Commit Graph
386 Commits
Author SHA1 Message Date
roboomp 20820b748c style: bun run fix 2026-06-04 06:52:55 +00:00
roboomp 32f07b24f7 fix(coding-agent): sync pi-natives on omp update
bun install -g <pkg>@<v> did not reliably re-resolve transitive
optionalDependencies, so @oh-my-pi/pi-natives and the platform leaf
@oh-my-pi/pi-natives-<tag> stayed at the previous version while
@oh-my-pi/pi-coding-agent moved. The loader’s validateLoadedBindings
then aborted because the .node file exposed the old
__piNativesV<old> sentinel instead of __piNativesV<new>.

buildBunInstallArgs now pins @oh-my-pi/pi-natives and (when the
running tag is one the release pipeline publishes) the platform
leaf to the same version it installs for @oh-my-pi/pi-coding-agent,
so bun replaces all three in lock-step. The leaf is gated by the
same SUPPORTED_PLATFORMS set the loader uses, so unsupported tags
still surface the original 'no matching version' diagnostic instead
of EBADPLATFORM.

Fixes #1824
2026-06-04 06:52:31 +00:00
can1357 dc4aeb7b88 refactor(coding-agent): renamed todo_write tool to todo
- Renamed `TodoWriteTool` to `TodoTool` and its source/prompt files.
- Updated tool registration, schema, renderers, and gating to `todo`.
- Adjusted cursor provider native tool names and tests to match.
- Renamed strike-animation constants and `todo-error-reminder` type.
2026-06-04 02:45:30 +02:00
Zaun 71a66140f1 fix(coding-agent): derive bun global cache path from bin 2026-06-03 14:37:26 +08:00
Zaun c2cbc89c7a fix(coding-agent): prune stale bun update cache
修复 omp update 更新后清理旧版 Bun 安装缓存。
2026-06-03 14:37:26 +08:00
Ogrodev c5011661db fix(coding-agent): bootstrap profiles for acp 2026-06-02 22:30:23 -03:00
Ogrodev f6d520df87 fix(coding-agent): hardened profile bootstrap and alias installation edge cases
Bootstrap: an unknown (extension) long flag now only protects a value-like
successor (mirroring parseArgs in args.ts), so a trailing global --profile/--alias
after a value-less extension flag is still extracted (omp --some-ext-flag --profile
work); a -- successor falls through to end-of-options instead of being swallowed.

Alias installer: on Windows the PowerShell edition is inferred from PSModulePath
(separator-anchored so WindowsPowerShell does not match pwsh), falling back to
POWERSHELL_DISTRIBUTION_CHANNEL, when $SHELL is unset; the fish alias path honors
$XDG_CONFIG_HOME. Env is threaded through install options for testability.

Also de-duplicated a stale 'Mnemosyne' changelog line left by the mnemosyne->mnemopi
rename and moved the profile-bootstrap edge-case note to [Unreleased].
2026-06-02 12:24:44 -03:00
Ogrodev d99590645c Merge remote-tracking branch 'upstream/main' into feat/profiles-and-alias
# Conflicts:
#	packages/coding-agent/src/cli/args.ts
2026-06-02 08:36:12 -03:00
can1357 7ad8e1260e feat(coding-agent): added Claude Code MITM proxy for /v1/messages capture
- Added local CONNECT proxy with TLS interception to capture Claude API traffic.
- Drives Claude Code via headless PTY/xterm and extracts the first /v1/messages exchange.
- Added `claude:trace` npm script and CLI with JSON/text output modes.
- Added integration test using a fake Claude script against a local TLS server.
2026-06-02 10:31:40 +02:00
can1357 3c398c7eb1 Merge remote-tracking branch 'origin/farm/48a24745/fix-anthropic-custom-headers-web-search' 2026-06-02 10:11:24 +02:00
roboomp 4bd0fe573c fix(anthropic): forward ANTHROPIC_CUSTOM_HEADERS for non-Foundry enterprise gateways
The Anthropic web search path built request headers via buildAnthropicSearchHeaders, which never threaded model headers through buildAnthropicHeaders, so ANTHROPIC_CUSTOM_HEADERS was dropped from every web-search request regardless of mode. The streaming path's resolveAnthropicCustomHeaders also gated on isFoundryEnabled(), so users with a corporate ANTHROPIC_BASE_URL + ANTHROPIC_CUSTOM_HEADERS (e.g. X-Gateway-Key) got 401s on web_search unless they set CLAUDE_CODE_USE_FOUNDRY=true.

Loosen the resolver to also apply when ANTHROPIC_BASE_URL points to a non-Anthropic host, export the baseUrl-keyed variant, and have buildAnthropicSearchHeaders pass the resolved custom headers as modelHeaders so search and streaming paths behave identically. Stock api.anthropic.com (no Foundry) still omits the headers.

Fixes #1693
2026-06-02 07:52:37 +00:00
roboomp 5b1e5a5c4a docs: documented ANTHROPIC_SEARCH_API_KEY and ANTHROPIC_SEARCH_BASE_URL
- Expanded the existing entries in docs/environment-variables.md so the override-semantics ('search-only, isolates from main ANTHROPIC_API_KEY / ANTHROPIC_BASE_URL / FOUNDRY_BASE_URL') are spelled out, and added a usage note for enterprise-gateway split routing.
- Surfaced the search-only env vars (ANTHROPIC_SEARCH_API_KEY / ANTHROPIC_SEARCH_BASE_URL / ANTHROPIC_SEARCH_MODEL) in the Anthropic provider section of docs/tools/web_search.md, where users were already looking.
- Added ANTHROPIC_SEARCH_BASE_URL alongside ANTHROPIC_SEARCH_API_KEY in 'omp --help' so the pair shows up together in the CLI env-var summary.

Fixes #1694
2026-06-02 07:49:59 +00:00
Can BölükandGitHub e5109e6c92 Merge pull request #1318 from ogormans-deptstack/feat/1313-hide-thinking-flag
feat: add --hide-thinking CLI flag to suppress thinking blocks in TUI
2026-06-02 09:31:49 +03:00
roboomp a3fbeb4a0a style: bun run fix 2026-06-02 06:19:00 +00:00
roboomp 9abce6e974 fix(update): pinned npm registry and bypassed bun cache for omp update
omp resolves the update target by querying https://registry.npmjs.org/ directly, but `bun install -g pkg@<version>` would then consult bun's on-disk manifest snapshot AND honour the user's npm-mirror configuration (corporate proxy, Taobao, …). Either source can lag the upstream registry by minutes-to-hours, in which case bun rejects the version with `No version matching "X" found for specifier "@oh-my-pi/pi-coding-agent" (but package exists)` even though the registry omp just queried is serving it.

The bun install step now runs with both `--no-cache` (skip the manifest snapshot) and `--registry=https://registry.npmjs.org/` (pin the official catalog regardless of bunfig/.npmrc) so the install observes the same registry state the version check used. The registry URL is centralised in an `NPM_REGISTRY` constant shared by `getLatestRelease` and `buildBunInstallArgs`.

Fixes #1686
2026-06-02 06:18:54 +00:00
can1357 7b3ea248d4 feat(coding-agent): enabled cross-project resume with folder/all scope fallback
- Enabled resume picker to preload sessions and toggle folder/all scope with Tab.
- Enabled resume flow to fall back to all-project sessions and switch cwd on resume.
- Added centralized applyCwdChange to refresh caches, commands, and UI after cwd updates.
- Updated session restoration to adopt restored session cwd and sessionDir when present.
2026-06-02 05:53:57 +02:00
can1357 783971f575 fix(history-storage): restored session_id column and prompt-history ranking
- Fixed `session_id` never being created or populated; every history row had `NULL` for session.
- Added schema migration (`ALTER TABLE history ADD COLUMN session_id`) for pre-existing databases.
- Wired interactive mode to call `setSessionResolver(...)` so prompts are stamped with the active session at submission time.
- Re-enabled session ranking in `--resume` and in-session pickers via `matchingSessionIds()`, merging fuzzy and prompt-history signals.
2026-06-02 05:15:56 +02:00
Ogrodev b4707629bf Fix CLI completion bootstrap tool imports 2026-06-01 22:37:01 -03:00
Ogrodev 575d06d8d3 Fix profile alias bootstrap 2026-05-31 13:29:43 -03:00
Ogrodev 1f67c58034 Merge branch 'main' of https://github.com/can1357/oh-my-pi into feat/profiles-and-alias
# Conflicts:
#	packages/coding-agent/src/cli.ts
#	packages/coding-agent/src/cli/args.ts
#	packages/coding-agent/src/main.ts
#	packages/utils/src/dirs.ts
2026-05-31 12:00:00 -03:00
can1357 1fbc2cbd79 fix(coding-agent): let extension flags shadow same-named built-ins in parseArgs
Follow-up to #1503. When an extension registered a flag whose name collides
with a value-taking built-in — e.g. plan-mode's boolean `--plan` vs the
built-in `--plan <plan-model>` selector — the extension-aware reparse still
took the built-in branch. `omp --extension plan-mode --plan "review the diff"`
consumed "review the diff" as the plan-model value, leaving parsed.messages
empty and overwriting result.plan with the prompt text. recoverFlagValue only
patched the extension flag value, not the corrupted parsed object that
applyExtensionFlags returns as initialArgs.

Fix at the source: parseArgs now checks the registered extension-flag set
BEFORE the built-in branches, so a registered flag is parsed with the
extension's semantics (boolean toggle / string value) and surfaces in
unknownFlags without consuming the following token or touching the built-in
field. This makes recoverFlagValue dead, so applyExtensionFlags is simplified
to read resolved values straight from unknownFlags.

Tests: parseArgs-level shadowing guard (boolean --plan keeps the message and
leaves result.plan unset); applyExtensionFlags message/built-in-field
preservation for colliding boolean (--plan) and string (--model) flags;
non-colliding flag-looking-value rule retained. Verified the new guards fail
without the shadowing fix.
2026-05-31 06:36:33 +02:00
Can BölükandGitHub 7ad52b25ff Merge pull request #1503 from erik-sv/upstream-pr/extension-flag-initial-message
fix(coding-agent): strip extension flags from the initial prompt
2026-05-31 07:25:03 +03:00
can1357 b48b825344 fix(coding-agent): process @file before session creation; drop built-in flag-name list
Two review fixes for the extension-flag/initial-prompt work:

1. @file ordering — `processFileArguments` runs `process.exit(1)` on a
   missing/unreadable file. It had been moved after `createSession`, which
   writes the terminal breadcrumb eagerly (SessionManager.create →
   #newSessionSync), so `omp @missing.md "x"` left a junk session/breadcrumb
   behind before exiting.

   Resolve extension-registered CLI flags BEFORE creating the session: load the
   session's extensions up front (new `loadSessionExtensions` helper, the single
   source of createAgentSession's discovery-branch logic), build an
   ExtensionFlagSink straight from the loaded extensions + runtime, re-parse
   argv, then process @file args — all before any session exists. The loaded
   result is handed back to createAgentSession via `preloadedExtensions` (now
   checked before `disableExtensionDiscovery`, so it can't double-load) and the
   same EventBus is shared, so no extra work. This keeps the P1#1 fix
   (`--flag @value` is the flag's value, not a file) while failing fast with no
   session side effects.

2. "Can we avoid the big list of names?" — removed the hand-maintained
   `BUILTIN_FLAG_NAMES` set (and its stale "rejected at registration" doc).
   `applyExtensionFlags` now always falls back to recovering a flag's value from
   argv when parseArgs didn't surface it; the recovery scan mirrors parseArgs's
   consumption rules (flag-looking space-form values stay their own flag) and is
   a no-op for flags that were absent or already surfaced, so no list of
   built-in names is needed.

Adds `ExtensionRunner.aggregateFlags` (static) so getFlags and the CLI's
pre-session sink share one implementation.

Tests: pre-session flag resolution via the exact main.ts sink pattern;
list-free recovery of an arbitrary colliding built-in (`--model`); and the
flag-looking-value rule. Verified typecheck + extension/runner/acp suites.
2026-05-31 06:23:15 +02:00
oldschoolaandcan1357 1452aecbe1 fixup(coding-agent): use generic example for github plugin install help 2026-05-31 04:46:08 +02:00
oldschoolaandcan1357 22e564a85d feat(coding-agent): accept GitHub/git URLs in plugin install
Extends `omp plugin install` to accept git sources alongside npm specs and
marketplace refs. Bun's installer already understands git URLs; the blocker
was `PluginManager.install`'s strict npm-name validator and the assumption
that the actual package name could be derived from the spec.

- `git-url.ts`: `parseGitUrl` now recognizes npm-style namespaced shorthand
  (`github:user/repo`, `gitlab:`, `bitbucket:`, `codeberg:`, `sourcehut:` /
  `srht:`), with optional `#ref` and `.git` suffix. Exposes `isGitSpec` as
  `parseGitUrl(s) !== null`. Existing protocol-URL and `git:` shorthand paths
  are untouched.
- `manager.ts`: `install()` branches on `isGitSpec`. Git specs go through a
  separate `validateGitSpec` (shell-metachar rejection only — `/`, `:`, `@`,
  `#`, `+` are legal) and the real package name is discovered by snapshotting
  `plugins/package.json` deps before `bun install` and diffing afterwards.
  Falls back to value-match on force-reinstall where the key already exists.
- Help text in `plugin-cli` documents the new sources and adds a github:
  example.

Smoke tested end-to-end on Windows with both forms against the test repo:
  PluginManager.install('github:oldschoola/omp-insights')
  PluginManager.install('https://github.com/oldschoola/omp-insights')
both resolve `@oldschoola/omp-insights@1.2.3` and write a correct lock entry.
Shell-injection probe (`github:foo/bar; rm -rf /`) is rejected.
2026-05-31 04:46:08 +02:00
Erik Svilichandcan1357 38d2341300 fix(coding-agent): preserve built-in-colliding extension flags instead of rejecting
The previous collision guard threw in registerFlag, which broke loading the
bundled plan-mode example extension (it registers `--plan`, also a built-in)
even when `--plan` was never passed — making a documented extension unusable.

Registering a built-in-named flag is a supported pattern: `--plan` is both the
built-in plan-model selector and plan-mode's boolean mode toggle, and the value
must reach both. So instead of rejecting, preserve delivery: remove the guard,
and in applyExtensionFlags recover a colliding flag's value from argv
(resolveCollidingFlag) when parseArgs routed it to the built-in branch and it
never reached unknownFlags. Non-colliding flags are unchanged (peer-* etc.).

Verified the real bundled plan-mode.ts loads with --plan registered and
delivered; replaced the reject-test with a loads-without-throwing regression
plus colliding-flag delivery coverage.
2026-05-31 04:45:51 +02:00
Erik Svilichandcan1357 d6f887d152 fix(coding-agent): close remaining extension-flag edge cases (GPT-5.5 review)
Three issues from an adversarial review, all rooted in the startup argv parse
running before extensions load:

1. Flag-looking string values (`--name --print`): the extension-aware reparse
   consumed the following token as the value, disagreeing with the startup
   parse that treated `--print` as the built-in flag — so the reparse could
   silently flip command shape. Extension string flags now consume a following
   token only in `--flag=value` form or when it is not flag-looking; pass a
   flag-looking value as `--flag=value`. Keeps both parses consistent.

2. `@file` string values (`--target @notes.md`): file args were processed from
   the startup parse, which misreads the value as a file and reads it into the
   prompt. processFileArguments now runs on the extension-aware parse
   (initialArgs.fileArgs); pipedInput stays early for mode detection.

3. Built-in collisions: an extension flag named like a built-in (e.g. `model`)
   was consumed by the built-in branch and never delivered to the runner.
   registerFlag now rejects names in BUILTIN_FLAG_NAMES with a clear error
   (isolated per-extension by loadExtension's try/catch).

Adds tests for all three plus the documented startup-parse misclassification.
2026-05-31 04:45:51 +02:00
Erik Svilichandcan1357 295c52a307 fix(coding-agent): drop unconsumed --flag=value values for non-consuming flags
Addresses review: a boolean flag in equals form still leaked its value. parseArgs
splices `--headless=true` into `--headless`, `true` so value-consuming flags can
pick the value up via `args[++i]`; a boolean flag sets itself without consuming
it, leaving `true` to fall through as a positional message — and since
applyExtensionFlags feeds this parse into buildInitialMessage, `omp
--headless=true "do the task"` sent `true` as the prompt.

Track the spliced value's index and, if no branch advanced past it (i.e. the
matched flag did not consume a value), drop it after the dispatch. Closes the
whole equals-form class — boolean extension flags and built-in non-consuming
flags (`--no-tools=true`, `--print=1`) alike — at the single parsing site.

Adds tests for boolean extension + built-in flags in equals form.
2026-05-31 04:45:51 +02:00
Erik Svilichandcan1357 b674e3a663 fix(coding-agent): unify extension-flag parsing through parseArgs
Addresses review: a string extension flag in equals form (--spawn-peer=reviewer)
was still leaking its value into the initial prompt. Root cause was a second,
hand-rolled argv parser in applyExtensionFlagValues that recognized only
`--flag` and `--flag value`, not `--flag=value`; it looked up the literal name
`spawn-peer=reviewer`, set nothing, and (because the reparse was gated on
"were values set") skipped the reparse entirely, so the extension-unaware
startup parse won — leaving `reviewer` as the first message. The extension
itself also never received the value.

Replace the duplicate parser with a single source of truth: extract
applyExtensionFlags() into cli/extension-flags.ts, which re-parses argv through
the same parseArgs() the startup pass uses (now seeded with the registered
flags) and pushes the resulting values onto the runner. parseArgs already
normalizes `--flag`, `--flag value`, and `--flag=value` identically, so no flag
form can be handled by one parser and missed by the other. The reparse is now
gated on registered-flag presence, not on values having been set.

Wires parseArgs's previously-unused `unknownFlags` output to the runner, and
removes the now-redundant parseArgs import from main.ts. Adds unit tests for
applyExtensionFlags across all flag forms (including equals form) plus the
no-runner / no-flags / no-args-passed gate cases.
2026-05-31 04:45:51 +02:00
Erik Svilichandcan1357 15f6f52e08 fix(coding-agent): make parseArgs non-mutating to fix double-splice on reparse
The `--option=value` handling splices the value into the argv to reuse the
`args[++i]` path, mutating the caller's array. The post-extension reparse in
runRootCommand then ran on that already-mutated argv, so

    omp --model=sonnet --spawn-peer reviewer "review"

re-spliced `sonnet` and leaked it into the initial prompt before "review".

parseArgs now copies its input and never mutates the caller's array, so
launch, acp, and the reparse are all safe. Drops the now-redundant
`[...rawArgs]` copy at the reparse site, and adds regression coverage for the
--option=value + extension-flag combo plus input non-mutation.
2026-05-31 04:45:51 +02:00
can1357 5f63165637 feat(setup-wizard): added interactive onboarding wizard on first launch
- Added setup wizard with provider login, glyph mode, and theme scenes shown once per setup version.
- Wired `omp setup` (no args) to trigger the wizard in a TTY; `--check`/`--json` still show help.
- Extracted `gradientEscape` and exported `PI_LOGO`/`ShineConfig` from welcome for shared use in splash/outro.
- Fixed race condition in `setSymbolPreset`/`setColorBlindMode` by tracking load request IDs.
2026-05-31 00:07:14 +02:00
can1357 d73393cf5c feat(cli): added shell completions for bash, zsh, and fish
- Added `omp completions ` command generating scripts from live command/flag metadata.
- Added hidden `omp __complete` helper for dynamic model and session candidates.
- Completions never drift from the CLI: flags, enums, and subcommands are derived from static descriptors.
2026-05-30 21:32:03 +02:00
can1357 f0b252449b feat(coding-agent): added tiny local model support for memory extraction and consolidation
- Added a new `providers.memoryModel` setting with tiny memory model options and `ONLINE_MEMORY_MODEL_KEY` default in settings.
- Updated Mnemosyne provider resolution so a configured local tiny model overrode remote completion and used new memory extraction and consolidation prompts.
- Expanded the tiny-model CLI registry to download and report all local tiny models (title plus memory) through a unified list.
2026-05-30 18:48:47 +02:00
can1357 a53acf1431 test(coding-agent): updated hashline preview tests to use snapshot-tagged headers
- Updated hashline streaming preview tests to generate snapshot-tagged section headers and use an in-memory snapshot store.
- Replaced untagged file markers in multi-section preview inputs with `formatHashlineHeader` values derived from recorded file contents.
- Changed the bash command error test to expect a returned `isError` result with exit code 1 instead of a rejected promise.
2026-05-30 17:51:11 +02:00
can1357 826c3b932d refactor(packages/coding-agent): reorganized tiny-title runtime stack
- Added tiny-title protocol contracts, including progress-state unions, message payloads, and transport interfaces.
- Added title text utilities to truncate long inputs, wrap `<user-message>` blocks, and normalize generated titles.
- Added tiny-title model registry and helpers with type-safe keys and runtime optional loading via optionalDependencies.
- Added client-side worker orchestration with spawn fallback, request queueing, progress/error routing, and smoke-test APIs.
- Added worker runtime for model resolution, prompt-based inference, lock-based install retries, and close-time cache clear.
2026-05-30 17:40:18 +02:00
Ogrodev 2e4f258050 fix(profiles): harden alias upsert, env precedence, and bootstrap flag handling
- profile-alias: refuse to rewrite a managed block whose start marker lacks a
  matching end marker instead of appending, which on the next install would
  splice from the stale start through the new end and delete intervening user
  shell config (data loss in dotfiles).
- dirs/cli: add resolveProfileEnv so OMP_PROFILE takes precedence and an
  explicitly-empty OMP_PROFILE selects the default profile instead of falling
  through to PI_PROFILE; share the rule across both env-read sites.
- dirs: reject uppercase profile names so profile identity/isolation is stable
  across case-sensitive and case-insensitive filesystems.
- profile-bootstrap: treat an unclassified bare long option as a possible
  extension string flag and forward its successor untouched (never as a global
  --profile/--alias), while exempting known value-less launch flags via
  VALUELESS_FLAGS so 'omp --print --profile work' still selects a profile.
- tests: cover all four contracts.
2026-05-30 11:05:30 -03:00
Ogrodev 458482613b fix(profile-bootstrap): extract profile flags beyond subcommand-shaped tokens
- Allow parsing global profile flags after an early launch token is chosen
- Only the first residual token can terminate subcommand dispatch scanning
- Keep `--profile` parsing active when later argv contains subcommand-like words
- Add coverage for launch argv that include command names before/after profile args
2026-05-30 10:17:35 -03:00
Ogrodev c41bb8c170 fix(profile-alias): align alias install handling for edge cases
- Reject /bin/sh as unsupported shell instead of mapping it to bash
- Make alias-shadow check for `omp` case-insensitive
- Preserve non-ENOENT read failures when loading shell config
- Treat missing shell config file as empty for fresh installs
- Add targeted tests for case-insensitive alias rejection, sh rejection, and read error behavior
2026-05-30 10:17:34 -03:00
Ogrodev 6c251ad5dd fix(coding-agent): validate profile before rendering alias script
- Use normalizeProfileName in installProfileAlias instead of raw trim/default checks
- Preserve error path for invalid/empty profile names before shell block rendering
- Keep behavior consistent with shared profile normalization logic
2026-05-30 09:39:26 -03:00
Ogrodev 3a50761153 fix(coding-agent): handle -- boundary and subcommands in CLI parsing
- Add POSIX `--` end-of-options handling in argument parser
- Stop consuming flags after `--` and pass remaining tokens as messages
- Stop global `--profile`/alias extraction at first registered subcommand
- Add focused tests for parseArgs and profile bootstrap boundary behavior
2026-05-30 09:08:15 -03:00
Ogrodev c800e1524a Merge remote-tracking branch 'upstream/main' into feat/profiles-and-alias
# Conflicts:
#	packages/coding-agent/src/cli.ts
2026-05-29 21:55:39 -03:00
bench-local f6ca76728b feat(ai): add Wafer Pass and Wafer Serverless providers
Wafer (https://wafer.ai) exposes a single OpenAI-compatible endpoint
(`https://pass.wafer.ai/v1`) for two SKUs whose entitlement differs
server-side, so we model them as two parallel providers — mirroring the
firepass/fireworks split so a user with both subscriptions can switch
without re-pasting:

- `wafer-pass` — flat-rate. `/v1/models` is filtered to entries whose
  `wafer.tier === "pass_included"`.
- `wafer-serverless` — pay-as-you-go superset of Pass.

Both issue `wfr_…` keys. `/login wafer-pass` and `/login wafer-serverless`
paste-and-validate via `/v1/models`. `WAFER_PASS_API_KEY` and
`WAFER_SERVERLESS_API_KEY` are wired through `getEnvApiKey`.

Bundled catalog:
- `wafer-pass`: GLM-5.1, Qwen3.5-397B-A17B.
- `wafer-serverless`: GLM-5.1, Qwen3.5-397B-A17B, Kimi-K2.6, Qwen3.6-35B-A3B.

Dynamic discovery via `/v1/models` overlays additional models at runtime
and folds the `wafer` envelope (tier, capabilities, cents/M pricing) into
the canonical `Model<"openai-completions">` shape. GLM-family entries
carry the zai-style thinking compat (`thinkingFormat: "zai"`,
`reasoningContentField: "reasoning_content"`) so reasoning tokens land in
the right field. Cents-per-million → dollars-per-million via /100.

Tests (`packages/ai/test/wafer.test.ts`, 5 cases): bundled catalog
contract for both providers and wire-id pass-through (case-sensitive,
no rewrite — `GLM-5.1` must round-trip verbatim or upstream 404s).
Optional `packages/ai/test/wafer.live.ts` exercises a real round-trip
against `pass.wafer.ai` when `WAFER_PASS_API_KEY` is set.
2026-05-27 20:45:33 -07:00
can1357 3d5f0d8868 refactor(coding-agent/cli): switched auth-broker serve to dedicated logger transport setter
- Updated the auth-broker CLI to import the transport setter from the logger module.
- Replaced the logger.setTransports call in runServe with the dedicated setTransports helper.
2026-05-28 00:51:35 +02:00
can1357 6491fff8f6 feat(ai): added strict auth-gateway mode with completion-probe checks
- Added strict `auth-gateway` check mode, propagated `--strict`, and updated strict output/exit rules.
- Added `checkCredentials` completion-probe support with timeout and provider-aware payload helpers.
- Changed OAuth credential checks to refresh first, preserve usage results, and skip completion on refresh failures.
- Added tests for completion-probe execution, OAuth refresh rejection, and `completion.reason`/sentinel behavior.
2026-05-28 00:35:15 +02:00
Ogrodev efac908118 fix(coding-agent): restore empty-string resume handling
Refactored the optional-value flag handling so per-flag quirks live in
shared metadata instead of the args.ts dispatch loop. Added
OPTIONAL_FLAGS in cli/flag-tables.ts with rejectEmpty and
rejectAtPrefix controls, then updated both parseArgs and the profile
bootstrap to consult the same source of truth.

This restores the pre-refactor behavior for `--resume`, `-r`, and
`--session`: an empty-string argv token is treated as “no value
provided”, leaving resume=true and the empty string to fall through as a
positional message on the next iteration. `--list-models` intentionally
keeps its existing empty-string behavior.

Added regressions for parseArgs(["--resume", ""]), parseArgs(["-r",
""]), parseArgs(["--session", ""]), the preserved
`--list-models` empty-string behavior, and the bootstrap path where an
empty-string resume value precedes `--profile`.
2026-05-27 10:09:15 -03:00
Ogrodev 09cb4fe6d7 fix(coding-agent): added --approval-mode to bootstrap STRING_VALUE_FLAGS
`--approval-mode` is a string-valued flag in args.ts (`args[++i]` with
no `-` prefix check), but profile-bootstrap.ts did not list it in
STRING_VALUE_FLAGS. As a result `omp --approval-mode --profile foo`
was rewritten to `argv: ["--approval-mode"]` and silently activated
profile `foo` instead of passing `--profile` through as the invalid
approval-mode value — the exact corruption the pre-parser exists to
prevent for string-valued flags.

Caught in code review of PR #1435 after upstream merge brought in
`--approval-mode`. `--auto-approve`/`--yolo` are boolean and require
no entry. Added a regression test that mirrors the existing
`--system-prompt` coverage so future upstream merges that add
string-valued flags can be caught the same way.
2026-05-27 08:14:43 -03:00
Ogrodev 680917f02a feat: added isolated profiles with --profile and --alias
Added named OMP profiles that isolate agent state (auth credentials,
sessions, settings, model cache, history, memories, blobs, plus
config root subdirs) under `~/.omp/profiles/<name>/agent/`. Activated
via `--profile <name>` or `OMP_PROFILE=<name>`; `default` maps back to
the regular `~/.omp/agent/` tree.

Added `--alias <command>` to generate a shell shortcut (e.g.
`omp-work`) that forwards `omp --profile <name>`. Detects the active
shell (bash, zsh, fish, PowerShell, pwsh), writes a wrapper into the
correct rc file, and preserves subcommands like `update`, `--version`,
and `--model` because the wrapper passes through argv unchanged.

The `--profile`/`--alias` bootstrap pre-parser lives in
`packages/coding-agent/src/cli/profile-bootstrap.ts` and runs before
any module that touches `getAgentDir()` (notably `@oh-my-pi/pi-utils/env`,
which eagerly loads `.env` from the agent directory at its own import
time). The pre-parser mirrors `parseArgs` value-consumption rules and
honors `--`, so commands like `omp --system-prompt --profile foo` pass
the literal `--profile` through as the prompt body instead of silently
activating profile `foo`.

XDG resolution for named profiles is keyed on the profile-specific
XDG path (`$XDG_*_HOME/omp/profiles/<name>`), never the base app root,
so a profile's location is decided once at first activation and stays
stable even after `omp config init-xdg` materializes the base later.
The default profile keeps its existing base-app-root check.

`setProfile(undefined)` (and `setProfile("default")`) restores the
pre-profile `PI_CODING_AGENT_DIR` snapshot taken at first activation
instead of unconditionally deleting it. `setAgentDir` refreshes the
snapshot since that call is the user explicitly redefining the
baseline.

Validation rejects profile names that match `.`/`..`, fail
`/^[A-Za-z0-9][A-Za-z0-9._-]{0,63}$/`, or hit a Windows reserved
device name (`CON`, `PRN`, `AUX`, `NUL`, `COM0-9`, `LPT0-9`, including
dotted variants like `CON.txt`) — those would let `setProfile` accept
the input only for directory creation to fail later with confusing
errors on Windows.
2026-05-27 07:50:45 -03:00
can1357 e4a16451ec feat(coding-agent): added coding-agent approval types and mode options
- Added `ToolTier`, `ToolApproval`, and `ToolApprovalDecision` types and exported approval APIs.
- Updated approval-mode options from `auto|prompt|custom` to `always-ask|write|yolo` and defaulted mode to `yolo`.
- Changed approval resolution to apply per-tool decisions first, then mode-tier limits, with legacy-mode migration.
- Assigned read/write/exec `approval` and approval-detail prompts across built-in, custom, extension, and MCP tools.
2026-05-26 21:52:16 +02:00
can1357 1aa5e980ac feat(coding-agent): added approval-mode CLI override for session tool settings
- Added a new `approvalMode` argument to CLI parsing with validation for `auto`, `prompt`, and `custom` values.
- Registered `--approval-mode` on the launch command so it appears in generated help output.
- Applied the parsed approval mode as a runtime override on `Settings`, ensuring downstream `tools.approvalMode` reads reflect the CLI value.
2026-05-26 21:06:26 +02:00
oldschoolaandcan1357 4d26453a0b feat(coding-agent): restore per-tool approval policies with safer defaults
Re-introduces the per-tool approval system from luzidd's commit 39124f3 (which
is no longer reachable from main) and improves it before re-landing.

What's restored:
- ApprovalPolicy (allow/deny/prompt) plus DEFAULT_APPROVAL_POLICIES.
- ACTION_EXCEPTIONS registry (LSP read-only, bash critical patterns).
- getApprovalPolicy() six-level resolution order.
- ExtensionToolWrapper.execute() gate before extension handlers.
- --auto-approve / --yolo CLI flag and tools.approval.<tool> user config.
- docs/approval-mode.md user guide.

What's improved over the original:
- Replaced unchecked 'as any' casts with typed unknown narrowing helpers.
- Validate userConfig values: invalid strings, numbers, etc. fall through to
  the built-in default instead of being silently honoured (typo no longer
  locks a tool out or grants implicit approval).
- Expanded CRITICAL_BASH_PATTERNS: chmod -R /, chown -R /, bash <(curl ...),
  writes to /etc/passwd|shadow|sudoers, shutdown/reboot/halt/init 0,
  kill -9 1, nc -e / nc -c reverse shells. Pattern shapes require a
  command-position boundary so 'npm run reboot-tests' and 'echo "shutdown the
  queue"' don't false-positive.
- Added DEBUG_READONLY_ACTIONS exception so DAP inspection actions (threads,
  stack_trace, variables, scopes, read_memory, …) auto-allow while
  execution-side actions (launch, attach, continue, evaluate, write_memory,
  set_breakpoint, …) still prompt.
- formatApprovalPrompt: labels mcp__<server>__<tool> calls as MCP server
  tools, surfaces ssh host + command, recognises the modern § hashline header
  for edit, and truncates >240-char fields so a heredoc-sized body cannot
  blow out the confirmation dialog.
- Test suite grown from 40 to 57 cases — new coverage for invalid user
  config, the extended critical-bash patterns, benign-keyword negatives,
  debug exceptions, MCP/ssh prompt formatting, and command truncation.

Verification:
- bun test packages/coding-agent/test/tools/approval.test.ts -> 57 pass
- bun x biome check . -> clean
- bun run check:ts across all 9 workspaces -> clean
2026-05-26 20:53:33 +02:00