Commit Graph

823 Commits

Author SHA1 Message Date
can1357 6b90d34924 Merge remote-tracking branch 'origin/farm/96461c96/fix-browser-cmux-pending-unhandled-rejection' 2026-07-04 11:27:29 +02:00
can1357 42fc4e6b0a refactor(agent): unified transcript block finalization logic
- Replaced commit-based stability checks with a unified `isTranscriptBlockFinalized` tracking mechanism.
- Removed deprecated provisional rendering configuration and flags across tool and renderer interfaces.
- Standardized native scrollback boundary logic to pin at the first unfinalized block using settled row verification.
- Updated and refactored test suites to validate block finalization and settled row boundaries instead of deprecated commit stability methods.
2026-07-04 11:22:05 +02:00
roboomp 8bd40a6db9 test(browser): restored cmux release mocks after each test
The cmux release regression tests install spies on CmuxSocketClient.prototype. Bun keeps those spies active across later browser-* files unless the file restores them explicitly, so browser-cmux-socket.test could stop exercising the real socket client depending on order.

Restore all Bun test mocks in afterEach after draining any test tabs, preserving mocked cleanup while preventing cross-file pollution.

Fixes #4499
2026-07-04 06:29:41 +00:00
roboomp a6a8258945 fix(browser): propagate cmux tab-close into the run body, not only the caller
Codex review of #4502 flagged that a bare `.catch(() => undefined)`
neutralizes the unhandledRejection but leaves the affected `runInTab`
call blocked inside `runCmuxCode` until timeout when the in-flight
code does not make another cmux socket request (e.g. `await
wait(60_000)`). `releaseTab` was signaling the run only by rejecting
an orphaned promise.

Wire the tab-close event all the way into the cmux run body:

- `PendingRun` gains a `closeAc: AbortController` that `releaseTab`
  aborts BEFORE calling `pending.reject`. `wait(...)` (via
  `waitForBrowserRun` -> `untilAborted`), in-flight cmux socket calls
  (via CmuxTab's `#request` -> `untilAborted`), and facade proxies
  (via `bindBrowserRunFacade`) all consume the composed signal, so
  the run body unwinds within a microtask instead of blocking to its
  own timeout.
- `runInTabWithSnapshot`'s cmux branch composes `closeAc.signal` into
  the run's signal (`AbortSignal.any([opts.signal, closeAc.signal])`)
  and now publishes `runCmuxCode(...)`'s outcome to the shared
  `promise` via `.then(resolve, reject)` and returns `await promise`.
  Both branches thus await the same promise, so `pending.reject`
  always has an attached handler (removing the original crash) AND
  the caller sees `Tab "..." was closed` immediately instead of
  waiting on the run's timeout.
- Drop the defensive `promise.catch(() => undefined)` — the promise
  is now actively consumed on both backends.

The new regression test adds a second case that exercises the
reviewer's exact scenario (`await wait(60_000);`) and asserts:
1. `pending.closeAc.signal.aborted` flips from `false` to `true`
   across `releaseTab`, with the tab-close error as its reason.
2. The awaited `runInTab(...)` rejects with `Tab "..." was closed`.
3. No `unhandledRejection` fires.

Verified locally by temporarily removing `closeAc.abort(...)` in
`releaseTab` — the new assertions fail; restoring it makes them pass.

Fixes #4499
2026-07-04 06:24:45 +00:00
roboomp 3622094e91 fix(browser): swallowed cmux tab-close rejection to prevent session crash
The cmux branch of `runInTabWithSnapshot` awaits `runCmuxCode(...)`
directly and never awaits/`.catch`es the `Promise.withResolvers()`
promise it stashes on `tab.pending`. When `releaseTab` walks pending
runs and calls `pending.reject(new ToolError("Tab ... was closed"))`
(a sibling subagent's `browser close --all`, session-scoped reap, etc.),
that orphaned promise had zero handlers and Bun surfaced the rejection
as `unhandledRejection`, which the CLI's top-level handler treats as
fatal — killing every other tab and subagent sharing the process, not
just the affected run.

Attach a no-op `.catch(() => undefined)` to the promise immediately
after creation. Inert for the worker branch (which still awaits the
same promise via `raceWithTimeout`, and attaching a second handler is
safe) and neutralizes the orphan on the cmux branch.

Adds a regression test that drives real `acquireBrowser` /
`acquireTab` / `runInTab` / `releaseTab` against a mocked
`CmuxSocketClient`, races `releaseTab` against an in-flight cmux run,
and asserts no `unhandledRejection` fires.

Fixes #4499
2026-07-04 06:06:18 +00:00
can1357 6f8e060419 Merge remote-tracking branch 'origin/farm/d78d878e/lsp-duplicate-edits' 2026-07-04 05:14:37 +02:00
can1357 98e450f0c4 Merge remote-tracking branch 'origin/farm/2dfff794/suppress-orphan-lsp-noise' 2026-07-04 05:13:55 +02:00
roboomp 2b8c8cadfb fix(read): kept raw artifact chunks verbatim and broadened path-only resolution
Skipped the workflow notice on raw selectors so bounded raw reads stay byte-for-byte, and taught resolveToolSearchScope to request pathOnly resolution so ast_grep/ast_edit scope-only calls no longer trip the inline-content cap on large artifacts.

Fixes #4482
2026-07-03 23:36:57 +00:00
roboomp 7497e68189 fix(read): shortened artifact paths in user-visible notices
shortenPath() the artifact.path leaked into the read-tool 'Artifact storage' and 'Unbounded raw read blocked' notices so $HOME never appears verbatim; details.resolvedPath keeps the absolute path for tooling.

Fixes #4482
2026-07-03 23:20:20 +00:00
roboomp a9bb4c7d59 fix(read): guarded large artifact raw reads
Resolved artifact:// reads to backing files before selector handling, streamed bounded reads, and blocked unbounded raw reads for large artifacts with recovery guidance.

Fixes #4482
2026-07-03 23:08:18 +00:00
roboomp cf908b1727 fix(lsp): deduped identical replacement edits
Collapsed duplicate byte-identical non-empty LSP text edits before overlap validation so rename_file accepts idempotent server output while still rejecting real conflicts.

Fixes #4458
2026-07-03 15:40:21 +00:00
roboomp 136bda2399 fix(lsp): suppressed orphan ts project diagnostics
Filtered TypeScript project-resolution diagnostics for files with no root marker ancestor while preserving syntax diagnostics. Added regression coverage for Bun scratch files outside project roots.\n\nFixes #4401
2026-07-03 05:54:49 +00:00
can1357 98338d0c55 Merge remote-tracking branch 'origin/farm/6f458e03/configurable-gemini-search-model' 2026-07-02 23:43:08 +02:00
can1357 b9ce7ef103 Merge remote-tracking branch 'origin/farm/b15f12c7/ssh-repaint-topology'
# Conflicts:
#	packages/coding-agent/src/tools/renderers.ts
2026-07-02 23:42:59 +02:00
can1357 e73a25489c feat(coding-agent/tools): migrated path input from array to semicolon-delimited string
- Changed the `path` property from an array of strings to a single semicolon-delimited string across tool definitions and tests.
- Updated validation error messages to reflect the new `path` input format.
- Adjusted all relevant test cases to provide path targets as semicolon-separated strings.
2026-07-02 17:48:46 +02:00
roboomp cc97fada73 fix(tui): repainted ssh topology flips
- Added renderer hooks for first-result placeholder replacement and partial-result settle repaints.\n- Enabled the hooks for SSH and covered the streamed-placeholder and settle seams.\n\nFixes #4314
2026-07-02 13:01:24 +00:00
roboomp 289ea08a39 fix(providers): made gemini search model configurable
Added providers.webSearchGeminiModel and GEMINI_SEARCH_MODEL so Gemini web_search requests use a selected grounding model while keeping gemini-2.5-flash as the fallback.

Covered OAuth, Developer API, and missing modelVersion fallback paths in Gemini web search tests.

Fixes #4312
2026-07-02 12:44:55 +00:00
can1357 95b91c7f73 feat(coding-agent/tools)!: replaced paths arrays with path strings
- Replaced `grep`, `glob`, and `ast_grep` `paths` inputs with optional single `path` strings while preserving default workspace-root behavior.
- Added shared `toPathList` normalization for legacy arrays and JSON-encoded arrays across tool execution and TUI renderers.
- Updated prompts, fixtures, shims, transcript summaries, and tests to send and display the new `path` argument.
- Updated collab-web search tool cards to read `path` while falling back to legacy `paths` for historical transcripts.
- Recorded the contiguous coding-agent changelog run for the tool-path breaking change and adjacent TTS entries.
2026-07-02 08:30:33 +02:00
can1357 51684b4b1d refactor(coding-agent): streamlined codebase by deduplicating helper logic and shims
- Consolidated duplicated inline thinking level comparisons into a unified `concreteThinkingLevel` helper.
- Enhanced legacy tool shims to respect isolated session settings and support legacy options.
- Cleaned up redundant UI render requests and extra status-line updates.
- Refactored `grep` tool shim to configure context dynamically via isolated settings.
- Disabled platform-incompatible shell shim tests on Windows environments.
2026-07-02 02:40:08 +02:00
can1357 978b950804 fix(coding-agent): resolved path resolution and fetch errors for fuzzy urls
- Fixed grep and ast-grep tools rejecting fuzzy url-shaped paths like schemeless www. or collapsed-scheme spellings.
- Applied the extra-CA wrapper to the model registry default fetch to respect the NODE_EXTRA_CA_CERTS environment variable.
- Moved isReadableUrlPath utility to path-utils to share recognition logic between reading and searching pipelines.
- Implemented a fallback that checks if a directory matching a fuzzy URL path exists locally before resolving it as an external URL.
- Added explicit errors for unsupported URL schemes to replace misleading local-path errors.
2026-07-02 01:51:09 +02:00
can1357 efbdb23581 fix(coding-agent): enabled closed union validation for yield labels
- Extends output schema validation to support `oneOf` and `anyOf` closed union schemas.
- Prevents unknown section label submissions when all union variants constraint allowed properties.
- Permits arbitrary yield labels when at least one union variant remains open.
- Supports JTD discriminator output schemas by treating union constraints disjunctively.
2026-07-02 01:51:09 +02:00
can1357 0823892295 fix(coding-agent): repaired type errors from merge sweep
- Restored CustomInputRow.priority field dropped in 3b80dc01d ask row budgeting.
- Narrowed dereferenced schema properties via isRecord in yield-assembly and output-schema-validator instead of untyped object access.
- Renamed stale advisorReadOnlyTools to advisorTools in advisor parity test.
- Narrowed AgentMessage content access in session-loader-stream test.
- Reformatted browser-schema test to satisfy biome.
2026-07-01 23:49:32 +02:00
can1357 1b3bcb98db refactor(coding-agent/tools): consolidated browser tool schemas into a single schema
- Consolidated `browserOpenSchema`, `browserCloseSchema`, and `browserRunSchema` into a single `browserSchema`.
- Simplified the `action` type definition to accept `'open' | 'close' | 'run'`.
- Updated schema validation tests to reflect the unified schema definition.
2026-07-01 23:18:17 +02:00
ben 510ed57712 fix(coding-agent): harden local ci isolation review fixes 2026-07-01 22:25:04 +02:00
can1357 021d4fc1e3 Merge PR #4161: fix(agent): interrupt waits for IRC delivery (@roboomp) 2026-07-01 21:53:19 +02:00
can1357 c982cb34e9 Merge PR #3987: fix(eval): keep agent progress commit-unstable while partial (@metaphorics) 2026-07-01 21:50:55 +02:00
can1357 aee8b091ee fix(agent): honor closed schema label edge cases 2026-07-01 21:50:54 +02:00
can1357 88e3e77f3e Merge PR #3927: fix(agent): reject stale yield labels for override schemas (@roboomp) 2026-07-01 21:50:54 +02:00
can1357 52003878b5 Merge PR #3865: fix(web-search): clarify DuckDuckGo bot detection failures (@roboomp) 2026-07-01 21:47:55 +02:00
can1357 3b80dc01de fix(tui): cap sparse ask other gaps 2026-07-01 21:42:24 +02:00
can1357 278b715ab8 Merge PR #3662: fix(tui): keep ask Other context visible (@roboomp) 2026-07-01 21:42:24 +02:00
can1357 8350e4a139 fix URL search scope edge cases 2026-07-01 21:42:23 +02:00
can1357 6066814d3e Merge PR #3650: fix(tools): materialize URL paths for search scopes (@roboomp) 2026-07-01 21:42:23 +02:00
can1357 12120a1cd4 Merge PR #3647: fix(tool): require browser run code in schema (@roboomp) 2026-07-01 21:42:23 +02:00
roboomp bce14d9cca fix(irc): preserved send receipt when reply wait is interrupted
op:send await:true runs the reply wait under the same signal as the pure wait
paths. When the tool signal aborts after delivery succeeded, throwing turned the
call into a skipped tool result, so the model was liable to resend the same
message on the next turn. Surface the delivery receipts as a successful result
with a note that the reply wait was cut short.
2026-07-01 17:03:33 +00:00
roboomp 619bfda3eb fix(agent): interrupted irc waits
Fixes #4160
2026-07-01 16:56:08 +00:00
roboomp 29d65875f7 fix(tool): rejected ssh tilde cwd
Validated SSH cwd before probing remote hosts so literal tilde paths are rejected instead of sent through quoted POSIX cd commands.

Fixes #4002
2026-07-01 03:54:18 +00:00
metaphorics 7460a66bf8 fix(eval): keep agent progress commit-unstable while partial
The eval tool's live agent()/parallel() subagent progress tree
(renderAgentProgressEvents) mutates on almost every progress tick: each
subagent's row inserts/removes a "current tool" line as it starts/stops a
tool call, and ticks its status icon/stats/duration in place. Meanwhile
options.isPartial holds true for the whole eval() cell — progress ticks
never carry an async completed/failed state, so the update handler keeps
passing isPartial: true throughout.

evalToolRenderer never opted out of the transcript's stable-prefix ratchet
for partial results, so ToolExecutionComponent.isTranscriptBlockCommitStable()
reported the block commit-stable during that churn. That let
deriveLiveCommitState promote still-mutating agent rows into native
scrollback (a "slow ticker"), and the renderer's committed-prefix resync
then repeatedly re-showed the frame tail under its "duplication, never
loss" contract — producing overlapping/duplicated subagent rows in the
TUI under heavy concurrent agent()/parallel() fan-out.

Set provisionalPartialResult: true on evalToolRenderer, the same opt-out
sshToolRenderer already uses for this class of bug (see the "pinned
expanded pending preview commit-unstable" fix). The block now stays
commit-unstable until the eval cell settles, keeping agent-progress rows
in the live, repaintable region for their whole lifetime.

Added eval-commit-stability.test.ts covering: partial → commit-unstable,
settled → commit-stable, non-opted-in tools (bash) unaffected, and
commit-unstable held across row-count/content churn between two partial
ticks.

Op: correct
Restores: spec:eval agent-progress rows must not be promoted into native scrollback while still mutating
2026-07-01 12:22:43 +09:00
can1357 d562f28c1b Merge remote-tracking branch 'origin/farm/795471ef/cancel-timed-out-browser-run' 2026-07-01 04:46:41 +02:00
can1357 2b9d2ca44e merge PR #3968: fix(browser): reap Chromium/Puppeteer on aborted open and session dispose 2026-07-01 04:40:46 +02:00
roboomp f7398a1aa8 fix(browser): bound cmux facades to runs
Wrapped cmux page, browser, and tab globals with per-run abort checks so stale continuations cannot reuse the long-lived CmuxTab after timeout.

Fixes #3964
2026-07-01 02:30:07 +00:00
roboomp 769a9e5807 fix(lsp): only teardown clients on in-flight flush aborts
Distinguish aborts that race an active sink.flush() from aborts that happen
before a queued write starts. Only the former leaves the sink flush pending
and requires killing/evicting the LSP client; pre-write aborts should reject
that caller without disrupting unrelated in-flight operations.

Add a regression with one notification blocked in flush and a second queued
notification whose signal aborts before its write starts, asserting the shared
client is not killed and only the first message is written.
2026-07-01 02:21:40 +00:00
roboomp db8560f934 fix(browser): stopped stale timed-out runs
Aborted browser run helpers and recycled timed-out workers so losing JavaScript continuations cannot mutate a live tab after timeout.

Fixes #3964
2026-07-01 02:21:19 +00:00
roboomp 0a1392de4b fix(lsp): skip init failure cache on caller abort
Caller cancellations and tool timeout signals are transient initialize failures.
Do not put them in the three-minute init failure backoff, so a later normal
LSP call can retry the server/cwd instead of failing fast as recently failed.

Add a regression that aborts a wedged initialize and then retries the same
server/cwd with a short explicit timeout, asserting it does not hit the
negative-cache error.
2026-07-01 02:13:59 +00:00
roboomp 7282230094 style: bun run fix 2026-07-01 02:09:17 +00:00
roboomp 19b85bca70 fix(browser): reap Chromium/Puppeteer on aborted open and session dispose
Two termination boundaries in the browser tool leaked browser-owned OS resources into the long-lived coding-agent process.

1. Aborted 'open' published an orphan. #open wrapped acquisition in untilAborted, which rejects its outer wrapper on abort but lets the inner launch resolve in the background; acquireBrowser then unconditionally stored the resolved handle in the module-global browsers map. releaseAllTabs walks tabs, not browsers, so the refCount:0 handle stayed alive to process exit.

2. Session dispose had no browser teardown. Browser/tab state lives in module-global maps, and AgentSession.dispose() had no hook to walk them, so headless/spawned Chromium the session opened survived it.

acquireBrowser now short-circuits before launch on a pre-aborted signal and disposes the handle when the launch completes after abort. TabSession records the creating session's id (opts.ownerSessionId, threaded through BrowserTool.#open), preserved across reuse so a subagent re-driving an existing tab does not yank teardown responsibility. AgentSession.dispose() invokes releaseTabsForOwner bounded by withTimeout(3s), mirroring the async-job/MCP disposal pattern.

Regression tests exercise both boundaries via spied CmuxSocketClient (no real puppeteer/socket) and cover: pre-aborted open short-circuit, aborted-mid-launch cleanup, releaseTabsForOwner reaping only owned tabs, and reuse preserving original ownership.

Fixes #3963
2026-07-01 02:09:04 +00:00
roboomp 11edbe01c2 style: bun run fix 2026-07-01 02:06:16 +00:00
roboomp 442ee57283 fix(lsp): honor tool signal in cold-start initialize and notification writes
Two client-level paths in the LSP tool bypassed the combined tool-timeout/
caller abort signal built in `LspTool.execute`, so a wedged server hung
past the advertised tool deadline and past user cancellation:

- `getOrCreateClient` took no `AbortSignal` and its `initialize`
  `sendRequest` was invoked with `signal = undefined`. With no signal
  and no explicit `timeoutMs`, `sendRequest` fell back to the hard-coded
  `DEFAULT_REQUEST_TIMEOUT_MS = 30000` internal timer, so a first-use
  `lsp` call against a server that wedged in `initialize` ignored the
  20s tool default (and any user-supplied shorter `timeout`) until the
  30s internal timer fired.
- `writeMessage`/`queueWriteMessage`/`sendNotification` had no timeout
  and no signal, so a `textDocument/didOpen`/`didChange`/`didSave` sent
  to a server that stopped draining stdin awaited `sink.flush()`
  forever. Because writes serialize through `client.writeQueue`, every
  later op on the client stalled behind the stuck flush too.

Thread the caller `AbortSignal` through `getOrCreateClient` (initialize
+ initialized notification) and through `sendNotification` /
`queueWriteMessage` / `writeMessage` so the sink flush is raced against
the signal. On abort, tear the client down: kill the process and evict
it from the active-clients map so the next `getOrCreateClient` call
spawns a fresh server instead of queueing behind the wedged sink.

Update the LSP tool callsites and internal helpers
(`captureDiagnosticVersions`, `captureOpenFileVersions`,
`syncFileContent`, `notifyFileSaved`, `formatContent`,
`getDiagnosticsForFile`, `reloadServer`, and the rename didClose /
didRenameFiles path) to forward their operation signal.

Warmup keeps its short explicit `initTimeoutMs` and passes no caller
signal; `sendRequest`'s existing `timeoutMs ?? (signal ? undefined : DEFAULT)`
policy still uses that fixed timer.

Fixes #3962
2026-07-01 02:06:03 +00:00
roboomp 578a2d7626 fix(ast): bounded ast search pagination payloads
Retained only the requested AST search page window in native ast_grep/ast_match and the coding-agent multi-target wrapper while preserving exact totals.

Fixes #3935
2026-06-30 23:54:17 +00:00
roboomp 7ee0779fb3 fix(agent): dereferenced root $ref for yield labels
- Resolved a root-level `$ref` before deriving the incremental-label map and the closed-schema flag, so caller schemas exported as `{$ref: '#/$defs/Closed', $defs: {...}}` reject unknown labels at the yield gate instead of leaking through to parent-side schema_violation.\n- Added a regression test using a top-level `$ref` into `$defs.Closed`.\n\nRefs #3926
2026-06-30 22:32:23 +00:00