Commit Graph
653 Commits
Author SHA1 Message Date
can1357 9155df2bf0 fix(coding-agent): scoped report_tool_issue enum to active built-in tools
- Built a dynamic enum from constructed built-in/hidden tools so MCP and extension tools are excluded from QA reports.
- Added allowlist guard to silently drop reports targeting non-built-in tools at runtime.
- Stripped `proxy_` prefix before allowlist check so passthrough-wrapped tools resolve correctly.
2026-05-17 05:45:25 +02:00
can1357 69aeb94621 fix(grievances): replaced hostname with platform/arch 2026-05-17 02:16:23 +02:00
can1357 0bb385f8ab feat(grievances): added consent gate & push
- Added `dev.autoqa.consent` setting and single-flight popup handler wired through `InteractiveMode`.
- Added `flushGrievances` to batch-POST unpushed rows to `dev.autoqaPush.endpoint` with cooldown and single-flight deduplication.
- Added `omp grievances push` subcommand with TTY progress bar for manual draining.
- Migrated shared DB logic to `openAutoQaDb` (with `pushed` column migration) exported from `report-tool-issue`.
2026-05-17 01:47:24 +02:00
can1357 39f34ada70 feat: added pure-JS sanitizeText
- Migrated sanitizeText from pi-natives to pi-utils as a pure-JS implementation, removing the native dependency across all call sites.
2026-05-16 20:12:26 +02:00
can1357 84ec8fba49 feat(coding-agent/eval): implemented JSON cell-based eval tool inputs
- Removed the legacy `parseEvalInput` parser module and `eval.lark`, eliminating `*** Cell` stream parsing.
- Replaced eval tool arguments from single `input` strings to ordered `cells` arrays in tool calls and schema.
- Updated execution to resolve language explicitly, map `py` to `python`, and apply timeout/reset defaults.
- Removed backend sniffing and `ABORT_WARNING` suffix handling, then updated docs and tests to the new JSON cells format.
2026-05-16 19:33:44 +02:00
can1357 64fcdc308f refactor(coding-agent)!: removed StringEnum helper and shortened tool schema descriptions
- Replaced all StringEnum(...) usages with z.enum([...]) across tools, examples, and tests.
- Removed StringEnum re-export from @oh-my-pi/pi-coding-agent public API.
- Condensed verbose tool parameter descriptions to minimal lowercase phrases.
- Renamed AuthCredentialStore to SqliteAuthCredentialStore at usage sites.
2026-05-16 19:26:32 +02:00
Can BölükandGitHub 58505b8423 Merge pull request #1109 from itzrnvr/fix/windows-pty-hang-root-cause
fix: PTY hangs on Windows — ConPTY deadlocks waiting for cursor position
2026-05-16 18:09:28 +02:00
can1357 32453aaff0 feat(agent): added AgentTelemetry across compaction and branch-summary
- Added optional AgentTelemetry to summary, handoff, branch-summary, and compact option types.
- Replaced one-shot `completeSimple` usage with `instrumentedCompleteSimple` across compaction, summary, and branch-summary calls and passed `oneshotKind`.
- Added `PiGenAIAttr.OneshotKind`, `InstrumentedChatSpanOptions`, and response-header forwarding in telemetry span lifecycle.
- Added `resolveTelemetry` propagation in coding-agent session and inspect-image paths to pass request-scoped telemetry.
- Added compaction telemetry test harness and span assertions for success, no-telemetry, and error cases.
2026-05-16 18:03:07 +02:00
Sanskar Singh 158b00266b fix: pass configured shell to PTY instead of hardcoding sh
The PTY runner hardcoded CommandBuilder::new("sh"), but on Windows the
user's shell might be a Git Bash absolute path that isn't on PATH. The
non-PTY path already uses the resolved shell from getShellConfig(). Now
the PTY path does the same, passing it through PtyStartOptions.shell.
2026-05-16 10:10:59 +05:30
Sanskar Singh cffc94a978 fix: prevent ClosePseudoConsole deadlock hanging PTY on Windows
ConPTY's ClosePseudoConsole can deadlock when it tries to flush output
to a pipe that nobody is reading (microsoft/terminal#1810). This caused
the PTY Promise to never resolve on Windows, making bash commands with
pty:true hang indefinitely.

Root cause: portable-pty's drop(master) calls ClosePseudoConsole
synchronously. If ConPTY's internal render thread is blocked writing to
a full/undrained output pipe, ClosePseudoConsole waits forever.

Fix (three parts):

1. Rust (pty.rs): Reordered teardown to follow Microsoft's recommended
   shutdown sequence:
   - Drop writer first (close ConPTY input pipe)
   - Drain reader thread with 500ms timeout (consume output pipe)
   - Drop master in a background thread with recv_timeout(2s):
     * Clean case: ClosePseudoConsole completes, thread reclaimed
     * Hung case: timeout expires, main thread returns anyway
   - Replace child.wait() with try_wait() polling on Windows
     (WaitForSingleObject can also hang in ConPTY)

2. TypeScript (bash-pty-selection.ts): Remove the Windows blanket
   disable that prevented PTY from ever being used on Windows.

3. Tests: Updated to verify PTY works on Windows with UI context.
2026-05-16 07:02:24 +05:30
Sanskar Singh 5d1a14e72a fix(coding-agent,pi-natives): Windows PTY hang root-cause fix with opt-out
Replaces the blanket PTY disable on Windows (PR #1105) with a targeted fix:

- TypeScript: PI_FORCE_PTY env var allows explicit Windows PTY opt-in.
  PTY is still disabled by default on Windows to prevent hangs, but power
  users who need interactive workflows can override.

- Rust: Adds ct.heartbeat() checks during PTY setup (openpty, spawn, reader
  creation) so the existing timeout mechanism works even during setup.

- Rust (Windows): Wraps openpty() in a 5-second startup timeout thread.
  If ConPTY hangs during pseudo-console creation, the Promise rejects with
  a clear error instead of hanging forever.

Fixes #1103 #1106
2026-05-16 05:03:23 +05:30
can1357 ece3c9d165 fix(ai): resolved tool strictness for loose additionalProperties schemas
- Preserved object schemas with explicit `additionalProperties` settings by avoiding strict coercion to false.
- Probed schema strictness before sanitization and set `tool.strict` false for non-strict schemas.
- Set `tool.strict` false for `null`, `true`, and unconstrained `outputSchema` fallbacks.
- Documented the fix in Unreleased changelog entries for both `ai` and `coding-agent` packages.
- Added regression tests covering loose `additionalProperties` and yield strictness behavior across tools.
2026-05-16 00:12:47 +02:00
can1357 85515f35a6 fix(coding-agent): added gap separators between noncontiguous search matches
- SearchTool now tracked the last emitted line and inserted ellipsis markers when noncontiguous match blocks were output.
- Display output gap markers were padded to align with code-frame gutters.
- Added a regression test that verified a no-context search emits an ellipsis between separated matches in the same file.
2026-05-15 23:46:23 +02:00
can1357 7282d92bf4 fix: normalized line-ending handling for text and TUI output flows
- Unified line-ending normalization to `replace(/\r\n?/g, "\\n")` in editor, scraper, benchmark, and utils modules.
- Added terminal-aware line sanitization in code-cell rendering to collapse inline carriage returns and avoid overwrite corruption.
- Tightened editor and paste sanitizers to trim control characters consistently after CR normalization.
2026-05-15 23:46:23 +02:00
can1357 2e6d96d3bc feat(coding-agent/tools): added open-ended line range shorthand for read selectors
- Updated read-line selector parsing to accept line-range selectors ending with a trailing dash.
- Mapped selectors with a trailing dash to open-ended ranges that read from the start line onward without requiring an explicit end.
- Updated read tool documentation to document `:50-` as the shorthand for reading from line 50 onward.
2026-05-15 23:46:23 +02:00
roboomp 13d77ad6ee fix(coding-agent): disable interactive pty on windows
Fixes #1103
2026-05-15 21:41:11 +00:00
can1357 2f2e72c5ac fix: updated metadata URLs and Bun WebSocket types
- Added homepage metadata entries to the Rust and Python package manifests.
- Replaced OpenRouter HTTP-Referer values with https://omp.sh/ in completion and image requests.
- Updated Codex WebSocket typing and construction to use Bun.WebSocket for handshake header capture.
Fixes #1102
2026-05-15 21:22:03 +02:00
can1357 03f09e7ee9 fix(coding-agent/tools): ignore literal refs when scanning yield schemas
YieldTool's unresolved-ref fallback now skips literal-value positions such as const, enum, default, and examples when looking for unresolved schema refs. Valid schemas containing data literals like { "": "literal" } no longer degrade to the loose schema and still reject invalid yield payloads.
2026-05-15 18:31:12 +02:00
can1357 46cff37ce4 fix(coding-agent/tools): yield falls back to loose schema on unresolved $ref
dereferenceJsonSchema leaves $ref strings in place when references are unresolvable (external URLs, missing definitions, certain cycles). The new yield-parameters builder now walks the resolved schema for any remaining $ref strings before installing validation; if any are found, it throws so the existing catch branch swaps in looseRecordSchema and disables strict validation. Previously YieldTool installed a validator that rejected every success payload with an unresolved-reference error.
2026-05-15 17:49:23 +02:00
can1357 45fe4df39e fix(ai): corrected AI tool handling via JSON-schema validation flow
- Replaced fromTypeBox conversion with a JSON-schema validator flow in ai tool handling and execution paths.
- Added recursive schema validation and expanded TypeBox checks for refs, enums, uniqueItems, and constraint keywords.
- Sanitized Azure/CCA tool schemas by dropping unsupported fields and rewriting oneOf tool branches as anyOf.
- Tightened argument and model-config validation, preserving unknown tool fields and adding apiKey plus compatibility flags.
2026-05-15 15:16:50 +02:00
can1357 2867e1f4e3 feat(deps): added pi.zod exports and removed TypeBox package exports
- Added canonical `pi.zod` schema API exports and removed TypeBox package exports/imports.
- Migrated Tool schema typing from TypeBox to shared `TSchema`/Zod flow with legacy TypeBox compatibility.
- Updated AI provider adapters and MCP/agent builders to convert tool params through `toolWireSchema()`.
- Reworked schema validation from AJV to Zod-safe parsing with `fromTypeBox`, `toolWireSchema`, and meta schema checks.
2026-05-15 14:46:54 +02:00
can1357 b642607ea9 feat(coding-agent/task): added telemetry propagation for subagent task handoffs
- Task tool sessions now expose and forward parent OpenTelemetry config when creating subagent tasks.
- Subprocess execution now derives child telemetry from the parent config with the subagent identity and child session conversation handling.
- Subagent creation now records a handoff span using the resolved parent telemetry handle before running the child loop.
2026-05-15 14:46:54 +02:00
can1357 995ba8e51e fix(coding-agent/tools): suppressed repeated bash fixup notices per session
- Tracked emission state so the bash fixup notice is shown at most once per BashTool instance.
2026-05-15 04:55:51 +02:00
can1357 4c494aaa3a feat(coding-agent/tools): defaulted GitHub search repo scope to the current checkout
- Added a `resolveSearchRepoScope` helper that uses an explicit `repo` when provided, skips defaulting when a query already contains a repo/org/user/owner scope qualifier, and otherwise resolves the current checkout via `resolveDefaultRepoMemoized`.
- Updated `search_issues`, `search_prs`, `search_code`, and `search_commits` to use the resolver before composing API queries, defaulting `repo` when omitted but silently falling back to an unscoped search on resolution failure.
- Documented the new search-repo defaulting rules in tool prompts, user docs, and the package changelog.
2026-05-15 04:38:58 +02:00
can1357 f0ff398607 fix(coding-agent/tools): stripped duplicate output notices from TUI tool renderers
- Added stripOutputNotice to output-meta to remove appended truncation notices when output metadata is available.
- Updated bash, eval, browser, read, and ssh renderers to strip the notice before display so the styled warning line is not duplicated.
- Left fallback behavior unchanged so outputs without a notice continue through unchanged.
2026-05-15 03:16:16 +02:00
can1357 7754607561 fix(coding-agent/tools): wrapped bash fixup notice in system-warning tags
- Updated `formatBashFixupNotice` to wrap the stripped-pattern warning in a `<system-warning>` wrapper.
- Reworded the notice to clarify output is already truncated and stderr is merged into stdout.
- Extended the Bash interceptor test to verify the warning tag appears for head/tail stripping.
2026-05-15 02:23:35 +02:00
can1357 92c42f44f7 fix(coding-agent/tools): resolved bash fixup parsing for head/tail chunks
- Added top-level parsing and segment splitting to apply bash fixups only on safe command chunks.
- Replaced `stripTrailingHeadTail` usage with `applyBashFixups` and array-based notice formatting.
- Fixed terminal `| head`/`| tail` and redundant `2>&1` stripping while preserving command semantics.
- Updated fixup tests for cross-command cases and removed superseded head-tail-only test coverage.
2026-05-15 02:12:28 +02:00
can1357 bddf9989b5 feat: added host-uri frame and rpc bridge for read/write/cancel routing
- Added `set_host_uri_schemes` and host-uri frame/type definitions; documented read/write/cancel behavior.
- Added `RpcHostUriBridge` in rpc mode to register schemes, dispatch read/write/cancel ops, and clear pending requests.
- Added internal URL write support with lowercased scheme matching, handler routing, and hashline-prefixed success output.
- Added Python host-uri APIs/exports, cancellable client request handling, and host-uri read/write test coverage.
2026-05-15 00:54:09 +02:00
can1357 9bbc7465ba feat(coding-agent): strip trailing | head/tail from single-line bash commands
Drop trailing `| head [args]` / `| tail [args]` pipes that exist purely
to limit output — the harness already truncates bash output and exposes
the full result via the bash-original artifact, so these pipes only
hide content from the agent.

Conservative gates (any failing leaves the command verbatim):

  - single-line only; multi-line scripts may legitimately end pipelines
    with head/tail to bound a generator or loop body
  - whitelisted limit-only args (-nN, -n N, -cN, -N, -q, -v, --lines[=N],
    --bytes[=N], --quiet, --verbose); rejects -f/-F/+N/filenames so
    `tail -f`, `tail -n +2` etc. stay intact
  - regex anchored at end of command; any downstream operator (`&&`,
    `||`, `;`, `&`, `>`, `|`, `` ` ``, `$(…)`, `)`) blocks the match, so
    `just build 2>&1 | tail -3 && just up && …` is untouched
  - refuses to reduce the command to an empty string
  - pipe boundary uses `[ \t]*`, not `\s*`, so a `|` on a continuation
    line cannot be swallowed

Consolidates the existing `timeoutClampNotice` and the new strip notice
into a single `pendingNotices: string[]` array threaded through every
execute branch (async, auto-background, ACP terminal, local exec).

New setting `bash.stripTrailingHeadTail` (default `true`).
2026-05-15 00:50:00 +02:00
can1357 fba055d8c9 ux(coding-agent/tools): added multiline job label display in tool output
- Updated job label rendering to split labels on newlines and cap visible lines by collapsed or expanded view state.
- Truncated each visible label line to the existing max width and appended an ellipsis when extra lines were hidden.
- Printed additional visible label lines as indented follow-on lines beneath the job header.
2026-05-14 23:44:25 +02:00
can1357 f24afe13f4 fix(read): added truncation tally markers and elision recovery footers
- Updated shell minimizer line truncation to append `...[+N]` with the count of dropped Unicode scalars when truncation occurs.
- Updated read summary rendering to track `elidedLines`, include them in tool details, and append a recovery footer for `:raw` or line-range access whenever elided spans are present.
- Updated read-tool prompts/docs/tests to cover the new elision-footers and recovery guidance.

Fixes #1046
2026-05-14 23:22:27 +02:00
can1357 933058a241 feat(goals): added per-session goal mode with token budget tracking
- Added GoalRuntime with wall-clock and token accounting, budget steering, and lifecycle operations (create, pause, resume, drop, complete).
- Exposed goal tool as a hidden agent tool, activated only when goal mode is enabled.
- Integrated goal continuation loop in InteractiveMode with auto-submit between turns.
- Added status line segment and theme icons for goal mode state.
2026-05-14 06:40:41 +02:00
can1357 8fc5b78f30 feat(read): added comma-separated scatter gather line selector support
- Extended selector regex and parser to accept ranges like `:5-16,960-973`.
- Ranges are sorted and merged automatically before reading.
- Out-of-bounds ranges surface as inline notices instead of errors.
- Added `#readLocalFileMultiRange` and `#buildInMemoryMultiRangeResult` for file, archive, notebook, and internal URL targets.
2026-05-14 05:58:25 +02:00
can1357 fe7b3d7005 refactor(coding-agent): removed intent property from WriteTool 2026-05-14 05:58:25 +02:00
can1357 ef5cbef51f feat(coding-agent): added resolve-based plan approval flow in coding-agent
- Removed ExitPlanModeTool and deleted exit-plan-mode docs/tests, dropping the old approval contract outputs.
- Replaced plan-mode approval flow from exit_plan_mode to resolve across session, SDK, controllers, and discovery.
- Added standing resolve handler accessors and updated resolve routing for queued or standing approval handlers.
- Added PlanApprovalDetails and enforced normalized, validated approval titles with readable plan-file requirements.
- Extended resolve schema and invocation signatures with optional extra metadata and reason trimming behavior updates.
- Updated plan and resolve prompts and changelog guidance to require resolve action, reason, and extra.title for apply/discard.
2026-05-14 05:33:30 +02:00
can1357 ba47b0e32f fix(tools): recovered malformed conflict:// paths during write conflict resolution
- Updated conflict URI parsing to accept `path:conflict://N` and record the removed prefix in `recoveredPrefix`.
- Updated write conflict handling to resolve single or wildcard IDs through shared helpers and append a recovery note when a malformed prefix was stripped.
- Added regression tests for recovered prefixes and end-to-end write-path recovery and documented the change in the changelog.
2026-05-14 05:03:04 +02:00
Can BölükandGitHub 26931fe8ce Merge pull request #1055 from jiwangyihao/fix/browser-worker-startup-errors
fix(browser): surface tab worker startup errors
2026-05-14 04:47:31 +02:00
Can BölükandGitHub 3d2bbe5e8f Merge branch 'main' into fix/browser-stealth-target-setup 2026-05-14 04:46:30 +02:00
can1357 f1f6516056 refactor: reorganized exports and removed obsolete helper branches
- Removed export leakage by demoting many helper and const symbols to module-local scope.
- Renamed underscore-prefixed internals and cache fields, then updated related references and `satisfies never` checks.
- Deleted obsolete logic branches and helpers, including harmony-stream interruption flow and unused benchmark runtime helpers.
- Updated Biome config and manifests by broadening lint coverage and removing an unused `@napi-rs/cli` dev dependency.
- Adjusted tests and utilities to use renamed test helpers and remove redundant private test-only helpers/locals.
2026-05-14 04:36:19 +02:00
can1357 c7d04f3a13 fix(coding-agent): constrained bash cwd auto-detect regex to single-line cd commands
- Updated BashTool's leading `cd` regex to stop matching newline characters so cwd extraction only applies to a single-line `cd ... &&` prefix.
- Added a regression test for multiline commands with a later-line `&&` to ensure each line of the script executes normally.
2026-05-13 19:19:50 +02:00
jiwangyihao 11a19eb8d4 fix(browser): bound stealth target setup during tab open
Keep the active page stealth setup synchronous, but make the broader CDP target UA override sweep selective and best-effort. Non-page or ephemeral Chrome targets can otherwise block worker initialization long enough for browser.open to hit the tool timeout before the tab worker sends ready.

Fixes #1053
2026-05-14 01:19:01 +08:00
jiwangyihao 8830b2e367 fix(browser): surface tab worker startup errors
Forward worker error and messageerror events while acquireTab waits for the initial ready/init-failed response. This prevents async worker module-load or early startup failures from being reported only as a generic tab worker init timeout.
2026-05-14 00:34:55 +08:00
can1357 7fd2a7b309 fix(coding-agent/tools): highlighted multi-line bash commands in result rendering
- Added a new formatBashCommandLines helper that syntax-highlighted each command line and applied the dim prefix only to the first line.
- Updated the shell renderer to emit command output as line-based entries instead of a single dimmed string.
- Extended the bash renderer test to verify multi-line commands keep ANSI styling on every rendered line.
2026-05-13 18:15:57 +02:00
can1357 6eda70aada refactor: replaced abortableSleep with scheduler.wait and fetchWithRetry
- Removed local `abortableSleep` in favour of Node's built-in `scheduler.wait` from `node:timers/promises`.
- Consolidated per-provider retry/fetch loops into a shared `fetchWithRetry` utility in `packages/utils`.
- Moved `extractHttpStatusFromError`, `isRetryableError`, and related helpers out of `packages/ai` into `packages/utils`.
- Deleted `extractRetryDelay` in favour of `extractRetryHint` with unified header and body parsing.
2026-05-13 16:40:58 +02:00
can1357 9828764cb4 feat(scripts-session-stats): added session-stats search relevance plotting
- Changed multi-file search paging to skip whole files and page results in file windows.
- Added per-file match caps, round-robin file selection, and new file-limit truncation reporting.
- Replaced match/result limit metadata with fileLimitReached and perFileLimitReached.
- Lowered read.defaultLimit default to 300 with 1 lead and 3 trailing context lines.
- Replaced the search skip test with file-pagination coverage and added per-file cap tests.
- Added session-stats analytics tooling to classify searches, detect repeats, and render relevance plots.
2026-05-13 11:38:09 +02:00
can1357 a541a63547 feat: added read-selector analyzers and coverage plotting tools
- Updated read range expansion to use 1 leading and 3 trailing context lines.
- Changed read.defaultLimit from 500 to 300 in settings defaults.
- Updated read docs and tests to reflect the asymmetric context line behavior.
- Added read-selector analyzers and replay simulators to evaluate coverage and savings.
- Added plotting tools that output new session-stats PNG dashboards from local usage data.
2026-05-13 11:33:42 +02:00
can1357 28b9ce7a0c feat(coding-agent): added middle-elision caps to OutputSink truncation
- Added `tools.artifactHeadBytes` and `tools.outputMaxColumns` settings with defaults in `SETTINGS_SCHEMA`.
- Expanded `OutputSink` with `headBytes`/`maxColumns` and middle truncate logic with elision markers and tracking.
- Updated output-meta to resolve sink settings, emit truncation metrics, and use `truncateMiddle` for spills.
- Integrated head and column limits into JS/Python/Bash/SSH/read output flows, with `:raw` skipping read truncation.
- Documented new output middle-elision and column-cap behavior in `CHANGELOG.md`.
- Added truncation tests for `OutputSink`, `truncateMiddle`, and read-tool line handling.
2026-05-13 11:19:11 +02:00
Ogrodevandcan1357 4e4e74be49 fix(coding-agent/acp): tighten ACP conformance per review feedback
Addresses the codex review comments on #1015 plus a sweep of adjacent
ACP conformance gaps surfaced while wiring them up.

Tool call + diff metadata
- acp-event-mapper: thread session cwd through and resolve every
  `ToolCallLocation` (initial args, in-flight updates, result details)
  to absolute paths against it; ACP requires absolute paths for
  client-side file mapping.
- edit/modes/patch: emit the destination path for moves in the diff
  result so post-edit "open file" actions land on the new file.

Permissions
- agent-session: pass cwd into `extractPermissionLocations` and resolve
  raw `path`/`file`/etc. fields against it before sending
  `session/request_permission`.
- agent-session: gate the permission wrapper on
  `bridge.capabilities.requestPermission && bridge.requestPermission`,
  matching the read/write/bash capability+method pattern.

acp-agent
- `authenticate`: validate `methodId` against the methods advertised by
  `initialize` and reject anything else, so malformed clients fail fast.
- `setSessionConfigOption(MODE_CONFIG_ID)`: also emit
  `current_mode_update` so clients tracking `modes.currentModeId` see
  the same transition `session/set_mode` would produce.
- Pass `runtime.notifyConfigChanged` to builtins; emit
  `available_commands_update` from a shared `reloadPlugins` helper
  reused by `/reload-plugins`, `/marketplace`, and `/plugins`.
- prompt resource handling: route `resource` content with `image/*`
  MIME into the `images` array instead of dropping it as an opaque
  blob; non-image blobs still fall back to the URI placeholder.
- pass session cwd to the event mapper.

Builtins
- model: call `runtime.notifyConfigChanged()` after a successful
  `setModel` so the ACP config selector reflects the new model
  immediately.
- mcp: redact query strings and userinfo from MCP server URLs before
  emitting them in `/mcp list` (prevents leaking `?exaApiKey=…` style
  secrets); wire `manager.setAuthStorage(...)` before `prepareConfig`
  in `/mcp test|resources|prompts` so OAuth servers can refresh tokens.
- ssh: reject non-integer `--port` values via a `^\d+$` guard instead
  of silently coercing through `Number.parseInt`; list project hosts
  first and dedupe user-scope duplicates to match capability-loader
  precedence.
- export: reject clipboard aliases (`--copy`, `clipboard`, `copy`)
  before passing them to `exportToHtml` as a filename.
- compact / force / move / browser: surface underlying failures via
  `usage(errorMessage(...))` instead of letting them crash the command.
- session save|delete: route through the active SessionManager so the
  persist writer is consulted and stale storage references are removed.
- marketplace / plugins / reload-plugins: call `runtime.reloadPlugins()`
  on install/uninstall/upgrade and enable/disable so slash command
  registries and command lists refresh consistently.
- shared.usage: make async and `await runtime.output(...)` so
  `sessionUpdate` text is never dropped or reordered.
- types: document the new `reloadPlugins` and `notifyConfigChanged`
  runtime hooks.

bash tool
- Use a shared `fireKill()` from the abort listener so `session/cancel`
  terminates the remote command immediately instead of waiting for the
  next `currentOutput()` round trip.
- Race `currentOutput()` against the abort signal so a stuck
  `terminal/output` RPC cannot delay cancellation.
- Kill the terminal before reading final output on timeout so a slow
  output read cannot let a timed-out command keep running past the
  enforced timeout.

Tests
- acp-agent.test: extend the existing config-option assertions to
  verify both `model` and `thinking_level` changes emit
  `config_option_update` notifications scoped to the right session.
- acp-builtins.test: cover `/model` emitting both
  `notifyTitleChanged` and `notifyConfigChanged`; lock in the parsed
  `mcp add` / `ssh add` call shapes so future arg-parser regressions
  fail the test instead of silently writing different configs; add a
  `reloadPlugins` stub plus a typed `notifyConfigChanged` slot to the
  shared test runtime factory.
- acp-stdout-hygiene.test: drain stderr in parallel and assert no
  JSON-RPC frame leaks onto it; terminate the spawned process so the
  stderr pump resolves deterministically.

CHANGELOG: itemize the above under `[Unreleased] > Fixed`.

CI
- bun run check: clean (TS + Rust)
- bun run test: 4128 pass / 689 skip / 0 fail (TS); 252 pass / 0 fail
  (Rust nextest)
- bun run ci:test:smoke: --version / --help / `stats --help` all OK
2026-05-13 06:00:45 +02:00
Ogrodevandcan1357 1a44cd2e36 Fix ACP review follow-ups 2026-05-13 06:00:45 +02:00
Ogrodevandcan1357 5c922856e5 feat(acp): route bash/read/write tools through ACP client bridge
- BashTool dispatches execution through the client bridge terminal channel when a bridge is present, falling back to local PTY otherwise
- ReadTool and WriteTool gate filesystem access through ACP permission checks
- Exports new tool wiring in the tools barrel
2026-05-13 06:00:44 +02:00