Commit Graph

6744 Commits

Author SHA1 Message Date
roboomp e414585155 fix(extensions): preserved unsafe schemas during install
- Lifted legacy Type.Unsafe documents into callable omptype schemas so Optional and Object composition preserve validation and required fields.
- Ran installed extension factories against the normal throwaway loader surface before accepting a plugin install.
- Added regression coverage and documented the stronger rollback gate.

Fixes #8143
2026-08-10 07:37:28 +00:00
can1357 6fb07028fd chore: bump version to 17.2.12 2026-08-08 20:57:55 +02:00
can1357 f87a8ecc19 Merge PR #7994: fix(session): surface empty handoff generation as failure not cancel (@roboomp) 2026-08-08 19:38:32 +02:00
can1357 afa54d87f0 Merge PR #8002: fix(web-search): parse double-encoded Z.AI results (@roboomp) 2026-08-08 19:38:32 +02:00
can1357 bca8d5281b Merge PR #8004: fix(agent): release parked subagent session memory on dispose (@roboomp) 2026-08-08 19:38:32 +02:00
can1357 ba8e4dabd4 Merge PR #8014: fix(tui): bound WSL idle animation CPU (@roboomp) 2026-08-08 19:38:31 +02:00
can1357 025c1c4df6 Merge PR #8023: fix(task): record subagent model performance (@roboomp) 2026-08-08 19:38:17 +02:00
can1357 7ca140f66e fix(ai): routed policy-rejected accounts through sibling rotation
- Added account-scoped policy error detection to correctly identify Codex cyber-policy rejections.
- Updated credential storage and retry logic to route denied accounts through sibling rotation instead of bypassing it.
- Ensured coding-agent sessions exhaust all sibling accounts before falling back on cyber denials.
- Added comprehensive test coverage for credential rotation and retry behavior on policy errors.
2026-08-08 19:29:49 +02:00
roboomp 506f57fbf2 fix(task): recorded subagent model performance
Shared the parent AgentStorage handle with isolated task settings while keeping setting overrides non-persistent.

Added regression coverage for task samples reaching the shared TPS/TTFT aggregate.

Fixes #8022
2026-08-08 15:59:27 +00:00
can1357 731c051733 feat(pi-shell/minimizer): implemented length threshold and empty preservation
- Add minimum character threshold to bypass minimization for short outputs.
- Add preserve-if-empty configuration and pipeline support for filters.
- Update test fixtures and integration tests to meet length thresholds.
2026-08-08 16:27:03 +02:00
can1357 a30cbbb75d feat(hashline): implemented syntax validation and veto checks for patch application
- Add a tree-sitter syntax probe and parser veto to prevent syntax-unaware boundary repairs.
- Reject span pastes from empty named registers instead of deleting ranges.
- Reject duplicate top-level snapshot row line numbers during parsing.
- Export new syntax module symbols and add associated tests and changelog updates.
2026-08-08 16:18:34 +02:00
roboomp a6aa462a60 fix(tui): bounded WSL idle animation CPU
- Removed the Loader backpressure cap so slow ConPTY paints retain the documented proportional duty cycle.

- Made WSL terminal-title working state static to avoid a second periodic OSC write loop.

Fixes #8012
2026-08-08 13:17:01 +00:00
roboomp 4ca6c376b4 fix(agent): detached append-only context on dispose
Disposed sessions remained reachable through lifecycle reviver closures. Agent.reset() cleared the live message array but left AppendOnlyContextManager attached, retaining its normalized provider transcript and stable prompt/tool prefix.

Detach the append-only manager during terminal disposal and extend the memory-release regression test to cover that second transcript copy.
2026-08-08 09:52:15 +00:00
roboomp ed6300b35e fix(agent): release parked subagent session memory on dispose
Keep-alive subagents are handed to AgentLifecycleManager.adopt, which stores
their reviver closure in the process-global #adopted map. The closure is
defined inside runSubagent's scope, which also captures the live AgentSession
(extension-runner callbacks, buildSubagentSessionOptions), so its lexical
environment pins the whole session graph. park() disposes and detaches the
session but leaves the adoption record indefinitely, and #doDispose never
dropped the in-memory transcript, session-manager entries, or the raw-SSE
debug buffer (whose trimmed records retain slice() views of full wire frames),
so every completed subagent's heavy state leaked for the process lifetime.

dispose() is terminal and every revival path reopens from disk, so #doDispose
now sheds retained conversation memory via agent.reset(),
RawSseDebugBuffer.clear(), and SessionManager.releaseRetainedEntries(). The
adoption record can still reference the session, but only as a husk.

Fixes #8003
2026-08-08 09:42:35 +00:00
roboomp a709a6604f fix(web-search): parsed double-encoded zai results
Decoded the extra JSON string layer returned by Z.AI MCP search and kept structured payloads out of answer text.

Added regression coverage for source extraction and plain prose preservation.

Fixes #8000
2026-08-08 09:04:04 +00:00
roboomp 7914e7c451 fix(session): preserved harness handoff abort reasons
Harness-initiated session aborts previously cancelled compaction before the handoff reason was recorded. The handoff catch then saw only an aborted signal and replaced the harness reason with "Handoff cancelled".

Abort the handoff first with the session reason, forward caller-signal reasons, and reserve "Handoff cancelled" for direct or unreasoned cancellation. Add a regression test for an in-flight handoff aborted through AgentSession.abort.

Fixes #7993
2026-08-08 09:02:28 +00:00
roboomp 92e574cb02 fix(session): surface empty handoff generation as failure not cancel
The #7904 fix stopped masking provider errors as "Handoff cancelled", but
an empty or whitespace-only generation still fell through: whitespace-only
text passed the `!handoffText` guard and produced a bogus handoff, while
empty text returned undefined which the interactive /handoff caller mapped
to "Handoff cancelled" with no detail and no log entry.

Treat empty/whitespace-only output as a real failure: a user-initiated
handoff throws "Handoff generation produced no content" (surfaced as
"Handoff failed: ...") and logs it; auto-handoff keeps returning undefined
so maintenance falls back to context-full compaction. Also log genuine
handoff failures in the command controller so they persist for debugging.

Fixes #7993
2026-08-08 08:21:16 +00:00
can1357 055a5d4f26 chore: bump version to 17.2.11 2026-08-07 23:38:40 +02:00
can1357 a9dcf0f8d1 chore: update changelogs 2026-08-07 23:38:26 +02:00
roboomp 5b3bed18b5 fix(launch): accepted empty daemon regex matches
Preserved zero-width readiness and wait matches across the daemon wire protocol, and isolated malformed completion events from unrelated pending RPCs.

Fixes #7908
2026-08-07 23:38:25 +02:00
roboomp a09dfd0ba8 fix(extensions): restored provider unregistration
Added the upstream unregisterProvider lifecycle to queued and initialized extension runtimes. Provider removal now clears runtime model/auth state before replacement, while failed factories restore the prior registration queue.

Fixes #7914
2026-08-07 23:38:25 +02:00
roboomp 4981eba1c2 fix(task): refreshed agent definitions without restart
Published per-cwd discovery snapshots to existing task tools and refreshed them from TUI, ACP, and Agent Control Center reload paths.

Added regressions for existing and future task tools across TUI and ACP reloads.

Fixes #7940
2026-08-07 23:38:25 +02:00
roboomp 7d4b2e7998 fix(agent): re-check context on cooldown-expiry revert in auto-continue path
A cooldown-expiry model revert runs at a turn boundary. The user-prompt
path reverts then re-checks accumulated context against the restored
model via runPrePromptCompactionIfNeeded, but the automatic
agent.continue() path (#scheduleAgentContinue) reverted and issued the
next request with no such check. When a transient failure had fallen
back to a larger-window model and the conversation then grew past the
original model's window, restoring the primary once its cooldown expired
sent a predictably oversized request to the smaller model.

maybeRestoreRetryFallbackPrimary now reports whether it actually
switched, and the auto-continue path runs the same post-revert
context-fit maintenance (compaction/promotion) the prompt path already
runs, but only when a revert occurred.

Fixes #7952
2026-08-07 23:38:24 +02:00
can1357 0e8142ad0e Merge PR #7904: fix(session): surface real handoff errors instead of false cancel (@roboomp) 2026-08-07 14:52:57 +02:00
roboomp 1e6638d8cd fix(session): surfaced real handoff errors instead of false cancel
The handoff catch in session-handoff.ts and the /handoff handler in
command-controller.ts mapped any error named AbortError to "Handoff
cancelled" regardless of whether the handoff signal was actually
aborted. Providers throw name-AbortError errors on non-user conditions
(stalls, idle timeouts, nested resolution failures), so a genuine
generation failure surfaced as a user cancellation and hid the cause.

Only report "Handoff cancelled" when handoffSignal.aborted is set;
re-throw the real error otherwise. The controller now trusts the
normalized "Handoff cancelled" message and drops its own AbortError
check so re-thrown provider failures render as "Handoff failed: ...".

Fixes #7903
2026-08-07 12:00:06 +00:00
can1357 422f5d137f chore: normalized changelogs after merging community fixes 2026-08-07 13:40:09 +02:00
can1357 37849df3e4 Merge PR #7759: docs(coding-agent): clarify js-debug-adapter install is not an npm package (@fcastillo18) 2026-08-07 13:39:54 +02:00
can1357 6606b55f7b Merge PR #7854: feat(coding-agent): mark child processes as agent-driven (@roboomp) 2026-08-07 13:39:54 +02:00
can1357 50741716b8 Merge PR #7888: fix(bash): constrain leading cd extraction to a single path token (@roboomp) 2026-08-07 13:39:54 +02:00
can1357 e6b1bd78d4 fix(status-line): clean up session accent metadata 2026-08-07 13:39:54 +02:00
can1357 ce122d7818 Merge PR #7867: fix(status-line): honor sessionAccent toggle for session_name segment (@CaelumSea) 2026-08-07 13:39:53 +02:00
can1357 c8096ee6e7 Merge PR #7773: fix(vault): pass vault= as top-level obsidian cli option (@roboomp) 2026-08-07 13:39:53 +02:00
can1357 0060ebacb1 Merge PR #7783: fix(acp): resolve session/load across legacy session directories (@roboomp) 2026-08-07 13:39:53 +02:00
can1357 a8a8188e4b Merge PR #7756: fix(coding-agent): preserve before_agent_start prompt override across base rebuilds (@roboomp) 2026-08-07 13:39:53 +02:00
can1357 7a6710cd55 Merge PR #7814: fix(coding-agent): clean up legacy Exa and computer settings (@chessl) 2026-08-07 13:39:52 +02:00
can1357 ee73df3aa2 Merge PR #7832: fix(coding-agent): prefer proxy-reported model name over bundled catalog name (@vinhnguyen1211) 2026-08-07 13:39:52 +02:00
can1357 73b91d89d4 Merge PR #7816: fix(coding-agent/tools): preserve native JSON Schema containers (@kimprap) 2026-08-07 13:39:52 +02:00
can1357 b50b05ee39 Merge PR #7790: fix(read): normalize recovery paths (@roboomp) 2026-08-07 13:39:52 +02:00
can1357 fe7774a1aa Merge PR #7806: fix(coding-agent): detect non-English questions in todo reminder guard (@roboomp) 2026-08-07 13:39:52 +02:00
can1357 5f758778b8 Merge PR #7785: fix(coding-agent): make prewalk lifecycle one-shot (@eggpeat) 2026-08-07 13:39:51 +02:00
can1357 62e219d355 Merge PR #7836: fix(commit): report hook refusals cleanly and honor --push on a clean tree (@roboomp)
# Conflicts:
#	packages/coding-agent/src/commands/commit.ts
2026-08-07 13:39:51 +02:00
can1357 9fc460e0d9 chore(coding-agent): correct commit fix changelog 2026-08-07 13:39:14 +02:00
can1357 551ba0d80e Merge PR #7844: fix(coding-agent): signalled fallback commits with a non-zero exit code (@zhang17-24) 2026-08-07 13:39:14 +02:00
can1357 9637a2cb0c Merge PR #7774: fix(tui): gate built-in renderers by tool provenance (@roboomp) 2026-08-07 13:37:57 +02:00
can1357 6e728f81de Merge PR #7840: fix(tui): make Ctrl+O expand tool output regardless of focus (@roboomp) 2026-08-07 13:37:57 +02:00
can1357 93f3c5c51c Merge PR #7782: fix(tree): stop rendering bookkeeping entries as empty rows (@ParadaCarleton) 2026-08-07 13:37:57 +02:00
can1357 9de48c2b1a Merge PR #7896: fix(natives): make Windows-host builds and addon loading work end to end (@zerx-lab) 2026-08-07 13:37:55 +02:00
can1357 68dece477f Merge PR #7772: fix(session): handle subscription-cap retry exhaustion (@roboomp) 2026-08-07 13:37:54 +02:00
zero 82436b0e93 fix(natives): make Windows-host builds and addon loading work end to end
Runtime: the loader's AVX2 probe used [System.Runtime.Intrinsics.X86.Avx2]
via powershell.exe, which only exists on .NET Core — stock Windows PowerShell
5.1 raised TypeNotFound, so every Windows host silently loaded the baseline
addon and paid ~270ms for the spawn on the startup path. Ask the kernel via
bun:ffi (IsProcessorFeaturePresent(PF_AVX2_INSTRUCTIONS_AVAILABLE), ~0.5ms)
and fall back to pwsh-then-powershell for Node embeds. scripts/host-detect.ts
shared the same broken probe for build-time variant selection.

Build: `bun run build:native` on a win32 host died deep inside the bazel msvc
repo rules (linux/mac exec hosts only, by design). The `host` pseudo-target
now delegates to the local napi build against real VS Build Tools, and other
targets fail fast with guidance. build-bindings.ts resolves the @napi-rs/cli
JS entry from its manifest (the node_modules/.bin shim is a PE launcher Bun
cannot parse) and auto-appends VS Build Tools' bundled CMake/Ninja to PATH
via vswhere so a vcvars prompt is no longer required. Cap maudio at
opt-level=1 to dodge a rustc ICE codegenning MaybeUninit<ma_fence> for
x86_64-pc-windows-msvc under the pinned nightly (Bazel's older pin is
unaffected).

Compile: Bun.Glob.scan yields backslash paths on Windows; the legacy Pi
virtual module used them verbatim for export keys and generated identifiers,
producing invalid JavaScript in compiled-binary builds.

Tests: strip ConPTY negotiation escapes in the pty argv test; ignore the
bazel-oh-my-pi convenience symlink.
2026-08-07 16:54:02 +08:00
roboomp 2597244b00 fix(bash): constrain leading cd extraction to a single path token
The `cd <path> && ...` extractor matched everything up to the first `&&`
with a greedy regex, so a redirect or extra argument before the `&&` was
swallowed into the structured cwd. `cd /tmp 2>/dev/null && echo ok` became
cwd `/tmp 2>/dev/null`, which failed fs.stat and killed the command before
the shell ran.

Replace the regex with `extractLeadingCdTarget`, a quote/escape-aware
scanner in shell-tokenize.ts that captures exactly one path token and
bails (leaving the command for the shell) when anything else — a redirect,
extra argument, shell expansion, or a non-`&&` separator — precedes the
top-level `&&`.

Fixes #7883
2026-08-07 06:43:55 +00:00