Commit Graph
490 Commits
Author SHA1 Message Date
can1357 21a7693dd7 fix(hashline): prevented exposing terminal newline as an addressable row
- Added `splitAddressableFileLines` to strip terminal newlines from line addressability without removing genuine blank lines.
- Updated coding-agent read tool context parsing to use addressable file lines.
2026-08-12 03:22:01 +02:00
can1357 63b39b7040 feat(coding-agent/utils): expanded tar extraction and validation logic
- Added archive and member size assertion limits along with path byte-length checks for PAX and GNU metadata targets.
- Added support for global PAX attributes, old-GNU name records, and signed GNU base-256 numeric header fields.
- Updated archive reading in WriteTool to accept a filesystem path instead of buffered bytes.
- Added test coverage for signed GNU base-256 values, PAX extensions, overlong path rejections, and oversized archives.
2026-08-12 03:04:17 +02:00
can1357 94a76a8f27 feat: hardened tar parser and optimize prompt handling
- Bound PAX sparse record memory overhead by caching sparse markers and specific keys.
- Update system prompt phrasing and tests for tool inventory and date displays.
2026-08-12 03:04:07 +02:00
can1357 a4d8860a6c feat: added google reasoning controls mcp stream resumption and tar support
- Added Google provider thinking configuration parameters and force-reasoning-off controls.
- Implemented MCP SSE stream resumption using Last-Event-ID and `SSEResumeError`.
- Added support for TAR old-GNU sparse extension blocks, path length checks, and archive entry overrides.
- Restricted external thinking support to specific models and added semver fallback parsing.
2026-08-12 02:32:45 +02:00
can1357 7e2663360f fix(read): bounded tar directory-alias resolution and resolved aliased link targets
- Capped directory-alias rewrites per lookup (ELOOP-style, 40) so a directory
  symlink targeting its own subtree (a -> a/b) throws a catchable ToolError
  instead of looping forever growing the path.
- Deferred pending tar link resolution while any directory on the target path
  is itself an unresolved link, and rewrote targets through established
  directory aliases before the exact-path lookup, so file symlinks routed
  through directory aliases materialize instead of dangling.
- Regression tests reproduce both shapes: pre-fix the aliased symlink read
  failed with 'cannot be materialized' and the self-cycle read hung.
2026-08-12 02:02:33 +02:00
can1357 c63b475f47 Merge PR #8260: fix(read): avoid libarchive for tar reads (@roboomp) 2026-08-12 01:53:49 +02:00
roboomp f30a60b797 fix(read): resolved archive-root symlink targets
Symlink targets that normalize to the archive root (current -> ., dir/up -> ..) now resolve as directory aliases to the root instead of being treated as dangling links. The lookup normalizer distinguishes an empty root target from an escaping target, and ArchiveReader treats a resolved-empty path as the root directory.

Fixes #4774
2026-08-11 22:06:41 +00:00
roboomp 1df67cc667 fix(read): honored GNU sparse PAX member names
GNU 1.0 sparse PAX entries now list under GNU.sparse.name with GNU.sparse.realsize as the displayed size, so root listings no longer expose the internal GNUSparseFile path and reads of the real name reject as sparse instead of reporting the member missing. The on-disk header size still drives offset advance and truncation.

Fixes #4774
2026-08-11 21:57:06 +00:00
roboomp 40ce90866e fix(read): resolved tar directory symlinks lazily
Kept directory symlinks as one alias node and rewrote requested paths through aliases in ArchiveReader instead of cloning every target descendant during indexing.

Full archive materialization now fails explicitly on directory aliases rather than expanding them without a bound.

Fixes #4774
2026-08-11 21:47:45 +00:00
roboomp e1360bbb9d fix(read): preserved symlinks and rejected partial tar indexes
Resolved safe file and directory symlinks against indexed members, while retaining dangling links as listed nodes that fail explicitly when read or materialized.

Required fully buffered tar inputs to reach an end-of-archive zero block so truncated downloads cannot expose partial listings.

Fixes #4774
2026-08-11 21:37:18 +00:00
roboomp 861d5f5909 fix(read): preserved tar hard-link members
Resolved hard-link targets after indexing so forward links and chains reuse the referenced member's storage and size. Missing, directory, or cyclic targets now surface catchable archive errors instead of silently dropping paths.

Fixes #4774
2026-08-11 16:11:16 +00:00
roboomp b49e41fc7a fix(read): rejected non-tar gzip payloads while indexing
A gzip stream whose decompressed payload never presents a complete tar header or terminating zero block (a plain .txt.gz, or a tar truncated before the first header) now raises a catchable ToolError instead of returning an empty index rendered as '(empty archive directory)'. fetch falls back to binary rendering.

Fixes #4774
2026-08-11 16:02:00 +00:00
roboomp 1588f79ecf fix(read): rejected truncated tar members while indexing
A member header declaring more bytes than remain in the buffer now throws a ToolError during indexing instead of being listed as a valid entry that only fails on read.

Fixes #4774
2026-08-11 15:52:07 +00:00
roboomp 5892cd1ea4 fix(read): avoided libarchive for tar reads
- Parsed tar and tar.gz members in-process with bounded gzip inflation.

- Added UTF-8 ustar-prefix coverage for the minimal libarchive crash shape.

Fixes #4774
2026-08-11 15:41:51 +00:00
can1357 b524dfe36f refactor: standardized outbound User-Agent headers on shared utility constant
- Define a centralized `USER_AGENT` constant in `@oh-my-pi/pi-utils` formatted as `omp/<version>`.
- Replace hardcoded and platform-specific user agent strings across AI providers, catalog scrapers, tools, and search providers with the unified `USER_AGENT`.
- Add unit tests for update-cli binary release distribution gating.
2026-08-11 15:38:32 +02:00
Anatoli Tsinovoy 5d8214ea77 fix(coding-agent): keep lineage timezone visible 2026-08-09 16:49:13 +03:00
roboomp a6aa462a60 fix(tui): bounded WSL idle animation CPU
- Removed the Loader backpressure cap so slow ConPTY paints retain the documented proportional duty cycle.

- Made WSL terminal-title working state static to avoid a second periodic OSC write loop.

Fixes #8012
2026-08-08 13:17:01 +00:00
can1357 7cebe901b7 refactor(coding-agent): narrowed over-exported internal symbols
- 28 symbols across discovery, mcp header policy, agent-hub projection and
  rendering, the agent registry, shell tokenizing and changelog comparison
  were exported but referenced only inside their own module; they are now
  module-private, shrinking the deep-import surface.
- Kept AGENT_PLUGIN_MANIFEST_SCHEMA, AGENT_PLUGIN_MCP_SCHEMA,
  parseAgentPluginManifest, clearAgentPluginRootCache and mergeMCPHeaders
  exported: each is a seam for tests that defend real parsing or header
  precedence behavior.
- Nothing reachable from an explicit exports entry or public barrel changed.
2026-08-08 06:32:01 +02:00
can1357 cac0887fee Merge PR #7708: fix(coding-agent): preserve shell quoting in POSIX $EDITOR commands (@metaphorics) 2026-08-05 22:16:29 +02:00
can1357 7ef3822de9 Merge PR #7706: fix(coding-agent): fall back to xsel for Linux X11 clipboard reads (@metaphorics) 2026-08-05 21:50:24 +02:00
metaphorics e9ee424ded fix(coding-agent): preserve POSIX editor quoting 2026-08-05 11:42:28 +00:00
can1357 e9888367d1 refactor: migrated packages to internal utility modules and removed external dependencies
- Implemented in-house, zero-dependency utility modules in `pi-utils` covering DOM manipulation, markdown parsing, templating, browser automation helpers, and terminal buffers.
- Migrated packages across the repository to consume the new internal utilities and `omptype` schema validators instead of external dependencies.
- Removed multiple external runtime and development dependencies including Zod, Marked, LRU cache, Turndown, and Puppeteer browser packages.
2026-08-05 13:39:09 +02:00
metaphorics 64f2639d61 fix(coding-agent): fall back to xsel for Linux clipboard 2026-08-05 10:51:01 +00:00
can1357 6da9460dff Merge PR #7488: fix(task): bound abort cleanup and quarantine late jobs (@metaphorics) 2026-08-05 01:12:02 +02:00
metaphorics 954894f1d4 refactor: centralize version comparison in pi-utils 2026-08-05 02:48:59 +09:00
metaphorics 687f3326b2 fix(task): bound abort cleanup and quarantine late jobs 2026-08-03 20:14:25 +09:00
can1357 0156ddcbe1 fix(coding-agent): kept computer worker graph off CLI startup
- The PR #7205 merge left cli.ts statically importing startComputerWorker,
  dragging the computer worker graph (and pi_natives via the pi-utils
  barrel) into normal CLI startup; --version died under --no-addons and
  dotenv loaded before profile bootstrap. worker-entry is now a
  self-starting side-effect module dispatched via dynamic import like
  every other worker selector, and utils/clipboard.ts imports the mime
  constant from its submodule instead of the barrel.
- Repointed the clipboard test spy at @oh-my-pi/pi-natives/clipboard —
  spying the barrel never intercepted the subpath the code imports, so
  the real native bridge ran (X11 timeouts on headless CI).
- Refreshed the pinned HTML export template digest and the scout gate
  phrase the system-prompt rewrite changed.
2026-08-03 00:02:29 +02:00
can1357 05af20a9f2 fix(coding-agent): prevented recursive argument placeholder expansion in substituteArgs
Extracted the coding-agent scope of PR #7077 (@santhreal): single-pass
placeholder matcher so positional values containing literal $@ or
$ARGUMENTS are never re-expanded. The unrelated utils formatting changes
in that PR were not taken.
2026-08-02 21:19:45 +02:00
can1357 71ca62cb1e Merge PR #7318: fix(coding-agent): support Wayland image paste (@roboomp)
# Conflicts:
#	packages/coding-agent/src/utils/clipboard.ts
2026-08-02 20:54:38 +02:00
can1357 ef852af986 feat(computer): implemented modular desktop backend and script workflows
- Replaced monolithic desktop native bindings and action batching with a modular cross-platform backend structure supporting Wayland, X11, macOS, and Win32.
- Updated the computer tool schema and supervisor to execute persistent JavaScript script runs with timeout clamping and asynchronous tool calling.
- Integrated accessibility (AX) tree snapshotting, node querying, and bounds-based hit testing across platform desktop layers.
- Added native clipboard bindings and updated coding-agent prompts, renderers, and tests to validate script-based computer workflows.
2026-08-02 19:46:25 +02:00
can1357 7c3b24ddf2 feat: implemented cross-platform window discovery and targeting capabilities
- Added window discovery, targeting, and frame validation for macOS, Windows, and Linux platforms.
- Updated computer tool and protocol definitions to support listing and targeting specific application windows.
- Refactored native computer tool exposure to function-only representation across models.
- Updated documentation and test suites to reflect window-scoped computer control capabilities.
2026-08-02 17:35:29 +02:00
roboomp 0e34798036 fix(coding-agent): supported wayland image mime types
List offered Wayland clipboard types and request the first image format supported by the existing image pipeline.
2026-08-01 20:14:09 +00:00
roboomp 2619141b01 fix(coding-agent): supported wayland image paste
Read image/png clipboard bytes with wl-paste before falling back to the native clipboard bridge on Linux Wayland sessions.

Fixes #7316
2026-08-01 20:05:54 +00:00
can1357 7c0ba657d5 Merge PR #7141: fix(bash): scope shell snapshots per uid so shared-/tmp accounts don't EACCES (@dangreco) 2026-07-31 19:16:57 +02:00
roboomp b9b60545ab fix(tui): contained synchronous image conversion failures
- Centralized PNG conversion behind an async boundary so constructor and encoder throws become promise rejections.
- Kept live and restored Kitty image rendering interactive by omitting failed conversions.
- Added regressions for both tool-result render paths.

Fixes #7160
2026-07-31 09:44:07 +00:00
Dan Greco 9bb96b22e7 fix(bash): scope shell snapshots per uid so shared-/tmp accounts don't EACCES
- The snapshot dir was one fixed name under the shared `os.tmpdir()`,
  created 0700 because the script inlines env-var values referenced by
  captured functions (#3470). The first account to run omp owns it, so on
  a box where a second Unix account runs omp every bash tool call died
  with `EACCES: permission denied, open
  '/tmp/omp-shell-snapshots/snapshot-bash-<uuid>.sh'`.
- `recursive: true` swallows EEXIST and `mode` is ignored for an existing
  dir, and the defensive `chmodSync` fails EPERM on a foreign-owned dir
  and was already swallowed, so the code walked straight into a dir it
  could not write.
- `mkdirSync` and the pre-create `writeFileSync` both sat outside any
  try/catch, so the error escaped `getOrCreateSnapshot` into
  `executeBash`. Nothing is cached on failure, so it repeated for every
  command instead of degrading once.
- Scope the dir per uid (`omp-shell-snapshots-<uid>`) and guard both
  filesystem calls: an unusable dir now logs at debug and returns `null`,
  which callers already handle as "run without a snapshot".
2026-07-30 22:54:33 -04:00
can1357 b9ae2a3f9b docs(hashline): condensed and clarified instructions in prompt documentation
- Condensed instructions and rule descriptions in `packages/hashline/src/prompt.md`.
- Streamlined formatting examples and anti-patterns for clarity.
- Clarified block operation boundaries and markdown heading section rules.
2026-07-30 07:21:44 +02:00
Wolfgang Schoenbergerandcan1357 757b0938ce fix(coding-agent): tighten startup changelog contracts
(cherry picked from commit e5490279ca0b400b143514e7ef3e38be0686bf31)
2026-07-30 01:42:01 +02:00
Wolfgang Schoenbergerandcan1357 a4dc5a094a feat(coding-agent): add startup changelog display modes
(cherry picked from commit bed594fecd1eae1917f3f047f883da5ba83317f9)
2026-07-30 01:41:57 +02:00
can1357 1d41b269f7 Merge PR #6997: perf(coding-agent): keep reftable branch resolution off the render path (@metaphorics) 2026-07-29 23:08:59 +02:00
robomp-botandcan1357 65707c7f4c fix(coding-agent): close VCS cache lifecycle gaps
(cherry picked from commit b88851334b07eb1da6743b51b542ea5d3222ccca)
2026-07-29 23:08:58 +02:00
robomp-botandcan1357 c5b0348150 fix(coding-agent): harden async reftable resolution
(cherry picked from commit e451f1d6f3537d4b58dfe479a6daf8919d169397)
2026-07-29 23:08:58 +02:00
robomp-botandcan1357 d966b3f8a0 perf(coding-agent): keep reftable branch resolution off the render path
(cherry picked from commit 5724c30ff66e2036ed03a2ce3514a9237a72a657)
2026-07-29 23:08:58 +02:00
can1357 2c99f2f2e8 fix(git): preserve effective character locale
(cherry picked from commit ef7abf60ad1b80642ba1731e043f8eeb82c6a6aa)
2026-07-29 23:08:21 +02:00
Rolando Diazandcan1357 b1c3ba8b8e fix(git): preserve UTF-8 locale for gh subprocesses
(cherry picked from commit e703aa00892b4589baa6c9dcb5f3ab2a3afb1662)
2026-07-29 23:08:20 +02:00
Rolando Diazandcan1357 62cffde87a fix(git): treat empty LC_CTYPE as unset
(cherry picked from commit 02364899ad23031d0ffe47be574ed547e249efa5)
2026-07-29 23:08:20 +02:00
Rolando Diazandcan1357 6ddea85d07 fix(git): preserve inherited UTF-8 character locale
(cherry picked from commit 4d51427cf144dd6415ee3b61158b5650011a796e)
2026-07-29 23:08:19 +02:00
Rolando Diazandcan1357 a38160e245 fix(git): preserve UTF-8 locale for child processes
(cherry picked from commit f7c46ea55fb016daf6c34ecadf87443dadc61047)
2026-07-29 23:08:19 +02:00
Rolando Diazandcan1357 fc093871c0 fix(git): force stable locale for non-interactive commands
(cherry picked from commit 29afa4c859ec89db5b6d3101495eb505cf85cb36)
2026-07-29 23:08:19 +02:00
can1357 56ea3bf8ee feat(coding-agent/cleanse): implemented cleanse command and workflow execution
- Add `omp cleanse` command and workflow execution infrastructure.
- Implement project file discovery, automatic checker execution, and multi-format diagnostic parsing.
- Provide subagent dispatch, session runtime, and task balancing with bin packing.
- Include comprehensive tests for diagnostic parsing and orchestration loops.
2026-07-28 10:22:17 +02:00