Commit Graph

1240 Commits

Author SHA1 Message Date
can1357 063a04cd04 Merge PR #4518: fix(tool): reject root glob paths (@roboomp) 2026-07-05 13:03:07 +02:00
can1357 661a8794ef Merge PR #4529: fix(tui): handle invalid path render args (@roboomp) 2026-07-05 13:03:06 +02:00
roboomp b1ef7ce6aa fix(tool): kept bash fixup compatibility shim
Restored the exported bash-command-fixup subpath and bundled legacy registry entry while keeping BashTool from using the rewrite.

Fixes #4562
2026-07-04 20:23:43 +00:00
roboomp 281a01a2a0 fix(tool): removed unused bash fixup wrapper
Deleted the coding-agent wrapper and tests for the stripTrailingHeadTail command rewrite now that BashTool executes pipelines as written.

Fixes #4562
2026-07-04 20:16:30 +00:00
roboomp 6a1ea9bf27 fix(tool): preserved bash pipeline output
Removed the bash tool execution-path rewrite that stripped trailing head/tail pipeline stages before running commands.

Added regression coverage for short-reading final pipeline stages.

Fixes #4562
2026-07-04 19:40:31 +00:00
roboomp 0b7f4865a7 fix(tui): handled invalid path render args
Validated path-like renderer inputs before calling path helpers so provider-supplied arrays or objects cannot crash TUI rendering before schema validation reports the bad tool call.

Added renderer regression coverage for read, write, and edit call/result components with array and object path arguments.

Fixes #4525
2026-07-04 15:47:52 +00:00
roboomp cf14a74dde fix(tool): rejected root glob paths
Rejected slash-only glob search paths before resolveToCwd can collapse them to the session cwd.

Added contract coverage for both / and // root inputs.

Fixes #4516
2026-07-04 13:51:53 +00:00
can1357 6b90d34924 Merge remote-tracking branch 'origin/farm/96461c96/fix-browser-cmux-pending-unhandled-rejection' 2026-07-04 11:27:29 +02:00
can1357 141244ab21 Merge remote-tracking branch 'origin/farm/1f0795db/guard-write-render-content' 2026-07-04 11:27:12 +02:00
can1357 42fc4e6b0a refactor(agent): unified transcript block finalization logic
- Replaced commit-based stability checks with a unified `isTranscriptBlockFinalized` tracking mechanism.
- Removed deprecated provisional rendering configuration and flags across tool and renderer interfaces.
- Standardized native scrollback boundary logic to pin at the first unfinalized block using settled row verification.
- Updated and refactored test suites to validate block finalization and settled row boundaries instead of deprecated commit stability methods.
2026-07-04 11:22:05 +02:00
can1357 6e2bba871e feat(agent): implemented automated retry recovery and transcript compaction
- Introduced an automated retry recovery system to track, manage, and persist recovered error states within agent sessions.
- Enabled compact transcript rendering for recovered auto-retry errors by removing heuristic commit machinery.
- Improved raw read tracking and provenance in the ReadTool to support refined file snapshot recording and hashline editing.
- Excluded recovered assistant messages from default model context and updated event controllers to handle retry recovery life cycles.
2026-07-04 11:22:04 +02:00
roboomp a6a8258945 fix(browser): propagate cmux tab-close into the run body, not only the caller
Codex review of #4502 flagged that a bare `.catch(() => undefined)`
neutralizes the unhandledRejection but leaves the affected `runInTab`
call blocked inside `runCmuxCode` until timeout when the in-flight
code does not make another cmux socket request (e.g. `await
wait(60_000)`). `releaseTab` was signaling the run only by rejecting
an orphaned promise.

Wire the tab-close event all the way into the cmux run body:

- `PendingRun` gains a `closeAc: AbortController` that `releaseTab`
  aborts BEFORE calling `pending.reject`. `wait(...)` (via
  `waitForBrowserRun` -> `untilAborted`), in-flight cmux socket calls
  (via CmuxTab's `#request` -> `untilAborted`), and facade proxies
  (via `bindBrowserRunFacade`) all consume the composed signal, so
  the run body unwinds within a microtask instead of blocking to its
  own timeout.
- `runInTabWithSnapshot`'s cmux branch composes `closeAc.signal` into
  the run's signal (`AbortSignal.any([opts.signal, closeAc.signal])`)
  and now publishes `runCmuxCode(...)`'s outcome to the shared
  `promise` via `.then(resolve, reject)` and returns `await promise`.
  Both branches thus await the same promise, so `pending.reject`
  always has an attached handler (removing the original crash) AND
  the caller sees `Tab "..." was closed` immediately instead of
  waiting on the run's timeout.
- Drop the defensive `promise.catch(() => undefined)` — the promise
  is now actively consumed on both backends.

The new regression test adds a second case that exercises the
reviewer's exact scenario (`await wait(60_000);`) and asserts:
1. `pending.closeAc.signal.aborted` flips from `false` to `true`
   across `releaseTab`, with the tab-close error as its reason.
2. The awaited `runInTab(...)` rejects with `Tab "..." was closed`.
3. No `unhandledRejection` fires.

Verified locally by temporarily removing `closeAc.abort(...)` in
`releaseTab` — the new assertions fail; restoring it makes them pass.

Fixes #4499
2026-07-04 06:24:45 +00:00
roboomp 3622094e91 fix(browser): swallowed cmux tab-close rejection to prevent session crash
The cmux branch of `runInTabWithSnapshot` awaits `runCmuxCode(...)`
directly and never awaits/`.catch`es the `Promise.withResolvers()`
promise it stashes on `tab.pending`. When `releaseTab` walks pending
runs and calls `pending.reject(new ToolError("Tab ... was closed"))`
(a sibling subagent's `browser close --all`, session-scoped reap, etc.),
that orphaned promise had zero handlers and Bun surfaced the rejection
as `unhandledRejection`, which the CLI's top-level handler treats as
fatal — killing every other tab and subagent sharing the process, not
just the affected run.

Attach a no-op `.catch(() => undefined)` to the promise immediately
after creation. Inert for the worker branch (which still awaits the
same promise via `raceWithTimeout`, and attaching a second handler is
safe) and neutralizes the orphan on the cmux branch.

Adds a regression test that drives real `acquireBrowser` /
`acquireTab` / `runInTab` / `releaseTab` against a mocked
`CmuxSocketClient`, races `releaseTab` against an in-flight cmux run,
and asserts no `unhandledRejection` fires.

Fixes #4499
2026-07-04 06:06:18 +00:00
roboomp 74a8289404 fix(coding-agent): guarded write renderer content
Coerced runtime write content before preview rendering so truthy non-string transcript values cannot crash CR normalization, line counting, or highlighting.

Added regression coverage for pending write calls and merged write results with non-string runtime content.

Fixes #4495
2026-07-04 05:22:21 +00:00
roboomp 2b8c8cadfb fix(read): kept raw artifact chunks verbatim and broadened path-only resolution
Skipped the workflow notice on raw selectors so bounded raw reads stay byte-for-byte, and taught resolveToolSearchScope to request pathOnly resolution so ast_grep/ast_edit scope-only calls no longer trip the inline-content cap on large artifacts.

Fixes #4482
2026-07-03 23:36:57 +00:00
roboomp 7497e68189 fix(read): shortened artifact paths in user-visible notices
shortenPath() the artifact.path leaked into the read-tool 'Artifact storage' and 'Unbounded raw read blocked' notices so $HOME never appears verbatim; details.resolvedPath keeps the absolute path for tooling.

Fixes #4482
2026-07-03 23:20:20 +00:00
roboomp ff397cf27a fix(read): kept large artifacts reachable from path-only resolvers
Bash URL expansion and search/grep only need sourcePath; they now request pathOnly resolution so large artifacts stay usable for search/copy workflows while unbounded content materialization stays blocked.

Fixes #4482
2026-07-03 23:17:46 +00:00
roboomp a9bb4c7d59 fix(read): guarded large artifact raw reads
Resolved artifact:// reads to backing files before selector handling, streamed bounded reads, and blocked unbounded raw reads for large artifacts with recovery guidance.

Fixes #4482
2026-07-03 23:08:18 +00:00
can1357 1301d5b07a Merge remote-tracking branch 'origin/farm/f5b6b32e/fix-edit-anchor-fresh-read' 2026-07-02 23:43:10 +02:00
can1357 b9ce7ef103 Merge remote-tracking branch 'origin/farm/b15f12c7/ssh-repaint-topology'
# Conflicts:
#	packages/coding-agent/src/tools/renderers.ts
2026-07-02 23:42:59 +02:00
roboomp 157c1d1c7d fix(acp): reuse resolved bash shell for terminal/create wrap
Addresses codex review on #4335: the previous wrap dropped to cmd.exe on Windows, which broke bash tool semantics for $VAR, $(...), source, and POSIX quoting even when the local executor would have resolved Git Bash / bash.exe. The wrap now takes the resolved ShellConfig (shell binary + login/-c args + optional prefix) from settings.getShellConfig() and reuses it for the ACP terminal/create shape, so the ACP path matches the local path on both platforms. Tests updated to stub getShellConfig and assert the resolved-shell shape deterministically.
2026-07-02 17:59:56 +00:00
roboomp 7b52f64680 fix(acp): wrap bash tool shell line in /bin/sh -c for terminal/create
The bash tool routes commands through the ACP client's terminal/create when the client advertises the terminal capability. It was passing the full shell line as the ACP command field with no args, which relies on the client interpreting command through a shell. Per the ACP protocol docs, command is the executable and args is its argv tail; a spec-conformant client spawns them directly (no implicit shell), so any bash line with a space, pipe, &&, redirect, or $(...) failed with ENOENT and the agent silently degraded to read-only tools.

The bash tool now wraps the shell line before the createTerminal call: { command: /bin/sh, args: [-c, line] } on POSIX and { command: cmd.exe, args: [/d, /s, /c, line] } on Windows. /d/s/c matches Node's spawn({ shell: true }) convention (/s preserves the whole shell line as one argv element on the receiving end). process.platform on the agent side proxies the client's platform, which matches the near-universal ACP shape of an editor spawning omp as a co-hosted subprocess.

Fixes #4333
2026-07-02 17:53:58 +00:00
can1357 e73a25489c feat(coding-agent/tools): migrated path input from array to semicolon-delimited string
- Changed the `path` property from an array of strings to a single semicolon-delimited string across tool definitions and tests.
- Updated validation error messages to reflect the new `path` input format.
- Adjusted all relevant test cases to provide path targets as semicolon-separated strings.
2026-07-02 17:48:46 +02:00
roboomp cc97fada73 fix(tui): repainted ssh topology flips
- Added renderer hooks for first-result placeholder replacement and partial-result settle repaints.\n- Enabled the hooks for SSH and covered the streamed-placeholder and settle seams.\n\nFixes #4314
2026-07-02 13:01:24 +00:00
roboomp fd6f733290 style: bun run fix 2026-07-02 08:53:25 +00:00
roboomp b38eba2be7 fix(coding-agent): exclude column-clipped lines from seen-line provenance
Codex reviewer flagged that the ranged-read fallback recommended by
the patcher's over-cap reveal path (`path:N-M`) itself applies the
512-column cap and still records the displayed line numbers via
`recordSeenLinesFromBody`. On a minified wide anchor line, `read
file:N` shows only the clipped prefix but the line lands in the
tag's seenLines — a subsequent edit anchored at N then slips past
the seen-line guard.

- `packages/coding-agent/src/edit/file-snapshot-store.ts`:
  `recordSeenLinesFromBody` grows an optional `excludedLines` set;
  parsed line numbers matching it are filtered before recording.
- `packages/coding-agent/src/tools/read.ts`:
  `#readLocalFileMultiRange` and the single-range disk path build a
  `clippedLines` set alongside `columnTruncated` for both direct-range
  lines and `buildLineEntriesWithBlockContext` context lines, then
  pass it into `recordSeenLinesFromBody`.
- `packages/coding-agent/src/tools/grep.ts`:
  same wiring for the match line via `match.truncated`, plus a
  conservative length+`...`-marker heuristic for context lines
  (native `crates/pi-natives/src/grep.rs` `truncate_line` doesn't
  propagate a per-line flag on `contextBefore`/`contextAfter`; a
  proper native-side flag is a follow-up).
- `packages/coding-agent/test/edit/seen-line-guard.test.ts`:
  new case reads a 4KB single line and asserts the clipped line
  number stays out of `seenLines` and the edit against it still
  rejects with the seen-line guard.
2026-07-02 08:53:18 +00:00
can1357 3830ad353e merge PR #3843 (surviving delta): perf: streaming-reveal/render throughput + core hot-path optimizations (@oldschoola)
# Conflicts:
#	packages/coding-agent/src/config/model-resolver.ts
2026-07-02 10:31:45 +02:00
can1357 ebf41281e7 fix(tui): stop spinner ticks for frozen pending previews
The github renderer materializes plain Text per display rebuild, so its
animatedPendingPreview opt-in requested 30fps repaints with a frozen
glyph for the whole run_watch wait; drop the flag. Custom tools with
only one of renderCall/renderResult never route to the animated generic
fallback, so gate the unregistered-renderer spinner on both being
absent. Regression tests for both no-tick contracts.
2026-07-02 10:30:06 +02:00
can1357 6429de3e83 merge PR #4172: fix(tui): animate live tool spinners (@roboomp) 2026-07-02 10:30:06 +02:00
can1357 95b91c7f73 feat(coding-agent/tools)!: replaced paths arrays with path strings
- Replaced `grep`, `glob`, and `ast_grep` `paths` inputs with optional single `path` strings while preserving default workspace-root behavior.
- Added shared `toPathList` normalization for legacy arrays and JSON-encoded arrays across tool execution and TUI renderers.
- Updated prompts, fixtures, shims, transcript summaries, and tests to send and display the new `path` argument.
- Updated collab-web search tool cards to read `path` while falling back to legacy `paths` for historical transcripts.
- Recorded the contiguous coding-agent changelog run for the tool-path breaking change and adjacent TTS entries.
2026-07-02 08:30:33 +02:00
can1357 0159d86023 Merge remote-tracking branch 'origin/farm/bf21f607/frame-rewind-completion' 2026-07-02 03:08:23 +02:00
roboomp 1109c25629 fix(agent): framed completed rewind context
Wrapped retained rewind reports with completion guidance so the post-rewind turn knows the checkpoint is closed.

Added repeat-rewind recovery errors and regression coverage for both the retained context and no-active-checkpoint path.

Fixes #4187
2026-07-02 00:56:06 +00:00
can1357 7e4d27a9e8 fix(coding-agent): fixed cross-file write batching regression in apply_patch
- Reverted to flushing only on the last file write or explicitly on early failure paths within `apply_patch` multi-file operations.
- Refactored error counting logic within single path entries to use clean booleans instead of numeric counters.
- Replaced custom preview capping logic in task progress rendering with `capPreviewLines` and added an option to hide the expand hint.
2026-07-02 02:46:55 +02:00
can1357 978b950804 fix(coding-agent): resolved path resolution and fetch errors for fuzzy urls
- Fixed grep and ast-grep tools rejecting fuzzy url-shaped paths like schemeless www. or collapsed-scheme spellings.
- Applied the extra-CA wrapper to the model registry default fetch to respect the NODE_EXTRA_CA_CERTS environment variable.
- Moved isReadableUrlPath utility to path-utils to share recognition logic between reading and searching pipelines.
- Implemented a fallback that checks if a directory matching a fuzzy URL path exists locally before resolving it as an external URL.
- Added explicit errors for unsupported URL schemes to replace misleading local-path errors.
2026-07-02 01:51:09 +02:00
can1357 efbdb23581 fix(coding-agent): enabled closed union validation for yield labels
- Extends output schema validation to support `oneOf` and `anyOf` closed union schemas.
- Prevents unknown section label submissions when all union variants constraint allowed properties.
- Permits arbitrary yield labels when at least one union variant remains open.
- Supports JTD discriminator output schemas by treating union constraints disjunctively.
2026-07-02 01:51:09 +02:00
can1357 9756d5f6c6 fix(coding-agent): separated network timeout for git clone and fetch
- Added GIT_NETWORK_TIMEOUT_MS (30 min) for clone/fetch with an overridable timeoutMs option; local plumbing keeps the 5-minute cap.
- Migrated fetch() from a positional AbortSignal to an options object.
2026-07-02 00:32:58 +02:00
can1357 0823892295 fix(coding-agent): repaired type errors from merge sweep
- Restored CustomInputRow.priority field dropped in 3b80dc01d ask row budgeting.
- Narrowed dereferenced schema properties via isRecord in yield-assembly and output-schema-validator instead of untyped object access.
- Renamed stale advisorReadOnlyTools to advisorTools in advisor parity test.
- Narrowed AgentMessage content access in session-loader-stream test.
- Reformatted browser-schema test to satisfy biome.
2026-07-01 23:49:32 +02:00
can1357 1b3bcb98db refactor(coding-agent/tools): consolidated browser tool schemas into a single schema
- Consolidated `browserOpenSchema`, `browserCloseSchema`, and `browserRunSchema` into a single `browserSchema`.
- Simplified the `action` type definition to accept `'open' | 'close' | 'run'`.
- Updated schema validation tests to reflect the unified schema definition.
2026-07-01 23:18:17 +02:00
can1357 5f1ed0fcde chore: reformat 2026-07-01 23:14:36 +02:00
can1357 32f5820d66 Merge PR #4167: fix(tui): cap subagent live progress output (@roboomp) 2026-07-01 21:53:20 +02:00
can1357 021d4fc1e3 Merge PR #4161: fix(agent): interrupt waits for IRC delivery (@roboomp) 2026-07-01 21:53:19 +02:00
can1357 c982cb34e9 Merge PR #3987: fix(eval): keep agent progress commit-unstable while partial (@metaphorics) 2026-07-01 21:50:55 +02:00
can1357 aee8b091ee fix(agent): honor closed schema label edge cases 2026-07-01 21:50:54 +02:00
can1357 88e3e77f3e Merge PR #3927: fix(agent): reject stale yield labels for override schemas (@roboomp) 2026-07-01 21:50:54 +02:00
can1357 3b80dc01de fix(tui): cap sparse ask other gaps 2026-07-01 21:42:24 +02:00
can1357 278b715ab8 Merge PR #3662: fix(tui): keep ask Other context visible (@roboomp) 2026-07-01 21:42:24 +02:00
can1357 8350e4a139 fix URL search scope edge cases 2026-07-01 21:42:23 +02:00
can1357 6066814d3e Merge PR #3650: fix(tools): materialize URL paths for search scopes (@roboomp) 2026-07-01 21:42:23 +02:00
can1357 12120a1cd4 Merge PR #3647: fix(tool): require browser run code in schema (@roboomp) 2026-07-01 21:42:23 +02:00
roboomp fb2804247a fix(tui): gated live tool spinner ticks
Added renderer metadata for pending and partial result paths that visibly consume spinner frames.

Stopped headerless bash pending previews from scheduling repaint ticks while preserving eval and shell header animation.
2026-07-01 18:34:12 +00:00