Commit Graph
446 Commits
Author SHA1 Message Date
roboomp bf232ca062 fix(extensions): scoped provider hooks to request model
Passed the per-request model through SDK payload callbacks and ExtensionRunner context creation.

Added regression coverage for Codex-primary and Anthropic-request contexts.

Fixes #6006
2026-07-18 16:52:15 +00:00
roboomp aaac0ace1d fix(extensions): created legacy auth database directory
Create the resolved agent database parent before the synchronous compatibility store opens SQLite, and cover a fresh nested agent directory.

Fixes #5879
2026-07-17 17:06:15 +00:00
roboomp 7e8c4fc01f fix(extensions): restored legacy provider compatibility
Restored the historical assistant-message stream factory and synchronous auth-storage facade needed by pi-provider-kimi-code.

Fixes #5879
2026-07-17 16:54:47 +00:00
can1357 86b6265ef5 Merge branch 'sweep/2026-07-17' into eval/pr-5592
# Conflicts:
#	packages/coding-agent/test/agent-session-checkpoint-rewind-branch.test.ts
2026-07-17 05:22:52 +02:00
can1357 22ae8045f2 merge PR #5768 via eval/pr-5768: fix(tools): keep essential built-ins top-level when re-registered without loadMo 2026-07-17 04:42:10 +02:00
can1357 cf434411f6 merge PR #5744 via eval/pr-5744: fix(tui): reinstated host stdin listeners removed during tool load 2026-07-17 04:40:04 +02:00
can1357 e56ac80b1d merge PR #5667 via eval/pr-5667: fix(extensions): isolated self-scheduled callbacks from killing the session 2026-07-17 04:37:10 +02:00
can1357 5d3ad91900 fix(plugins): preserve CommonJS ESM interop 2026-07-17 04:18:10 +02:00
can1357 9a413bf812 fix(coding-agent): restore flowing stdin after guarded load 2026-07-17 03:57:12 +02:00
roboomp 5340a9517a fix(tools): keep essential built-ins top-level when re-registered without loadMode
Extension/SDK/RPC registerTool defaulted an omitted loadMode to
"discoverable". A UI-only re-register of an essential built-in
(read/write/bash/edit/glob) then became discoverable and, with tools.xdev
on, was unmounted from the top-level schema. read/write dropping also
broke the xd:// transport (read xd://, write xd://<tool>), leaving the
model with no callable coding essentials.

- Add defaultLoadModeForToolName: omitted loadMode resolves to "essential"
  for known essential built-in names, "discoverable" otherwise.
- Apply it at all four adapter boundaries (extension wrapper, custom-tools
  wrapper, sdk customToolToDefinition, rpc normalizeHostToolDefinitions).
- Transport invariant: read/write never mount under xdev regardless of
  loadMode (they carry the transport).
- Regression test covering the demotion, transport invariant, and a drift
  guard tying the essential-name set to the tool classes.

Fixes #5764
2026-07-16 23:08:02 +00:00
roboomp d2aeaeced6 fix(tui): reinstated host stdin listeners removed during tool load
The host guard's stdin restore only dropped listeners a module added; a
module that removed a snapshot listener (e.g. a factory calling
process.stdin.removeAllListeners("data") when a subagent re-runs preloaded
factories against a live parent TUI) permanently stripped ProcessTerminal's
input handler. Reconcile each guarded event back to the pre-load snapshot:
when membership changed, removeAllListeners then re-add the snapshot in
order, restoring both additions dropped and removals reinstated. Snapshot
via rawListeners so once-wrapped handlers round-trip intact.

Fixes #5618
2026-07-16 19:48:08 +00:00
roboomp 1fea9b149f fix(tui): guarded stdin against custom-tool import hijack
Custom tool/extension/hook/plugin modules under ~/.claude/tools are
evaluated with live side effects during createAgentSession. A module that
attaches a stdin consumer at import time — an MCP StdioServerTransport
built at module top level, or a bare process.stdin.resume() — steals
Bun's single stdin reader, so the TUI receives exactly one data event and
goes permanently deaf after the first keypress. Under tmux the terminal's
automatic DA1 reply is that one event, so the first user keystroke is
already dead: the input-deafness reported in #5378/#5618.

Broadened the loader's withExitGuard (renamed withHostGuard) to also
snapshot and restore process.stdin around third-party module evaluation:
any data/readable/end/close/error listener the module adds is removed, and
the stream's paused and raw-mode state is restored to the pre-load
snapshot. The exit guard already fenced process.exit; stdin is the same
class of host-state hijack.

Fixes #5618
2026-07-16 19:35:43 +00:00
robomp-bot c972e44be8 fix(coding-agent): skip Warp stop when agent_end will continue 2026-07-16 20:00:45 +09:00
roboomp 8a61515819 fix(extensions): isolated self-scheduled callbacks from killing the session
Extension-scheduled setInterval/setTimeout/detached callbacks ran outside
the handler-dispatch try/catch, so a throw surfaced as a process-level
uncaughtException and the global postmortem handler tore down the whole
session instead of isolating the misbehaving extension.

- Added ManagedTimers backing sanctioned ctx.setInterval/setTimeout/clearTimer:
  callbacks run with handler-dispatch isolation (throw/rejection logged and
  routed through onError), handles are unref'd, and all are cleared on
  session_shutdown.
- Wired the helpers into ExtensionRunner.createContext and the runner-less
  command-context fallback; onSession now inherits the runner context.
- Documented in-process no-isolation behavior and the managed timers in
  docs/extensions.md and docs/skills/authoring-extensions.md.

Fixes #5664
2026-07-16 07:17:10 +00:00
roboomp 8f15dbf106 fix(plugins): preserved commonjs sibling requires
- Added a graph-owned CommonJS evaluator with shared module.exports and cycle-aware caching.

- Covered sibling require interop across ESM-imported CommonJS modules.

Fixes #5658
2026-07-16 06:11:32 +00:00
roboomp 2cf0c402f9 fix(plugins): refreshed commonjs helpers on reload
- Rebuilt synchronous CommonJS wrappers from current source for every legacy extension load.

- Added a same-process helper edit regression.

Fixes #5658
2026-07-16 05:53:19 +00:00
roboomp 33340f82ce fix(plugins): restored legacy commonjs compatibility
- Added DefaultPackageManager discovery compatibility for legacy extensions.

- Loaded graph-owned CommonJS modules through synchronous default bridges.

Fixes #5658
2026-07-16 05:41:35 +00:00
can1357 9afedb591e feat(coding-agent): added opt-in task prewalk and tightened --tools and xdev behavior
- Added a `task.prewalk` option (default `false`), removed default task `prewalk` flags, and updated prewalk resolution so bunded generic task execution only prewalks when explicitly enabled.
- Enforced strict `--tools` validation in CLI parsing, making unknown tool names fail fast with `CliUsageError` instead of being silently filtered.
- Migrated legacy discovery settings (`tools.discoveryMode`, `tools.essentialOverride`, MCP discovery keys) into updated `tools.xdev` handling with preserved explicit override behavior.
- Hardened xdev/ACP execution flow by capping `docsAll` payloads with overflow listing and remapping `xd://` dispatches/approval gating for correct execute/read behavior and reduced duplicate prompts.
2026-07-15 18:39:36 +02:00
can1357 84d873f2ca Merge remote-tracking branch 'origin/farm/ceed3a6a/compiled-appserver-extension-exit' 2026-07-15 15:31:51 +02:00
can1357 5ff277349c refactor(coding-agent): consolidated tool surface onto xd:// devices and hub
- Added the `xd://` virtual device protocol (`internal-urls/xd-protocol.ts`, `tools/xdev.ts`): tools declaring `loadMode: "discoverable"` are unmounted from the request tools array and driven via `read xd://` (list/docs+schema) and `write xd://<tool>` (execute), gated by the `tools.xdev` setting (default on) and inlined into the system prompt.
- Merged the `irc`, `job`, and `launch` tools into a single `hub` tool (`tools/hub/`, `async/job-manager.ts`): messaging keeps `send`/`inbox`/`list`, job control maps to `wait`/`cancel`/`jobs`, process supervision keeps `start`/`logs`/`stop`/`restart`/`describe` with `ps`, and the unified `wait` races background jobs against peer messages; SDK `IrcTool`/`JobTool`/`LaunchTool` are replaced by `HubTool`.
- Removed the hidden `resolve` tool in favor of the `xd://resolve`/`xd://reject`/`xd://propose` resolution devices, auto-including `write` whenever a deferrable tool or plan mode is present.
- Removed the BM25 tool-discovery system: the `search_tool_bm25` tool, the `tool-discovery` module, the `tools.discoveryMode`/`mcp.discoveryMode`/`mcp.discoveryDefaultServers`/`tools.essentialOverride` settings, per-tool MCP selection, and the `mcp_tool_selection` message type.
- Unified tool presentation on `ToolLoadMode` (`essential`|`discoverable`), replacing the custom-tool `xdev?: boolean` opt-out; custom, extension, MCP, RPC host, image-generation, and TTS tools now default to `discoverable`, and added a `satisfies` predicate to `SoftToolRequirement`.
- Removed the standalone `ssh` command tool and `ssh/ssh-executor` (the `ssh://` read/write/search protocol stays), and made `--tools` address hidden built-ins.
- Updated collab-web to render `xd://` dispatches and `hub` op families, dropped the `search_tool_bm25`/`ssh`/`report-finding` renderers, refreshed tool docs and prompts, and migrated the affected tests and changelogs.
2026-07-15 15:16:29 +02:00
roboomp 24960899ac fix(coding-agent): lazily loaded compiled extension modules
Generated per-module loaders instead of eagerly evaluating the entire bundled compatibility graph during extension bootstrap.

This prevents appserver startup from cycling through its own retained command modules before the Unix socket is created.

Fixes #5568
2026-07-15 10:54:13 +00:00
can1357 7de519eabc Merge PR #5499: fix(plugins): preserve native CommonJS helper loading (@roboomp) 2026-07-14 23:11:10 +02:00
can1357 55ad1ff1bc Merge PR #5505: fix(plugins): refresh stale Bun git cache before reinstall (@roboomp) 2026-07-14 23:11:07 +02:00
can1357 1e1569d58e Merge PR #5465: fix(extensions): let tool_result rewrite thrown failure content (@roboomp) 2026-07-14 22:58:48 +02:00
roboomp 2439f77e70 fix(plugins): refreshed stale bun git cache before reinstall
Fetched current heads and tags into Bun's matching cached bare clone before running bun update.

Added an isolated HTTP git regression covering a moved branch with a stale cache.

Fixes #5401
2026-07-14 19:37:06 +00:00
roboomp 7881fce976 fix(plugins): preserved native commonjs helper loading
Kept synchronous require() targets on Bun’s native loader while retaining hooks for native-addon rewrites.

Added regression coverage for ESM extensions loading CommonJS helper files.

Fixes #5373
2026-07-14 19:22:00 +00:00
roboomp 5303c3852e fix(extensions): let tool_result rewrite thrown failure content
ExtensionToolWrapper caught a thrown tool exception, emitted tool_result
with the modifiable result, then rethrew the original executionError whenever
the effective error state stayed true. This discarded any replacement content
or details a handler returned, so an extension could only surface modified
content by returning isError: false, which wrongly converted the failure into
a success.

Return the (possibly modified) result carrying isError instead of rethrowing.
The agent loop already honors AgentToolResult.isError (coerceToolResult) and
surfaces it as a tool error on the wire, so replacement failure content now
reaches the model while the call remains an error. No-modification, error->success, and success->error paths keep their existing semantics.

Fixes #5302
2026-07-14 18:01:02 +00:00
can1357 edc0511433 Merge PR #4967: fix(plugin): handle pinned git source replacements (@roboomp) 2026-07-14 18:45:31 +02:00
can1357 4b5c32a092 Merge PR #4950: fix(mcp): resolve local image paths for tool calls (@roboomp) 2026-07-14 18:45:22 +02:00
can1357 f9f6ed9e8d feat(coding-agent): replaced legacy pi/ role alias prefix with
- Replaced legacy `pi/` role alias prefix with canonical `@` syntax across model resolution, documentation, and tests.
- Added support for bare `*` default alias and multiple alias prefix detection with custom role resolution in `resolveConfiguredRolePattern()`.
- Enhanced thinking suffix parsing to accept unambiguous abbreviations (minimum 2 characters) for effort and level selectors.
- Extended `resolveCliModel()` and `filterAvailableModelsByEnabledPatterns()` to accept settings parameter for role alias resolution from `--model` flag.
2026-07-13 23:26:33 +02:00
roboomp 459682cc63 fix(plugins): skipped invalid custom tool entries
Validated custom tool factory results before registering plugin-provided tools so one malformed feature entry is reported and skipped instead of crashing startup.

Added regression coverage for null entries and mixed valid/null factory arrays.

Fixes #5189
2026-07-11 14:31:07 +00:00
can1357 6f65a58d1b merge PR #4375: feat(ask): add rich interactive dialog
Closes #4375
2026-07-11 14:15:55 +02:00
can1357 d469064d1a fix: handle stale tests 2026-07-11 07:54:19 +02:00
can1357 33c161d9dd refactor(coding-agent): restructured plugin system and build logic
- Migrated legacy static bundled-module registry to a dynamic Bun-based in-memory plugin system.
- Removed over 4,000 lines of manually maintained registry files to reduce maintenance overhead.
- Implemented CJS absolute path rewriting and native-addon load hooks to improve FFI dependency resolution.
- Standardized binary build processes by centralizing compilation logic into shared utilities.
2026-07-11 07:33:22 +02:00
roboomp bc9f4c4be6 fix(coding-agent): armed ask timeout for legacy ui
Added an explicit timeout presentation capability so interactive queued dialogs defer the fallback while older UI implementations still get an immediate tool-owned timeout.

Refs #4995
2026-07-10 04:13:18 +00:00
roboomp fcf389ae72 fix(coding-agent): deferred ask timeout until display
Started the ask tool fallback timeout from the selector presentation callback so queued dialogs do not consume the user's response window.

Refs #4995
2026-07-10 02:49:33 +00:00
roboomp facfb3c35a fix(coding-agent): synced ask fallback timeout resets
Reset the ask tool fallback timeout whenever the interactive selector resets its UI countdown, preventing late keypresses from falling back to the original recommended option.

Refs #4995
2026-07-09 23:37:50 +00:00
roboomp 63adfeece5 fix(plugin): handled pinned git source replacements
- Removed the stale pinned dependency edge before invoking Bun for same-repository git source replacements so Bun does not construct a dependency loop.

- Added a regression test for the pinned-to-unpinned GitHub plugin replacement path.

Fixes #4960
2026-07-09 18:35:43 +00:00
roboomp 3ebcb36901 fix(mcp): threaded local roots through startup tools
- Copied localProtocolOptions through SDK-created custom tool contexts so startup MCP tools resolve '/data/workspaces/can1357__oh-my-pi__4946/.omp-session/2026-07-09T16-06-43-993Z_019f47a1-a619-7000-9062-5f5d863afa45/local' against the active session.
- Exposed localProtocolOptions on extension contexts and covered the runner propagation path.

Fixes #4946
2026-07-09 17:17:27 +00:00
roboomp b097019fef fix(mcp): resolved local image paths for tool calls
- Resolved session '/data/workspaces/can1357__oh-my-pi__4946/.omp-session/2026-07-09T16-06-43-993Z_019f47a1-a619-7000-9062-5f5d863afa45/local' file arguments before forwarding MCP tools/call requests to external servers.
- Threaded local protocol options into custom MCP tool context and added focused coverage for image_path attachments.

Fixes #4946
2026-07-09 16:38:24 +00:00
can1357 c944870566 fix(coding-agent): implemented pi's ui.addAutocompleteProvider API
Extensions calling ctx.ui.addAutocompleteProvider (e.g. @ff-labs/pi-fff)
crashed at load with 'TypeError: ... is not a function' because omp's
ExtensionAPI.ui omitted pi's autocomplete-provider API; the throw also
aborted the rest of a try/catch-guarded session_start init.

ExtensionUIContext now declares addAutocompleteProvider(factory).
Interactive mode stacks each factory on the built-in editor provider in
registration order, re-applies the stack on every slash-command refresh,
and skips throwing/malformed factories; RPC, ACP, and headless contexts
accept the factory as a no-op, matching upstream pi's RPC behavior.

Fixes #4919
2026-07-09 18:27:23 +02:00
e429166673 fix(coding-agent): queued extension sendUserMessage as steer while streaming
Extension sendUserMessage() without deliverAs fell through to prompt(),
which throws AgentBusyError during an active stream; the message was
dropped and surfaced as 'Extension sendUserMessage failed'. Route the
omitted-deliverAs path through prompt() with streamingBehavior 'steer'
so streaming queues a steer with normal prompt-flow side effects
(keyword notices, advisor auto-resume reset) and idle still starts a
turn.

ACP skill-command prompts now pass streamingBehavior 'steer'; the RPC
skill fast-path honors the prompt command's streamingBehavior field
(default steer) like the plain-prompt path already did. Documented the
extension-facing delivery semantics.

Synthesized from PR #4942 (prompt-flow steer routing, docs, tests) and
PR #4922 (RPC streamingBehavior threading, steer regression test);
dropped PR #4942's unrelated workflow-notice.md ellipsis churn.

Fixes #4923

Co-authored-by: roboomp <omp@can.ac>
Co-authored-by: metaphorics <metaphorics@users.noreply.github.com>
2026-07-09 18:27:22 +02:00
can1357 74385fcbfb merge PR #4435: fix(agent): emit session_switch for handoff 2026-07-08 15:19:38 +02:00
can1357 d03ecad0bc merge PR #4690: fix(coding-agent): handle JSON imports in legacy plugin validator 2026-07-08 15:19:37 +02:00
roboomp f44fcdfb7d fix(coding-agent): hid marketplace clone temp paths
Displayed cloned marketplace catalog validation errors with repository-relative catalog paths and the original source identifier.

Fixes #4702
2026-07-06 11:05:50 +00:00
roboomp 47c172c70a fix(coding-agent): handled json imports in plugin validator
- Left JSON files imported with import attributes on Bun's native loader instead of registering them with the legacy source rewrite hook.
- Added a regression test for loadLegacyPiModule loading a JSON import-attribute target.

Fixes #4687
2026-07-06 08:17:32 +00:00
roboomp dd3375981f fix(coding-agent): preserved enabled duplicate skills
Applied source toggles before skill-name dedup so disabled higher-priority providers no longer hide enabled lower-priority authored skills.

Added regression coverage for disabled claude versus enabled agents duplicate names and managed dead-last behavior.

Fixes #4648
2026-07-06 00:51:24 +00:00
roboomp b0a84847b7 fix(agent): emitted handoff session switch hook
Fixes #4434
2026-07-05 19:19:02 +00:00
can1357 734aed4c03 Merge PR #4382: fix(compaction): keep plan-mode guidance off the session_before_compact hook (@roboomp) 2026-07-05 13:25:28 +02:00
can1357 8ec34a7662 Merge PR #4349: fix(session): handle malformed custom messages (@roboomp) 2026-07-05 13:25:24 +02:00