Commit Graph

202 Commits

Author SHA1 Message Date
can1357 cf8ac5b2f1 Merge PR #3496: fix(tui): guard streaming Esc cancellation (@roboomp) 2026-06-27 01:39:35 +02:00
can1357 eb4a02433c refactor: consolidated json parsing and stream utilities
- Centralized JSON parsing and stream processing logic by moving utilities from `packages/ai` to the shared `@oh-my-pi/pi-utils` package.
- Standardized import paths for JSON parsing and streaming across the agent, ai, and coding-agent packages.
- Refactored SSE stream handling to use consolidated `parseStreamingJson` logic and introduced robust error recovery for malformed container-shaped tail events.
- Cleaned up legacy bundled registry references and updated related module exports and tests to reflect the new utility structure.
2026-06-27 00:11:42 +02:00
can1357 ab7c1829e7 fix: respect focused session thinking toggle 2026-06-26 23:27:50 +02:00
can1357 6a83a27e91 Merge PR #3314: fix(tui): auto-hide provider thinking blocks when thinking is off (@oldschoola) 2026-06-26 23:27:40 +02:00
can1357 68d7593244 chore: reorg 2026-06-26 12:24:42 +02:00
roboomp 257b515353 fix(coding-agent): attach every image in a multi-file Finder selection
Reviewer caught: the macOS file-URL loop returned after the first
image-shaped path, silently dropping the rest of a multi-image
selection. The bracketed-paste handler in `CustomEditor.handleInput`
already iterates every extracted image path; the keybind path now does
the same. Mixed selections (one .pdf + two images) still attach all
images and skip the non-images.

Tests cover (a) multi-image selection (3 attached), (b) mixed selection
with the file-URL fallback owning the outcome (text fallback MUST NOT
run when at least one file URL was an image).

Refs #3506
2026-06-25 23:35:31 +00:00
roboomp b3f99dc634 fix(coding-agent): reach macOS public.file-url pasteboard via osascript
Reviewer caught (correctly) that the #3506 text fallback relied on
`clipboard.readText()`, which on Darwin shells out to `pbpaste(1)` —
pbpaste only surfaces plain text / RTF / EPS, so a Finder Cmd+C
pasteboard (`public.file-url` only, no plain text, no raw image bytes)
made readText() return empty and the new path-detection never ran.

Add a Darwin-only `readMacFileUrlsFromClipboard` helper that pipes a
small AppleScript through `osascript -` to coerce the pasteboard via
`«class furl»` and emit POSIX paths one per line. Wire it into
`InputController.handleImagePaste` between the readImage and readText
calls; the first image-shaped path routes through
`handleImagePathPaste`, non-image file URLs (e.g. a copied .pdf) fall
through to the existing text fallback. The clipboard interface field is
optional so existing test fixtures keep working without changes.

Tests: covers (a) Darwin file-URL pasteboard with empty pbpaste,
(b) non-image file URLs falling through to text, (c) the helper itself
on darwin/non-darwin and when osascript fails.

Refs #3506
2026-06-25 23:25:00 +00:00
roboomp e1dc21e0b5 fix(coding-agent): attach image on clipboard image-file paste
When the clipboard exposes only a file URL for an image (e.g. Finder
`Cmd+C` on a `.png`, certain screenshot tools), arboard's
`get_image()` returns `ContentNotAvailable`. `handleImagePaste` then
fell through to the #1628 smart-paste text fallback and pasted the path
verbatim, while the terminal-mediated paste round-tripped through
bracketed-paste's `extractBracketedImagePastePaths` and attached the
image — producing the asymmetric "for image I need control+v which is
very odd" symptom on macOS.

Refactor `custom-editor.ts` to share the bracketed-paste path-detection
logic via a new `extractImagePathFromText` export, then route the text
fallback through `handleImagePathPaste` whenever the clipboard text is
exactly one explicit image file path. Both keybind- and terminal-mediated
paste now agree.

Fixes #3506
2026-06-25 23:06:39 +00:00
roboomp 99668abd41 fix(agent): minted per-turn sentinel for streaming esc arm
Replaced the streamingComponent/session token fallback with a per-turn sentinel that is reset on every agent_start/agent_end. The arm now survives the pre-message_start to post-message_start transition (and any later message_update churn) within a single turn instead of re-arming when streamingComponent first appears.
2026-06-25 19:22:33 +00:00
roboomp 4dc0c6a3b2 fix(agent): keyed streaming esc arm on streamingComponent
EventController replaces ctx.streamingMessage with a fresh immutable snapshot on every message_update, so keying the Esc arm on that reference invalidated it between presses and re-armed instead of cancelling. The arm now keys on ctx.streamingComponent — created once per message_start and stable across deltas — with ctx.session as the pre-message_start fallback, still cleared on agent_start/agent_end.
2026-06-25 19:06:34 +00:00
roboomp 3158435b8a fix(agent): cleared streaming esc arm on turn boundary
Subscribed the input controller to session lifecycle events so a fallback streaming Esc arm taken pre-message_start cannot carry across an agent_end/agent_start pair and abort a fresh turn within the 2s window.
2026-06-25 19:01:22 +00:00
roboomp a538cddd33 fix(tui): guarded streaming escape cancel
Added a two-step Esc guard for active streaming responses and deferred ordinary render scheduling behind queued input so Esc delivery stays responsive under streaming load.

Fixes #3493
2026-06-25 18:52:09 +00:00
can1357 61da80d2ae Merge PR #3468 into sweep 2026-06-25 18:53:34 +02:00
roboomp 039c93be60 fix(tui): restore streaming steer image draft on prompt error
Wrap the streaming Enter steer dispatch in try/catch so prompt failures restore text plus pendingImages / pendingImageLinks / imageLinks and surface showError instead of losing an image-only draft.\n\nAlso remove a forbidden ReturnType<> from the follow-up image regression helper.\n\nFixes #3467
2026-06-25 13:53:00 +00:00
roboomp b0bbd872c4 fix(tui): restore followup image draft on prompt error
Snapshot pendingImageLinks alongside pendingImages at the top of handleFollowUp and wrap both the streaming and idle session.prompt dispatches in try/catch that restores text + pendingImages + pendingImageLinks + imageLinks and surfaces showError, mirroring the main submit and focused submit error paths so an image-only or text+image Ctrl+Enter draft survives dispatch rejection.\n\nFixes #3467
2026-06-25 13:47:06 +00:00
roboomp a2a217277c fix(tui): restore focused submit image draft on prompt error
Snapshot pendingImageLinks and re-seed editor.pendingImages / pendingImageLinks / imageLinks in the focused-session submit catch block so an image-only or text+image draft survives a viewSession.prompt rejection, mirroring the main controller error path.\n\nFixes #3467
2026-06-25 13:40:14 +00:00
roboomp e24b70c09a fix(tui): queued image-only streaming submits
Treat pending pasted images as submit content in the main and focused input controller paths so image-only Enter/Ctrl+Enter submissions queue instead of dropping or aborting.\n\nFixes #3467
2026-06-25 13:32:18 +00:00
roboomp 184f6dd809 style: bun run fix 2026-06-25 11:41:56 +00:00
roboomp 8506fbdf52 fix(coding-agent): switched ctrl-z handler to SIGSTOP-self to defeat brush tokio SIGTSTP hijack
brush-core's Process::wait calls tokio::signal::unix::signal(SIGTSTP) to
detect when its children get stopped. Per tokio's documented contract,
the first call for a SignalKind permanently replaces the kernel-default
handler for the lifetime of the process. So once omp has executed any
bash tool call — even /usr/bin/true — SIGTSTP's default "stop" action
is gone, and InputController.handleCtrlZ's process.kill(0, "SIGTSTP")
gets swallowed by tokio. The TUI tore down via ui.stop() but the process
kept running in Sl+ state, leaving the user with a dead terminal that
only kill -9 could recover.

Send SIGSTOP to our own PID instead. SIGSTOP can't be caught, blocked,
or ignored — it stops the process at the kernel regardless of installed
handlers. Targeting self (not pgid=0) also leaves long-lived children
(MCP stdio servers, the persistent brush native shell) running across
the suspend, so they no longer freeze mid-IPC during a quick fg/bg
detour.

Fixes #3461
2026-06-25 11:33:35 +00:00
can1357 57e9848c8c refactor(coding-agent): removed automatic file attachment for non-image paste paths
- Removed `onPasteFilePath` handler to prevent automatic background file attachment when pasting paths.
- Updated `CustomEditor` to treat non-image paths as literal text input.
- Cleaned up unused file system utilities and paste path resolution logic.
2026-06-25 12:57:54 +02:00
can1357 d88d9bd6d8 Merge PR #3352: fix: store slash commands in input history (@oldschoola) 2026-06-24 18:26:17 +02:00
roboomp 4f20d10454 fix(tui): attached pasted file paths
Converted bracketed non-image filesystem path pastes into session-local attachment references while preserving the existing image path flow.

Added regression coverage for editor routing and controller local file attachment behavior.

Fixes #3360
2026-06-24 14:21:45 +00:00
oldschoola ff249f19e9 fix(tui): check thinking level directly instead of effectiveHideThinkingBlock
The previous guard used effectiveHideThinkingBlock which combines
hideThinkingBlock preference AND thinking-off state. When thinking
was enabled but hideThinkingBlock was true (user manually hid blocks),
the guard blocked the toggle, preventing users from showing blocks
again via Ctrl+T.

Fix: check session.thinkingLevel === Off directly, so the guard only
fires when thinking is genuinely off. When thinking is on, the toggle
works normally regardless of the current hideThinkingBlock preference.

Updated tests to set thinkingLevel on the mock context.
2026-06-23 16:02:10 -07:00
oldschoola c77fdffea9 fix(tui): guard both no-op cases for thinking toggle when thinking is off 2026-06-23 16:02:10 -07:00
oldschoola 579ba6a1dc fix(tui): auto-hide thinking blocks when thinking level is off
Some providers (MiniMax, GLM, DeepSeek) return thinking blocks in
their responses even when reasoning is disabled — the model generates
thinking content regardless of the reasoning_effort parameter.

When the user sets thinking level to "off", they expect no thinking
content to be visible. Previously, thinking blocks would still appear
because the hideThinkingBlock setting was independent of the thinking
level and defaulted to false (show).

Fix: add effectiveHideThinkingBlock computed property that returns
true when hideThinkingBlock is true OR the session thinking level is
"off". All render paths (streaming, transcript rebuild, component
construction) now read the effective value instead of the raw setting.

The toggle (Ctrl+T) is guarded: when thinking is off, it shows a
status message ("Thinking is off — enable thinking to show blocks")
instead of silently no-op'ing or corrupting the persisted setting.

Fixes #626
2026-06-23 16:02:10 -07:00
oldschoola a6bfb8c0e1 fix: record slash commands with inline prompts to history
Address P2 review: when executeBuiltinSlashCommand returns a string
(e.g. /loop 10 fix bug → 'fix bug'), the original slash command text
was not recorded to history — only the extracted prompt was. Now the
original text is added to history before reassigning, so Up Arrow
recalls '/loop 10 fix bug' rather than just 'fix bug'.

Applied to both Enter and Ctrl+Enter submit paths.
2026-06-23 15:23:14 -07:00
oldschoola 00fd6f2263 fix: handle colon-separator bypass and /join secrets in history filter
Address three P1 code review comments on PR #3352:

1. Colon-separator bypass: parseSlashCommand() treats ':' as an argument
   separator, but shouldSkipHistory only split on whitespace. So
   /login:?code=abc&state=xyz bypassed the filter. Now uses the same
   earliest-whitespace-or-colon splitting as parseSlashCommand.

2. /join <link> secret: the collab join link carries a 32-byte room key
   and optional write token. Add /join to the denylist — skip any /join
   with arguments.

3. Added regression tests for colon-separator forms and /join denylist.
2026-06-23 15:01:07 -07:00
oldschoola c6c2c386bc fix: skip all /login args from history (P1 security review)
parseCallbackInput() accepts three forms: redirect URLs, query strings
(?code=...), and raw auth codes — all carry OAuth secrets. The previous
filter only skipped URL-like inputs, leaking query strings and raw codes.

Skip ALL /login commands with any argument. The minor convenience loss
(can't recall /login <provider>) is far less important than the risk of
persisting OAuth authorization codes.
2026-06-23 14:17:35 -07:00
oldschoola 715eb0792c fix: store slash commands in input history (#3148)
Previously only 4 commands (/plan, /goal, /mcp, /ssh) stored their text
in history via per-handler addToHistory calls. All other built-in slash
commands were silently skipped because executeBuiltinSlashCommand returned
true before the input controller's addToHistory was reached.

- Centralize history recording in the input controller after successful
  slash command dispatch, for both Enter and Ctrl+Enter submit paths.
- Remove all 10 per-command addToHistory calls from slash command handlers
  to prevent duplicates.
- Add shouldSkipHistory() security filter to exclude commands that may
  carry secrets: /login <url> (OAuth callback with code=/state= params)
  and /mcp add --token <token> (bearer token).
- Add regression tests for the security filter (8 cases).
- Update 7 existing test files to remove handler-level addToHistory
  assertions (now the input controller's responsibility).
2026-06-23 14:11:12 -07:00
can1357 93db34b0d5 refactor(coding-agent): consolidated editor state and unify transcript rendering
- Centralized draft state and image management by migrating fields from context to the CustomEditor component.
- Standardized transcript row construction by introducing shared helpers for background jobs, IRC traffic, and file mentions.
- Refactored redundant UI logic and helper functions into reusable utility modules to streamline message submission and component rendering.
- Standardized event handler types by consolidating lifecycle definitions into a shared module while maintaining public API stability.
2026-06-22 06:11:57 +02:00
can1357 aa87848f1a fix(coding-agent): prevented accidental cancellation of background maintenance
- Stop the Esc key from aborting active background maintenance (compaction, handoff, or retry) while a subagent is focused.
- Remove "(esc to cancel)" hints from maintenance loaders when a subagent is active to avoid false affordance.
- Ensure that main-session maintenance remains cancellable via Esc when no subagent is focused.

Fixes #2819
2026-06-21 00:00:35 +02:00
can1357 9f34c45d94 fix(coding-agent/modes): restricted branch key input to focused editor
- Added a check to ensure the editor is focused before allowing the branch keyboard shortcut.
2026-06-20 23:57:29 +02:00
can1357 aaac4e414f Merge PR #2950: feat(coding-agent): add copy affordance to completed /btw answers (@wolfiesch)
Adds 'c copy' to the completed /btw panel footer (alongside b branch / Esc
dismiss), copying the sanitized visible answer to the clipboard. The copy
shortcut is guarded by canCopyBtw + main-editor focus + empty editor.
2026-06-20 23:56:24 +02:00
can1357 282963ee2f feat(coding-agent): supported omitting thinking summaries
- Added `omitThinking` setting to allow instruction of upstream providers to omit thinking summaries.
- Decoupled UI-level thinking block visibility from backend data retrieval.
- Updated session creation to use `omitThinking` for configuring provider-side summaries.
2026-06-20 08:14:54 +02:00
can1357 bc96f52cb7 feat(coding-agent): forced display reset on thinking visibility toggle
- Replace individual component invalidation with a full display reset when toggling thinking block visibility.
- Ensure stale snapshots of thinking blocks in terminal scrollback are retired correctly.
2026-06-19 04:12:25 +02:00
Wolfgang Schoenberger 66de05b615 fix(coding-agent): keep btw copy shortcut in editor focus 2026-06-18 13:30:26 -07:00
Wolfgang Schoenberger a2addd1175 feat(coding-agent): add btw copy affordance 2026-06-18 13:28:37 -07:00
roboomp 6cd16d6373 fix(tui): required space after python prompt sigil
Treat shell-style leading variables such as $HOME as normal chat text instead of Python eval input. Keep local Python shortcuts available through explicit $ <code> and $$ <code> prefixes.\n\nFixes #2944
2026-06-18 07:39:15 +00:00
can1357 4a1f3483c7 feat(coding-agent): promote completed /btw answers into branches (#2894) 2026-06-18 02:50:23 +02:00
KamijoToma 895cd6f157 fix(coding-agent): guard retry shortcut in collab 2026-06-18 02:35:33 +08:00
KamijoToma 9ecea39282 fix(coding-agent): address retry keybinding review 2026-06-18 02:21:44 +08:00
KamijoToma 6116b97a54 Add retry keybinding 2026-06-18 01:51:11 +08:00
KamijoToma d4df729396 fix(coding-agent): harden btw branch promotion 2026-06-18 01:15:07 +08:00
KamijoToma 52b3155cbd feat(coding-agent): branch completed btw answers 2026-06-18 00:58:23 +08:00
can1357 1e3909a151 fix(coding-agent/session): split queued-message editor restore between dequeue and interrupt
- Generalized `isUserQueuedMessage` to a user-attribution predicate (`role === "user"` or custom `attribution === "user"` and not display-suppressed) so visible agent-authored steers (advisor cards, IRC/extension asides) and hidden goal/plan/budget steers are all excluded from editor restore, not just advisor cards.
- Gave `AgentSession.clearQueue` a `{ forInterrupt }` option: plain Alt+Up dequeue restores user messages and preserves every other queued message for the continuing stream, while Esc+abort keeps only advisor cards (for `abort()`'s `#extractQueuedAdvisorCards` preservation) and drops other internal steers so the post-abort `#drainStrandedQueuedMessages` can't auto-resume the interrupted run.
- Threaded `forInterrupt: options?.abort` from `InputController.restoreQueuedMessagesToEditor` and kept `queuedMessageCount` on actual displayable-queue semantics so `hasPendingMessages()`/RPC and the empty-submit abort gate stay accurate.
- Updated skill-queue tests to cover both policies (hidden and visible agent-authored steers preserved on dequeue, dropped on interrupt) and refreshed the changelog entry.
2026-06-16 16:27:53 +02:00
can1357 bbb41a3c93 fix(coding-agent/modes): started orphaned idle submits as real prompts instead of steering them
- Changed `InputController`'s no-input-waiter submit path to call `session.prompt(text, { streamingBehavior: "steer", images })` instead of `session.steer(text, images)`, so a submission made while the loop is idle between turns starts a real prompt rather than queueing behind a non-resumable transcript; the steer streaming behavior still preserves queueing if a background turn races in.
- Updated the failure-recovery comment to reference prompt dispatch rejection.
- Rewrote `input-controller-orphan-submit.test.ts` to assert the `prompt` dispatch path and added a real-session case proving an orphaned idle submit starts via `agent.prompt` (not `continue`) and leaves no queued messages.
- Added the `### Fixed` CHANGELOG block under `[Unreleased]`; its three entries are adjacent lines forming one indivisible run, so this commit also carries the changelog text for the queued-restore and breadcrumb fixes that follow.
2026-06-16 16:05:23 +02:00
can1357 b1c0243bab fix(coding-agent): fixed advisor auto-resume suppression for user interruptions
- Passed USER_INTERRUPT_LABEL through abort paths in collab, ACP, RPC, runtime, and SDK flows.
- Added userInitiated to synthetic continue inputs and session prompt calls.
- Suppressed advisor auto-resume during user aborts and preserved queued concerns.
- Cleared suppression on user prompts and reclaimed parked advisor cards on abort settle.
2026-06-15 20:51:56 +02:00
can1357 fc2ba5073a fix(coding-agent): fixed interactive input queueing during session race windows
- Added a streamingBehavior field to submitted user inputs and threaded it through interactive mode types and controller start-up.
- Updated interactive submission dispatch to default to followUp queueing while preserving explicit steer intent when provided.
- Changed tests to verify followUp and steer queueing behavior, preventing AgentBusyError from race-window busy sessions.
2026-06-15 11:38:31 +02:00
can1357 a1070d055e feat(coding-agent/modes): updated large-paste menu with explicit attachment actions
- Replaced large-paste wrap options with a single `<attachment>` wrapper action.
- Added explicit local-file attachment and inline paste choices to the selector.
- Updated the changelog to document the new large-paste action set.
2026-06-15 07:33:25 +02:00
roboomp b0d0bd5bcb fix(coding-agent): cap session_shutdown extension handler at 2s
ExtensionRunner.emit shared the generic 30s EXTENSION_HANDLER_TIMEOUT_MS budget with every event, including the fire-and-forget session_shutdown teardown event extensions cannot observe. A hung third-party handler — observed on Windows with omp-discord-presence 0.1.2 waiting on a stuck Discord IPC pipe — held AgentSession.dispose() for the full window, making Ctrl+C look ignored for 30s.

session_shutdown now uses a dedicated 2s SESSION_SHUTDOWN_HANDLER_TIMEOUT_MS cap routed through a per-event handlerTimeoutForEvent() lookup so generic and shutdown budgets are independently configurable. The interactive-mode Ctrl+C path adds a defence-in-depth hard-exit: when isShuttingDown is true a fresh Ctrl+C exits with code 130 (the session JSONL has already been sync-flushed by the first press) instead of stacking another no-op shutdown() call.

Fixes #2600
2026-06-15 01:08:26 +00:00