Commit Graph
65 Commits
Author SHA1 Message Date
roboomp fe4e553be3 fix(coding-agent): clear bash auto-background threshold timer
waitForManagedBashJob raced job completion against a bare
Bun.sleep(thresholdMs), which cannot be cancelled. When completion,
abort, or steering won the race, the losing Bun.sleep timer stayed
scheduled and ref'd, keeping Bun's event loop alive until the threshold
expired — delaying SDK/headless shutdown and accumulating timers under
fast command rates.

Replace the Bun.sleep with a Promise.withResolvers settled by a
cancellable setTimeout, and route every outcome (including the former
no-signal early return) through one try/finally that clears the timer
and removes the abort/steer listeners.

Add a child-process regression test that runs the real auto-background
path for a fast command against a 30s threshold and asserts the process
exits promptly instead of being held for the full threshold.

Fixes #7235
2026-08-01 05:14:43 +00:00
roboomp 223122d6b0 fix(cli): generated titles for positional initial messages
Moved automatic title eligibility and persistence into AgentSession so editor and CLI bootstrap submissions share one path.

Added a PTY regression probe covering the positional-message launch flow.

Fixes #7166
2026-07-31 10:28:48 +00:00
Kyle McCleary dba303e2e0 Merge remote-tracking branch 'origin/main' into feat/security-native 2026-07-29 20:31:08 -07:00
Kyle McCleary 089a9963f8 feat(security): OMP-native security subsystem (planner handoff) 2026-07-29 18:47:51 -07:00
can1357 857b70fe99 Merge remote-tracking branch 'refs/remotes/pr/6535' into prep/6535
# Conflicts:
#	packages/coding-agent/src/extensibility/extensions/runner.ts
2026-07-30 01:42:24 +02:00
can1357 0249fa4715 Merge PR #7036: feat(rpc): expose live fast-mode control and token throughput (@fredluz) 2026-07-30 01:26:49 +02:00
can1357 672857d238 Merge PR #7025: fix(coding-agent): coalesce models config resource probe (@paralin) 2026-07-29 23:09:10 +02:00
Christian Stewartandcan1357 a43c7a4d36 fix(coding-agent): coalesce models config resource probe
The models config resource regression started two cold child processes inside one five-second test. Under parallel CI chunk load, the second child could still be waiting for pipe drain or process exit after the validator had completed.

Keep the process boundary as the owner of the lifecycle measurement and run the missing and custom phases in one child. The missing phase closes its storage and registry before the baseline snapshot, while the custom phase proves schema identity and retention without changing config loading or validator cleanup semantics.

Signed-off-by: Christian Stewart <christian@aperture.us>
(cherry picked from commit 81fa98491544c7fbcbf075922889e0a9e1a0a3b4)
2026-07-29 23:09:10 +02:00
usr-bin-roygbivandcan1357 363925dce4 style: follow Node import conventions
(cherry picked from commit b5c695605c13169c4d0a70101913476ead19dba8)
2026-07-29 23:08:22 +02:00
usr-bin-roygbivandcan1357 4436038127 fix(launch): isolate legacy xterm replay
(cherry picked from commit 47baab894a224f3354085b4794337a211d3cf5c8)
2026-07-29 23:08:21 +02:00
Frederico Luz 511524e3e4 fix(rpc): normalize legacy get_state fields 2026-07-29 20:39:25 +01:00
usr-bin-roygbiv 1ea02eccaf fix(coding-agent): harden lazy HTML asset contracts 2026-07-28 02:57:54 +00:00
usr-bin-roygbiv 9570656f87 perf(coding-agent): load HTML export assets on first use 2026-07-28 02:44:03 +00:00
can1357 41ce810cff fix(mcp): preserved native resource URIs and opaque scheme routing
- Native (non-mcp://) resource URIs now pass through byte-for-byte via
  rawHref; slash elision applies only to the legacy mcp:// wrapper, so
  catalog://root/ style URIs match exact-equality server lookups.
- resources/templates/list failure no longer discards a successful
  resources/list (Promise.allSettled; templates retried later).
- Opaque RFC 3986 URIs (urn:doc, custom:item) are recognized by both
  the router and read-cli discovery gates, with drive-path and
  read-selector false positives guarded.
- Review follow-up for PR #6790.
2026-07-27 16:15:02 +02:00
Dongmen Laohu 2c77c8535a fix(mcp): resolve native resource URIs 2026-07-27 18:59:12 +08:00
can1357 dccf0d3c8a Merge PR #6748: perf(launch): isolate PTY replay in broker (@usr-bin-roygbiv) 2026-07-27 04:58:28 +02:00
can1357 94069484ce Merge PR #6749: perf(coding-agent): load changelog asset on demand (@usr-bin-roygbiv) 2026-07-27 04:58:28 +02:00
can1357 dc038b838e Merge PR #6747: perf(coding-agent): replace legacy Babel traversal (@usr-bin-roygbiv) 2026-07-27 04:58:28 +02:00
can1357 73a3fe6983 Merge PR #6745: perf: lazily construct models config schema (@usr-bin-roygbiv) 2026-07-27 04:58:28 +02:00
can1357 48a4f1b1e6 Merge PR #6742: perf(coding-agent): lazily construct computer schema (@usr-bin-roygbiv) 2026-07-27 04:58:27 +02:00
can1357 e07db86f2d Merge PR #6670: fix(mcp): map mounted tools to xd routes (@jeffscottward) 2026-07-27 04:58:27 +02:00
usr-bin-roygbiv bd371eec14 perf(coding-agent): load changelog asset on demand 2026-07-27 01:21:58 +00:00
usr-bin-roygbiv 403f90783e perf(launch): isolate PTY replay in broker 2026-07-27 01:17:19 +00:00
usr-bin-roygbiv fc254b55f3 perf: defer models config schema construction 2026-07-27 01:10:23 +00:00
usr-bin-roygbiv d8ec26dac7 perf(coding-agent): replace legacy Babel traversal 2026-07-27 00:51:45 +00:00
usr-bin-roygbiv 73add3f98c perf(coding-agent): lazily construct computer schema 2026-07-27 00:39:09 +00:00
Roy 6b348471d9 test(catalog): cover lazy provider materialization 2026-07-27 00:36:56 +00:00
Jeff Scott Ward fcdd33d2fe fix(mcp): map mounted tools to xd routes 2026-07-26 01:02:11 -04:00
usr-bin-roygbiv 9ceebb2a4d fix(workers): isolate compiled host selectors 2026-07-25 08:31:54 +00:00
usr-bin-roygbiv 237692deab fix(computer-use): re-enter single worker host 2026-07-25 07:45:56 +00:00
usr-bin-roygbiv a7e988b604 fix(computer-use): isolate worker process entry 2026-07-25 07:13:12 +00:00
usr-bin-roygbiv f1fb05df80 fix(eval): statically link rejection interceptor 2026-07-25 04:24:25 +00:00
Anthony "Asterisk" Ambuehl 29625f08c2 feat(mcp): add mcp_notification extension event + multi-listener API
Convert MCPManager's dangling single-slot setOnNotification callback into
a multi-listener API and expose server-initiated MCP notifications as an
extension event so extensions can bridge push-capable MCP servers (e.g.
peer messaging, ticket nudges) into session behavior.

API changes:
- Removed: MCPManager.setOnNotification(handler) — single-slot, zero callers
- Added:   MCPManager.addNotificationListener(listener): () => void
           Multi-listener with per-listener error isolation, returns unsub.
- Added:   'mcp_notification' extension event
           Payload: { server: string; method: string; params: unknown }

Wired in sdk.ts: one listener bridges to extensionRunner.emitMcpNotification,
captured under postmortem for teardown.

Tests: 3 new (multi-listener fanout, error isolation, unsubscribe),
fixture pattern matches neighboring mcp tests. bun check passes (biome +
tsgo).

Docs: extensions.md (new MCP notifications subsection with bridging
example), mcp-runtime-lifecycle.md (Server-initiated notifications
section), CHANGELOG.
2026-07-24 13:36:03 -07:00
Baris Demirdelen 140fd58b70 Add test for late mcp startup in acp 2026-07-23 22:10:15 +02:00
can1357 f833810d0e fix(rpc): stream v2 chunk frames with backpressure and recover stale page cursors
Two fixes on top of the paged transport:

- Near-limit v2 framing no longer materializes the full base64 transport:
  chunk lines are generated lazily from a single serialization, the 64 MiB
  reassembly ceiling is enforced via Buffer.byteLength before any
  full-payload allocation, and RPC stdout writes drain with backpressure
  one physical line at a time. Peak RSS for a 63 MiB response drops
  ~686 MB -> ~521 MB; a rejected 80 MiB response drops ~507 MB -> ~259 MB
  (parity with the v1 path).

- get_messages_page errors now carry a machine-readable code
  (session_busy | stale_cursor). Both bundled clients' high-level
  getMessages() drains discard partial pages and fall back to the legacy
  snapshot on either code — previously a cursor invalidated by a
  background mutation (e.g. an appended bash message) threw instead of
  falling back. Direct page calls remain strict.
2026-07-23 12:38:13 +02:00
Wolfgang Schoenberger a0cb946057 fix(rpc): preserve v2 snapshot semantics 2026-07-22 19:00:48 -07:00
Wolfgang Schoenberger ce8c9dc75f feat(rpc): page stable message histories 2026-07-22 18:38:03 -07:00
Wolfgang Schoenberger 2a6bcc7984 feat(rpc): add negotiated lossless output framing 2026-07-22 18:38:02 -07:00
Wolfgang Schoenberger 7e6a9f5d5d fix(coding-agent): await RPC worker reaping 2026-07-18 15:13:08 -07:00
Wolfgang Schoenberger 2e90458a79 fix(coding-agent): bound RPC output and reap failed workers 2026-07-18 15:13:08 -07:00
roboomp fe54ebc990 fix(rpc): claimed stdin before extension discovery
Claimed Bun's singleton stdin reader before loading extensions and passed the owned stream into RPC and RPC-UI mode.

Added process-level regressions for both modes with a startup extension that attempts to lock stdin.

Fixes #5898
2026-07-17 19:29:47 +00:00
Victor Araújo 323ef8ec73 fix(coding-agent): restored xdev for explicit tools 2026-07-16 18:41:58 -03:00
Colin Mason 9c9da2387d harden js eval subprocess 2026-07-13 09:57:19 -04:00
roboomp 65bc422e83 fix(coding-agent): handled inline image pdf delimiters
Skipped binary inline-image payload bytes after the PDF ID operator so tokenizer scanning resumes at post-image content.

Advanced past stray closing delimiters while recovering malformed content streams to avoid zero-width tokenizer iterations.

Fixes #4512
2026-07-04 12:18:06 +00:00
can1357 d84a54e579 fix(coding-agent): introduced a shutdown coordinator to manage background tasks
- Introduced `RpcShutdownCoordinator` to track background tasks and manage deferred shutdowns safely.
- Guaranteed all background bash task response frames are fully written before the process exits.
- Re-checked shutdown requests automatically as each tracked background task settles.
- Latched the shutdown sequence to prevent concurrent execution from duplicate triggers.
- Updated `mock-rpc-agent` to consume stdin via an async iterator to match standard behavior.
- Added comprehensive unit tests in `rpc-input-frame.test.ts` covering background task coordination.
2026-07-02 02:40:07 +02:00
can1357 82232cefb6 Merge PR #4117: fix(rpc): dispatch bash concurrently and reset abort controller on restart (@roboomp) 2026-07-01 21:53:16 +02:00
roboomp eb4d2a9e93 fix(rpc): dispatch bash concurrently and reset abort controller on restart
The RPC transport did not treat cancellation as an independent, resettable
control plane, so two lifecycle contract violations shared a root cause:

A. Server-side: the stdin loop in `rpc-mode.ts` awaited each commands
   `handleCommand` before pulling the next frame, so `abort_bash` queued
   behind the `bash` it must cancel. Extracted `dispatchRpcInputFrame` and
   dispatch `bash` in the background: the input loop keeps reading, so
   `abort_bash` (or any other command) can preempt an in-flight shell.
   Response correlation still rides `command.id`; ordering across
   concurrent commands is documented as not guaranteed.

B. Client-side: `RpcClient.stop()` aborted the shared `#abortController`
   but never replaced it, so a subsequent `start()` handed a pre-aborted
   signal to `readJsonl` and the stdout reader exited immediately with a
   spurious "Agent process exited before ready" while the spawned child
   leaked in `#process`. Mint a fresh `AbortController` inside `start()`
   and clean up the child on any post-spawn failure.

Adds:
- `dispatchRpcInputFrame` unit tests covering the concurrent bash + abort
  ordering, serial dispatch of other commands, and background error
  reporting.
- `RpcClient` lifecycle tests covering start->stop->start on the same
  instance (via a mock fixture agent) and retry after a failed start.
- Documents the bash concurrency contract in `docs/rpc.md`.

Fixes #4079
2026-07-01 07:15:09 +00:00
roboomp 15dfda45a4 fix(edit): guarded apply_patch against clobber and swallowed multi-file failures
The apply_patch language documents `*** Add File` and `*** Move to` as
strictly non-overwriting (create / rename), but the fs-level create and
rename paths in applyNormalizedPatch wrote through to the resolved target
without checking whether it already existed. Existing destinations were
silently replaced, and in the rename case the source was also deleted.

The multi-file executeApplyPatchPerFile aggregator caught each per-file
exception, appended an error entry, and kept iterating. Later files
still ran against an inconsistent post-state, and the aggregate result
had no top-level isError — so a mixed partial application looked like a
successful edit to the agent loop.

Changes:
- Add fs.exists guards before the create write and before the rename
  write/delete in packages/coding-agent/src/edit/modes/patch.ts. Both
  reject with ApplyPatchError before any side effect.
- Make executeApplyPatchPerFile in packages/coding-agent/src/edit/index.ts
  stop at the first per-file failure, list applied vs. skipped files in
  the aggregate text, and propagate isError, matching executeSinglePathEntries.
- Rename the two apply-patch scenario fixtures (010_move_..., 011_add_...)
  that pinned the buggy overwrite behavior to _rejects_ variants, and
  flip their expected/ trees so source and pre-existing destination
  remain byte-identical after the rejected apply.
- Cover both failure modes with new regressions in
  packages/coding-agent/test/core/apply-patch.test.ts and a new
  packages/coding-agent/test/core/apply-patch-multi-file.test.ts.

Fixes #4074
2026-07-01 07:05:25 +00:00
jms830 6a0e80ee56 fix(mcp): treat resources/templates/list -32601 as empty, not a resource-load failure 2026-06-16 21:25:03 -04:00
can1357 12bada4ce0 fix: hardened deferred MCP discovery and streaming render fast paths
- Recomputed `tools.discoveryMode: "auto"` in the deferred MCP closure in `sdk.ts` once the real tool count is known: a toolset crossing the threshold now flips discovery on, registers and activates `search_tool_bm25`, and skips `activateAll` instead of force-activating every MCP tool.
- Guarded the deferred MCP task against disposed sessions: added `AgentSession.isDisposed` and `enableMCPDiscovery()`, and the late connect now calls `disconnectAll()` instead of refreshing tools onto a dead session.
- Cleared `#fastPathKey`/`#fastPathItems` in `AssistantMessageComponent.invalidate()` so theme/symbol changes rebuild reused Markdown children instead of keeping stale captured themes.
- Memoized unusable read summaries as a `false` sentinel in `read.ts` so the per-session LRU no longer retains full sources of unsummarizable files.
- Broadened `HAS_REF_DEF` in `markdown.ts` to match backslash-escaped reference labels (`[a\]b]: x`) and cleared frozen stream-lex state on blank `setText()`.
- Added regression tests: deferred auto-discovery flip and mid-connect dispose (`sdk-mcp-auto-discovery.test.ts` + `many-tools-mcp.ts` fixture), fast-path child rebuild on invalidate, and escaped-ref-def incremental-lex equivalence.
2026-06-12 11:14:39 +02:00