Commit Graph
634 Commits
Author SHA1 Message Date
Git-on-my-level 98d25e3c67 fix(auth-broker): retain cache resilience on server errors 2026-07-26 18:24:56 +00:00
Hermes DevOps BotandGit-on-my-level 3a73349d93 fix(auth-broker): revalidate fresh snapshot caches 2026-07-26 18:05:30 +00:00
can1357 0758245eeb docs(task): fix effort-omission and settings-snapshot wording per review
- effort row: omission keeps the agent's configured selector (auto only for
  agents configured auto, e.g. bundled task; scout/sonic use medium)
- Flow step 12: settings snapshot is not a verbatim copy — tier.* re-resolved
  via tier.subagent, plus per-spawn read-summarize / workspace-root overrides
2026-07-26 15:45:32 +02:00
can1357 8550a0af54 Merge PR #6597: docs: reconcile omp:// task/eval docs with 17.1.3 runtime (@roboomp) 2026-07-26 15:45:32 +02:00
can1357 f6e6ad5bea Merge PR #6617: docs(bash): document bundled jaq divergence (@roboomp) 2026-07-26 15:45:31 +02:00
can1357 d1dc436d1e Merge PR #6596: fix(coding-agent): preserve Claude computer coordinates (@wolfiesch)
# Conflicts:
#	docs/computer-use.md
#	packages/coding-agent/src/tools/computer.ts
#	packages/coding-agent/test/tools/computer.test.ts
2026-07-26 15:44:51 +02:00
can1357 56a8ab1413 Merge PR #6697: fix(coding-agent): match bash deny/prompt patterns per command segment (@roboomp) 2026-07-26 15:41:28 +02:00
roboomp e650607cad fix(coding-agent): segment bash approval commands with shell-aware tokenizer
The regex splitter only recognized `&&`, `||`, `;`, `|` and newlines, so a
single `&` (background operator) — also a command terminator — slipped a
dangerous command past a deny rule (`sleep 1 & rm -rf /tmp/x`), which under
approvalMode: yolo executed with no prompt.

Extract the shell-aware tokenizer from gh-cache-invalidation into a shared
tools/shell-tokenize.ts and reuse it for deny/prompt segmentation. It honors
every command boundary (`&&`, `||`, `;`, `|`, single `&`, subshells,
newlines) plus quoting and escapes, so both callers share one implementation.

Fixes #6695
2026-07-26 11:36:19 +00:00
roboomp 85110c366c fix(coding-agent): match bash deny/prompt patterns per command segment
bashApprovalPatternToRegExp anchors globs with ^...$ against the whole
normalized command, so a bash.patterns deny rule only fired when the
dangerous command was first in the line. A compound command such as
`cd /tmp && rm -rf /tmp/x` bypassed the rule and, under approvalMode:
yolo, executed with no prompt -- deny is the guard that outranks yolo.

deny/prompt rules now match the whole command or any single segment
(split on &&, ||, ;, |, newlines). allow rules still require the entire
command to match and never apply to compound lines, so a narrow allow
cannot vouch for a smuggled unsafe segment.

Fixes #6695
2026-07-26 11:28:48 +00:00
Wolfgang Schoenberger 153e1b1f5c docs(computer): describe coordinate-safe capture sizing 2026-07-26 02:55:20 -07:00
Wolfgang Schoenberger fc68288477 fix(coding-agent): scope computer capture limits 2026-07-26 02:53:01 -07:00
Wolfgang Schoenberger 25dc887fb2 fix(coding-agent): preserve computer coordinates across providers 2026-07-26 02:53:00 -07:00
roboomp 0f2ea2cd07 docs(bash): preserve false in jaq null-index workaround
Recommend [.a.b?][0] instead of .a.b? // null, which clobbered a legitimate false/null to the fallback.

Fixes #6614
2026-07-25 13:21:40 +00:00
roboomp 67a53a3a49 docs(bash): documented bundled jaq divergence
Documented that non-PTY jq is backed by jaq and provided portable null-indexing syntax.

Fixes #6614
2026-07-25 13:14:55 +00:00
roboomp 0c7f6e1e5a docs: reconcile omp:// task/eval docs with 17.1.3 runtime
- task.md: subagents inherit async.enabled and bash.autoBackground.enabled
  from the parent (since 17.1.0), not force-disabled/"internally synchronous"
- task.md: document the per-spawn effort parameter ("lo"|"med"|"hi")
- eval.md: document the eval agent(model=...) per-call model selector, which
  the agent-bridge still accepts and forwards

Fixes #6594
2026-07-25 08:38:49 +00:00
usr-bin-roygbiv 6b7e2ccc40 docs(computer-use): document routing diagnostics 2026-07-25 00:42:23 +00:00
usr-bin-roygbiv c12c282aa5 fix(computer): gate native Responses transport 2026-07-25 00:42:23 +00:00
can1357 03e6564c05 feat(hashline): enabled leniency rule for bare bullet minus rows
- Add leniency rule in parser to auto-accept bare `-` rows as literal content when hunks represent Markdown bullet lists.
- Emit MINUS_BULLET_AUTO_PIPED_WARNING when bullet-shaped rows lack explicit plus prefixes.
- Reject ambiguous or non-bullet minus rows to prevent unified-diff contamination.
2026-07-24 15:36:32 +02:00
can1357 c6dcfa4137 feat(coding-agent): compacted oversized sse payloads in debug buffer
- Added tool schema and description compaction for oversized data payloads in `packages/coding-agent/src/debug/raw-sse-buffer.ts`.
- Implemented head-tail trimming to preserve leading and trailing event fields when events exceed character budgets.
- Added test coverage verifying SSE debug event truncation, elision markers, and JSON-safe tool compaction behavior.
2026-07-24 15:20:36 +02:00
can1357 9f8aa87dbf feat(task): removed per-call model override from task tool
- Removes `model` field from task item/schema, TaskParams, and TaskItem types.
- Removes model selector validation, formatting, and approval display logic.
- Updates task tool priority docs to reflect that model is no longer per-call overridable.
- Updates eval agent() helper docs and prompt templates to remove model parameter.
- Updates tests to reflect removal of model override capability.
2026-07-24 14:51:48 +02:00
can1357 11eb003fc8 fix: screenshot latency, somehow calling screencapture is faster ??? 2026-07-24 06:39:49 +02:00
can1357 aad7ee8fa3 feat(ai): implemented lite response overrides and computer call unrolling for codex
- Updated the OpenAI Codex provider to unroll native computer calls and tool outputs into standard function calls.
- Added support for the `PI_CODEX_RESPONSES_LITE` environment variable override via the request transformer.
- Updated documentation and tests to cover lite response resolution and native computer response unrolling.
2026-07-24 06:10:00 +02:00
usr-bin-roygbiv 68ac163e2c fix(computer): harden native desktop execution 2026-07-24 01:40:05 +00:00
can1357andusr-bin-roygbiv 681d7daf65 feat(computer): unified native addon, /computer toggle, function tool
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
  a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
  XTest input with keysym mapping) compiled into the core addon on every
  published target; Linux arm64 and musl are now supported and headless
  hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
  lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
  build dependencies, and the now-unreferenced vendored libspa crate;
  reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
  XTest layouts reject negative origins and coordinates beyond 0..=32767,
  batch coordinates stay bound to the frame last returned to JS with
  intermediate screenshots deferred, coordinate input requires a
  previously returned frame, and failed chord releases still release
  every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
  no input is emitted after expiry and wait-heavy batches are rejected
  upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
  scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
  a regular function tool with a typed GA action schema across OpenAI,
  Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
  session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
2026-07-24 01:40:05 +00:00
usr-bin-roygbiv 57f8acdd18 fix(native): harden desktop input and compatibility 2026-07-24 01:40:05 +00:00
usr-bin-roygbiv 87f37bcb1f fix(native): support Ubuntu 22 desktop builds 2026-07-24 01:40:05 +00:00
usr-bin-roygbiv b9504f65e7 feat: add native Codex computer use 2026-07-24 01:40:04 +00:00
can1357 64c78532c2 Merge PR #6447: feat: add native Alibaba Token Plan provider (@eggpeat) 2026-07-24 02:25:25 +02:00
can1357 b33e705aef Merge PR #6416: feat(ai): add process-scoped OAuth account pools (@atyrode) 2026-07-24 02:24:30 +02:00
Brent e184fe8f8d feat: add native Alibaba Token Plan provider 2026-07-23 23:04:00 +00:00
Alex TYRODE e0928070c2 feat(extensions): expose session service tiers 2026-07-23 21:49:20 +00:00
Alex TYRODE 60920e1c00 Merge upstream main into feat/auth-broker-account-pools 2026-07-23 21:37:51 +00:00
Alex TYRODE e6ab870d37 fix(ai): close auth broker account pool gaps 2026-07-23 21:28:17 +00:00
roboomp 48be4674e9 docs: document /vibe mode and /fresh command
/vibe (a full director/worker orchestration mode) had no user-facing
documentation, and /fresh appeared only as a matrix row in the
session-operations doc whose title already promised a "fresh" section.
Neither was mentioned in the README.

- Add docs/vibe-mode.md: enable/disable, fast/good worker tiers, the five
  vibe_* control tools, and the director workflow.
- Add a "## Fresh" section to the session-operations doc describing the
  provider-stream/session-state reset and its contrast with /new and /drop.
- Add a "Session controls" subsection to the README linking both docs.

Fixes #6440
2026-07-23 21:12:08 +00:00
Alex TYRODE faabe089e8 feat(ai): add process-scoped OAuth account pools 2026-07-23 19:30:49 +00:00
can1357 5b3275c7ae feat(coding-agent): introduced ordered provider priority lists for search and images
- Replaced single-provider preferences with ordered priority lists for web search and image generation.
- Added a `MultiSelectSubmenu` component supporting toggle and reordering interactions in settings.
- Implemented migration logic to convert legacy single-provider preferences into ordered priority lists.
- Updated setup wizard scenes, image generation fallback logic, and search provider chains to use priority lists.
2026-07-23 20:44:50 +02:00
can1357 878b8fd556 Merge PR #6029: feat(omp): configure web search provider order (@riverpilot)
# Conflicts:
#	packages/coding-agent/src/modes/controllers/selector-controller.ts
2026-07-23 20:18:08 +02:00
can1357 c0c1622012 Merge PR #4636: feat(secrets): add friendly names to secret placeholders (@Mathews-Tom)
# Conflicts:
#	packages/ai/test/pi-native-client.test.ts
#	packages/coding-agent/src/advisor/runtime.ts
#	packages/coding-agent/src/prompts/tools/eval.md
2026-07-23 17:56:24 +02:00
can1357 794515fd1a Merge PR #6363: feat(coding-agent): support per-command bash approval rules (@WahidinAji) 2026-07-23 17:30:32 +02:00
can1357 f833810d0e fix(rpc): stream v2 chunk frames with backpressure and recover stale page cursors
Two fixes on top of the paged transport:

- Near-limit v2 framing no longer materializes the full base64 transport:
  chunk lines are generated lazily from a single serialization, the 64 MiB
  reassembly ceiling is enforced via Buffer.byteLength before any
  full-payload allocation, and RPC stdout writes drain with backpressure
  one physical line at a time. Peak RSS for a 63 MiB response drops
  ~686 MB -> ~521 MB; a rejected 80 MiB response drops ~507 MB -> ~259 MB
  (parity with the v1 path).

- get_messages_page errors now carry a machine-readable code
  (session_busy | stale_cursor). Both bundled clients' high-level
  getMessages() drains discard partial pages and fall back to the legacy
  snapshot on either code — previously a cursor invalidated by a
  background mutation (e.g. an appended bash message) threw instead of
  falling back. Direct page calls remain strict.
2026-07-23 12:38:13 +02:00
can1357 3e09e4b1ea Merge PR #6330: feat(coding-agent): add lossless paged RPC transport (@wolfiesch) 2026-07-23 12:27:38 +02:00
Cakrawala 6d7457663f feat(coding-agent): support per-command bash approval rules 2026-07-23 17:11:41 +07:00
panosAthDBX bfef3f7eea fix(task): reject sparse model fallback arrays 2026-07-23 09:53:54 +01:00
panosAthDBX 10e1ba911c test(task): cover model override precedence 2026-07-23 09:50:25 +01:00
panosAthDBX 1c8d9db6dd feat(task): allow per-call model selection 2026-07-23 09:42:39 +01:00
Wolfgang Schoenberger a0cb946057 fix(rpc): preserve v2 snapshot semantics 2026-07-22 19:00:48 -07:00
Wolfgang Schoenberger ce8c9dc75f feat(rpc): page stable message histories 2026-07-22 18:38:03 -07:00
Wolfgang Schoenberger 2a6bcc7984 feat(rpc): add negotiated lossless output framing 2026-07-22 18:38:02 -07:00
can1357 b6e68fd243 fix(coding-agent): updated mentions of explore -> scout 2026-07-23 00:12:07 +02:00
can1357 d3bc8d19d1 Merge PR #6223: docs: correct /advisor as session-scoped, not persisted (@roboomp) 2026-07-22 21:13:23 +02:00