Commit Graph

1543 Commits

Author SHA1 Message Date
can1357 bf8e07ae1b Merge PR #6733: fix(coding-agent): safely glob memory directories (@usr-bin-roygbiv) 2026-07-27 04:58:26 +02:00
usr-bin-roygbiv 49d5145fff fix(coding-agent): preserve encoded memory glob bases 2026-07-26 21:33:13 +00:00
can1357 f8dbb3669f feat(utils): implemented windows shell resolution for bash execution
- Added resolveWindowsShell to locate Git Bash, scoop installs, and path binaries with a fallback to cmd.exe.
- Updated bash-executor to prevent wrapping user commands in cmd.exe when using fallback shell paths.
- Updated installation script to report optional shell status rather than failing when bash is absent.
2026-07-26 20:27:16 +02:00
Roy 90cb91489e fix(coding-agent): safely glob memory directories 2026-07-26 16:36:47 +00:00
can1357 d1dc436d1e Merge PR #6596: fix(coding-agent): preserve Claude computer coordinates (@wolfiesch)
# Conflicts:
#	docs/computer-use.md
#	packages/coding-agent/src/tools/computer.ts
#	packages/coding-agent/test/tools/computer.test.ts
2026-07-26 15:44:51 +02:00
can1357 56a8ab1413 Merge PR #6697: fix(coding-agent): match bash deny/prompt patterns per command segment (@roboomp) 2026-07-26 15:41:28 +02:00
can1357 9b651f2869 Merge PR #6616: fix(cursor): sync native todo list from server-resolved tool calls (@quantmind-br) 2026-07-26 15:41:27 +02:00
Diogo Soares Rodrigues 9088fe821b fix(cursor): await error-drain transforms and sanitize mirrored todo labels
Two boundary defects on the mirrored-todo path.

1. The Agent error drain snapshotted #cursorToolResultBuffer without
   awaiting entry.pending, unlike #emitCursorSplitAssistantMessage. An
   async cursorOnToolResult still running when the provider errored
   patched an entry the catch path had already detached, so the
   pre-transform payload was persisted. A provider error is exactly when
   a transform is most likely to be in flight.

2. The todo renderer interpolated mirrored provider text straight into
   terminal output. A Cursor snapshot carries model-authored task
   content, phase names and summary text verbatim, so a label holding
   ANSI/C0 sequences rewrote the terminal on every render and replay.
   sanitizeText alone is not enough - it preserves tabs, which punch
   holes in bordered output - so every display path now funnels through
   one forDisplay() helper: task labels, blocker notes, phase headers,
   the zero-task fallback, and the streaming renderCall preview. Raw
   values are untouched; content and phase name are the identity keys
   the local list is looked up by and what gets persisted.
2026-07-26 09:29:13 -03:00
roboomp e650607cad fix(coding-agent): segment bash approval commands with shell-aware tokenizer
The regex splitter only recognized `&&`, `||`, `;`, `|` and newlines, so a
single `&` (background operator) — also a command terminator — slipped a
dangerous command past a deny rule (`sleep 1 & rm -rf /tmp/x`), which under
approvalMode: yolo executed with no prompt.

Extract the shell-aware tokenizer from gh-cache-invalidation into a shared
tools/shell-tokenize.ts and reuse it for deny/prompt segmentation. It honors
every command boundary (`&&`, `||`, `;`, `|`, single `&`, subshells,
newlines) plus quoting and escapes, so both callers share one implementation.

Fixes #6695
2026-07-26 11:36:19 +00:00
roboomp 85110c366c fix(coding-agent): match bash deny/prompt patterns per command segment
bashApprovalPatternToRegExp anchors globs with ^...$ against the whole
normalized command, so a bash.patterns deny rule only fired when the
dangerous command was first in the line. A compound command such as
`cd /tmp && rm -rf /tmp/x` bypassed the rule and, under approvalMode:
yolo, executed with no prompt -- deny is the guard that outranks yolo.

deny/prompt rules now match the whole command or any single segment
(split on &&, ||, ;, |, newlines). allow rules still require the entire
command to match and never apply to compound lines, so a narrow allow
cannot vouch for a smuggled unsafe segment.

Fixes #6695
2026-07-26 11:28:48 +00:00
Wolfgang Schoenberger 0c5fa60c77 fix(coding-agent): cap captures for resizing transports
Use the resolved supportsImageDetailOriginal capability to constrain native computer frames whenever a Responses transport clamps screenshot detail to auto. Preserve the established Claude-family fallback for transports that do not expose this capability.

Cover Copilot GPT-5 Responses through real catalog model resolution and the controller's observable capture options.
2026-07-26 02:53:01 -07:00
Wolfgang Schoenberger fc68288477 fix(coding-agent): scope computer capture limits 2026-07-26 02:53:01 -07:00
Wolfgang Schoenberger 25dc887fb2 fix(coding-agent): preserve computer coordinates across providers 2026-07-26 02:53:00 -07:00
usr-bin-roygbiv c898f513fa fix(computer-use): report Azure runtime fallback 2026-07-25 21:00:35 +00:00
usr-bin-roygbiv 9ceebb2a4d fix(workers): isolate compiled host selectors 2026-07-25 08:31:54 +00:00
usr-bin-roygbiv 237692deab fix(computer-use): re-enter single worker host 2026-07-25 07:45:56 +00:00
usr-bin-roygbiv a7e988b604 fix(computer-use): isolate worker process entry 2026-07-25 07:13:12 +00:00
usr-bin-roygbiv 9bab62ee55 fix(computer-use): address routing review gaps 2026-07-25 02:14:36 +00:00
usr-bin-roygbiv 8e2d654880 fix(computer-use): route enabled desktop control 2026-07-25 00:42:23 +00:00
usr-bin-roygbiv 40937af750 test(computer): exercise packaged desktop session 2026-07-25 00:42:23 +00:00
usr-bin-roygbiv 8af48840fe fix(coding-agent): statically dispatch computer worker 2026-07-25 00:42:23 +00:00
usr-bin-roygbiv c8d465803a fix(computer): default missing actions to read approval 2026-07-25 00:42:23 +00:00
can1357 bef97a69bb Merge PR #6529: fix(coding-agent): guard retain renderer streaming args (@roboomp) 2026-07-25 00:59:14 +02:00
roboomp 144043ad48 fix(coding-agent): used session settings in file guards
Passed session-scoped settings through Edit and Write generated-file checks and fell back to schema defaults when no global singleton exists.

Guarded inline image sizing against an uninitialized global settings proxy and added isolated-session regression coverage.

Fixes #6549
2026-07-24 22:42:38 +00:00
roboomp d7c7ca033d fix(coding-agent): guarded retain renderer streaming args
- Treated transient non-array retain items as absent during TUI streaming.
- Added regression coverage for malformed partial renderer arguments.
- Documented the fix in the coding-agent changelog.

Fixes #6528
2026-07-24 15:52:01 +00:00
can1357 c55b28a26d chore(coding-agent): format eval display helpers 2026-07-24 16:49:31 +02:00
can1357 ff49b986d5 feat(coding-agent/tools): introduced language-specific code formatters for display rendering
- Added language-specific code formatters for JavaScript, Julia, Python, and Ruby to improve display rendering.
- Integrated display formatting into browser run and eval render tools while preserving verbatim execution.
- Added comprehensive test suites verifying formatting stability, lexical safety, and streaming behavior.
2026-07-24 16:26:03 +02:00
can1357 27e019981a feat(coding-agent/tools): updated bash tool prompt to list available shell builtins
- Added available shell builtins list to the bash tool prompt template.
- Added helper to check if shell builtins are disabled via settings or environment.
2026-07-24 15:02:00 +02:00
can1357 fdf921a3c4 fix(coding-agent): marked ast_edit previews as staged proposals
- Prepended a model-visible PREVIEW_PENDING_NOTICE to ast_edit preview
  results; the TUI-only proposed badge never reached the model, so
  preview diffs read as already-applied edits.
- Rendered the resolve reminder with the source tool name via
  Handlebars instead of a generic 'This is a preview'.
- Documented the xd://resolve / xd://reject two-phase flow in the
  ast_edit tool prompt.
2026-07-24 12:03:49 +02:00
can1357 d4792ed38b fix(tools): leniently inferred missing todo op from unambiguous payloads
- Kept op required in the todo schema; lenientArgValidation now routes raw args to execute(), where resolveTodoParams re-validates and repairs an omitted op (list -> init, phase+items -> append, bare items on empty list -> init).
- Ambiguous op-less calls surface the schema error as a retryable tool error instead of a hard validation failure.
2026-07-24 12:03:06 +02:00
can1357 75cc0a054f feat(coding-agent/tools): added default card fallback for tool rendering
- Extracted #formatToolExecution into a standalone formatDefaultToolExecution module.
- Updated xdev renderXdevCall and renderXdevResult to use the default card when no mounted renderer exists.
- Added fallback rendering that shows tool label, args, and output with appropriate theming.
- Added integration test verifying generic card renders for mounted tools without bespoke renderers.
2026-07-24 08:19:13 +02:00
can1357 024f49220e fix(coding-agent): handled xdev execution errors with mounted tool renderer
- Catch execution errors in XdevRegistry and render them using the mounted tool's error handling.
- Preserve xdev dispatch context when device execution fails.
2026-07-24 08:03:17 +02:00
can1357 4f97aea2db Merge PR #6468: fix(tools): closed spilled output descriptors on error/abort paths (@roboomp) 2026-07-24 06:51:36 +02:00
roboomp 31098f9248 fix(tools): closed spilled output descriptors on error/abort paths
OutputSink.dump() was the only path that closed the spill Bun.FileSink.
The bash and Python executors re-throw on failure and their finally
blocks never closed the sink, so any large-output command that errored
leaked the artifact descriptor until an unrelated read (e.g. a SKILL.md
load) hit EMFILE.

Added an idempotent OutputSink.dispose() that closes the sink exactly
once (awaiting any in-flight sink creation, guarding post-finalize
resurrection) and wired it into every executor's finally block.

Fixes #6463
2026-07-24 03:44:12 +00:00
usr-bin-roygbiv 68ac163e2c fix(computer): harden native desktop execution 2026-07-24 01:40:05 +00:00
can1357 681d7daf65 feat(computer): unified native addon, /computer toggle, function tool
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
  a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
  XTest input with keysym mapping) compiled into the core addon on every
  published target; Linux arm64 and musl are now supported and headless
  hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
  lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
  build dependencies, and the now-unreferenced vendored libspa crate;
  reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
  XTest layouts reject negative origins and coordinates beyond 0..=32767,
  batch coordinates stay bound to the frame last returned to JS with
  intermediate screenshots deferred, coordinate input requires a
  previously returned frame, and failed chord releases still release
  every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
  no input is emitted after expiry and wait-heavy batches are rejected
  upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
  scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
  a regular function tool with a typed GA action schema across OpenAI,
  Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
  session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
2026-07-24 01:40:05 +00:00
usr-bin-roygbiv 57f8acdd18 fix(native): harden desktop input and compatibility 2026-07-24 01:40:05 +00:00
usr-bin-roygbiv b9504f65e7 feat: add native Codex computer use 2026-07-24 01:40:04 +00:00
can1357 0868861abd test(eval): matched allowed-agents wording in tool description 2026-07-24 02:41:35 +02:00
can1357 1e1d2e91ea style: applied biome formatting 2026-07-24 02:27:35 +02:00
can1357 77669aed54 Merge PR #6395: feat: configure xdev prompt docs (@joeshull) 2026-07-24 02:25:35 +02:00
can1357 0abc977d98 Merge PR #6397: fix(write): reject local read-selector-shaped write targets (@roboomp) 2026-07-24 02:24:04 +02:00
can1357 041adb2b1f fix(xdev): tolerated malformed inline-device allowlist config
Settings.get returns raw merged config without element validation, so a
scalar or non-string tools.xdevInlineDevices entry reached Bun.Glob and
threw while building the system prompt. Normalized the allowlist to
string patterns and compiled globs once per render.
2026-07-24 02:23:22 +02:00
Joe Shull f4641c165e feat: allowlist xdev prompt docs 2026-07-24 02:23:22 +02:00
Joe Shull f15191c37d feat: configure xdev prompt docs 2026-07-24 02:23:22 +02:00
can1357 3d64910bb0 feat(coding-agent/live): added realtime voice interaction with Codex Live sessions (experimental)
- Added `src/live/` subsystem with WebRTC transport, protocol parser, session controller, and headless Chromium audio injection.
- Added `LiveVisualizer` component with phase states, transcript display, and animated waveform rendering.
- Added `/live` slash command and `LiveCommandController` to toggle live voice sessions.
- Suppressed local TTS via `vocalizer.suspend()` during live mode to prevent audio conflicts.
- Added live-instructions and agent-final-message prompts for agent messaging context.
- Added `protocol.test.ts` covering event parsing, chunking, and context message construction.
2026-07-24 02:20:43 +02:00
can1357 7eeaba0471 refactor(coding-agent/session): restructured monolithic agent session
- Extracted internal handlers and logic from AgentSession into dedicated runner, guard, and coordinator modules.
- Created standalone modules for bash execution, evaluation runners, IRC bridging, and prewalk coordination.
- Established dedicated session components for tracking stats, todos, streams, and retry fallback chains.
- Preserved existing session behavior while significantly reducing monolithic class size and complexity.
2026-07-24 01:24:44 +02:00
can1357 9c44ad185c fix(read): restored untilAborted import dropped by merge overlap of #6404 and #6417
- #6417 moved findUniqueSuffixMatch (the only prior untilAborted user) out of read.ts and removed the import; #6404 added new untilAborted callsites in regions git auto-merged without conflict.
2026-07-23 22:19:37 +02:00
can1357 72ff07ff84 Merge PR #6428: fix(memory): synchronize live backend lifecycle (@roboomp) 2026-07-23 22:15:25 +02:00
can1357 2ecba08e2a Merge PR #6407: fix(browser): bound open timeout and lease browser across tab acquisition (@roboomp) 2026-07-23 22:15:24 +02:00