Commit Graph

1099 Commits

Author SHA1 Message Date
can1357 dccf0d3c8a Merge PR #6748: perf(launch): isolate PTY replay in broker (@usr-bin-roygbiv) 2026-07-27 04:58:28 +02:00
usr-bin-roygbiv 403f90783e perf(launch): isolate PTY replay in broker 2026-07-27 01:17:19 +00:00
shoucandanghehe 62e24ffc16 test(coding-agent): follow promise fixture convention 2026-07-26 23:56:27 +08:00
shoucandanghehe cdf373b77d fix(coding-agent): handle asynchronous LSP pipe failures 2026-07-26 23:37:12 +08:00
can1357 d1dc436d1e Merge PR #6596: fix(coding-agent): preserve Claude computer coordinates (@wolfiesch)
# Conflicts:
#	docs/computer-use.md
#	packages/coding-agent/src/tools/computer.ts
#	packages/coding-agent/test/tools/computer.test.ts
2026-07-26 15:44:51 +02:00
can1357 56a8ab1413 Merge PR #6697: fix(coding-agent): match bash deny/prompt patterns per command segment (@roboomp) 2026-07-26 15:41:28 +02:00
can1357 9b651f2869 Merge PR #6616: fix(cursor): sync native todo list from server-resolved tool calls (@quantmind-br) 2026-07-26 15:41:27 +02:00
Diogo Soares Rodrigues 9088fe821b fix(cursor): await error-drain transforms and sanitize mirrored todo labels
Two boundary defects on the mirrored-todo path.

1. The Agent error drain snapshotted #cursorToolResultBuffer without
   awaiting entry.pending, unlike #emitCursorSplitAssistantMessage. An
   async cursorOnToolResult still running when the provider errored
   patched an entry the catch path had already detached, so the
   pre-transform payload was persisted. A provider error is exactly when
   a transform is most likely to be in flight.

2. The todo renderer interpolated mirrored provider text straight into
   terminal output. A Cursor snapshot carries model-authored task
   content, phase names and summary text verbatim, so a label holding
   ANSI/C0 sequences rewrote the terminal on every render and replay.
   sanitizeText alone is not enough - it preserves tabs, which punch
   holes in bordered output - so every display path now funnels through
   one forDisplay() helper: task labels, blocker notes, phase headers,
   the zero-task fallback, and the streaming renderCall preview. Raw
   values are untouched; content and phase name are the identity keys
   the local list is looked up by and what gets persisted.
2026-07-26 09:29:13 -03:00
roboomp e650607cad fix(coding-agent): segment bash approval commands with shell-aware tokenizer
The regex splitter only recognized `&&`, `||`, `;`, `|` and newlines, so a
single `&` (background operator) — also a command terminator — slipped a
dangerous command past a deny rule (`sleep 1 & rm -rf /tmp/x`), which under
approvalMode: yolo executed with no prompt.

Extract the shell-aware tokenizer from gh-cache-invalidation into a shared
tools/shell-tokenize.ts and reuse it for deny/prompt segmentation. It honors
every command boundary (`&&`, `||`, `;`, `|`, single `&`, subshells,
newlines) plus quoting and escapes, so both callers share one implementation.

Fixes #6695
2026-07-26 11:36:19 +00:00
roboomp 85110c366c fix(coding-agent): match bash deny/prompt patterns per command segment
bashApprovalPatternToRegExp anchors globs with ^...$ against the whole
normalized command, so a bash.patterns deny rule only fired when the
dangerous command was first in the line. A compound command such as
`cd /tmp && rm -rf /tmp/x` bypassed the rule and, under approvalMode:
yolo, executed with no prompt -- deny is the guard that outranks yolo.

deny/prompt rules now match the whole command or any single segment
(split on &&, ||, ;, |, newlines). allow rules still require the entire
command to match and never apply to compound lines, so a narrow allow
cannot vouch for a smuggled unsafe segment.

Fixes #6695
2026-07-26 11:28:48 +00:00
Wolfgang Schoenberger 0c5fa60c77 fix(coding-agent): cap captures for resizing transports
Use the resolved supportsImageDetailOriginal capability to constrain native computer frames whenever a Responses transport clamps screenshot detail to auto. Preserve the established Claude-family fallback for transports that do not expose this capability.

Cover Copilot GPT-5 Responses through real catalog model resolution and the controller's observable capture options.
2026-07-26 02:53:01 -07:00
Wolfgang Schoenberger fc68288477 fix(coding-agent): scope computer capture limits 2026-07-26 02:53:01 -07:00
Wolfgang Schoenberger 25dc887fb2 fix(coding-agent): preserve computer coordinates across providers 2026-07-26 02:53:00 -07:00
usr-bin-roygbiv 9bab62ee55 fix(computer-use): address routing review gaps 2026-07-25 02:14:36 +00:00
usr-bin-roygbiv 40937af750 test(computer): exercise packaged desktop session 2026-07-25 00:42:23 +00:00
usr-bin-roygbiv c8d465803a fix(computer): default missing actions to read approval 2026-07-25 00:42:23 +00:00
can1357 bef97a69bb Merge PR #6529: fix(coding-agent): guard retain renderer streaming args (@roboomp) 2026-07-25 00:59:14 +02:00
can1357 8851e93d21 Merge PR #6551: fix(coding-agent): use session settings in file guards (@roboomp) 2026-07-25 00:59:14 +02:00
roboomp 144043ad48 fix(coding-agent): used session settings in file guards
Passed session-scoped settings through Edit and Write generated-file checks and fell back to schema defaults when no global singleton exists.

Guarded inline image sizing against an uninitialized global settings proxy and added isolated-session regression coverage.

Fixes #6549
2026-07-24 22:42:38 +00:00
can1357 f23bc266a8 feat(natives): enabled per-language rewrite rules for mixed-language paths
- Remove uniform language inference requirement, allowing mixed-language paths to rewrite each file in its own language.
- Update `ast_edit_blocking` in `crates/pi-natives/src/ast.rs` to compile rewrite rules per language and skip unsupported languages gracefully.
- Update `ast-edit.md` prompt documentation to reflect mixed-language path support.
- Add test coverage verifying mixed-language tree rewrites.
2026-07-24 21:52:29 +02:00
roboomp d7c7ca033d fix(coding-agent): guarded retain renderer streaming args
- Treated transient non-array retain items as absent during TUI streaming.
- Added regression coverage for malformed partial renderer arguments.
- Documented the fix in the coding-agent changelog.

Fixes #6528
2026-07-24 15:52:01 +00:00
can1357 c55b28a26d chore(coding-agent): format eval display helpers 2026-07-24 16:49:31 +02:00
can1357 ff49b986d5 feat(coding-agent/tools): introduced language-specific code formatters for display rendering
- Added language-specific code formatters for JavaScript, Julia, Python, and Ruby to improve display rendering.
- Integrated display formatting into browser run and eval render tools while preserving verbatim execution.
- Added comprehensive test suites verifying formatting stability, lexical safety, and streaming behavior.
2026-07-24 16:26:03 +02:00
can1357 5acdefc7b3 feat(coding-agent/web): introduced structured web-search query parsing module
- Implemented a structured web-search query parsing module supporting directives, tokenization, date parsing, and syntax serialization.
- Updated search providers to map query directives and date bounds to native provider parameters and filters.
- Added lenient result constraint post-filtering and configuration settings for enhanced engine routing.
- Added comprehensive unit and integration tests covering query parsing, constraint filtering, and provider-specific request mapping.
2026-07-24 16:05:14 +02:00
can1357 d4792ed38b fix(tools): leniently inferred missing todo op from unambiguous payloads
- Kept op required in the todo schema; lenientArgValidation now routes raw args to execute(), where resolveTodoParams re-validates and repairs an omitted op (list -> init, phase+items -> append, bare items on empty list -> init).
- Ambiguous op-less calls surface the schema error as a retryable tool error instead of a hard validation failure.
2026-07-24 12:03:06 +02:00
usr-bin-roygbiv 68ac163e2c fix(computer): harden native desktop execution 2026-07-24 01:40:05 +00:00
can1357 681d7daf65 feat(computer): unified native addon, /computer toggle, function tool
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
  a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
  XTest input with keysym mapping) compiled into the core addon on every
  published target; Linux arm64 and musl are now supported and headless
  hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
  lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
  build dependencies, and the now-unreferenced vendored libspa crate;
  reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
  XTest layouts reject negative origins and coordinates beyond 0..=32767,
  batch coordinates stay bound to the frame last returned to JS with
  intermediate screenshots deferred, coordinate input requires a
  previously returned frame, and failed chord releases still release
  every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
  no input is emitted after expiry and wait-heavy batches are rejected
  upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
  scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
  a regular function tool with a typed GA action schema across OpenAI,
  Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
  session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
2026-07-24 01:40:05 +00:00
usr-bin-roygbiv 57f8acdd18 fix(native): harden desktop input and compatibility 2026-07-24 01:40:05 +00:00
usr-bin-roygbiv b9504f65e7 feat: add native Codex computer use 2026-07-24 01:40:04 +00:00
can1357 e23359fd1a fix(prompts): restored JS spread operator mangled into Unicode ellipsis by reformat
- 24e2a52615 turned ...f into …f inside the workflow-notice parallel example, making the copyable snippet a syntax error.
2026-07-23 23:15:31 +02:00
can1357 2ecba08e2a Merge PR #6407: fix(browser): bound open timeout and lease browser across tab acquisition (@roboomp) 2026-07-23 22:15:24 +02:00
can1357 bbf0402990 fix(coding-agent): surface JSON-RPC error code so -32601 method-not-found is recognized regardless of message text
Codex P2 on #6403: sendRequest rejected with only the server's error
message; a server answering rust-analyzer/reloadWorkspace with code
-32601 but nonstandard text (e.g. "Unknown request") would fail
isMethodNotFoundError and turn lsp reload into a hard error instead of
falling back to the generic reload. Include the code in the rejection
message so the existing -32601 substring check matches. Adds a
regression test with a -32601/"Unknown request" response.
2026-07-23 22:15:23 +02:00
can1357 221c93c88b Merge PR #6403: fix(coding-agent): propagate cancellation from lsp reload instead of false restart (@roboomp) 2026-07-23 22:15:23 +02:00
can1357 418076e44a fix: treat escaped quotes inside double-quoted backticks as inner quoting
Bash treats \" inside a backtick substitution nested in double quotes as
a quote delimiter for the inner command; the generic backslash-skip made
isInsideShellQuote report such quoted literals as unquoted, wrongly
expanding internal URLs inside them (Codex P2 review finding).
2026-07-23 22:15:23 +02:00
can1357 5ac3094d88 Merge PR #6418: fix(tool): expand internal urls inside backtick substitutions (@roboomp) 2026-07-23 22:15:23 +02:00
can1357 c991270145 Merge PR #6404: fix(coding-agent): make PDF image cache content-aware (@roboomp) 2026-07-23 22:15:22 +02:00
roboomp 70e92d32a6 fix(tool): expand internal urls inside backtick substitutions
isInsideShellQuote opened an expansion context for $() command
substitution but never tracked legacy backtick substitution, so an
unquoted skill:// (or other supported scheme) nested directly inside a
backtick pair within double quotes kept the outer quote active and was
left literal. Treat an unescaped backtick as an expansion-context
boundary on the same substitution stack, restoring the outer quote when
the pair closes, matching $() behavior including nesting in either
order. Single-quoted and escaped-backtick text stay literal.

Fixes #5645
2026-07-23 19:20:08 +00:00
roboomp d4b1fd5107 fix(browser): bound open timeout and lease browser across tab acquisition
The browser tool's open action only passed the requested timeout to acquireTab; acquireBrowser ran under the caller signal alone, so CDP discovery/connect could run through its own fixed 5s/30s waits past the requested deadline. A freshly-created browser also sat in the registry at refCount 0 during worker/surface acquisition: the worker-abort branch released it only on tempHold (never on the fresh refCount-0 case), orphaning the handle, and two different-name opens sharing one refCount-0 browser let a single failure dispose it out from under the survivor.

Compose one open deadline from the caller signal and params.timeout and thread it through both acquireBrowser and acquireTab; caller cancellation stays ToolAbortError, the requested timeout becomes a timeout ToolError. Hold one explicit registry lease across tab acquisition, released exactly once on the mutually-exclusive success/rollback paths, and make the worker-abort browser release mirror the error paths' refCount-0 check.

Fixes #6365
2026-07-23 19:02:38 +00:00
roboomp 7877df00e4 fix(coding-agent): made pdf image cache content-aware
- Snapshotted source bytes before deriving path-and-content cache generations.
- Coalesced cold extraction with independent caller cancellation and atomic publication.
- Covered replacement, mutation, concurrency, cleanup, isolation, and component limits.

Fixes #6368
2026-07-23 18:58:58 +00:00
roboomp eeb3fa6ace fix(coding-agent): propagated cancellation from lsp reload instead of false restart
reloadServer caught every error from both fallback mechanisms in bare
catch blocks, so a caller cancel or tool timeout was swallowed and fell
through to `proc.kill(); return "Restarted"` -- reporting a successful
restart while killing the server with no replacement.

- Propagate ToolAbortError/timeout from both the rust-analyzer request
  and the didChangeConfiguration notification fallback.
- Gate the fallback on genuine method-not-found via isMethodNotFoundError
  instead of any error.
- Replace the blind proc.kill with shutdownClientInstance: remove the
  client from the registry by identity and await confirmed process exit,
  surfacing a truthful teardown error when the process outlives the kill.

Fixes #6369
2026-07-23 18:58:15 +00:00
can1357 5b3275c7ae feat(coding-agent): introduced ordered provider priority lists for search and images
- Replaced single-provider preferences with ordered priority lists for web search and image generation.
- Added a `MultiSelectSubmenu` component supporting toggle and reordering interactions in settings.
- Implemented migration logic to convert legacy single-provider preferences into ordered priority lists.
- Updated setup wizard scenes, image generation fallback logic, and search provider chains to use priority lists.
2026-07-23 20:44:50 +02:00
can1357 344714aea7 Merge PR #4890: feat(coding-agent): use Grok 4.5 for xAI web search (@metaphorics)
# Conflicts:
#	packages/coding-agent/src/web/search/providers/xai.ts
2026-07-23 20:16:05 +02:00
can1357 154d4ace9f Merge PR #4448: feat(todo): add blocked status with block/unblock ops (@mattwilkinsonn)
# Conflicts:
#	packages/coding-agent/src/modes/interactive-mode.ts
#	packages/coding-agent/src/prompts/tools/todo.md
2026-07-23 17:32:43 +02:00
can1357 9d5f158e23 fix(coding-agent): preserved default markdown rendering for internal-URL reads
Gated the read.renderMarkdown opt-in at read time (details tagging) instead
of inside the renderer. The renderer gate silently flipped every
protocol-supplied text/markdown read (skill://, pr://, issue://, history://,
rule://, omp://, agent://, vault://, local://, memory://, ssh://) from the
formatted markdown cell to the raw code cell when the setting was off, which
regressed default TUI behavior. Local file tagging now happens only when the
setting is enabled, so the default render path is byte-identical to the
pre-setting behavior while opt-in previews still work end-to-end.

Also inlined the tautological isMarkdownContentPath wrapper, pinned the
widened prose-summary bypass (.mdx stays verbatim when prose summaries are
off) with a test, and documented it under Changed in the changelog.
2026-07-23 17:30:33 +02:00
can1357 42a3da21de Merge PR #4001: feat(coding-agent): opt-in Markdown read previews (@oldschoola) 2026-07-23 17:30:33 +02:00
can1357 09d02c641f fix(coding-agent): closed bash approval rule bypasses
Tested the shell-control guard against the raw command: whitespace
normalization collapsed newlines/CR before the guard ran, so
'git status\nrm file.txt' rode a 'git *' allow rule while bash executed
both lines. Honored tool-owned allow/prompt policies in yolo mode so
per-command prompt rules were no longer silently discarded under the
default approvalMode. Added precision regression tests through the real
matcher (separators, subshells, redirects, env prefixes, path/quoting
variants) that fail on the unfixed head.
2026-07-23 17:30:32 +02:00
can1357 794515fd1a Merge PR #6363: feat(coding-agent): support per-command bash approval rules (@WahidinAji) 2026-07-23 17:30:32 +02:00
can1357 0f54c0df70 fix(tools): autoqa consent handling from default off to opt-in 2026-07-23 13:24:45 +02:00
Cakrawala 6d7457663f feat(coding-agent): support per-command bash approval rules 2026-07-23 17:11:41 +07:00
can1357 536d37ac07 Merge PR #5137: perf(coding-agent): avoid cold LSP startup on format-only writes (@wolfiesch) 2026-07-23 11:37:13 +02:00