Commit Graph

547 Commits

Author SHA1 Message Date
can1357 ac5500beda feat(coding-agent): introduced interactive cleanse command and mode interface
- Introduce CleanseBoardModel and clean up status board rendering logic.
- Decouple CLI and interactive modes with CleanseRunUi interface and core runner.
- Add CleansePanelComponent and controller to manage interactive cleanse overlay.
- Register builtin `/cleanse` slash command and integrate into interactive mode.
2026-08-20 04:15:54 +02:00
can1357 eced7ab08a feat: implemented live status board utility and agent progress tracking
- Implement a live status board utility for transient multi-line CLI status displays with TTY fallback support.
- Add progress callback support and forward subagent progress events to runner hooks.
- Update cleanse execution flow to track checker runs, agent progress, and status rendering.
- Add comprehensive unit tests for live board repainting and cleanse progress assertions.
2026-08-20 03:22:54 +02:00
can1357 5fb8d1f8bf Merge PR #8995: fix(cli): strip launch-global flags before non-launch subcommands (@roboomp) 2026-08-19 12:21:02 +02:00
roboomp ec56f8d4cf fix(cli): strip launch-global flags before non-launch subcommands
`resolveCliArgv` hoisted a subcommand hidden behind leading global launch
flags to the front and forwarded those flags to the subcommand's own
parser (#2970). Launch-shaped commands (`launch`/`acp`) share the launch
flag surface, but strict-parsing subcommands like `update` declare only
their own flags, so a leading `--cwd` reached `node:util.parseArgs` and
threw `Unknown option '--cwd'`. This bit users whose shell alias/wrapper
runs `omp --cwd <dir> update`.

Leading launch-global flags are now stripped when the hoisted subcommand
is not launch-shaped, and still forwarded for `launch`/`acp`. Shared the
launch-command set with the profile bootstrap to keep one source of truth.

Fixes #8891
2026-08-19 10:10:16 +00:00
roboomp 9cc881ce5b fix(mcp): refresh broker-backed MCP OAuth credentials
Remote OAuth MCP servers dropped out of /mcp under `omp auth-broker
serve` once their access token expired: neither the client nor the
broker could complete the refresh.

- Client: the MCP manager threw on the broker-redacted refresh sentinel
  (REMOTE_REFRESH_SENTINEL) instead of asking the broker to refresh. It
  now routes redacted MCP refreshes through
  AuthStorage.forceRefreshCredentialById, which calls back to the broker
  (the real refresh token never leaves the broker host).
- Broker: the serve process had no mcp_oauth:* refresh path, so
  POST /v1/credential/:id/refresh answered "Unknown OAuth provider". Its
  AuthStorage is now built with a refreshOAuthCredential override that
  refreshes MCP credentials with a generic refresh_token grant from the
  credential's embedded token endpoint and client id. The background
  refresher keeps MCP tokens live through the same path.

Extract shared refreshManagedMcpOAuthCredential and
mcpOAuthServerUrlFromCredentialId helpers so both paths use identical
refresh material selection and RFC 8707 fallback-resource logic.

Fixes #8933
2026-08-19 09:34:51 +00:00
can1357 8b741e5bc8 Merge PR #8785: fix(update): surface actionable message for unsupported proxy schemes (@roboomp) 2026-08-19 01:36:57 +02:00
can1357 2b35d690b0 docs(coding-agent): align resolveUpdateTarget docstring with symlink-gated manager probes 2026-08-19 01:36:05 +02:00
can1357 b4db9c84e7 Merge PR #8734: fix(coding-agent): resolve update target from the running binary, not the PATH launcher (@roboomp) 2026-08-19 01:36:04 +02:00
Anatoli Tsinovoy 16ad301117 fix(stats): restore configurable dashboard bind host 2026-08-17 09:46:49 +03:00
roboomp 42cbee962f fix(update): surface actionable message for unsupported proxy schemes
omp update re-threw Bun's raw fetch() UnsupportedProxyProtocol error, telling CLI users to pass verbose:true to fetch() — an instruction unavailable through the CLI. The update fetch catches now detect this failure and report which proxy env var uses an unsupported scheme plus the http/https requirement.

Fixes #8784
2026-08-17 03:08:38 +00:00
roboomp ead0a4ceb4 fix(coding-agent): resolved update target from running binary, not PATH launcher
resolveUpdateTargetFromPath gated the symlink->realpath resolution on
allowPackageManagers, so binary-only releases (a major bump or an explicit
omp.dist: "binary") wrote to the raw PATH symlink instead of the binary it
resolves to. On an admin shared install where /usr/local/bin/omp is a
root-owned symlink into a group-writable dir this either failed with EACCES
(writing <link>.new into the root-owned dir) or replaced the symlink with a
full copy, stranding the shared install behind a split-brain second binary.

Target selection no longer depends on the release's distribution channel: a
foreign symlink (a non-manager alias, an admin symlink into a shared install)
resolves to its real binary and the launcher is left intact in every channel.
A package-manager launcher (bun/npm) keeps its deliberate in-place takeover on
a binary-only release, detected by re-classifying the launcher as if managers
were allowed rather than by the channel flag. The manager bin dirs are probed
in the binary channel only when the launcher is a symlink, so plain-file
installs stay probe-free.

Fixes #8732
2026-08-16 15:00:23 +00:00
can1357 ac4caf3d75 Merge PR #8414: fix(models): isolate ambient hooks from catalog listing (@starlink-awaken) 2026-08-16 02:13:40 +02:00
can1357 a3c15d2dec feat(coding-agent/tools): implemented pdf page screenshot rendering
- Add `renderPdfPageScreenshot` to render PDF pages via headless Chromium.
- Update `ReadTool` to intercept legacy PDF image paths and return page screenshots.
- Ensure daemon clients are closed on read command exit.
2026-08-14 14:37:56 +02:00
can1357 642d6c0b31 fix(coding-agent): preserved linked update ownership
Detected npm and Bun ownership from the bin link immediate target within each precise global node_modules root. Foreign aliases now update their resolved standalone binary without replacing the alias.

Fixes #8468
2026-08-14 00:27:16 +02:00
can1357 6ecb1e3383 Revert "fix(coding-agent): routed foreign aliases to binary updates"
This reverts commit 834002adc5.
2026-08-14 00:13:49 +02:00
roboomp 834002adc5 fix(coding-agent): routed foreign aliases to binary updates
Resolved npm and bun bin-entry symlinks before selecting the update method, and preserved foreign aliases by replacing their standalone target.

Fixes #8468
2026-08-14 00:03:33 +02:00
can1357 b279db1790 test: refactored test suites to eliminate time-based sleeps and polling loops
- Replaced time-based sleeps and polling loops with event-driven promise resolvers and fake timers across agent and tool tests.
- Migrated test suites to share in-memory auth storage and fixtures using lifecycle hooks.
- Updated catalog model definitions, metadata, and configurations.
2026-08-13 19:32:22 +02:00
can1357 219123244e fix(update): serialize target swap under a per-target lock
Two overlapping `omp update` runs now share the target only for the
swap + stale-artifact sweep, guarded by withFileLock. This closes the
rollback race the unique-temp fix left open: a concurrent run's sweep
could delete a live run's .bak before its failed verification rolled it
back. The download stays outside the lock (unique temp path, safe to
overlap). Adds a regression covering a failed verification overlapping a
successful update.
2026-08-13 17:57:01 +02:00
can1357 69862139b3 Merge PR #8435: fix(update): unique temp path for concurrent self-updates (@roboomp) 2026-08-13 17:32:50 +02:00
roboomp 1d6d35bd24 fix(update): unique temp path for concurrent self-updates
Two overlapping `omp update` runs shared the fixed `<binary>.new` temp
path. downloadVerifiedBinary unlinks the target before writing, so the
second run's unlink deleted the first run's still-downloading temp file;
the first kept writing to its open fd (size and digest still passed),
then chmod hit the missing path and aborted with ENOENT.

Give the temp path the same unique per-attempt suffix the backup path
already uses (pid, timestamp, and a new process-local counter that also
covers same-millisecond, same-process collisions). Generalize the stale
backup sweep to also reclaim orphaned `.new` temp files, age-gated by the
download window so a concurrent run's in-progress temp is never deleted.

Fixes #8434
2026-08-13 15:17:41 +00:00
roboomp 3749478239 fix(cli): validated allowlists after tool discovery
Moved strict --tools validation to the completed session registry so extension modules, custom tool directories, and plugin manifest tools are all eligible while unknown names still fail startup.
2026-08-13 09:12:12 +00:00
roboomp 6980275a50 fix(cli): allowed extension tools in allowlists
Deferred --tools validation until extension discovery, then validated against built-in and registered tool names while preserving strict rejection of unknown names.

Fixes #8421
2026-08-13 08:53:59 +00:00
starlink-awaken d3ad83b3a8 fix(models): isolate ambient hooks from catalog listing 2026-08-13 15:01:53 +08:00
can1357 1132c3e31c feat: implemented anthropic keep-alive and migration support for updates
- Added Anthropic prompt-cache refresh scheduling and state management to keep prompts warm across idle sessions.
- Updated pricing models and database stats tracking to calculate and store cost-weighted cache savings.
- Integrated cache savings metrics and efficiency displays into the stats CLI, dashboard routes, and UI components.
- Added support for package renaming, manifest pointer tracking, and installation migration during CLI updates.
2026-08-13 04:59:33 +02:00
can1357 b60bef961c feat: introduced nix packaging and path-based binary resolution
- Add comprehensive Nix flake definitions, derivations, modules, and CI workflows.
- Update tests and executables to resolve binaries from PATH rather than absolute paths.
- Ensure byte reproducibility and zeroed timestamps in embedded dashboard archives.
- Add handling for Nix-managed installations in CLI update checks.
2026-08-13 03:52:47 +02:00
can1357 386dc826ef Merge PR #8236: fix(cli): handle standalone profile aliases (@roboomp) 2026-08-13 01:14:51 +02:00
can1357 a4d8860a6c feat: added google reasoning controls mcp stream resumption and tar support
- Added Google provider thinking configuration parameters and force-reasoning-off controls.
- Implemented MCP SSE stream resumption using Last-Event-ID and `SSEResumeError`.
- Added support for TAR old-GNU sparse extension blocks, path length checks, and archive entry overrides.
- Restricted external thinking support to specific models and added semver fallback parsing.
2026-08-12 02:32:45 +02:00
can1357 19c0afcc0d feat: implemented external thinking flags and transport reasoning controls
- Added the `--external-thinking` CLI flag alongside model capability checks to gate external thinking tool availability.
- Updated Anthropic and Google transports to honor `forceReasoningOff` for native thinking-off controls.
- Renamed the `thoughts` property and parameter to `notes` across think fixtures, tools, and tests.
- Updated system prompt instructions and test suites to verify transport-specific thinking and tool activation.
2026-08-12 02:23:17 +02:00
can1357 93fed035f6 feat(coding-agent/cleanse): introduced discovery subagent and tui flows
- Added discovery subagent and custom checker specifications for alternative toolings across multiple languages.
- Implemented interactive TUI flows for target picking and free-form request discovery.
- Added output parsers for popular static analysis and linting tools.
- Increased default maximum subagents cap and documented the new capabilities.
2026-08-12 00:58:12 +02:00
can1357 1217ee1317 feat(coding-agent/compress): implemented semantic compression command and protocol
- Implemented the `omp compress` command with batch processing, file resolution, and concurrency support.
- Added the semantic compression protocol, session factory, and rewrite-approve evaluation loop.
- Included prompt templates, tool descriptions, and comprehensive test coverage for compression targets.
- Generalized the progress reporter module for shared use across CLI commands.
2026-08-12 00:46:08 +02:00
can1357 052095e156 test(coding-agent): fixed think-tool CI failures in gallery and activation tests
- Added a curated think gallery fixture; the generic fallback carries no
  thoughts field, so the streaming state rendered zero lines.
- Seeded the shared test registry with a runtime openai key: the prompt
  preflight validates through the registry, not the per-request getApiKey
  override, so keyless CI runners threw before reaching the mock server.
- Expected reasoning effort "none" — the only disable level the Responses
  wire accepts; "off" is not a wire value.
2026-08-11 21:16:13 +02:00
can1357 af52e1de0f refactor(coding-agent): verified binary updates by explicit path
- Extracted version verification logic into a reusable function accepting an explicit binary path.
- Updated shim takeover to verify the newly placed executable path directly instead of re-resolving via PATH.
2026-08-11 16:02:23 +02:00
can1357 87a18e3880 feat(cli): enabled binary updates and script-shim takeover on windows
- Added `resolveReleaseDist` and `shouldForceBinaryUpdate` to parse package manifests and gate major updates to binary releases.
- Implemented `updateViaShimTakeover` in `update-cli.ts` to seamlessly replace Windows script launchers with standalone binaries.
- Added comprehensive unit tests covering release distribution parsing, binary force updates, and script-shim takeover behavior.
2026-08-11 15:49:50 +02:00
roboomp 133e42e34b fix(cli): handled standalone profile aliases
Detected Bun-compiled entry points before preserving source invocations. Added a regression for the virtual bunfs argv shape and documented the fix.

Fixes #8233
2026-08-11 09:19:01 +00:00
roboomp b7d83ed931 fix(cli): kept marketplace uninstall scope positional
The earlier dry-run change moved scope into an options object, silently
ignoring the legacy uninstallPlugin(id, "user") runtime shape still reachable
from compiled or plain-JS callers. Restore scope as the positional second
argument and carry dryRun in a trailing options bag, preserving the existing
call shape while keeping the non-mutating dry-run path.

Fixes #8178
2026-08-10 18:10:30 +00:00
roboomp 15a9346c29 fix(cli): preserved uninstall dry-run validation
Route marketplace dry-runs through MarketplaceManager's normal pre-mutation
validation so ambiguous or mismatched scopes fail exactly as real uninstalls
do. Move the manager's scope argument into an options object and add a dry-run
option that returns only after all removal planning has succeeded.

Fixes #8178
2026-08-10 18:02:21 +00:00
roboomp e2925a527b fix(cli): honored dry-run in plugin uninstall
handleUninstall dropped the parsed dryRun flag and unconditionally called
mktMgr.uninstallPlugin / manager.uninstall, so `omp plugin uninstall
<plugin> --dry-run` removed the plugin on both the marketplace and npm
routes. Propagate dryRun into handleUninstall and short-circuit before
both removal calls, reporting the resolved removal (with its source)
instead of mutating state.

Fixes #8178
2026-08-10 17:53:49 +00:00
can1357 9637a2cb0c Merge PR #7774: fix(tui): gate built-in renderers by tool provenance (@roboomp) 2026-08-07 13:37:57 +02:00
can1357 102eaa4543 feat(cli): added omp share command for saved sessions
Shares a saved session by id prefix or .jsonl path without launching the
agent - same encrypted upload, store selection, and share.redactSecrets
handling as the /share slash command.
2026-08-07 06:00:07 +02:00
can1357 9628c2e2e6 Merge PR #7754: feat(omp): load only explicitly trusted extensions (@oleksoleksoleks) 2026-08-06 13:24:29 +02:00
roboomp 931f61867c fix(tui): gated built-in renderers by tool provenance
- Routed session tool provenance through live and rebuilt transcript render paths.
- Kept same-named extension tools on the generic renderer while preserving native tool rendering.
- Added regression coverage for an external recall result collision.

Fixes #7770
2026-08-06 01:36:25 +00:00
Alexander Kirilin 9154c56a69 feat(omp): load only explicitly trusted extensions
Co-authored-by: Eric Singer <singer.ericm@gmail.com>
2026-08-05 16:32:45 -04:00
can1357 e9888367d1 refactor: migrated packages to internal utility modules and removed external dependencies
- Implemented in-house, zero-dependency utility modules in `pi-utils` covering DOM manipulation, markdown parsing, templating, browser automation helpers, and terminal buffers.
- Migrated packages across the repository to consume the new internal utilities and `omptype` schema validators instead of external dependencies.
- Removed multiple external runtime and development dependencies including Zod, Marked, LRU cache, Turndown, and Puppeteer browser packages.
2026-08-05 13:39:09 +02:00
can1357 a66805bd78 Merge PR #7634: fix(stats): restrict dashboard to loopback (@roboomp) 2026-08-05 01:11:58 +02:00
metaphorics 726698e2b0 fix(release): validate explicit versions and drop duplicate comparators
Review findings on #7586:
- validate an explicit release version before comparing; the shared
  comparator never throws, so 999.bad previously reached every manifest
- ci-release-notes imports the comparator by relative path: the
  release_github job runs without bun install
- route Bun cache pruning through compareVersions and delete
  compareSemverLikeVersions
- regression test for the release-version guard
2026-08-05 02:48:59 +09:00
metaphorics 954894f1d4 refactor: centralize version comparison in pi-utils 2026-08-05 02:48:59 +09:00
roboomp 951051086d fix(stats): opened dashboard on bound hostname
Threaded the loopback hostname returned by startServer through the omp stats CLI and /stats slash command so the browser and logged URL target the actual listener instead of localhost.

Fixes #7633
2026-08-04 15:34:09 +00:00
can1357 c53a47f97d Merge PR #7287: fix(coding-agent): prune archived session stats (@alphastorm)
# Conflicts:
#	packages/coding-agent/src/session/session-manager.ts
2026-08-03 15:15:36 +02:00
can1357 10625d2e9a Merge PR #7376: feat(coding-agent): add OpenAI service tier override (@paralin)
# Conflicts:
#	packages/coding-agent/src/commands/launch.ts
2026-08-02 21:22:41 +02:00
can1357 f1c7eda7de Merge PR #7205: perf(cli): keep root help off runtime graph (@eggpeat)
# Conflicts:
#	packages/coding-agent/src/cli-commands.ts
#	packages/coding-agent/src/cli/args.ts
2026-08-02 20:59:12 +02:00