Commit Graph

622 Commits

Author SHA1 Message Date
can1357 56a8ab1413 Merge PR #6697: fix(coding-agent): match bash deny/prompt patterns per command segment (@roboomp) 2026-07-26 15:41:28 +02:00
roboomp e650607cad fix(coding-agent): segment bash approval commands with shell-aware tokenizer
The regex splitter only recognized `&&`, `||`, `;`, `|` and newlines, so a
single `&` (background operator) — also a command terminator — slipped a
dangerous command past a deny rule (`sleep 1 & rm -rf /tmp/x`), which under
approvalMode: yolo executed with no prompt.

Extract the shell-aware tokenizer from gh-cache-invalidation into a shared
tools/shell-tokenize.ts and reuse it for deny/prompt segmentation. It honors
every command boundary (`&&`, `||`, `;`, `|`, single `&`, subshells,
newlines) plus quoting and escapes, so both callers share one implementation.

Fixes #6695
2026-07-26 11:36:19 +00:00
roboomp 85110c366c fix(coding-agent): match bash deny/prompt patterns per command segment
bashApprovalPatternToRegExp anchors globs with ^...$ against the whole
normalized command, so a bash.patterns deny rule only fired when the
dangerous command was first in the line. A compound command such as
`cd /tmp && rm -rf /tmp/x` bypassed the rule and, under approvalMode:
yolo, executed with no prompt -- deny is the guard that outranks yolo.

deny/prompt rules now match the whole command or any single segment
(split on &&, ||, ;, |, newlines). allow rules still require the entire
command to match and never apply to compound lines, so a narrow allow
cannot vouch for a smuggled unsafe segment.

Fixes #6695
2026-07-26 11:28:48 +00:00
usr-bin-roygbiv 6b7e2ccc40 docs(computer-use): document routing diagnostics 2026-07-25 00:42:23 +00:00
usr-bin-roygbiv c12c282aa5 fix(computer): gate native Responses transport 2026-07-25 00:42:23 +00:00
can1357 03e6564c05 feat(hashline): enabled leniency rule for bare bullet minus rows
- Add leniency rule in parser to auto-accept bare `-` rows as literal content when hunks represent Markdown bullet lists.
- Emit MINUS_BULLET_AUTO_PIPED_WARNING when bullet-shaped rows lack explicit plus prefixes.
- Reject ambiguous or non-bullet minus rows to prevent unified-diff contamination.
2026-07-24 15:36:32 +02:00
can1357 c6dcfa4137 feat(coding-agent): compacted oversized sse payloads in debug buffer
- Added tool schema and description compaction for oversized data payloads in `packages/coding-agent/src/debug/raw-sse-buffer.ts`.
- Implemented head-tail trimming to preserve leading and trailing event fields when events exceed character budgets.
- Added test coverage verifying SSE debug event truncation, elision markers, and JSON-safe tool compaction behavior.
2026-07-24 15:20:36 +02:00
can1357 9f8aa87dbf feat(task): removed per-call model override from task tool
- Removes `model` field from task item/schema, TaskParams, and TaskItem types.
- Removes model selector validation, formatting, and approval display logic.
- Updates task tool priority docs to reflect that model is no longer per-call overridable.
- Updates eval agent() helper docs and prompt templates to remove model parameter.
- Updates tests to reflect removal of model override capability.
2026-07-24 14:51:48 +02:00
can1357 11eb003fc8 fix: screenshot latency, somehow calling screencapture is faster ??? 2026-07-24 06:39:49 +02:00
can1357 aad7ee8fa3 feat(ai): implemented lite response overrides and computer call unrolling for codex
- Updated the OpenAI Codex provider to unroll native computer calls and tool outputs into standard function calls.
- Added support for the `PI_CODEX_RESPONSES_LITE` environment variable override via the request transformer.
- Updated documentation and tests to cover lite response resolution and native computer response unrolling.
2026-07-24 06:10:00 +02:00
usr-bin-roygbiv 68ac163e2c fix(computer): harden native desktop execution 2026-07-24 01:40:05 +00:00
can1357 681d7daf65 feat(computer): unified native addon, /computer toggle, function tool
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
  a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
  XTest input with keysym mapping) compiled into the core addon on every
  published target; Linux arm64 and musl are now supported and headless
  hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
  lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
  build dependencies, and the now-unreferenced vendored libspa crate;
  reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
  XTest layouts reject negative origins and coordinates beyond 0..=32767,
  batch coordinates stay bound to the frame last returned to JS with
  intermediate screenshots deferred, coordinate input requires a
  previously returned frame, and failed chord releases still release
  every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
  no input is emitted after expiry and wait-heavy batches are rejected
  upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
  scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
  a regular function tool with a typed GA action schema across OpenAI,
  Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
  session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
2026-07-24 01:40:05 +00:00
usr-bin-roygbiv 57f8acdd18 fix(native): harden desktop input and compatibility 2026-07-24 01:40:05 +00:00
usr-bin-roygbiv 87f37bcb1f fix(native): support Ubuntu 22 desktop builds 2026-07-24 01:40:05 +00:00
usr-bin-roygbiv b9504f65e7 feat: add native Codex computer use 2026-07-24 01:40:04 +00:00
can1357 64c78532c2 Merge PR #6447: feat: add native Alibaba Token Plan provider (@eggpeat) 2026-07-24 02:25:25 +02:00
can1357 b33e705aef Merge PR #6416: feat(ai): add process-scoped OAuth account pools (@atyrode) 2026-07-24 02:24:30 +02:00
Brent e184fe8f8d feat: add native Alibaba Token Plan provider 2026-07-23 23:04:00 +00:00
Alex TYRODE e0928070c2 feat(extensions): expose session service tiers 2026-07-23 21:49:20 +00:00
Alex TYRODE 60920e1c00 Merge upstream main into feat/auth-broker-account-pools 2026-07-23 21:37:51 +00:00
Alex TYRODE e6ab870d37 fix(ai): close auth broker account pool gaps 2026-07-23 21:28:17 +00:00
roboomp 48be4674e9 docs: document /vibe mode and /fresh command
/vibe (a full director/worker orchestration mode) had no user-facing
documentation, and /fresh appeared only as a matrix row in the
session-operations doc whose title already promised a "fresh" section.
Neither was mentioned in the README.

- Add docs/vibe-mode.md: enable/disable, fast/good worker tiers, the five
  vibe_* control tools, and the director workflow.
- Add a "## Fresh" section to the session-operations doc describing the
  provider-stream/session-state reset and its contrast with /new and /drop.
- Add a "Session controls" subsection to the README linking both docs.

Fixes #6440
2026-07-23 21:12:08 +00:00
Alex TYRODE faabe089e8 feat(ai): add process-scoped OAuth account pools 2026-07-23 19:30:49 +00:00
can1357 5b3275c7ae feat(coding-agent): introduced ordered provider priority lists for search and images
- Replaced single-provider preferences with ordered priority lists for web search and image generation.
- Added a `MultiSelectSubmenu` component supporting toggle and reordering interactions in settings.
- Implemented migration logic to convert legacy single-provider preferences into ordered priority lists.
- Updated setup wizard scenes, image generation fallback logic, and search provider chains to use priority lists.
2026-07-23 20:44:50 +02:00
can1357 878b8fd556 Merge PR #6029: feat(omp): configure web search provider order (@riverpilot)
# Conflicts:
#	packages/coding-agent/src/modes/controllers/selector-controller.ts
2026-07-23 20:18:08 +02:00
can1357 c0c1622012 Merge PR #4636: feat(secrets): add friendly names to secret placeholders (@Mathews-Tom)
# Conflicts:
#	packages/ai/test/pi-native-client.test.ts
#	packages/coding-agent/src/advisor/runtime.ts
#	packages/coding-agent/src/prompts/tools/eval.md
2026-07-23 17:56:24 +02:00
can1357 794515fd1a Merge PR #6363: feat(coding-agent): support per-command bash approval rules (@WahidinAji) 2026-07-23 17:30:32 +02:00
can1357 f833810d0e fix(rpc): stream v2 chunk frames with backpressure and recover stale page cursors
Two fixes on top of the paged transport:

- Near-limit v2 framing no longer materializes the full base64 transport:
  chunk lines are generated lazily from a single serialization, the 64 MiB
  reassembly ceiling is enforced via Buffer.byteLength before any
  full-payload allocation, and RPC stdout writes drain with backpressure
  one physical line at a time. Peak RSS for a 63 MiB response drops
  ~686 MB -> ~521 MB; a rejected 80 MiB response drops ~507 MB -> ~259 MB
  (parity with the v1 path).

- get_messages_page errors now carry a machine-readable code
  (session_busy | stale_cursor). Both bundled clients' high-level
  getMessages() drains discard partial pages and fall back to the legacy
  snapshot on either code — previously a cursor invalidated by a
  background mutation (e.g. an appended bash message) threw instead of
  falling back. Direct page calls remain strict.
2026-07-23 12:38:13 +02:00
can1357 3e09e4b1ea Merge PR #6330: feat(coding-agent): add lossless paged RPC transport (@wolfiesch) 2026-07-23 12:27:38 +02:00
Cakrawala 6d7457663f feat(coding-agent): support per-command bash approval rules 2026-07-23 17:11:41 +07:00
panosAthDBX bfef3f7eea fix(task): reject sparse model fallback arrays 2026-07-23 09:53:54 +01:00
panosAthDBX 10e1ba911c test(task): cover model override precedence 2026-07-23 09:50:25 +01:00
panosAthDBX 1c8d9db6dd feat(task): allow per-call model selection 2026-07-23 09:42:39 +01:00
Wolfgang Schoenberger a0cb946057 fix(rpc): preserve v2 snapshot semantics 2026-07-22 19:00:48 -07:00
Wolfgang Schoenberger ce8c9dc75f feat(rpc): page stable message histories 2026-07-22 18:38:03 -07:00
Wolfgang Schoenberger 2a6bcc7984 feat(rpc): add negotiated lossless output framing 2026-07-22 18:38:02 -07:00
can1357 b6e68fd243 fix(coding-agent): updated mentions of explore -> scout 2026-07-23 00:12:07 +02:00
can1357 d3bc8d19d1 Merge PR #6223: docs: correct /advisor as session-scoped, not persisted (@roboomp) 2026-07-22 21:13:23 +02:00
roboomp 2fcef1390e docs: corrected /advisor as session-scoped, not persisted
The advisor-watchdog.md slash-command table described /advisor,
/advisor on, and /advisor off as toggling the persisted advisor.enabled
setting. Commit 3c5e32f21b made the toggle session-local: setAdvisorEnabled
mutates only the in-memory #advisorEnabled field and writes nothing to
config.yml. Corrected the three rows to describe the session-scoped
override.

Fixes #6128
2026-07-21 21:20:34 +00:00
Will 2a0d819e7c fix(ai): scope OpenAI Codex credential identity by ChatGPT workspace
One ChatGPT email can hold several workspaces (a personal Plus/Pro plan
plus Team/Enterprise seats), each with its own workspace-scoped OAuth
token and independent limit pools. Codex credentials were deduped by
bare email, so logging into the second workspace silently replaced the
first, and usage reports from the two pools merged into one row.

- capture the workspace (chatgpt_account_id) as orgId at login, with
  the plan type as its display label; token refreshes never rewrite it
- key openai-codex credential identity as email + org via the existing
  org-scoped machinery; legacy email-keyed rows are claimed in place by
  the first workspace-scoped login, and workspace-less credentials
  never clobber workspace-scoped rows
- exclude the org-mirroring account base from same-org row claims so
  two members of one workspace (shared chatgpt_account_id) keep
  separate rows
- partition usage-report dedupe by workspace and require every shared
  identity dimension to agree when reconciling codex usage blocks

Fixes the openai-codex half of #2966 (anthropic half shipped in #5170);
also covers the #633 scenario.
2026-07-19 22:45:16 -04:00
Alexander Kirilin 735be36df6 feat(omp): configure web search provider order 2026-07-18 20:12:26 -04:00
can1357 c6602de1cf Merge PR #5687: feat(config): add PI_CONFIG_FILES settings overlay env var (@roboomp) 2026-07-18 20:12:48 +02:00
can1357 17212e22e3 Merge PR #5779: fix(tui): prevent vibe_wait TV-wall scrollback stacking (@roboomp) 2026-07-18 20:12:47 +02:00
can1357 f560db8cfe Merge PR #5810: fix(lsp): raise timeout ceiling to 300 seconds (@roboomp) 2026-07-18 20:12:46 +02:00
can1357 ea147d9d05 Merge PR #5915: docs(advisor): clarify concern delivery after a self-ended yield (@roboomp) 2026-07-18 19:57:43 +02:00
can1357 822e461b5a Merge PR #5942: fix(coding-agent): drain advisor reviews in print mode (@paralin)
# Conflicts:
#	packages/coding-agent/test/print-mode-working-indicator.test.ts
#	packages/coding-agent/test/silent-abort-print-mode.test.ts
2026-07-18 19:43:17 +02:00
roboomp 61fdd4dfbc fix(coding-agent): enabled js-debug child sessions
Added TCP server transport for vscode-js-debug and recursively handled startDebugging requests, breakpoint synchronization, active child routing, and tree cleanup.

Fixes #5984
2026-07-18 11:56:42 +00:00
Christian Stewart c8f1972c8c fix(coding-agent): drain advisor reviews in print mode 2026-07-18 01:51:00 -07:00
roboomp 1da8471bef docs(advisor): distinguished immune-turn asides from preserved cards
The normal-yield conclusion claimed a blocked steer is always preserved as a card. During the advisor.immuneTurns cooldown, resolveAdvisorDeliveryChannel returns aside and the note rides the YieldQueue to the next step boundary, not a card. Qualified the conclusion to separate the card cases from the aside downgrade.
2026-07-17 21:59:05 +00:00
roboomp 42810e14cb docs(advisor): documented plan and ACP delivery constraints
Clarified that plan mode preserves every would-be advisor steer, including live-streaming notes, because only user-driven turns converge on ask/resolve.

Documented that ACP bridges deferring agent-initiated turns preserve idle advice unless the bridge allows those turns, while advice can still steer an already-streaming turn.

Updated the severity table and changelog to make all delivery statements conditional on these session and client constraints.
2026-07-17 21:56:27 +00:00