Commit Graph

1340 Commits

Author SHA1 Message Date
can1357 0697e7f688 refactor(coding-agent): split secret obfuscator into domain modules
- Separated deterministic replacement generation, placeholder derivation,
  placeholder-range scanning and message-tree transforms out of the 2647-line
  module; obfuscator.ts now holds the types and SecretObfuscator.
- ephemeralPlaceholderKey stays a single instance and both global regexes stay
  beside the code that resets their lastIndex, so placeholder stability and
  the security argument in the moved comments are preserved verbatim.
- Repointed every importer at the real modules rather than leaving a re-export
  shim; the public ./secrets barrel exports the same 15 names as before.
2026-08-08 06:32:01 +02:00
roboomp 7d4b2e7998 fix(agent): re-check context on cooldown-expiry revert in auto-continue path
A cooldown-expiry model revert runs at a turn boundary. The user-prompt
path reverts then re-checks accumulated context against the restored
model via runPrePromptCompactionIfNeeded, but the automatic
agent.continue() path (#scheduleAgentContinue) reverted and issued the
next request with no such check. When a transient failure had fallen
back to a larger-window model and the conversation then grew past the
original model's window, restoring the primary once its cooldown expired
sent a predictably oversized request to the smaller model.

maybeRestoreRetryFallbackPrimary now reports whether it actually
switched, and the auto-continue path runs the same post-revert
context-fit maintenance (compaction/promotion) the prompt path already
runs, but only when a revert occurred.

Fixes #7952
2026-08-07 23:38:24 +02:00
can1357 a8a8188e4b Merge PR #7756: fix(coding-agent): preserve before_agent_start prompt override across base rebuilds (@roboomp) 2026-08-07 13:39:53 +02:00
can1357 5f758778b8 Merge PR #7785: fix(coding-agent): make prewalk lifecycle one-shot (@eggpeat) 2026-08-07 13:39:51 +02:00
can1357 68dece477f Merge PR #7772: fix(session): handle subscription-cap retry exhaustion (@roboomp) 2026-08-07 13:37:54 +02:00
Brent 2efe8896ea fix(coding-agent): make prewalk lifecycle one-shot 2026-08-06 19:57:10 +00:00
roboomp f6c5a43a1f fix(session): handled subscription-cap retry exhaustion
- Classified subscription and plan rate caps as credential-rotatable usage limits while preserving transient per-minute throttles.

- Applied reason-specific backoff to transient rate limits and collapsed exhausted retry attempts behind one budget-labeled terminal error.

- Covered classification, delay selection, persisted transcript aggregation, and retry event propagation.

Fixes #7767
2026-08-06 01:31:22 +00:00
roboomp 3df56506c7 fix(coding-agent): preserve before_agent_start prompt override across base rebuilds
The per-turn systemPrompt returned by before_agent_start was applied only to the agent state, so any base-prompt rebuild firing in the prompt window (context-overflow compaction/promotion, memory promotion, MCP/RPC tool refresh, hindsight MM-TTL refresh) re-pushed the rebuilt base via setSystemPrompt and silently dropped the override before the request.

SessionTools now tracks the active per-turn override and re-applies it on every base rebuild during the turn, clearing it when the turn ends.

Fixes #7755
2026-08-05 21:28:37 +00:00
can1357 677b6f10f5 Merge PR #7735: fix(coding-agent): return ToolInfo[] from getAllTools extension API (@roboomp) 2026-08-05 22:15:46 +02:00
roboomp 2cf500dcc0 fix(session): isolated rewind reports by checkpoint cycle
- Bounded rewind report recovery to messages created after the active checkpoint.

- Added resumed-context regression coverage for late stale rewind results.

Fixes #7739
2026-08-05 16:26:56 +00:00
roboomp 83496b8211 fix(coding-agent): returned ToolInfo[] from getAllTools extension API
The ExtensionAPI getAllTools() wired to session.getAllToolNames(),
returning bare tool-name strings. Upstream @earendil-works/pi-coding-agent
promises ToolInfo[] with sourceInfo, so extensions loaded through the
legacy-pi shim (e.g. gentle-pi) crashed on t.sourceInfo.source at every
session start.

Added SourceInfo/ToolInfo types plus SessionTools.getAllToolInfos(), which
returns { name, description, parameters, sourceInfo } and classifies each
tool as builtin/mcp/sdk/extension. Rewired every getAllTools action site
(interactive, acp, print/rpc, subagent executor) and the example extension.

Fixes #7732
2026-08-05 15:42:06 +00:00
brymko 56931915f1 feat(coding-agent): added fatal session recovery hints
Registered live session resume commands with postmortem handling so a
fatal rejection or exception identifies every recoverable agent before
cleanup. Escaped terminal control characters in recovery output.
2026-08-05 14:31:03 +08:00
can1357 eb56330c9c chore(changelog): normalized unreleased entries after merges 2026-08-05 02:32:48 +02:00
can1357 a6eafcbf6b fix(ai): keep concurrency caps out of auth rotation
(cherry picked from commit bd6285ad9b16ae6f0a75e336a1c4bf961d3e43c7)
2026-08-05 02:32:36 +02:00
metaphorics 5726fac646 fix(ai): tighten concurrency-cap classification and account-cap gating
Reset-window rotation requires account-specific wording; concurrency caps require an actual cap signal; credential removal gated on AuthFailed without UsageLimit so a valid-but-blocked 403 credential is retained.

(cherry picked from commit 2f72752c2586352a4f7e9e814af1cdb0cf192af4)
2026-08-05 02:32:35 +02:00
can1357 94c838faea Merge PR #7539: fix(coding-agent): complete usage-aware fallback integration (@eggpeat) 2026-08-05 01:12:02 +02:00
roboomp 929ab1a20f fix(coding-agent): allowed retries for buffered print output
Made text replay safety depend on whether the active output sink has committed streamed text.

Kept tool calls, images, and server tools replay-unsafe while covering text and JSON print policies plus a transient socket-close recovery.

Fixes #7625
2026-08-04 13:50:09 +00:00
Brent 353bbc034b fix(coding-agent): harden usage fallback review races 2026-08-03 17:15:57 +00:00
can1357 1a8caad23e chore: update docs + rename reset to clear 2026-08-03 18:37:23 +02:00
Brent db97103c32 fix(coding-agent): complete usage-aware fallback integration 2026-08-03 16:34:35 +00:00
can1357 fc04aa6fa7 refactor(coding-agent): deferred startup parsing and schema compilation
- Wrapped security contract schemas in a lazy initializer with jitless scopes to eliminate startup JIT compilation tax.
- Enabled jitless scope configuration in auth-broker wire schemas to skip definition-time codegen.
- Deferred startup changelog parsing to overlap with interactive session creation.
2026-08-03 16:31:27 +02:00
can1357 a418920ec1 feat: made /reset semantically different
Closes #4447
2026-08-03 15:46:46 +02:00
can1357 267856deb8 Merge PR #7475: fix(session): prevent stale /btw branch promotion (@roboomp) 2026-08-03 15:12:03 +02:00
can1357 6a44844c57 Merge PR #7377: fix(hub): wake owners when supervised processes exit (@paralin) 2026-08-03 15:12:03 +02:00
can1357 b1d75bb55b fix(session): preserve title on first-turn branches 2026-08-03 14:46:24 +02:00
roboomp 98f484bd2f fix(session): validated session identity for /btw branch
Branched session files preserve entry ids, so leaf-id equality alone let a stale /btw answer promote into a different loaded session. Capture the originating session id at /btw start and require it to match at both the controller gate and every branchFromBtw checkpoint.

Fixes #7474
2026-08-03 09:22:32 +00:00
roboomp 7a1183da91 fix(session): prevented stale /btw branch promotion
- Passed the authorized leaf through the branch executor and revalidated it before rewriting history.
- Refused promotion during active turns and bounded post-prompt drains.
- Consumed unavailable branch keys while showing pending and refusal state in the panel.

Fixes #7474
2026-08-03 09:07:12 +00:00
Christian Stewart 302148523f fix(hub): wake owners when supervised processes exit
Publish terminal daemon completions to the session that started the
process so idle agents can resume without polling hub status.

Persist every unacknowledged generation with a stable completion ID and
immutable snapshot. Replay the collection after reconnect or broker
recovery, and clear each event only after the owning client acknowledges
it.

Signed-off-by: Christian Stewart <christian@aperture.us>
2026-08-03 01:31:39 -07:00
can1357 965d1239cf Merge PR #7310: fix(omp): refresh context budget after shake (@oleksoleksoleks) 2026-08-02 20:53:46 +02:00
can1357 160bdd05c3 fix(agent): keep session scout notices live 2026-08-02 20:52:57 +02:00
Alexander Kirilin e50138f2a6 fix(omp): refresh context budget after shake 2026-08-02 12:12:07 -04:00
Slava Zavadsky 9885ee34fc fix(agent): stop leaking scout into prompts when it is disabled
Hard-coded 'scout' references reached the model even when the scout
agent was disabled via task.disabledAgents or absent from the session
spawn list. Gate every such reference on scout actually being spawnable:
the task tool description, the delegation gates, the plan-mode and
workflowz notices, the glob/grep/ast-grep guidance, and the task
specialization advisory. Prompt shape is otherwise unchanged; only
erroneous references to the unavailable subagent are dropped.

Closes #7313
2026-08-01 23:50:33 -04:00
can1357 992963f949 feat(coding-agent): allowed switching to models smaller than session context with compaction
- Make over-context models selectable in the model picker by graying them instead of disabling them.
- Trigger automatic session compaction with the current model prior to switching when an over-context model is chosen.
2026-08-01 20:59:24 +02:00
can1357 93a9f0d991 Merge PR #7262: fix(coding-agent): refresh context files on plugin reload (@roboomp) 2026-08-01 20:13:38 +02:00
can1357 401ff44f08 Merge PR #7202: fix(agent): route codex v2 compaction through websockets (@roboomp)
# Conflicts:
#	packages/ai/src/providers/openai-codex-responses.ts
2026-08-01 20:13:28 +02:00
roboomp 55115f4bfd fix(coding-agent): refresh advisor context prompt on reload
Rebuilt advisor runtimes with the rediscovered context files so advisor turns stop evaluating against stale AGENTS.md instructions after /reload-plugins.

Fixes #7258
2026-08-01 11:46:55 +00:00
roboomp 838d120249 fix(coding-agent): reused effective prompt cache key
- Reused the agent's explicit or inherited cache identity for ephemeral side turns.
- Forwarded the same effective key through manual and automatic native compaction.
- Added regression coverage for all three secondary request paths.

Fixes #7218
2026-08-01 03:44:59 +00:00
roboomp 5283c4c99b fix(agent): routed codex v2 compaction through websockets
- Reused the live Codex provider session for WebSocket-first V2 compaction.
- Fell back to SSE V2 on WebSocket transport failure before the existing V1 fallback.
- Propagated the configured WebSocket preference through manual, automatic, and advisor compaction paths.
- Added transport reuse and fallback regression coverage.

Fixes #7198
2026-07-31 21:00:15 +00:00
can1357 06649b7407 feat(coding-agent): rewrote codex saved-reset trigger algorithm
- Replaced the reactive weekly-only auto-redeem predicate with a pool-wide
  planner: an expiry-salvage sweep piggybacks on the 5-minute usage
  heartbeat and spends any account's reset that would otherwise expire
  within codexResets.salvageHorizonHours, and the blocked-turn path scans
  all stored accounts with eligibility built from the exact exhausted
  5h/weekly windows (openai/codex#28525), unblocking at the latest reset
  among them.
- Made the live 429's parsed unblock timestamp authoritative for the
  active account (pre-block snapshots survive cache invalidation via
  in-flight adoption and last-good fallback), synthesizing the candidate
  when no usable report exists, and overlaying live credit counts from
  the dedicated credits route since a stale /wham/usage zero is never
  corrected upstream.
- Treated nothing_to_reset, credit_list_failed, and thrown consumes as
  non-terminal: the episode key is released and deferred 30 minutes
  instead of burying a banked credit; redeemResetCredit now spends the
  soonest-expiring credit.
- Added planner unit fixtures plus integration regressions driving the
  real triggers end to end, with an injectable per-session coordinator
  seam and a sweep settlement handle.
2026-07-31 20:39:12 +02:00
can1357 bd96752b83 fix(rpc): serialize IRC wake finalization 2026-07-31 19:28:43 +02:00
can1357 e02510f8c9 Merge PR #7108: fix(rpc): restore frames for IRC-revived subagents (@roboomp) 2026-07-31 19:28:42 +02:00
can1357 03c923d376 Merge PR #7140: fix(agent): suppress redundant xd:// mount notice after catalog rebuild (@roboomp) 2026-07-31 19:16:57 +02:00
can1357 3a68ce7eb0 Merge PR #7167: fix(cli): generate titles for positional initial messages (@roboomp) 2026-07-31 19:07:17 +02:00
roboomp 19818fd8fb fix(cli): skipped titles for positional extension commands
Applied the extension-command eligibility check inside the shared AgentSession title gate so editor and CLI bootstrap submissions cannot diverge.

Added direct regression coverage for programmatic startup submissions.

Fixes #7166
2026-07-31 10:34:46 +00:00
roboomp 223122d6b0 fix(cli): generated titles for positional initial messages
Moved automatic title eligibility and persistence into AgentSession so editor and CLI bootstrap submissions share one path.

Added a PTY regression probe covering the positional-message launch flow.

Fixes #7166
2026-07-31 10:28:48 +00:00
roboomp 4119bc461e fix(agent): resolve xd:// notice after final prompt override
A before_agent_start extension can replace the base system prompt after the
mount notice was consumed. Catalog-backed additions were then marked
announced and suppressed even though the provider request no longer contained
the catalog.

Reserve the notice's pre-user message position, wait until the extension has
selected the final prompt, and suppress catalog-backed additions only when no
per-turn replacement dropped the base catalog. Explicit replacements retain
the mount notice as the device-discovery channel.

Fixes #7139
2026-07-31 02:45:21 +00:00
can1357 652647770e feat(coding-agent): added app.live.toggle keybinding and map display reset to alt+l
- Add the `app.live.toggle` keybinding defaulted to `Ctrl+L` to start or stop live voice mode.
- Remap the default display-reset action (`app.display.reset`) from `Ctrl+L` to `Alt+L`.
- Update the live visualizer to listen for stop keys so the toggle chord terminates active sessions.
2026-07-31 00:20:04 +02:00
roboomp 8d0a193f19 fix(rpc): guarded IRC wake recovery by prompt generation
- Captured the prompt generation before an IRC wake and passed it to the post-prompt recovery wait.
- Stops the wait from following a successor turn once an abort supersedes the wake, so the wake monitor finalizes promptly instead of misattributing successor progress.

Fixes #7105
2026-07-30 20:16:20 +00:00
roboomp 4670a34590 fix(rpc): waited for IRC wake session settlement
- Kept IRC run monitors attached through post-prompt retry and continuation recovery.
- Flushed the final deferred agent_end before terminal lifecycle emission.
- Covered empty-stop retry ordering for RPC event subscribers.

Fixes #7105
2026-07-30 19:53:39 +00:00
roboomp b2d18b6920 fix(rpc): restored frames for IRC-revived subagents
- Monitored autonomous IRC wake turns with the task executor lifecycle and progress channels.
- Preserved monitoring after idle-TTL parking and session revival.
- Covered RPC subscriptions for both idle and parked keep-alive agents.

Fixes #7105
2026-07-30 19:42:58 +00:00