357 850225a694 style: applied biome formatting after community fix merges 2026-08-07 13:40:52 +02:00
can1357 bd6e87b297 feat(utils): added repair and rawKeys options to parseFrontmatter
- repair: false disables lenient recovery (ambiguous-scalar quoting, tab
  replacement, leading HTML-comment stripping) so spec-conformant loaders
  reject malformed input instead of silently repairing it.
- rawKeys: true preserves frontmatter keys verbatim; exported
  normalizeFrontmatterKeys for callers that validate raw keys first.
2026-08-07 05:59:19 +02:00
can1357 6e40e3e9fd fix(utils/marked): closed lists at an end-of-input blank run
- A blank run at EOF now breaks the list without consuming the blank,
  matching real marked: '- item\n\n' lexes as a tight list plus a space
  token instead of a loose list whose raw includes the blank.
- Completes the 17.2.10 mid-document fix; same-marker continuation and
  indented item content across blanks are unaffected.
- Added list/blank boundary token-shape tests (verified against marked
  v15) since the tui incremental tests compare the lexer to itself.
2026-08-06 14:40:13 +02:00
can1357 0992c9314f fix(utils/template): added handlebars lookup builtin
- {{lookup obj key}} resolves proto-safe obj[key] like Handlebars'
  built-in; a user-registered lookup helper still takes precedence.
- Restores slash-command/prompt-template arg consumption via
  {{default (lookup . "arguments") "none"}}.
2026-08-06 14:18:32 +02:00
can1357 ef39946bfe fix(utils/marked): kept list-trailing blank line out of the list token
- A blank line before a non-continuing top-level line (including plain
  paragraphs) now closes the list without consuming the blank, so it
  always lexes as a separate space token like real marked.
- List token shape no longer depends on the follower's block type,
  restoring the TUI streaming lexer's freeze invariant (lex(prefix) ++
  lex(tail) == lex(full) under append-only growth).
- A list followed by a paragraph is now tight, not loose, per CommonMark.
2026-08-06 14:18:32 +02:00
can1357 dedd4449c9 refactor(utils/marked): removed biome lint ignore comment from generic token interface
- Removed the biome-ignore lint comment for explicit any on the Generic token interface.
2026-08-06 13:32:15 +02:00
can1357 6c84c3e8fc Merge PR #7691: fix(utils): support PowerShell as custom shellPath (@metaphorics) 2026-08-05 21:50:25 +02:00
can1357 e9888367d1 refactor: migrated packages to internal utility modules and removed external dependencies
- Implemented in-house, zero-dependency utility modules in `pi-utils` covering DOM manipulation, markdown parsing, templating, browser automation helpers, and terminal buffers.
- Migrated packages across the repository to consume the new internal utilities and `omptype` schema validators instead of external dependencies.
- Removed multiple external runtime and development dependencies including Zod, Marked, LRU cache, Turndown, and Puppeteer browser packages.
2026-08-05 13:39:09 +02:00
metaphorics b86f788ae7 fix(utils): support PowerShell as custom shellPath 2026-08-05 10:24:35 +00:00
brymko 01ed58d684 docs(utils): documented fatal recovery hint contract 2026-08-05 14:31:03 +08:00
brymko 56931915f1 feat(coding-agent): added fatal session recovery hints
Registered live session resume commands with postmortem handling so a
fatal rejection or exception identifies every recoverable agent before
cleanup. Escaped terminal control characters in recovery output.
2026-08-05 14:31:03 +08:00
metaphoricsandcan1357 7262d9762e fix(ai): honor account reset windows and statusless concurrency caps
Account-reset hint evaluated before short retry hints; account-scoped caps rotate on status 403 or undefined (Devin statusless trailer); statusless concurrency caps marked transient; transient same-model retries use the concurrency backoff.

Refuted: quota-worded concurrency caps were already excluded from rotation before the usage-limit text match.
(cherry picked from commit f2b9a18d715ddbcb6ae703670f2212da36bb2826)
2026-08-05 02:32:35 +02:00
metaphoricsandcan1357 9d51aabce9 fix(ai): address PR review feedback (#6958)
(cherry picked from commit 19327455a482ffdf8dfebcfb47b12fe0d4c888da)
2026-08-05 02:32:35 +02:00
can1357 84fc295f0c Merge PR #7586: refactor: centralize version comparison in pi-utils (@metaphorics) 2026-08-05 01:11:56 +02:00
can1357 e76d998c01 Merge PR #7498: fix(utils): honor current PATH in cached lookups (@usr-bin-roygbiv) 2026-08-05 01:11:56 +02:00
metaphorics 3802d2dd80 chore(ts): enforce noImplicitOverride 2026-08-05 02:49:01 +09:00
metaphorics 954894f1d4 refactor: centralize version comparison in pi-utils 2026-08-05 02:48:59 +09:00
can1357 455493dfad feat: introduced native file lock bindings for cross-process advisory locking
- Added native `FileLock` bindings supporting cross-process advisory locking on Linux, Unix, and Windows.
- Replaced directory-based file locking and custom stale-lock reclamation with OS-backed native locks.
- Updated TypeScript declarations, native bindings, and package documentation for the new API.
- Added comprehensive unit tests and fixtures validating single-owner constraints and process death handoff.
2026-08-03 16:09:09 +02:00
can1357 9fb082bf14 refactor(utils): consolidated file locking into pi-utils file-lock
- Moved the coding-agent lock-directory primitive to @oh-my-pi/pi-utils/file-lock
  and migrated settings, MCP config-writer, and security store imports.
- Replaced the stats aggregator's parallel ~200-line token/breaker lock protocol
  with the shared primitive: dead owners reclaimed immediately, live-but-wedged
  owners after STATS_SYNC_LOCK_STALE_MS, unstamped acquisitions after the new
  acquireStaleMs grace (10s).
- Shared primitive now treats EPERM kill probes as live owners.
- Rewrote the stats lock-reclamation regressions against the shared protocol
  and moved the file-lock contract test into pi-utils.
2026-08-03 15:25:03 +02:00
usr-bin-roygbiv 1bb5b445fe style(utils): format effective PATH lookup 2026-08-03 13:03:35 +00:00
usr-bin-roygbiv a5f5f53c35 fix(utils): honor current PATH in which lookups 2026-08-03 12:53:38 +00:00
usr-bin-roygbiv 55a5574bdd Revert "fix(utils): honor current PATH in which lookups"
This reverts commit 960c21baf9.
2026-08-03 12:45:29 +00:00
usr-bin-roygbiv 960c21baf9 fix(utils): honor current PATH in which lookups 2026-08-03 12:45:13 +00:00
can1357 f1c7eda7de Merge PR #7205: perf(cli): keep root help off runtime graph (@eggpeat)
# Conflicts:
#	packages/coding-agent/src/cli-commands.ts
#	packages/coding-agent/src/cli/args.ts
2026-08-02 20:59:12 +02:00
can1357 980c78538b Merge PR #7395: fix(postmortem): resolve native hard-exit per call (@roboomp) 2026-08-02 20:53:35 +02:00
can1357 3f61117994 Merge PR #7362: fix(auth): guard config-value resolvers against case-insensitive env hijack (@roboomp) 2026-08-02 20:53:20 +02:00
roboomp e27b0e81ec fix(postmortem): resolve native hard-exit per call
The postmortem module bound the native hard-exit once at module init
(process.reallyExit.bind(process)). The shipped bundle defers this
module's evaluation until first access, which can land inside a
withHostGuard window where process.reallyExit is the ExtensionExitError-
throwing stub; .bind() then froze that stub permanently, so every later
host-owned exit (SIGHUP 129, SIGINT 130, fatal 1) threw and re-entered
the unhandled-rejection fatal path in a loop (exit 129 storm).

Resolve the native exit on every call instead of binding at init, and
have withHostGuard stamp its throwing replacement with the native
primitive it shadows so a signal arriving mid-guard still exits (#6488)
without the guard poisoning later exits (#7393).

Fixes #7393
2026-08-02 17:32:12 +00:00
roboomp a6521f07ed fix(auth): guarded config-value resolvers against case-insensitive env hijack
On Windows process.env/Bun.env lookups are case-insensitive, so the
"env var name, else literal" resolvers turned a literal /login key like
`public` (OpenCode Zen's free key) into the built-in PUBLIC=C:\Users\Public,
sending `Authorization: Bearer C:\Users\Public` and 401ing every request.

Added `$envExact` in pi-utils, which trusts an env lookup only when an
exact-case key is enumerated (the only case-preserving signal on Windows;
the getter and hasOwnProperty/getOwnPropertyDescriptor traps are all
case-insensitive there). Wired it into all three resolvers:
resolve-config-value.ts, model-registry.ts, and auth-storage.ts.

Fixes #7361
2026-08-02 06:53:18 +00:00
can1357 92c79d80c7 feat: introduced OMP Browser Relay extension with CDP RPC execution
- Implement the OMP Browser Relay extension with WebSocket communication and CDP RPC execution.
- Add browser relay server, daemon management, and bridge multiplexing in the coding agent.
- Introduce CLI commands and settings schema options for configuring and installing the relay.
- Add utility functions and test suites supporting environment parsing and relay lifecycle handling.
2026-08-02 05:33:07 +02:00
can1357 72c66c87c1 fix(xdg): adopted legacy secret-placeholder.key and marketplaces.json at XDG paths 2026-08-01 20:46:25 +02:00
can1357 03e54555f9 Merge PR #7065: fix(xdg): fix files and folder for xdg-maintained (@Parsifa1) 2026-08-01 20:39:29 +02:00
can1357 f13f9b1228 fix(utils): recognize underscore Bun test entrypoints 2026-08-01 20:14:39 +02:00
can1357 5b2aefe584 Merge PR #7263: fix(tui): prevent test env from suppressing interactive launch (@roboomp)
# Conflicts:
#	packages/utils/test/env.test.ts
2026-08-01 20:14:08 +02:00
roboomp 9f9c9758a1 fix(tui): prevented test env from suppressing interactive launch
Scoped test-runtime detection to explicit runner markers and Bun test entrypoints, so application NODE_ENV/BUN_ENV values no longer make ProcessTerminal headless.

Added subprocess regression coverage and propagated the private marker to test children.

Fixes #7261
2026-08-01 11:39:57 +00:00
Parsifa1 ea437745a3 fix(xdg): move secret-placeholder.key, marketplaces.json, and run/ out of config root
These four paths bypassed DirResolver's XDG-aware rootSubdir/agentSubdir
hooks, resolving directly against getConfigRootDir()/getAgentDir() and
ignoring XDG state/data layout. Add XDG-aware path helpers in dirs.ts
and route all four through them:

- secret-placeholder.key → $XDG_STATE_HOME/omp/ (state, agent flattened)
- marketplaces.json      → $XDG_DATA_HOME/omp/  (data)
- run/daemons/<hash>/    → $XDG_STATE_HOME/omp/run/ (state)
- run/provider-inflight/ → $XDG_STATE_HOME/omp/run/ (state)

omp config init-xdg migrates secret-placeholder.key and marketplaces.json
from their legacy locations; run/ is ephemeral and rebuilds on restart.
2026-08-01 06:40:48 +00:00
pi3123 edb3feda9b Bound synchronous SQLite busy-waits in headless hosts
Headless hosts (print/RPC/ACP/eval/SDK) run the agent loop on the same
thread as bun:sqlite, so a lock-contention busy-wait of the interactive
5s timeout freezes the protocol loop for seconds at a time with no
liveness signal. Use a 1s busy_timeout for session-critical databases
(agent.db, history.db, stats.db) when the host is not interactive, and
let the existing asynchronous open/retry paths recover from contention.
2026-07-31 19:59:48 -07:00
Brent a572fcb9be fix(cli): preserve help metadata contracts 2026-07-31 22:01:19 +00:00
Brent 9df3067930 perf(cli): keep root help off runtime graph 2026-07-31 21:28:41 +00:00
Kyle McCleary 089a9963f8 feat(security): OMP-native security subsystem (planner handoff) 2026-07-29 18:47:51 -07:00
can1357 897b0c8d6c Merge PR #6920: fix(tui): prevent Windows pane-close deadlock (@roboomp) 2026-07-29 23:08:31 +02:00
roboompandcan1357 313f3fa1c4 fix(tui): prevented Windows pane-close deadlock
Skipped stdout draining after ProcessTerminal observes a native Windows terminal disconnect, while preserving normal postmortem cleanup and drain behavior for every other shutdown path.

Fixes #6917

(cherry picked from commit b45fc00ab4b5075ccb9650584947dde061beea20)
2026-07-29 23:08:31 +02:00
usr-bin-roygbivandcan1357 574f400b0f fix(utils): pin logger rotation entrypoint
(cherry picked from commit 6dc31019848a20053e66df947c48e087cce8566a)
2026-07-29 23:08:28 +02:00
usr-bin-roygbivandcan1357 08b280d550 perf(utils): avoid Winston runtime dispatch
(cherry picked from commit e5aeff8153551c8c4a5cb6a47c7ed00cba32000f)
2026-07-29 23:08:27 +02:00
can1357 b778617178 chore: reformat + rewrite changelogs 2026-07-28 11:19:34 +02:00
can1357 f0db9aa816 fix(utils): base child-shell filtering on real launcher values
Compiled Bun binaries autoload project dotenv files, so snapshotting Bun.env inside one captured the secrets as launcher-owned and forwarded them to every shell. Drop that branch and record launcher values, restoring an empty launcher value that Bun overwrote with a dotenv secret.
2026-07-28 10:58:59 +02:00
can1357 532e4c318c fix(utils): filter NODE_ENV dotenv files and keep escaped quotes in dotenv values
- filterChildShellEnv now also filters Bun-autoloaded .env.{NODE_ENV||development}
  entries, closing the .env.production/.env.development leak into child shells.
- parseEnvLine skips backslash-escaped quotes when locating the closing
  delimiter, restoring baseline/Bun-literal handling of values like JSON="{\"a\":1}"
  that the new parser truncated.
- Adds a parseEnvFile regression test for escaped quotes.
2026-07-28 10:58:59 +02:00
can1357 0a5727670f Merge PR #6814: fix(cli): stop forwarding project dotenv to shells (@roboomp) 2026-07-28 10:58:59 +02:00
can1357 c307f7361a fix: fall back to musl libc soname when loading prctl 2026-07-28 10:58:58 +02:00
roboomp b9f1c32f69 fix(utils): parsed dotenv with bun-compatible syntax
Handled export prefixes and quote-aware inline comments when parsing dotenv files, and filtered child shells by launcher provenance so injected values are dropped regardless of value formatting.

Covered export and inline-comment forms in unit and shell-filter tests.

Fixes #6813
2026-07-27 15:37:13 +00:00
roboomp 048b415670 fix(utils): preserved launcher-owned shell variables
Tracked project values loaded by OMP separately from names present in the original launch environment, preserving parent values even when dotenv repeats the same bytes.

Covered Bun-autoloaded and no-env-file launch modes.

Fixes #6813
2026-07-27 15:31:46 +00:00