Commit Graph

8 Commits

Author SHA1 Message Date
roboomp ed37f076ef fix(read): render wide SQLite tables as vertical blocks
The ASCII table renderer in `sqlite-reader.ts` shrank columns down to
`MIN_COLUMN_WIDTH=1` to fit the 120-cell budget. With ~20+ columns
(the reporter had 33) every multi-char cell collapsed to a lone `…`
and the final per-line `truncateToWidth(..., MAX_RENDER_WIDTH)` then
chopped the right edge — so the read tool returned a table of nothing
but ellipses with the rightmost cells missing entirely.

Bump the per-column floor to 3 (so cells always show at least two real
glyphs alongside the ellipsis) and, when the column count alone forces
the floor over budget, fall back to a per-row vertical block layout —
mirroring `psql`'s expanded display mode. Each row becomes a
`column: value` group with column names padded so colons align and
the value line truncated to the same 120-cell budget.

Fixes #3107
2026-06-20 07:55:09 +00:00
can1357 c3054d5cea fix(coding-agent): capped read-stack resource use and fixed selector routing
tar/tgz stat-gated at 256MB, zip entries reject oversized declared sizes; raw ?q= sqlite capped at 1000 rows; giant-file reads stop scanning to EOF; multi-range reads slice one pass; malformed URL selectors error instead of dumping; archive-root selectors, member tag immutability, case-insensitive selector tokens, session-pinned artifact lookups, shared+escaped suffix globs; archive dir listings honor offsets; binary files get a NUL-sniff notice.
2026-06-10 01:27:17 +02:00
can1357 cbd7c20105 feat(coding-agent/tools): added binary routing for notebook, sqlite, and archive payloads
- Added archive format sniffing to identify ZIP, TAR, and TAR.GZ from file bytes.
- Added MIME/extension and header-based routing for notebook, sqlite, and archive payloads.
- Added archive entry rendering with slash-terminated dirs and size suffixes.
- Added tests for archive, sqlite, notebook, and fallback binary dispatch scenarios.
2026-06-07 06:55:52 +02:00
can1357 b522fde56d perf(sqlite-reader): replaced full COUNT(*) scan with bounded row probing
- Added ROW_COUNT_PROBE_CAP to limit rows scanned when counting tables, preventing JS thread freezes on large databases.
- Used sqlite_stat1 estimates for tables exceeding the cap; exact counts only for provably small tables.
- Introduced TableRowCount type with exact/estimate/atLeast variants reflected in rendered output.
2026-06-02 05:24:21 +02:00
can1357 a019994091 feat: added tree-sitter summarizeCode support and N-API summary exports
- Updated read schema, path utilities, and dispatch to parse selectors from :raw/:L suffixes on path, removing standalone sel usage.
- Changed truncation/error notices to continue with :<nextOffset> and :1 guidance for read and sqlite pagination.
- Added summarizeCode support with tree-sitter summaries, read.summarize settings, and N-API Summary types/exports.
- Added tests and docs updates for path-embedded selectors, summary behavior, and explicit raw/offset SQL/read cases.
2026-05-04 04:24:33 +02:00
JunghwanNA 0d6968f7a6 Keep sqlite where filters inside the paginated helper
The SQLite read helper is documented as a structured selector path
with explicit pagination, while raw SQL already has a separate
q=SELECT escape hatch. This change rejects SQL control syntax outside
quoted strings so helper filters cannot override LIMIT/OFFSET, while
still allowing semicolons inside quoted literals such as LIKE '%;%'.

Constraint: Preserve the documented q=SELECT raw SQL path unchanged
Rejected: Replace where= with a new filter DSL | too broad for a regression fix
Confidence: high
Scope-risk: narrow
Directive: Keep table?where=... as a structured helper; if broader SQL is needed, route it through q=SELECT instead
Tested: bun --cwd=packages/natives run build; bun --cwd=packages/coding-agent run check; bun --cwd=packages/coding-agent test test/tools/sqlite.test.ts
Not-tested: Manual interactive omp read invocation against a live SQLite file
2026-04-24 07:25:09 +02:00
can1357 cafa86a6cf fix(tools/sqlite): reject comments, terminators, and pagination keywords in where=
The structured SQLite helper interpolates `where=` directly into SQL.
A crafted clause like `where=1=1 LIMIT 1000000 --` could comment out
the helper's bound `LIMIT ? OFFSET ?`, returning the full table in
violation of the documented pagination contract.

Validate where= at the selector boundary and reject SQL comments,
statement terminators, and pagination/attach/pragma keywords. Raw SQL
remains available via ?q=SELECT... for callers that need it.

Fixes #735
2026-04-24 06:33:20 +02:00
can1357 2cd8f52f4e feat(tools): added SQLite database operations with read/write support and query validation
- Added SQLite path parsing and candidate validation for `.sqlite`, `.db`, `.db3`, and `.sqlite3` targets in read/write flows.
- Added SQLite read operations for table lists, schema views, row lookups, paginated queries, and raw SELECT mode.
- Added SQLite write operations for insert, update-by-key, and delete-by-key using JSON5 row payloads.
- Updated selector routing to validate SQLite headers and fall back to normal file reads/writes when not databases.
- Secured read mode by enforcing query validation to block destructive SQL execution on SQLite inputs.
2026-04-11 08:57:58 +02:00