Commit Graph

136 Commits

Author SHA1 Message Date
can1357 9b8715ee78 Merge PR #6493: fix(coding-agent): bypass extension guards during shutdown (@roboomp) 2026-07-26 15:41:31 +02:00
usr-bin-roygbiv 9ceebb2a4d fix(workers): isolate compiled host selectors 2026-07-25 08:31:54 +00:00
roboomp e09eda00cd fix(coding-agent): bypassed extension guard for shutdown
- Captured the native hard-exit function for postmortem signal, fatal, and manual exits.
- Added bounded child-process coverage for SIGINT and fatal cleanup during pending guarded loads.
- Preserved extension and hook exit isolation and made the EPIPE race assertion observe the real exit event.

Fixes #6488
2026-07-24 07:26:22 +00:00
can1357 fc6256372d test: fix local-midnight logger flake and stale kimi k3 thinking format pin
- logger-multiprocess asserted the UTC day (toISOString) while DailyRotateFile names files with the LOCAL date, failing nightly between 00:00 and 02:00 local (UTC+2); the per-pid rotation-file invariant now matches any dated name.
- kimi-code k3 bundled compat moved to thinkingFormat 'kimi' with the catalog regen; the K3 named-tool-choice downgrade gate keys on provider/id/baseUrl, so only the stale precondition needed updating.
2026-07-23 00:13:14 +02:00
can1357 ac8e9e05bb fix(utils): made runtime module resolver uninstallable
installRuntimeModuleResolver patched Module._resolveFilename process-wide
with no way back. In the shared bun test process the leaked patch broke
createRequire relative requires for every later test file (Bun 1.3.14 calls
a JS _resolveFilename override with parent === undefined, so './x' resolves
'from ""'), failing legacy-pi-inplace-load only in full-suite runs.

The installer now returns an uninstaller that drops the registration and
restores the pristine resolver when no runtime roots remain; the known Bun
limitation is documented so the patch stays scoped to worker runtimes.
2026-07-18 22:17:04 +02:00
can1357 f92d8feeec merge PR #5761 via eval/pr-5761: fix(utils): bounded default ptree stderr retention 2026-07-17 04:42:10 +02:00
roboomp edba577e7a fix(utils): bounded default ptree stderr retention
Default ChildProcess unconditionally pushed every raw stderr chunk into
`#stderrChunks`, so long-lived noisy subprocesses (LSP/DAP/RPC) grew OMP
memory linearly despite the 32 KiB visible tail cap.

- Allocate `#stderrChunks` only when full capture is requested at spawn.
- Decouple retention from stream exposure via `spawnInternal`, so
  `exec({ stderr: "full" })` retains without an unused live tee.
- Reject retroactive `wait({ stderr: "full" })` on a default child with a
  clear error instead of returning truncated data.

Fixes #5759
2026-07-16 21:41:44 +00:00
roboomp 7b5d936f95 fix(utils): pruned stale pid log namespaces
Kept live process logs isolated while globally retaining only the five newest files from completed processes.

Removed one-use audit files after their owning process exits and covered short-lived invocation cleanup.

Fixes #5716
2026-07-16 14:56:28 +00:00
roboomp 7550bd887c fix(utils): isolated fatal logging teardown
Made fatal reporting bypass revoked stderr streams and armed a referenced forced-exit watchdog around bounded cleanup.

Separated rotating log and audit namespaces by PID and disabled compression pipelines so concurrent TUI processes cannot race shared rotation state.

Fixes #5716
2026-07-16 14:46:40 +00:00
can1357 2c355102ce chore: applied biome formatting to merged sources 2026-07-16 03:52:48 +02:00
can1357 f7ed718302 fix(utils): share active postmortem cleanup 2026-07-16 03:50:06 +02:00
can1357 fd54f897f4 merged PR #5419: fix(acp): await teardown on stdio disconnect
# Conflicts:
#	packages/coding-agent/src/modes/acp/acp-mode.ts
2026-07-16 03:50:06 +02:00
can1357 362f89a2ec Merge remote-tracking branch 'origin/farm/fe301a84/reduce-stream-decoding-cpu' 2026-07-15 09:54:59 +02:00
can1357 404ebb0fb0 Merge remote-tracking branch 'origin/farm/ae7a5593/ttsr-inline-regex-flags-and-scope-quoting' 2026-07-15 09:54:46 +02:00
roboomp 22fa8f6623 perf(stream): batched response decoding
- Batched complete SSE lines into one UTF-8 decode per source chunk.

- Parsed Ollama NDJSON bytes directly without TextDecoder buffering.

Fixes #5542
2026-07-15 02:55:02 +00:00
can1357 984a97fa51 style: formatted evaluator test additions 2026-07-14 23:11:49 +02:00
can1357 0418d8622a fix(cli): handle native parser usage errors 2026-07-14 23:11:11 +02:00
can1357 33f61cc511 Merge PR #5496: fix(cli): print concise usage error instead of source dump (@roboomp) 2026-07-14 23:11:11 +02:00
roboomp 6a4bd404c9 test(cli): reset usage-error exit status
Restore an initially unset process.exitCode to zero so Bun does not retain the expected usage-error status after the test.
2026-07-14 20:20:36 +00:00
roboomp 6dc48a8b02 fix(cli): print concise usage error instead of source dump
Argument/flag validation failures in the minimal CLI framework threw a
plain Error that bubbled to the process-level catch in cli.ts, which
dumps a Bun.inspect code frame — a minified dist/cli.js excerpt in
compiled binaries. A missing model on `omp bench` looked like a crash.

- Add CliUsageError; throw it from Command.parse for missing/invalid
  args and flags.
- Catch CliUsageError in run(): print `error: <msg>` plus the command
  usage line to stderr, exit 1, no stack.
- Render required variadic positionals as MODELS... in usage, not the
  misleading optional [MODELS]; extract commandUsageLine helper.

Fixes #5369
2026-07-14 19:16:59 +00:00
roboomp 86824c94e9 fix(ttsr): registered rules with inline regex flags and malformed scope
Rules whose condition led with a PCRE-style inline flag group (e.g.
`(?i)`) never registered: `new RegExp("(?i)...")` throws in Bun/JS, so
the condition failed to compile and `TtsrManager.addRule` dropped the
rule as having zero usable conditions.

- Add `compileRuleCondition` in capability/rule.ts translating a leading
  `(?i)`/`(?m)`/`(?s)` group into native RegExp flags; wire it into the
  TtsrManager and both ttsr-cli compile sites.
- Strip surrounding quotes from scope tokens so a malformed
  `scope: "text","thinking"` recovers to canonical `text`/`thinking`.
- Reparse each value in parseFrontmatter's YAML fallback so one bad line
  can't leave sibling values wrapped in literal quotes.

Fixes #4796
2026-07-14 19:01:47 +00:00
can1357 3efbce97b5 Merge PR #5295: fix(utils): bound Mermaid ASCII pathfinder (@roboomp) 2026-07-14 19:16:08 +02:00
roboomp 953859d956 fix(acp): awaited teardown on stdio disconnect
Registered ACP session disposal with postmortem and replaced the hard EOF exit with the awaited graceful shutdown path.

Classified stdio-write EPIPE separately from worker IPC EPIPE so ACP peer loss exits successfully after cleanup.

Fixes #4788
2026-07-14 16:20:48 +00:00
roboomp cc2041ab7f fix(utils): bounded mermaid ascii pathfinder
- Added bounded A* routing extents plus an expansion backstop so unreachable attachment points return null instead of searching the unbounded quadrant.
- Covered the reported declaration-order graph and an enclosed destination attachment point.
- Documented the Mermaid ASCII routing fix in the utils changelog.

Fixes #5293
2026-07-12 18:54:28 +00:00
Kormákur 9af5835b20 chore: remove noisy test 2026-07-11 00:43:49 +00:00
Kormákur 17486d2009 fix(utils): create log dir before redirecting stderr guard
On a fresh profile ~/.omp/logs may not exist yet (the logger creates it
lazily), so opening getLogPath() with "a" threw and the guard fell back to
/dev/null — discarding macOS diagnostics and native crash reports instead
of preserving them in the omp log. mkdir the redirect target's parent
(recursive) before opening; the /dev/null fallback stays as the safety net.
2026-07-11 00:38:55 +00:00
Kormákur 4eaca82fa6 fix(tui): suppress unmanaged macOS stderr writes corrupting the viewport
On macOS, libmalloc writes runtime diagnostics (e.g. "MallocStackLogging:
can't turn off malloc stack logging because it was not enabled") directly
to fd 2 of the running TUI process at arbitrary times, painting into the
viewport. The existing env-strip only protects child processes.

Add a fd-level stderr guard in pi-utils (suppressTerminalStderr /
restoreTerminalStderr) that dup2-redirects fd 2 to the omp log file while
the TUI owns the terminal, and restores it at every ownership handoff
(external editor, Ctrl+Z suspend, shutdown, crash restore). Postmortem
fatal handlers restore fd 2 before printing so crash reports stay visible.

Mirrors openai/codex#24459.
2026-07-11 00:16:42 +00:00
can1357 0006252d6e test(utils): validated tool error handling and cleanup signal propagation
- Added comprehensive test suite for `postmortem` utility error handling, covering cleanup symbol marking, cause chain depth validation, and process exception suppression.
- Added tests for `browser-run-cancellation` ensuring proper `unhandledRejection` suppression and correct `ToolAbortError` propagation during teardown.
- Implemented `collectUnhandledRejections` helper to verify silence of process-level rejections during async race conditions in browser runs.
- Added integration-style probe tests for `postmortem` to verify that marked cleanup errors allow process survival while unmarked ones remain fatal.
2026-07-06 08:07:25 +02:00
can1357 fdd7bdef7b feat(ai): improved reasoning block separation and validation
- Mark demoted thinking blocks with a symbol to decouple paragraph separators from the raw text content.
- Update `openai-completions` to conditionally insert a newline only when a demoted thinking block is followed by other content.
- Ensure terminal demoted thinking blocks are trimmed to prevent trailing whitespace that causes rejection by the Anthropic API.
2026-07-05 16:25:12 +02:00
can1357 d63c69d7c3 feat(utils): implemented buffer classification for stream parsing
- Implemented classifyJsonPrefix to categorize buffers as complete, valid prefix, or invalid based on RFC 8259 strictness.
- Added utility to support disambiguation of identifierless streaming tool-call deltas during model response processing.
- Validated classifier logic with comprehensive suite covering nested structures, escape sequences, and strict formatting rules.
2026-07-05 15:57:24 +02:00
can1357 17552b9135 feat(utils): recovered unquoted bareword strings in json parser
- Added support for parsing unquoted bareword strings in object and array value positions.
- Implemented safety checks to prevent bareword recovery from masking structure, consuming non-finite atoms, or swallowing valid JSON delimiters.
- Included logic to preserve URL-style and Windows-style paths containing colons while rejecting invalid or ambiguous syntax.
2026-07-02 07:52:12 +02:00
can1357 d5b26b6b97 build(utils): relocated tls-fetch utility to the utilities package
- Extracted the `tls-fetch` implementation and tests from `@oh-my-pi/pi-ai` to `@oh-my-pi/pi-utils`.
- Exported the `wrapFetchForExtraCa` and `withExtraCaFetch` utilities publicly from `@oh-my-pi/pi-utils`.
- Introduced `ExtraCaError` to replace the AI-specific `ValidationError` for missing `NODE_EXTRA_CA_CERTS` paths.
- Updated imports in `packages/ai/src/stream.ts` to consume the relocated utility.
2026-07-02 01:51:09 +02:00
can1357 6c552e39cf fix(utils): handled unquoted YAML plain scalars containing colon-space in frontmatter
- Added preprocessing to quote ambiguous plain scalars containing a colon-space sequence when standard YAML parsing fails.
- Preserves the parsed types of unaffected fields and prevents fallback warnings for common unquoted description strings.
- Added tests to verify successful recovery of unquoted values and continued fallback warning coverage for unrecoverable syntax.
2026-06-30 17:44:19 +02:00
roboomp 650d34f111 fix(utils): preserved long retry hint fail-fast
- Restored the fetchWithRetry early return for Retry-After and quota hints larger than maxDelayMs.

- Added coverage so oversized provider retry hints do not sleep and retry internally.
2026-06-30 13:24:47 +00:00
roboomp cd6ba0214f fix(ai): hardened ollama malformed tool-call handling
- Added a fetchWithRetry response-body gate so deterministic 5xx provider failures can skip retry delays.

- Stopped retrying llama.cpp malformed tool-call JSON responses from local Ollama and surfaced recovery guidance.

- Covered the Ollama parse-failure path and generic retry gate behavior.

Fixes #3899
2026-06-30 13:20:11 +00:00
can1357 e8090bb48a feat: introduced binary file detection to prevent encoding corruption
- Introduced `isProbablyBinary` utility to sniff file headers for NUL bytes or invalid UTF-8 sequences.
- Updated `ReadTool` to use the binary sniffer, preventing mojibake corruption in output when reading non-text files.
- Refined `file-mentions` auto-reads to skip binary files and mark them as `binary` in the message transcript.
- Added comprehensive unit tests for binary detection logic, covering NUL bytes, truncated multibyte characters, and path-based file sniffing.
2026-06-30 02:59:41 +02:00
roboomp 777b609e63 fix(cli): preserved windows extension paths
Rejoined split Windows extension module paths before launch parsing finishes and stripped extended-length Win32 prefixes before Bun import and worker spawn APIs see them.

Fixes #3804
2026-06-29 11:50:36 +00:00
roboomp 7d6a5c6de0 fix(utils): normalized ptree.bytes() return type to Uint8Array
Bun's `Response(stream).bytes()` returns the raw `ArrayBuffer` once the
body arrives in more than one chunk, which happens for subprocess stdout
past ~128 KB. The public contract of `ptree.ChildProcess.bytes()` is
`Promise<Uint8Array>`, and callers — most visibly the `ssh://` read
path's `decodeUtf8Text` — rely on `Uint8Array` methods such as `.indexOf`
and `.subarray`. On larger remote text files this surfaced as:

  TypeError: bytes.indexOf is not a function

Normalize the result at the boundary: when `Response.bytes()` hands back
an `ArrayBuffer`, wrap it in a zero-copy `Uint8Array` view before
returning. Adds a regression test that drives a 256 KB stdout payload
through `ptree.spawn(...).bytes()` and asserts the contract.

Fixes #3712
2026-06-28 10:04:53 +00:00
can1357 a241cb0999 test: restore directory profile state after cache tests 2026-06-27 01:39:34 +02:00
can1357 9dea09e238 Merge PR #3264: feat(coding-agent): cache successful document conversions (@wolfiesch) 2026-06-27 01:39:33 +02:00
can1357 453865bb71 test(utils): dropped EBUSY-window test using banned mock.module/global mutation
The #3348 change is a single retry-window constant (25->50ms); the test asserted
it via mock.module("node:fs") + process.platform/Bun.sleepSync mutation, which
AGENTS.md bans (leaks across the full suite). The retry-on-EBUSY loop already has
coverage; a config constant does not warrant a global-mutating test.
2026-06-27 00:23:16 +02:00
can1357 eb4a02433c refactor: consolidated json parsing and stream utilities
- Centralized JSON parsing and stream processing logic by moving utilities from `packages/ai` to the shared `@oh-my-pi/pi-utils` package.
- Standardized import paths for JSON parsing and streaming across the agent, ai, and coding-agent packages.
- Refactored SSE stream handling to use consolidated `parseStreamingJson` logic and introduced robust error recovery for malformed container-shaped tail events.
- Cleaned up legacy bundled registry references and updated related module exports and tests to reflect the new utility structure.
2026-06-27 00:11:42 +02:00
can1357 4a5dce8a94 test(utils): cover Windows EBUSY retry window
(cherry picked from commit 5173f91457804a7456788130e1ae9fc8975deeed)
2026-06-26 23:43:03 +02:00
can1357 9cd9349d05 Merge PR #3362: fix(utils): handle trailing-truncated JSON in readSseJson (@usr-bin-roygbiv) 2026-06-26 23:27:38 +02:00
can1357 a13c8d2698 fix(utils): prevented winston warnings when transports are disabled
- Set logger to silent mode when no transports are active to avoid "no transports" errors during log emission.
- Added a regression test to verify that disabling all transports suppresses warnings and that log output resumes after re-enabling transports.
2026-06-25 12:46:49 +02:00
can1357 c58ec21242 fix(tui/utils): corrected state restoration for TTY and environment variables
- Corrected TTY property restoration to properly delete injected properties instead of redefining them as truthy values.
- Updated environment restoration to modify process.env keys individually to prevent breaking environment object reference bindings.
- Prevented pollution of TTY-gated code and environment variable state across test suites.
2026-06-24 15:30:29 +02:00
can1357 ea01c3998c fix(mermaid): enforced deterministic colorMode during golden test runs
- Pin colorMode to none in golden test suites to prevent nondeterministic ANSI escape sequences.
- Normalize render calls across test files to ensure stable output comparison.
- Prevent test flakes caused by environment-specific TTY auto-detection in the renderer.
2026-06-24 15:30:29 +02:00
Wolfgang Schoenberger 3a2ab8ad7d test: restore full env state in document-conversion cache tests
Snapshot and restore PI_CODING_AGENT_DIR, OMP_PROFILE, PI_PROFILE, and
XDG_CACHE_HOME instead of relying on setAgentDir(originalAgentDir), which
cannot restore previously-unset or profile-derived env state. Reset the
profile snapshot and rebuild dirs from env in cleanup to prevent
suite-order pollution.

Also reject empty cached content in parseCacheEntry() to harden the
cache contract against corrupted/empty entries.
2026-06-24 03:08:48 -07:00
usr_bin_roygbiv 5f22e58a61 fix(utils): require string closed in hasValidPredecessorForComma 2026-06-23 23:53:04 -05:00
usr_bin_roygbiv 2a31d063b2 fix(utils): handle string escapes and partial unicode escapes at EOF in getClosingSuffix 2026-06-23 23:43:46 -05:00