Commit Graph

660 Commits

Author SHA1 Message Date
Kyle McCleary 089a9963f8 feat(security): OMP-native security subsystem (planner handoff) 2026-07-29 18:47:51 -07:00
can1357 5711b763e0 docs(auth): align remaining credential ladders
(cherry picked from commit c606fe3a106611be413f140310ee47a88324cded)
2026-07-29 23:09:09 +02:00
can1357 5c79f5bc4a Merge PR #7023: docs(auth): correct credential precedence (@wolfiesch) 2026-07-29 23:09:09 +02:00
Wolfgang Schoenberger 031beb1751 docs(auth): correct credential precedence
(cherry picked from commit 33ede5efbc52cedc9819cb65c642cfeab82c337c)
2026-07-29 23:09:09 +02:00
can1357 b5ad903788 fix(ttsr): exclude deleted patch text from matcher digest
(cherry picked from commit b4812365368368a5706131c3ff1ecd52fd64662d)
2026-07-29 23:08:24 +02:00
can1357 b98a6853b3 Merge PR #6886: docs: clarify ttsr edit/write matcherDigest is introduced lines (@roboomp) 2026-07-29 23:08:23 +02:00
Éverton Toffanetto e94442b694 fix(ai): preserve legacy Codex SQLite compatibility
(cherry picked from commit 3e5e7b6ea910c56765b4707f617e20b056f3d342)
2026-07-29 23:08:11 +02:00
Éverton Toffanetto db9aa4af1c fix(ai): preserve Codex broker block compatibility
(cherry picked from commit 7de50a84c3d46279e0249617e22ba22222ff8174)
2026-07-29 23:08:10 +02:00
can1357 b550858265 ci: upgraded continuous integration workflows and migrated bazel dependency locking
- Updated CI workflows and GitHub actions to enhance Bazel cache keying, credential masking, and validation checks.
- Migrated dependency locking from Cargo.Bazel.lock to MODULE.bazel.lock using rules_rust crate_universe.
- Updated build configuration, documentation, and tooling scripts to reflect the lockfile and cache changes.
2026-07-28 12:53:23 +02:00
roboomp e7f26be1af docs: clarify ttsr edit/write matcherDigest is introduced lines
The TTSR lifecycle doc called the edit/write match target the
"reconstructed source snapshot", which reads as the whole prospective
file. For edit that is wrong: every mode's matcherDigest returns only
the lines the call introduces (new_text / + body rows / added diff
lines). Only write passes whole content. Reworded lines 57 and 78 to
match the code contract in streaming.ts.

Fixes #6885
2026-07-28 10:27:00 +00:00
can1357 ac6cd57bd4 Merge PR #6820: fix(coding-agent): preserve parent todos in vibe mode (@Iron-Ham) 2026-07-28 10:59:37 +02:00
can1357 0e556ee32a docs(marketplace): document plugin mcpServers manifest pointer and correct stale extensions note 2026-07-28 10:59:35 +02:00
can1357 b6bd241943 Merge PR #6873: fix(discovery): honor plugin MCP manifest pointers (@roboomp) 2026-07-28 10:59:35 +02:00
roboomp 8f31a123d6 fix(discovery): honored plugin MCP manifest pointers
Resolved mcpServers file pointers from OMP and Claude plugin manifests before the conventional root config fallback.

Updated marketplace installer documentation for runtime symlink and lockfile registration.

Fixes #6871
2026-07-28 07:12:46 +00:00
can1357 e7009452b4 feat(coding-agent/tools): simplified browser screenshot persistence and return paths
- Remove the per-call `save` option from `tab.screenshot()` to simplify usage.
- Update `tab.screenshot()` to return the saved file path as a promise string.
- Configure screenshot persistence to use daemon path or custom `browser.screenshotDir`.
- Add comprehensive tests verifying temp path return and custom directory saving.
2026-07-28 06:40:31 +02:00
can1357 1bba24f191 Merge PR #6830: feat(coding-agent): capability-aware inspect_image with tri-state mode and /vision toggle (@epsilver) 2026-07-27 23:07:26 +02:00
can1357 da6d11de0e feat(agent): introduced prepareToolCall phase supporting argument replacement
- Added a prepareToolCall phase to the agent loop running before tool scheduling for validation and hooks.
- Updated BeforeToolCallContext and result types to support argument replacement instead of in-place mutation.
- Updated coding-agent extension handling and runner to track emitted tool calls and re-evaluate approvals on input revisions.
- Added comprehensive test coverage for argument replacement, concurrency resolution, and schema validation.
2026-07-27 22:55:20 +02:00
can1357 46707e3e36 Merge PR #6681: feat(extensions): let tool_call handlers revise tool input (@psyrendust) 2026-07-27 22:27:09 +02:00
alexis@epsilver.xyz c33b98e260 feat(coding-agent): capability-aware inspect_image with tri-state mode and /vision toggle
Replace the inspect_image.enabled boolean with inspect_image.mode
(auto|on|off, default auto). In auto the tool is registered only when
the active model lacks native image input, so vision-capable models
(e.g. kimi-code/k3) read images inline with their own capabilities
instead of delegating to a separate vision model. on/off force
registration regardless of model capability.

- New utils/inspect-image-mode.ts resolves the effective state from the
  /vision session override, the persisted setting, and model capability
- read tool re-evaluates the effective state per image read and
  re-renders its description, so it returns decoded image blocks again
  whenever inspect_image is hidden
- /vision [on|off|auto|status] slash command (modeled on /computer)
  overrides the mode for the current session only
- Tool set is reconciled on model switch with a status notice when
  inspect_image appears/disappears
- Legacy inspect_image.enabled true/false migrates to mode on/off
2026-07-27 16:24:02 -04:00
Hesham Salman 7f7e742db6 fix(coding-agent): preserve parent todos in vibe mode 2026-07-27 13:52:25 -04:00
can1357 fae0e5df31 Merge PR #6765: feat(catalog,ai): add SiliconFlow providers with dynamic-only model discovery (@iacore) 2026-07-27 15:57:47 +02:00
can1357 da044f33ef Merge PR #6784: fix(tui): route editor word delete through keybindings registry (@roboomp) 2026-07-27 15:57:45 +02:00
roboomp dda720af41 fix(tui): allowed remote raw backspace opt-in
Windows Terminal identity is commonly lost across SSH and container hops,
leaving only the ambiguous raw 0x08 byte. Added the conservative
PI_TUI_RAW_BACKSPACE_IS_CTRL=1 opt-in so those sessions can map it to
ctrl+backspace without changing the default for terminals where 0x08 means
plain Backspace.

Restored the public isWindowsTerminalSession and matchesRawBackspace exports
and route the parser wrappers through matchesRawBackspace. Documented the
runtime flag and covered local WT, remote opt-in, SSH, and 0x7f behavior.

Fixes #6782
2026-07-27 10:28:00 +00:00
can1357 8facd237d5 feat(build): migrated native pipeline to bazel with remote caching
- Replaced the napi-cli/cargo-zigbuild/cargo-xwin/sccache build path with
  Bazel: rules_rust + crate_universe over Cargo.lock, hermetic zig cc
  toolchains (linux-gnu pinned to glibc 2.17, linux-musl), host Xcode for
  darwin, and a repo-local hermetic clang-cl + llvm-ml + xwin toolchain for
  windows-msvc (bazel/toolchains/msvc).
- All eight shipped addons build as //:natives-<target> via the release
  transition in bazel/defs.bzl (opt, thin LTO, cgu=16, stripped, canonical
  .node naming); scripts/bazel-natives.ts is the single driver for local
  dev and CI.
- Rust validation moved to bazel test + clippy aspects (strict workspace
  policy for opted-in crates, default lints elsewhere, mirroring cargo
  semantics) and the rustfmt aspect; cargo stays as the dev-iteration
  surface, with brush-core/brush-builtins promoted to workspace members
  and excluded from cargo dev tasks to keep their historical scope.
- CI caches through an in-cluster bazel-remote action cache (TLS + basic
  auth, cluster-internal only); GitHub-hosted runners never touch the
  infrastructure and use an actions/cache-backed disk cache instead.
- Deleted the hand-rolled caching machinery: ci-target-cache,
  ci-native-artifact-cache, ci-build-native, native-source-hash,
  find-native-artifacts, restore-linux-native, native-prewarm workflow,
  ensure-* toolchain actions, and all sccache/Swatinem wiring.
- Warm native rebuilds drop from ~20 minutes to seconds; a cold client
  with a warm remote cache rebuilds the linux x64 pair in ~2.5 minutes.
2026-07-27 12:22:19 +02:00
iacore dab5934548 feat(catalog,ai): add SiliconFlow providers with dynamic-only model discovery
Adds siliconflow and siliconflow-cn OpenAI-compatible providers
(api.siliconflow.com / api.siliconflow.cn), with the model list fetched
live from each region's /v1/models endpoint instead of a bundled
catalog (dynamicModelsAuthoritative, no models.dev mapping).

SiliconFlow's /v1/models serves every model type (chat, embedding,
reranker, image, audio, video) with no per-model type field, so
discovery filters non-chat ids out of the picker. The filter was
validated against the live catalog to match the server's own
type=text&sub_type=chat classification exactly (64/64, no false
drops, no false keeps).

Wires SILICONFLOW_API_KEY / SILICONFLOW_CN_API_KEY into env-key
discovery and registers API-key login providers so
`omp login siliconflow` / `omp login siliconflow-cn` stores a
credential validated against each region's /v1/models endpoint.
2026-07-27 13:06:50 +08:00
Git-on-my-level 98d25e3c67 fix(auth-broker): retain cache resilience on server errors 2026-07-26 18:24:56 +00:00
Hermes DevOps Bot 3a73349d93 fix(auth-broker): revalidate fresh snapshot caches 2026-07-26 18:05:30 +00:00
can1357 0758245eeb docs(task): fix effort-omission and settings-snapshot wording per review
- effort row: omission keeps the agent's configured selector (auto only for
  agents configured auto, e.g. bundled task; scout/sonic use medium)
- Flow step 12: settings snapshot is not a verbatim copy — tier.* re-resolved
  via tier.subagent, plus per-spawn read-summarize / workspace-root overrides
2026-07-26 15:45:32 +02:00
can1357 8550a0af54 Merge PR #6597: docs: reconcile omp:// task/eval docs with 17.1.3 runtime (@roboomp) 2026-07-26 15:45:32 +02:00
can1357 f6e6ad5bea Merge PR #6617: docs(bash): document bundled jaq divergence (@roboomp) 2026-07-26 15:45:31 +02:00
can1357 d1dc436d1e Merge PR #6596: fix(coding-agent): preserve Claude computer coordinates (@wolfiesch)
# Conflicts:
#	docs/computer-use.md
#	packages/coding-agent/src/tools/computer.ts
#	packages/coding-agent/test/tools/computer.test.ts
2026-07-26 15:44:51 +02:00
can1357 56a8ab1413 Merge PR #6697: fix(coding-agent): match bash deny/prompt patterns per command segment (@roboomp) 2026-07-26 15:41:28 +02:00
roboomp e650607cad fix(coding-agent): segment bash approval commands with shell-aware tokenizer
The regex splitter only recognized `&&`, `||`, `;`, `|` and newlines, so a
single `&` (background operator) — also a command terminator — slipped a
dangerous command past a deny rule (`sleep 1 & rm -rf /tmp/x`), which under
approvalMode: yolo executed with no prompt.

Extract the shell-aware tokenizer from gh-cache-invalidation into a shared
tools/shell-tokenize.ts and reuse it for deny/prompt segmentation. It honors
every command boundary (`&&`, `||`, `;`, `|`, single `&`, subshells,
newlines) plus quoting and escapes, so both callers share one implementation.

Fixes #6695
2026-07-26 11:36:19 +00:00
roboomp 85110c366c fix(coding-agent): match bash deny/prompt patterns per command segment
bashApprovalPatternToRegExp anchors globs with ^...$ against the whole
normalized command, so a bash.patterns deny rule only fired when the
dangerous command was first in the line. A compound command such as
`cd /tmp && rm -rf /tmp/x` bypassed the rule and, under approvalMode:
yolo, executed with no prompt -- deny is the guard that outranks yolo.

deny/prompt rules now match the whole command or any single segment
(split on &&, ||, ;, |, newlines). allow rules still require the entire
command to match and never apply to compound lines, so a narrow allow
cannot vouch for a smuggled unsafe segment.

Fixes #6695
2026-07-26 11:28:48 +00:00
Wolfgang Schoenberger 153e1b1f5c docs(computer): describe coordinate-safe capture sizing 2026-07-26 02:55:20 -07:00
Wolfgang Schoenberger fc68288477 fix(coding-agent): scope computer capture limits 2026-07-26 02:53:01 -07:00
Wolfgang Schoenberger 25dc887fb2 fix(coding-agent): preserve computer coordinates across providers 2026-07-26 02:53:00 -07:00
Larry Gordon ed457a9d4f feat(extensions): let tool_call handlers revise tool input
A `tool_call` handler (extension or hook) could previously only block a
tool. It can now also return `input` to replace the arguments the tool
executes with, so a handler can normalize or rewrite a built-in's input
without reimplementing the tool.

The returned object is the raw execution input passed to the tool's
`execute` (the handler owns its correctness), not the normalized
`event.input` view, which may carry derived gate-only fields (e.g.
hashline `edit` `path`/`paths`) that are not real parameters. It is
ignored when `block` is set, and not applied to `computer` tool calls
whose event input is a synthetic actions view rather than the real
params. When multiple handlers set `input`, the last one wins.

Honored in both the extension and hook tool wrappers; documented in
docs/extensions.md, docs/hooks.md, and docs/skills/authoring-hooks.md.
2026-07-25 23:16:04 -07:00
roboomp 0f2ea2cd07 docs(bash): preserve false in jaq null-index workaround
Recommend [.a.b?][0] instead of .a.b? // null, which clobbered a legitimate false/null to the fallback.

Fixes #6614
2026-07-25 13:21:40 +00:00
roboomp 67a53a3a49 docs(bash): documented bundled jaq divergence
Documented that non-PTY jq is backed by jaq and provided portable null-indexing syntax.

Fixes #6614
2026-07-25 13:14:55 +00:00
roboomp 0c7f6e1e5a docs: reconcile omp:// task/eval docs with 17.1.3 runtime
- task.md: subagents inherit async.enabled and bash.autoBackground.enabled
  from the parent (since 17.1.0), not force-disabled/"internally synchronous"
- task.md: document the per-spawn effort parameter ("lo"|"med"|"hi")
- eval.md: document the eval agent(model=...) per-call model selector, which
  the agent-bridge still accepts and forwards

Fixes #6594
2026-07-25 08:38:49 +00:00
usr-bin-roygbiv 6b7e2ccc40 docs(computer-use): document routing diagnostics 2026-07-25 00:42:23 +00:00
usr-bin-roygbiv c12c282aa5 fix(computer): gate native Responses transport 2026-07-25 00:42:23 +00:00
can1357 03e6564c05 feat(hashline): enabled leniency rule for bare bullet minus rows
- Add leniency rule in parser to auto-accept bare `-` rows as literal content when hunks represent Markdown bullet lists.
- Emit MINUS_BULLET_AUTO_PIPED_WARNING when bullet-shaped rows lack explicit plus prefixes.
- Reject ambiguous or non-bullet minus rows to prevent unified-diff contamination.
2026-07-24 15:36:32 +02:00
can1357 c6dcfa4137 feat(coding-agent): compacted oversized sse payloads in debug buffer
- Added tool schema and description compaction for oversized data payloads in `packages/coding-agent/src/debug/raw-sse-buffer.ts`.
- Implemented head-tail trimming to preserve leading and trailing event fields when events exceed character budgets.
- Added test coverage verifying SSE debug event truncation, elision markers, and JSON-safe tool compaction behavior.
2026-07-24 15:20:36 +02:00
can1357 9f8aa87dbf feat(task): removed per-call model override from task tool
- Removes `model` field from task item/schema, TaskParams, and TaskItem types.
- Removes model selector validation, formatting, and approval display logic.
- Updates task tool priority docs to reflect that model is no longer per-call overridable.
- Updates eval agent() helper docs and prompt templates to remove model parameter.
- Updates tests to reflect removal of model override capability.
2026-07-24 14:51:48 +02:00
can1357 11eb003fc8 fix: screenshot latency, somehow calling screencapture is faster ??? 2026-07-24 06:39:49 +02:00
can1357 aad7ee8fa3 feat(ai): implemented lite response overrides and computer call unrolling for codex
- Updated the OpenAI Codex provider to unroll native computer calls and tool outputs into standard function calls.
- Added support for the `PI_CODEX_RESPONSES_LITE` environment variable override via the request transformer.
- Updated documentation and tests to cover lite response resolution and native computer response unrolling.
2026-07-24 06:10:00 +02:00
usr-bin-roygbiv 68ac163e2c fix(computer): harden native desktop execution 2026-07-24 01:40:05 +00:00
can1357 681d7daf65 feat(computer): unified native addon, /computer toggle, function tool
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
  a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
  XTest input with keysym mapping) compiled into the core addon on every
  published target; Linux arm64 and musl are now supported and headless
  hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
  lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
  build dependencies, and the now-unreferenced vendored libspa crate;
  reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
  XTest layouts reject negative origins and coordinates beyond 0..=32767,
  batch coordinates stay bound to the frame last returned to JS with
  intermediate screenshots deferred, coordinate input requires a
  previously returned frame, and failed chord releases still release
  every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
  no input is emitted after expiry and wait-heavy batches are rejected
  upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
  scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
  a regular function tool with a typed GA action schema across OpenAI,
  Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
  session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
2026-07-24 01:40:05 +00:00