Commit Graph
459 Commits
Author SHA1 Message Date
can1357 9c54d25a4e Merge PR #6298: fix(cli): dispose model-listing extensions (@roboomp) 2026-07-22 21:13:22 +02:00
can1357 b9072f1991 fix(extensibility): validate Type.Unsafe against the draft-2020-12 upgraded schema
Aligns the shim's runtime safeParse/__validator with the wire/tool-call
path, so legacy draft-07 documents (tuple items) accept the same values
validateToolArguments does. Adds a regression test.
2026-07-22 21:13:21 +02:00
can1357 d6cbf9a6aa Merge PR #6241: fix(extensibility): add Type.Unsafe to typebox shim (@roboomp) 2026-07-22 21:13:21 +02:00
can1357 9995325ad5 fix(sdk): carry strict through the custom-tool definition bridge
customToolToDefinition rebuilt ToolDefinition without strict, so the
Task proxies' (and startup MCP tools') explicit strict:false was dropped
before RegisteredToolAdapter and the OpenAI-family serializers saw it.
Declare strict on ToolDefinition, copy it in the bridge, and cover the
proxy -> definition -> registered adapter path in the parity test.
2026-07-22 21:13:21 +02:00
roboomp 29f773ece2 fix(cli): disposed model-listing extensions
Emitted session_shutdown after model rendering and centralized managed timer cleanup across one-shot listings and agent sessions.

Added regression coverage for the extension shutdown lifecycle.

Fixes #6297
2026-07-22 15:51:47 +00:00
roboomp 040c1d5891 fix(extensibility): validated unsafe schemas at runtime
Used the shared JSON Schema validator for Type.Unsafe so direct safeParse calls and composed shim schemas reject invalid values while preserving valid input identity.

Added direct and composed runtime regression assertions.
2026-07-21 22:42:09 +00:00
roboomp 49e63c1f2c fix(extensibility): added Type.Unsafe to typebox shim
Preserved raw JSON Schema documents while keeping the shim validator identity-based, allowing provider wire conversion and runtime argument validation to consume MCP input schemas.

Added direct shim and remapped-extension regression coverage.

Fixes #6221
2026-07-21 22:34:44 +00:00
can1357 1bf08608a4 Merge PR #4964: fix(cli): resolve bundled extension imports (@roboomp)
# Conflicts:
#	packages/coding-agent/src/extensibility/plugins/legacy-pi-compat.ts
#	packages/coding-agent/src/main.ts
#	packages/coding-agent/src/prompts/system/workflow-notice.md
#	packages/coding-agent/test/extensibility/legacy-pi-bundled-virtual.test.ts
2026-07-20 22:53:16 +02:00
can1357 b5033707b9 Merge PR #5969: fix(extensibility): re-export getPackageDir/getProjectDir from legacy pi shim (@roboomp) 2026-07-18 19:42:51 +02:00
roboomp bf232ca062 fix(extensions): scoped provider hooks to request model
Passed the per-request model through SDK payload callbacks and ExtensionRunner context creation.

Added regression coverage for Codex-primary and Anthropic-request contexts.

Fixes #6006
2026-07-18 16:52:15 +00:00
roboomp 5082763d49 fix(extensibility): guarantee string getPackageDir in compiled shim builds
omp's canonical getPackageDir() returns undefined inside a bun --compile
binary (import.meta.dir is /$bunfs/root, no owning package.json — issue
#1423). Re-exporting it directly broke pi's string-valued contract:
legacy extensions doing path.join(getPackageDir(), ...) crashed at
runtime in the shipped binary, the primary distribution.

Wrap the canonical helper so the shim always returns a string, falling
back to the executable's directory in compiled mode (where the binary is
the install root). PI_PACKAGE_DIR and dev/source/npm-dist walk-up still
win. Test covers the compiled-mode fallback via isCompiledBinary spy.

Fixes #5968
2026-07-18 06:50:00 +00:00
roboomp 4a25993682 fix(extensibility): re-export getPackageDir/getProjectDir from legacy pi shim
The legacy pi compatibility shim only forwarded getAgentDir (via
`export * from "../index"`). getProjectDir and getPackageDir were absent,
so any pi extension importing either from @earendil-works/pi-coding-agent
failed Bun's static export check during extension validation and the
install was rolled back.

Re-export getProjectDir from @oh-my-pi/pi-utils and getPackageDir from
omp's canonical config helper (returns the coding-agent package root,
matching pi semantics).

Fixes #5968
2026-07-18 06:41:55 +00:00
roboomp aaac0ace1d fix(extensions): created legacy auth database directory
Create the resolved agent database parent before the synchronous compatibility store opens SQLite, and cover a fresh nested agent directory.

Fixes #5879
2026-07-17 17:06:15 +00:00
roboomp 7e8c4fc01f fix(extensions): restored legacy provider compatibility
Restored the historical assistant-message stream factory and synchronous auth-storage facade needed by pi-provider-kimi-code.

Fixes #5879
2026-07-17 16:54:47 +00:00
can1357 86b6265ef5 Merge branch 'sweep/2026-07-17' into eval/pr-5592
# Conflicts:
#	packages/coding-agent/test/agent-session-checkpoint-rewind-branch.test.ts
2026-07-17 05:22:52 +02:00
can1357 22ae8045f2 merge PR #5768 via eval/pr-5768: fix(tools): keep essential built-ins top-level when re-registered without loadMo 2026-07-17 04:42:10 +02:00
can1357 cf434411f6 merge PR #5744 via eval/pr-5744: fix(tui): reinstated host stdin listeners removed during tool load 2026-07-17 04:40:04 +02:00
can1357 e56ac80b1d merge PR #5667 via eval/pr-5667: fix(extensions): isolated self-scheduled callbacks from killing the session 2026-07-17 04:37:10 +02:00
can1357 5d3ad91900 fix(plugins): preserve CommonJS ESM interop 2026-07-17 04:18:10 +02:00
can1357 9a413bf812 fix(coding-agent): restore flowing stdin after guarded load 2026-07-17 03:57:12 +02:00
roboomp 5340a9517a fix(tools): keep essential built-ins top-level when re-registered without loadMode
Extension/SDK/RPC registerTool defaulted an omitted loadMode to
"discoverable". A UI-only re-register of an essential built-in
(read/write/bash/edit/glob) then became discoverable and, with tools.xdev
on, was unmounted from the top-level schema. read/write dropping also
broke the xd:// transport (read xd://, write xd://<tool>), leaving the
model with no callable coding essentials.

- Add defaultLoadModeForToolName: omitted loadMode resolves to "essential"
  for known essential built-in names, "discoverable" otherwise.
- Apply it at all four adapter boundaries (extension wrapper, custom-tools
  wrapper, sdk customToolToDefinition, rpc normalizeHostToolDefinitions).
- Transport invariant: read/write never mount under xdev regardless of
  loadMode (they carry the transport).
- Regression test covering the demotion, transport invariant, and a drift
  guard tying the essential-name set to the tool classes.

Fixes #5764
2026-07-16 23:08:02 +00:00
roboomp d2aeaeced6 fix(tui): reinstated host stdin listeners removed during tool load
The host guard's stdin restore only dropped listeners a module added; a
module that removed a snapshot listener (e.g. a factory calling
process.stdin.removeAllListeners("data") when a subagent re-runs preloaded
factories against a live parent TUI) permanently stripped ProcessTerminal's
input handler. Reconcile each guarded event back to the pre-load snapshot:
when membership changed, removeAllListeners then re-add the snapshot in
order, restoring both additions dropped and removals reinstated. Snapshot
via rawListeners so once-wrapped handlers round-trip intact.

Fixes #5618
2026-07-16 19:48:08 +00:00
roboomp 1fea9b149f fix(tui): guarded stdin against custom-tool import hijack
Custom tool/extension/hook/plugin modules under ~/.claude/tools are
evaluated with live side effects during createAgentSession. A module that
attaches a stdin consumer at import time — an MCP StdioServerTransport
built at module top level, or a bare process.stdin.resume() — steals
Bun's single stdin reader, so the TUI receives exactly one data event and
goes permanently deaf after the first keypress. Under tmux the terminal's
automatic DA1 reply is that one event, so the first user keystroke is
already dead: the input-deafness reported in #5378/#5618.

Broadened the loader's withExitGuard (renamed withHostGuard) to also
snapshot and restore process.stdin around third-party module evaluation:
any data/readable/end/close/error listener the module adds is removed, and
the stream's paused and raw-mode state is restored to the pre-load
snapshot. The exit guard already fenced process.exit; stdin is the same
class of host-state hijack.

Fixes #5618
2026-07-16 19:35:43 +00:00
robomp-bot c972e44be8 fix(coding-agent): skip Warp stop when agent_end will continue 2026-07-16 20:00:45 +09:00
roboomp 8a61515819 fix(extensions): isolated self-scheduled callbacks from killing the session
Extension-scheduled setInterval/setTimeout/detached callbacks ran outside
the handler-dispatch try/catch, so a throw surfaced as a process-level
uncaughtException and the global postmortem handler tore down the whole
session instead of isolating the misbehaving extension.

- Added ManagedTimers backing sanctioned ctx.setInterval/setTimeout/clearTimer:
  callbacks run with handler-dispatch isolation (throw/rejection logged and
  routed through onError), handles are unref'd, and all are cleared on
  session_shutdown.
- Wired the helpers into ExtensionRunner.createContext and the runner-less
  command-context fallback; onSession now inherits the runner context.
- Documented in-process no-isolation behavior and the managed timers in
  docs/extensions.md and docs/skills/authoring-extensions.md.

Fixes #5664
2026-07-16 07:17:10 +00:00
roboomp 8f15dbf106 fix(plugins): preserved commonjs sibling requires
- Added a graph-owned CommonJS evaluator with shared module.exports and cycle-aware caching.

- Covered sibling require interop across ESM-imported CommonJS modules.

Fixes #5658
2026-07-16 06:11:32 +00:00
roboomp 2cf0c402f9 fix(plugins): refreshed commonjs helpers on reload
- Rebuilt synchronous CommonJS wrappers from current source for every legacy extension load.

- Added a same-process helper edit regression.

Fixes #5658
2026-07-16 05:53:19 +00:00
roboomp 33340f82ce fix(plugins): restored legacy commonjs compatibility
- Added DefaultPackageManager discovery compatibility for legacy extensions.

- Loaded graph-owned CommonJS modules through synchronous default bridges.

Fixes #5658
2026-07-16 05:41:35 +00:00
can1357 9afedb591e feat(coding-agent): added opt-in task prewalk and tightened --tools and xdev behavior
- Added a `task.prewalk` option (default `false`), removed default task `prewalk` flags, and updated prewalk resolution so bunded generic task execution only prewalks when explicitly enabled.
- Enforced strict `--tools` validation in CLI parsing, making unknown tool names fail fast with `CliUsageError` instead of being silently filtered.
- Migrated legacy discovery settings (`tools.discoveryMode`, `tools.essentialOverride`, MCP discovery keys) into updated `tools.xdev` handling with preserved explicit override behavior.
- Hardened xdev/ACP execution flow by capping `docsAll` payloads with overflow listing and remapping `xd://` dispatches/approval gating for correct execute/read behavior and reduced duplicate prompts.
2026-07-15 18:39:36 +02:00
can1357 84d873f2ca Merge remote-tracking branch 'origin/farm/ceed3a6a/compiled-appserver-extension-exit' 2026-07-15 15:31:51 +02:00
can1357 5ff277349c refactor(coding-agent): consolidated tool surface onto xd:// devices and hub
- Added the `xd://` virtual device protocol (`internal-urls/xd-protocol.ts`, `tools/xdev.ts`): tools declaring `loadMode: "discoverable"` are unmounted from the request tools array and driven via `read xd://` (list/docs+schema) and `write xd://<tool>` (execute), gated by the `tools.xdev` setting (default on) and inlined into the system prompt.
- Merged the `irc`, `job`, and `launch` tools into a single `hub` tool (`tools/hub/`, `async/job-manager.ts`): messaging keeps `send`/`inbox`/`list`, job control maps to `wait`/`cancel`/`jobs`, process supervision keeps `start`/`logs`/`stop`/`restart`/`describe` with `ps`, and the unified `wait` races background jobs against peer messages; SDK `IrcTool`/`JobTool`/`LaunchTool` are replaced by `HubTool`.
- Removed the hidden `resolve` tool in favor of the `xd://resolve`/`xd://reject`/`xd://propose` resolution devices, auto-including `write` whenever a deferrable tool or plan mode is present.
- Removed the BM25 tool-discovery system: the `search_tool_bm25` tool, the `tool-discovery` module, the `tools.discoveryMode`/`mcp.discoveryMode`/`mcp.discoveryDefaultServers`/`tools.essentialOverride` settings, per-tool MCP selection, and the `mcp_tool_selection` message type.
- Unified tool presentation on `ToolLoadMode` (`essential`|`discoverable`), replacing the custom-tool `xdev?: boolean` opt-out; custom, extension, MCP, RPC host, image-generation, and TTS tools now default to `discoverable`, and added a `satisfies` predicate to `SoftToolRequirement`.
- Removed the standalone `ssh` command tool and `ssh/ssh-executor` (the `ssh://` read/write/search protocol stays), and made `--tools` address hidden built-ins.
- Updated collab-web to render `xd://` dispatches and `hub` op families, dropped the `search_tool_bm25`/`ssh`/`report-finding` renderers, refreshed tool docs and prompts, and migrated the affected tests and changelogs.
2026-07-15 15:16:29 +02:00
roboomp 24960899ac fix(coding-agent): lazily loaded compiled extension modules
Generated per-module loaders instead of eagerly evaluating the entire bundled compatibility graph during extension bootstrap.

This prevents appserver startup from cycling through its own retained command modules before the Unix socket is created.

Fixes #5568
2026-07-15 10:54:13 +00:00
can1357 7de519eabc Merge PR #5499: fix(plugins): preserve native CommonJS helper loading (@roboomp) 2026-07-14 23:11:10 +02:00
can1357 55ad1ff1bc Merge PR #5505: fix(plugins): refresh stale Bun git cache before reinstall (@roboomp) 2026-07-14 23:11:07 +02:00
can1357 1e1569d58e Merge PR #5465: fix(extensions): let tool_result rewrite thrown failure content (@roboomp) 2026-07-14 22:58:48 +02:00
roboomp 2439f77e70 fix(plugins): refreshed stale bun git cache before reinstall
Fetched current heads and tags into Bun's matching cached bare clone before running bun update.

Added an isolated HTTP git regression covering a moved branch with a stale cache.

Fixes #5401
2026-07-14 19:37:06 +00:00
roboomp 7881fce976 fix(plugins): preserved native commonjs helper loading
Kept synchronous require() targets on Bun’s native loader while retaining hooks for native-addon rewrites.

Added regression coverage for ESM extensions loading CommonJS helper files.

Fixes #5373
2026-07-14 19:22:00 +00:00
roboomp 5303c3852e fix(extensions): let tool_result rewrite thrown failure content
ExtensionToolWrapper caught a thrown tool exception, emitted tool_result
with the modifiable result, then rethrew the original executionError whenever
the effective error state stayed true. This discarded any replacement content
or details a handler returned, so an extension could only surface modified
content by returning isError: false, which wrongly converted the failure into
a success.

Return the (possibly modified) result carrying isError instead of rethrowing.
The agent loop already honors AgentToolResult.isError (coerceToolResult) and
surfaces it as a tool error on the wire, so replacement failure content now
reaches the model while the call remains an error. No-modification, error->success, and success->error paths keep their existing semantics.

Fixes #5302
2026-07-14 18:01:02 +00:00
can1357 edc0511433 Merge PR #4967: fix(plugin): handle pinned git source replacements (@roboomp) 2026-07-14 18:45:31 +02:00
can1357 4b5c32a092 Merge PR #4950: fix(mcp): resolve local image paths for tool calls (@roboomp) 2026-07-14 18:45:22 +02:00
can1357 f9f6ed9e8d feat(coding-agent): replaced legacy pi/ role alias prefix with
- Replaced legacy `pi/` role alias prefix with canonical `@` syntax across model resolution, documentation, and tests.
- Added support for bare `*` default alias and multiple alias prefix detection with custom role resolution in `resolveConfiguredRolePattern()`.
- Enhanced thinking suffix parsing to accept unambiguous abbreviations (minimum 2 characters) for effort and level selectors.
- Extended `resolveCliModel()` and `filterAvailableModelsByEnabledPatterns()` to accept settings parameter for role alias resolution from `--model` flag.
2026-07-13 23:26:33 +02:00
roboomp 459682cc63 fix(plugins): skipped invalid custom tool entries
Validated custom tool factory results before registering plugin-provided tools so one malformed feature entry is reported and skipped instead of crashing startup.

Added regression coverage for null entries and mixed valid/null factory arrays.

Fixes #5189
2026-07-11 14:31:07 +00:00
can1357 6f65a58d1b merge PR #4375: feat(ask): add rich interactive dialog
Closes #4375
2026-07-11 14:15:55 +02:00
can1357 d469064d1a fix: handle stale tests 2026-07-11 07:54:19 +02:00
can1357 33c161d9dd refactor(coding-agent): restructured plugin system and build logic
- Migrated legacy static bundled-module registry to a dynamic Bun-based in-memory plugin system.
- Removed over 4,000 lines of manually maintained registry files to reduce maintenance overhead.
- Implemented CJS absolute path rewriting and native-addon load hooks to improve FFI dependency resolution.
- Standardized binary build processes by centralizing compilation logic into shared utilities.
2026-07-11 07:33:22 +02:00
roboomp bc9f4c4be6 fix(coding-agent): armed ask timeout for legacy ui
Added an explicit timeout presentation capability so interactive queued dialogs defer the fallback while older UI implementations still get an immediate tool-owned timeout.

Refs #4995
2026-07-10 04:13:18 +00:00
roboomp fcf389ae72 fix(coding-agent): deferred ask timeout until display
Started the ask tool fallback timeout from the selector presentation callback so queued dialogs do not consume the user's response window.

Refs #4995
2026-07-10 02:49:33 +00:00
roboomp facfb3c35a fix(coding-agent): synced ask fallback timeout resets
Reset the ask tool fallback timeout whenever the interactive selector resets its UI countdown, preventing late keypresses from falling back to the original recommended option.

Refs #4995
2026-07-09 23:37:50 +00:00
roboomp 63adfeece5 fix(plugin): handled pinned git source replacements
- Removed the stale pinned dependency edge before invoking Bun for same-repository git source replacements so Bun does not construct a dependency loop.

- Added a regression test for the pinned-to-unpinned GitHub plugin replacement path.

Fixes #4960
2026-07-09 18:35:43 +00:00
roboomp 1966d041f0 fix(cli): registered bundled namespace resolver
Registered the bundled virtual resolver on the omp-legacy-pi-bundled namespace while keeping the file-namespace scheme fallback for build-time resolution.

Updated the regression test to cover registry-key resolver inputs.

Fixes #4954
2026-07-09 18:30:25 +00:00