Commit Graph
6258 Commits
Author SHA1 Message Date
can1357 bf8e07ae1b Merge PR #6733: fix(coding-agent): safely glob memory directories (@usr-bin-roygbiv) 2026-07-27 04:58:26 +02:00
can1357 03d9b7f048 fix(coding-agent): canonicalized config paths in failure-safety test injections
The lock-race and EPERM regression tests compared injection predicates
against the uncanonicalized temp config path, but the atomic writer
resolves it via realpath; on macOS /var -> /private/var made the mocks
never fire and both tests failed. Compared against the realpath instead.
2026-07-27 04:58:26 +02:00
can1357 4aa5d0b6b2 Merge PR #6726: fix(coding-agent): prevented invalid configs from being overwritten (@Ant39140) 2026-07-27 04:58:25 +02:00
can1357 d64eba7187 Merge PR #6746: perf(catalog): lazily materialize provider models (@usr-bin-roygbiv) 2026-07-27 04:58:25 +02:00
can1357 4be05b373a Merge PR #6722: fix(auth-broker): revalidate fresh snapshot caches (@Git-on-my-level) 2026-07-27 04:58:25 +02:00
can1357 9d76e168ba Merge PR #6706: fix(ai): preserve custom Anthropic web-search history (@roboomp) 2026-07-27 04:58:24 +02:00
Roy 773a0aee6d perf(catalog): materialize bundled models per provider 2026-07-27 00:43:15 +00:00
Roy 6b348471d9 test(catalog): cover lazy provider materialization 2026-07-27 00:36:56 +00:00
usr-bin-roygbiv 49d5145fff fix(coding-agent): preserve encoded memory glob bases 2026-07-26 21:33:13 +00:00
usr-bin-roygbiv 6b65fd2996 fix(coding-agent): preserve question-mark memory globs 2026-07-26 20:58:33 +00:00
Ant39140 d68c9dadf9 fix(coding-agent): rejected configs quarantined during startup 2026-07-27 03:49:51 +08:00
Ant39140 20d96304f2 fix(coding-agent): prevented invalid configs from being overwritten
- Treated missing files separately from malformed or unreadable configs.
- Backed up malformed YAML and wrote settings atomically without dropping pending changes.
- Reported success only after saving, with regression tests for global and project configs.
2026-07-27 03:26:40 +08:00
Git-on-my-level 98d25e3c67 fix(auth-broker): retain cache resilience on server errors 2026-07-26 18:24:56 +00:00
Hermes DevOps BotandGit-on-my-level 3a73349d93 fix(auth-broker): revalidate fresh snapshot caches 2026-07-26 18:05:30 +00:00
Roy 90cb91489e fix(coding-agent): safely glob memory directories 2026-07-26 16:36:47 +00:00
can1357 713856c9e0 Merge PR #6557: fix(update): verify GitHub release asset and digest (@rvagg) 2026-07-26 15:45:31 +02:00
can1357 87c0aa38bb Merge PR #6558: fix(tui): make provider error blocks expandable via ctrl+o (@roboomp) 2026-07-26 15:45:10 +02:00
can1357 cc5f5a29a6 Merge PR #6665: fix(coding-agent): route js-debug commands to the stopped script child (@roboomp) 2026-07-26 15:45:09 +02:00
can1357 fb38343a89 Merge PR #6581: fix(utils): correct shell path config guidance (@roboomp) 2026-07-26 15:45:09 +02:00
can1357 e1cdacd89a Merge PR #6691: fix(stt): resolve Windows workspace sherpa addon (@roboomp) 2026-07-26 15:45:09 +02:00
can1357 b646234c41 Merge PR #6646: fix(secrets): avoid hashline placeholder collisions (@roboomp) 2026-07-26 15:45:09 +02:00
can1357 d1dc436d1e Merge PR #6596: fix(coding-agent): preserve Claude computer coordinates (@wolfiesch)
# Conflicts:
#	docs/computer-use.md
#	packages/coding-agent/src/tools/computer.ts
#	packages/coding-agent/test/tools/computer.test.ts
2026-07-26 15:44:51 +02:00
omp-evalandcan1357 c8b37c8d2e fix(plugins): return bare Kitty delete sequences from legacy pi-tui shim
Upstream Pi's deleteKittyImage/deleteAllKittyImages return unwrapped control
sequences; legacy callers such as pi-sprite wrap tmux passthrough themselves.
Aliasing OMP's auto-wrapping encodeKittyDeleteImage (and hand-wrapping
deleteAllKittyImages) double-wrapped under tmux, so the outer terminal dropped
the delete command. Match the upstream bare-sequence contract and pin it in
the regression test.
2026-07-26 15:41:31 +02:00
can1357 5905ec0430 Merge PR #6507: fix(plugins): restore pi-sprite legacy compatibility (@roboomp) 2026-07-26 15:41:31 +02:00
can1357 9b8715ee78 Merge PR #6493: fix(coding-agent): bypass extension guards during shutdown (@roboomp) 2026-07-26 15:41:31 +02:00
can1357 60b0968e1f Merge PR #6484: fix(coding-agent): resume agent after /tree ask re-answer (@roboomp) 2026-07-26 15:41:31 +02:00
can1357 525173615c Merge PR #6500: fix(coding-agent): count only rendered skills in /context accounting (@roboomp) 2026-07-26 15:41:30 +02:00
can1357 0a83d9f364 Merge PR #6570: fix(plan-mode): prefer newest draft during review (@roboomp) 2026-07-26 15:41:30 +02:00
can1357 e1b607f9ee Merge PR #6584: fix(coding-agent): re-export estimateTokens from legacy pi shim (@roboomp) 2026-07-26 15:41:30 +02:00
can1357 bc5b660d19 Merge PR #6649: fix(coding-agent): restore legacy pi automode compatibility (@roboomp) 2026-07-26 15:41:30 +02:00
can1357 1ebe2cc63a Merge PR #6608: fix(coding-agent): handle vibe session commands safely (@roboomp) 2026-07-26 15:41:30 +02:00
can1357 97ea63920b fix(coding-agent): keep bun/npm routing for regular-file entries on Windows
Bun's global bin entry on Windows is a regular-file .exe shim, not a
symlink, so the standalone-binary override would have rerouted a
legitimate bun-managed install to in-place binary replacement and
clobbered the shim. Gate the override on POSIX, where package-manager
bin entries are always symlinks; add a regression test.
2026-07-26 15:41:30 +02:00
can1357 e0c26cc262 Merge PR #6527: fix(coding-agent): self-update binary install when its dir overlaps npm/bun bin dir (@am423) 2026-07-26 15:41:29 +02:00
can1357 5aa599f9ac fix(cli): treat cleared (empty-string) credentials as unset in config list
The settings panel persists "" when a credential is cleared and renders
that as unset; config list now uses the same semantics instead of
masking the empty string as a configured credential.
2026-07-26 15:41:29 +02:00
can1357 a0f03309a9 Merge PR #6588: fix(cli): redact credential settings in config list (@wolfiesch) 2026-07-26 15:41:29 +02:00
can1357 18bd043c86 fix(cli): keep CLI --models scope pinned and defer scoped thinking with the role
The #6694 deferral must not apply when the scope comes from the --models
flag: createAgentSession re-resolves the default role against
settings.enabledModels only and never sees parsed.models, so leaving
options.model unset let a saved out-of-scope default silently escape an
explicit CLI scope. Pin scopedModels[0] for CLI scopes as before.

When the default role IS deferred (settings-derived scope), also skip
seeding options.thinkingLevel from scopedModels[0]'s explicit suffix —
explicit options win in createAgentSession and would override the
re-resolved role's own thinking selector.
2026-07-26 15:41:29 +02:00
can1357 57bfdbc4c1 Merge PR #6698: fix(cli): defer out-of-scope default role so extension models resolve (@roboomp) 2026-07-26 15:41:29 +02:00
can1357 56a8ab1413 Merge PR #6697: fix(coding-agent): match bash deny/prompt patterns per command segment (@roboomp) 2026-07-26 15:41:28 +02:00
can1357 0e3f695a56 Merge PR #6701: fix(coding-agent): stop the live advisor runtime when /settings disables it (@paolomazzitti) 2026-07-26 15:41:28 +02:00
can1357 ca4f0d6c56 Merge PR #6494: fix(session): cancel in-flight session_stop handlers (@roboomp) 2026-07-26 15:41:28 +02:00
can1357 e758f10a96 Merge PR #6660: fix(prewalk): apply same-model effort downgrades instead of skipping (@roboomp) 2026-07-26 15:41:28 +02:00
can1357 c5a819b162 Merge PR #6669: fix(session): retry reasonless tool-call aborts (@roboomp) 2026-07-26 15:41:28 +02:00
can1357 9b651f2869 Merge PR #6616: fix(cursor): sync native todo list from server-resolved tool calls (@quantmind-br) 2026-07-26 15:41:27 +02:00
can1357 7bbe140914 Merge PR #6626: fix(advisor): propagate advisor provider session id via metadata (@roboomp) 2026-07-26 15:38:52 +02:00
can1357 2cc6b28d98 Merge PR #6537: fix(advisor): bound Codex SSE retries (@jeffscottward) 2026-07-26 15:38:52 +02:00
roboomp 2fb9f888ad fix(ai): preserved custom anthropic web-search history
Retained complete native web-search call/result pairs through leaked-thinking projection at their original source anchors.

Kept opaque server-tool blocks atomic during persistence, stripped them on reparent, and covered custom continuations plus compaction retention.

Fixes #6703
2026-07-26 13:32:08 +00:00
Diogo Soares Rodrigues 9088fe821b fix(cursor): await error-drain transforms and sanitize mirrored todo labels
Two boundary defects on the mirrored-todo path.

1. The Agent error drain snapshotted #cursorToolResultBuffer without
   awaiting entry.pending, unlike #emitCursorSplitAssistantMessage. An
   async cursorOnToolResult still running when the provider errored
   patched an entry the catch path had already detached, so the
   pre-transform payload was persisted. A provider error is exactly when
   a transform is most likely to be in flight.

2. The todo renderer interpolated mirrored provider text straight into
   terminal output. A Cursor snapshot carries model-authored task
   content, phase names and summary text verbatim, so a label holding
   ANSI/C0 sequences rewrote the terminal on every render and replay.
   sanitizeText alone is not enough - it preserves tabs, which punch
   holes in bordered output - so every display path now funnels through
   one forDisplay() helper: task labels, blocker notes, phase headers,
   the zero-task fallback, and the streaming renderCall preview. Raw
   values are untouched; content and phase name are the identity keys
   the local list is looked up by and what gets persisted.
2026-07-26 09:29:13 -03:00
Diogo Soares Rodrigues c7c375f5e1 fix(cursor): settle todo cards whose completion outruns the streamed block
When Cursor packs toolCallStarted and toolCallCompleted into one HTTP/2
chunk, the bridge tool_execution_end (synchronous callback, fired
mid-parse) reaches the interactive controller before the streamed
toolcall_start (queued on AssistantMessageEventStream, delivered a
microtask later). The controller found no pendingTools entry, dropped
the completion, and the card created afterwards animated forever.

Two halves, each necessary:

- Hold an early todo completion in #orphanedToolCompletions and replay
  it when the streamed block creates its component.
- Guard card creation from cumulative message_update frames with the
  turn-scoped #toolTimelineComponents map. Without this, the update
  after the replay re-lists the same toolCall block, finds pendingTools
  empty again, and spawns a second, permanently pending card. This is
  also why emitting a synthetic tool_execution_start from the bridge
  (previous attempt, reverted) could not work.

Both maps are cleared together at the existing transcript-anchor reset
sites. The normal ordering (start first) is covered by a control test.
2026-07-26 09:29:13 -03:00
Diogo Soares Rodrigues cc210094ef fix(cursor): refuse todo dependency graphs and sanitize failure text
Two review findings on the native todo sync.

- TodoItem.dependencies is a graph the local model cannot store: rows
  are keyed by content, carry no id, and hold no edges. An imported
  dependent row files as plain pending and nextActionableTask then
  offers work the server considers blocked. Refuse snapshots with an
  edge pointing at an unfinished row; edges whose blockers already
  finished constrain nothing and still mirror.

- The todo failure warning interpolated the provider error verbatim.
  Collapse and truncate it at the render boundary.

Also documents two known, unfixed defects: an async cursorOnToolResult
transformer resolving after the buffer drain, and the todo card
lifecycle race. Emitting a synthetic tool_execution_start for the
latter was measured and rejected -- the completion deletes the entry it
creates, so the late streamed block adds a second card.
2026-07-26 09:29:13 -03:00
Diogo Soares Rodrigues 0639246d27 fix(cursor): settle refused and failed native todo calls
Only a successful snapshot settled a native todo block. A `read_todos`
narrowed by a filter and a server `UpdateTodosError` both went
unanswered: no `tool_execution_end`, so the card animated forever, and
no `toolResult`, so `buildSessionContext` stripped the block on rebuild.

Every completed native todo call now settles. The refusal path carries
no `details.phases` -- `event-controller` feeds that straight into
`setTodos`, so echoing the current list back would let a call that
changed nothing overwrite live panel state. A server error is carried
through as a failed result instead of collapsing into the benign no-op.

Each regression is covered by a test verified to fail without its fix.
2026-07-26 09:29:13 -03:00