Commit Graph

3548 Commits

Author SHA1 Message Date
Mathews-Tom ea65e8a2f2 Merge remote-tracking branch 'upstream/main' into feat/secret-friendly-names
# Conflicts:
#	packages/coding-agent/src/eval/__tests__/julia-prelude.test.ts
2026-06-23 17:12:13 +05:30
can1357 af2e53e070 fix(test): align :async: background-retention test with nohup reparenting
`nohup cmd &` is now a transparent background wrapper that double-forks the
operand so it reparents to init (commit 00dcd54597). The shell only tracks
the short-lived intermediate fork, so `$!` is no longer the surviving
process — the prior test read `$!`, then `process.kill(pid, 0)` checked an
already-reaped pid and failed on Linux (the failing CI job).

Split into two contracts:
- plain `&` retention: stays a child of the shell, counted by
  `liveBackgroundJobCount`, kept alive by the retain map; `$!` is the real
  child pid we assert on.
- nohup reparenting: the operand writes its own pid before `exec`ing the
  long sleep, and that (post-exec-stable) pid is asserted to survive across
  turns — independent of `$!`.
2026-06-23 09:45:11 +02:00
can1357 a6bdef85a2 feat(ai): added support for reasoning items in replay sanitization
- Added `sanitizeOpenAIResponsesReasoningItemForReplay` to process reasoning-type items by stripping unique identifiers and filtering properties.
- Updated the main sanitization utility to route reasoning items through the new logic.
2026-06-23 08:18:59 +02:00
can1357 2787b6dff7 chore: update changelogs 2026-06-23 08:18:29 +02:00
can1357 c311c30cad fix(coding-agent): resolved local image protocol and process handling
- Standardized `local://` image processing to prevent file corruption during decoding.
- Refactored local path resolution logic to enforce safety constraints and path containment.
- Implemented an image fast-path in `ReadTool` to correctly render local images before text decoding.
- Added comprehensive test coverage for image rendering, text compatibility, and path security.
- Resolved an event loop hang associated with `omp --resume` operations.
2026-06-23 05:16:25 +02:00
can1357 26443eefac fix(coding-agent): terminated process on cancelled startup resume picker
- Force process exit when the startup session picker is cancelled instead of returning.
- Prevent hanging the event loop caused by long-lived startup handles such as theme listeners and timers.
- Add regression test case to verify clean process termination upon picker cancellation.
2026-06-23 05:15:08 +02:00
can1357 92d03466b7 Merge branch 'farm/c8a3da70/fix-resume-delete-scroll' into resume picker
Resolve the session-selector.ts conflict by integrating the delete-dialog
content-slot fix (#3283) on top of the fullscreen mouse-picker refactor.

The branch swapped the delete-confirmation dialog INTO a single content
slot (replacing the SessionList) so the picker is always
`chrome + max(list, dialog) + chrome` and never overflows the viewport.
Adjustments baked into this merge:

- Wrap the SessionList in `#contentSlot` and keep the dialog swapping into
  that slot, but preserve the new fullscreen path: mouse hit-testing,
  the pinned footer (`#footerLines`/`#footerStart`), and fill-height
  trimming all still work because the render offset now tracks
  `#contentSlot` (the list lives one level down).
- Keep both CHANGELOG entries (picker mouse/fullscreen + #3283 fix) and
  the ported scroll-stability regression test.
2026-06-23 02:46:56 +02:00
can1357 cffb804d3a feat(coding-agent): added mouse support and fullscreen rendering to session picker
- Enabled fullscreen overlay rendering for the terminal session picker.
- Implemented full mouse support including wheel-based scrolling and click-to-select functionality.
- Anchored the session picker footer to the bottom of the viewport to correct UI flickering.
- Added comprehensive unit tests for mouse interaction and layout constancy during resizing.
2026-06-23 02:25:30 +02:00
roboomp e266782604 fix(session-selector): swap delete dialog into SessionList slot
Earlier rounds shrank the SessionList by the dialog's row count to keep
the picker inside the viewport, but the SessionList could only claw back
whole session rows and bottomed out at zero entries. On a narrow
terminal with a long session title the dialog still wrapped past what
the SessionList could free, the picker overflowed the viewport, and the
TUI committed the header into native scrollback.

The picker now hosts the SessionList inside a single contentSlot
Container. Opening the delete confirmation swaps the dialog INTO that
slot (replacing the SessionList); closing it swaps the SessionList back.
The dialog therefore competes only with the SessionList's rendered
budget, not with the SessionList AND the picker chrome, so the picker
frame stays bounded by terminalRows even when the dialog wraps to many
rows. SessionList's external-reserve plumbing is no longer needed and is
removed.

Addresses PR #3285 second-round review feedback.
2026-06-23 00:05:53 +00:00
roboomp 964dc480c9 fix(session-selector): derive delete-dialog reserve from rendered height
The first round of the issue #3283 fix reserved a fixed 12 SessionList
rows for the delete confirmation dialog. On a narrow terminal or against
a long session name, HookSelectorComponent's Markdown title and help
text wrap past 12 rows; the picker would still overflow even after the
SessionList shrank to zero entries, and the TUI committed the picker
header into native scrollback again.

SessionSelectorComponent now overrides render() to measure the dialog's
actual rendered height at the live width before super.render() walks
the children, and pushes that as the SessionList's external-row reserve.
The dialog's own Container memoization makes the extra pre-render
essentially free.

Addresses PR #3285 review feedback.
2026-06-22 23:56:25 +00:00
can1357 c4e23fed15 fix(coding-agent/tools): enabled live stdout streaming for running cells
- Update the eval tool to stream stdout chunks directly into the active cell's output buffer while the process is still running.
- Prevent long-running cells from appearing empty in the UI by surfacing incremental output before the backend resolves.
- Add regression tests to ensure streamed output is captured mid-execution and reconciled with final results.
2026-06-23 01:46:45 +02:00
can1357 6ff37e346a feat(coding-agent): extended --thinking CLI flag options
- Added `off` and `auto` as valid inputs for the `--thinking` CLI flag.
- Centralized thinking level definitions in `CLI_THINKING_LEVELS` to keep flag options, shell completions, and validation in sync.
- Configured CLI parsing to reject `inherit` as an explicit input to prevent unintended configuration suppression.
2026-06-23 01:46:36 +02:00
can1357 1dd78b207e feat(coding-agent): removed unused eval helper functions
- Removed deprecated eval prelude helpers `append`, `tree`, `diff`, `sort`, `uniq`, and `counter` from all supported runtimes.
- Cleaned up runtime implementations, protocol definitions, and UI rendering logic associated with the removed helpers.
- Updated project documentation, prompts, and test suites to reflect the reduced helper API surface.
- Recorded functional changes in the package changelog.
2026-06-23 01:39:24 +02:00
roboomp ecdff42513 fix(session-selector): keep /resume header pinned after delete
The delete-confirmation dialog mounted as a sibling below the picker's
bottom border briefly grew the picker past the terminal height. The TUI's
append-only renderer committed the picker's top rows (header + first
sessions) into native scrollback to fit the dialog within the viewport.
When the dialog closed and the picker re-rendered shorter, `windowTop`
stayed pinned at `#committedRows`, leaving the picker stranded below the
committed prefix — the user saw the header scrolled off the top.

SessionList now exposes `setExternalReserveRows`; SessionSelectorComponent
reserves the dialog's worst-case height while the dialog is mounted so
the picker's total rendered output stays within the terminal viewport
and the TUI never commits its rows.

Fixes #3283
2026-06-22 23:38:11 +00:00
can1357 060f4004e7 feat(coding-agent): refactored eval tool to single-step execution
- Transitioned the eval tool from batch multi-cell execution to a single-step input structure with flat parameters.
- Updated core agent logic, UI components, and documentation to support state persistence across incremental eval calls.
- Restricted bash tool capabilities by requiring explicit use of `read` or `find` instead of `ls` or `find`.
- Added support for Ruby and Julia language runtimes to the eval tool and associated web renderers.
2026-06-23 00:59:58 +02:00
can1357 899c0ef08b feat: simplified todo tool to single operation interface
- Refactored `todo` tool to accept a single operation object instead of an `ops` array.
- Implemented parameter normalization to maintain backward compatibility with legacy array-based tool calls.
- Updated tool instructions, documentation, and UI rendering components to reflect the new interface.
- Added compatibility tests to verify rendering and execution for both legacy and current operation formats.
2026-06-23 00:54:54 +02:00
can1357 2ff005a354 fix(coding-agent/modes): resolved escape key handling under kitty keyboard protocol
- Update input handler to recognize CSI-u escape sequences using `matchesKey`.
- Ensure legacy bare escape sequences remain supported in environments without the protocol.
- Add test coverage for both CSI-u and legacy escape inputs.
2026-06-23 00:36:54 +02:00
can1357 cdc83c1de7 feat(coding-agent/utils): added minimum dimension scaling to image resize
- Added `minDimension` option to ensure images meet minimum size requirements for vision backends.
- Implemented logic to scale up undersized input images while respecting maximum constraints.
- Clamped minimum dimension floor to avoid resolution conflicts with defined maximum bounds.
2026-06-23 00:34:01 +02:00
can1357 241d519b57 Merge remote-tracking branch 'origin/farm/f6500cc6/fix-ask-other-escape' 2026-06-23 00:02:15 +02:00
can1357 378507e52a Merge remote-tracking branch 'origin/farm/3b4c9332/exa-search-rate-limit' 2026-06-23 00:02:08 +02:00
can1357 44b62419c5 Merge remote-tracking branch 'origin/farm/fc89a4e3/goal-auto-compaction-still-not-triggering' 2026-06-23 00:01:47 +02:00
can1357 bda98c63ef feat(coding-agent): elevated eval to an essential tool to ensure
- Elevated `eval` to an essential tool to ensure availability across all discovery modes.
- Updated system and tool prompts to mandate the use of `eval` for non-trivial shell operations like conditionals, loops, heredocs, and complex pipelines.
- Restricted `bash` usage to simple binary invocations and single-fact computation to reduce shell-escaping and execution errors.
2026-06-23 00:01:05 +02:00
Mathews-Tom 21d8b0e3f5 Merge remote-tracking branch 'upstream/main' into feat/secret-friendly-names
# Conflicts:
#	packages/coding-agent/src/eval/__tests__/julia-prelude.test.ts
2026-06-23 02:23:42 +05:30
can1357 24d58033bb refactor(eval): rename agent() params agent_type→agent, return_handle→handle
The eval agent() helper used `agent_type`/`return_handle` (snake_case) in
Python/Ruby/Julia and `agentType`/`returnHandle` (camelCase) in JS, forcing
the prelude docs to repeat every option twice ("JS same but camelcased").
Both are now single lowercase words identical across all four runtimes, and
`agent` matches the `task` tool's existing agent-selection parameter.

- Renamed across py/js/rb/jl preludes (signatures, forwarding, docstrings).
- Renamed the `__agent__` bridge wire protocol + `EvalAgentArgs` (`agentType`
  → `agent`, `returnHandle` → `handle`) so no prelude-side remap is needed.
- Updated prompt docs (workflow-notice.md, tools/eval.md), repo docs
  (docs/tools/eval.md, docs/python-repl.md), and all bridge/prelude tests.
- CHANGELOG: Breaking Changes entry under [Unreleased].
2026-06-22 22:12:24 +02:00
roboomp a305e68a53 fix(compaction): compact goal runs between tool turns
Active goal loops can stay inside one agent run while the model keeps
emitting tool calls, so the normal agent_end threshold maintenance never
runs. That lets context grow past the soft threshold until provider
overflow or user abort.

Run threshold maintenance from the per-turn onTurnEnd hook for active
goals, splice the compacted agent state back into the live loop message
array, and suppress queued continuations because the current run is
already continuing. Cover the mid-run tool-call path and the non-goal
control case.

Refs #3174
2026-06-22 20:02:33 +00:00
roboomp 5b6e9f904d fix(eval): paused timeout over baseline capture and surfaced nested stash-restore failures
Two Codex P2 findings landed against 978d2a76d0 that were not in the previously delivered review event:

1) prepareIsolationContext() (which runs captureBaseline → walks nested repos and untracked diffs) was running OUTSIDE withBridgeTimeoutPause; on dirty/large repos the baseline walk can exceed the eval idle timeout while the runtime is blocked. Moved the prep call into the pause closure so the watchdog is suspended for the whole bridge call from prep through cleanup.

2) applyNestedPatches() swallowed git stash pop failures with only a logger.warn, so a stash-pop conflict after a successful agent commit was invisible to the workflow. Changed the helper to return Promise<string[]> of warnings; applyEligibleNestedPatches now wraps them in a <system-notification> appended to the merge summary so the caller actually sees the partial-success case.

Added regression tests:
- bridge: prepare fires after timeout-pause and before timeout-resume.
- runner: applyEligibleNestedPatches surfaces stash-restore warnings as a system-notification.
- worktree (real git): a pre-existing dirty edit on the same file the agent patches causes stash pop to conflict; the helper returns a warning naming the nested repo and the stash entry is preserved for manual recovery.

Fixes #3196
2026-06-22 21:57:35 +02:00
can1357 2f2acaf928 Merge pull request #3205: feat(eval): isolated/apply/merge options for agent() helper
Resolves conflict in test/task/worktree.test.ts by keeping both the
getRepoRoot (main) and applyNestedPatches (PR) describe blocks.

Extends the PR's Python/JS work to the remaining workflow runtimes:
- eval/rb/prelude.rb, eval/jl/prelude.jl: agent() now accepts and
  forwards isolated/apply/merge (as booleans) plus returnHandle, and the
  return_handle node carries isolated/patch_path/branch_name/
  nested_patches/changes_applied/isolation_summary.

Post-merge fixups:
- task/index.ts: drop dead commitStyle var (the dedup refactor reads
  task.isolation.commits inside makeIsolationCommitMessage).
- CHANGELOG: move the misplaced Added entry under [Unreleased], correct
  the stale "defaults track task.isolation.mode" wording to the final
  strict opt-in behavior, and note all four runtimes.

Fixes #3196
2026-06-22 21:56:45 +02:00
can1357 a8a0cc8a40 fix(coding-agent): prevented streaming output duplication in scrollback
- Clamped tool output preview height to the available viewport rows to stop redundant banner commits.
- Added `outputBlockContentWidth` helper to accurately measure visual lines for scrollback budget calculations.
- Updated `bash` and `eval-render` output wrapping to account for block padding and inner content width.
- Added regression test confirming streaming tool output maintains a stable line count without duplicating headers.
2026-06-22 21:43:19 +02:00
roboomp abc9a8f292 fix(task): restored nested stash with index state
git stash pop without --index restores stashed staged changes as unstaged. When a nested repo had staged WIP before the isolated agent ran, the pop in applyNestedPatches() brought the content back but lost the user's index state.

Pass { index: true } so pop uses --index, matching the root merge path that already does the same thing.

Added a regression test that stages a pre-existing edit in the nested repo, runs applyNestedPatches, and asserts the file is still in the index (porcelain "M  " with the trailing space) and the cached diff still shows the staged WIP.

Fixes #3196
2026-06-22 19:41:59 +00:00
roboomp 978d2a76d0 fix(task): preserved nested-repo dirty state across nested patch apply
applyNestedPatches() applied the captured patch then ran git.stage.files(nestedDir), which stages every working-tree change in the nested repo. A nested repo that was already dirty before the agent ran ended up with the user's unrelated work-in-progress committed alongside the agent delta.

Stash any pre-existing dirty state (tracked + untracked) before applying the patch and pop it back in the finally block after the commit, so the agent commit contains only the captured patch and the user's in-flight work is restored on top of it. A failing stash pop logs a warning and leaves the stash entry intact for manual recovery; the broader nested-apply failure path is already non-fatal.

Added a worktree integration test that confirms a pre-existing untracked file in the nested repo is not staged into the agent commit and is still present in the working tree afterwards.

Fixes #3196
2026-06-22 19:34:42 +00:00
roboomp 28137f46d9 refactor(task): deduped nested patch apply + commit-message factory
TaskTool and the eval agent() bridge each held a private copy of the nested-repo patch eligibility gate and the AI commit-message factory; isolation policy could drift between the two callers.

Moved both into task/isolation-runner.ts:
- applyEligibleNestedPatches(opts) — single nested-patch gate (skip on patch-mode parent failure, skip on branch-mode unmerged root, fail non-fatally with a system-notification suffix).
- makeIsolationCommitMessage(session) — single factory that yields the AI commit-message callback when task.isolation.commits === "ai" and a model registry is wired, undefined otherwise.

Both call sites now invoke the helpers; behavior is unchanged. Removed the now-dead generateCommitMessage/applyNestedPatches imports from each caller.

Added unit tests for the new helper covering the skip-on-patch-failure, skip-on-unmerged-branch, success, and failure-suffix paths.

Fixes #3196
2026-06-22 19:22:24 +00:00
can1357 5c21b28786 feat: optimized handoff generation and harden request safety
- Introduced `generateHandoffFromContext` to enable provider-aware oneshot generation and improved cache hit rates via the live-turn pipeline.
- Updated `buildSideRequestContext` to support pinning custom system prompts, preventing per-turn hook leakage during handoff.
- Added concurrency guards across CLI and RPC modes to block manual `/handoff` requests while a session is actively streaming.
- Standardized handoff execution to force `toolChoice: "none"` and enforce consistent cache-routing behavior.
2026-06-22 20:05:40 +02:00
roboomp 921904b3de fix(web-search): cancelled queued exa waits
Raced queued Exa throttle waits against the caller abort signal so requests cancelled behind an earlier throttle wait reject immediately without breaking the serialized throttle chain.

Added regression coverage for cancelling a third Exa request queued behind another delayed request.

Fixes #3271
2026-06-22 17:59:17 +00:00
roboomp 022010ad97 fix(web-search): aborted exa throttle waits
Made Exa request pacing observe cancellation during the configured delay instead of waiting for the full delay before checking the signal.

Added regression coverage for a queued Exa request cancelled while throttled.

Fixes #3271
2026-06-22 17:54:15 +00:00
roboomp 9e32c19793 fix(web-search): paced exa search requests
Added configurable Exa search request pacing via exa.searchDelayMs so repeated web_search calls no longer burst directly into Exa rate limits.

Covered the provider contract with a focused Exa test and recorded the back-to-back request repro.

Fixes #3271
2026-06-22 17:47:28 +00:00
roboomp 12aedd7388 fix(coding-agent): returned to ask options after custom escape
Keep the ask tool on the current question when the custom answer editor is dismissed, so Escape from Other returns to the option selector instead of aborting or recording an empty answer.

Fixes #3269
2026-06-22 17:10:49 +00:00
Mathews-Tom 40f1b34a21 Merge remote-tracking branch 'upstream/main' into feat/secret-friendly-names
# Conflicts:
#	packages/coding-agent/src/secrets/obfuscator.ts
2026-06-22 22:10:49 +05:30
can1357 58b3c41ed1 fix(coding-agent): align MiniMax login test with multi-key append + per-key logout
API-key /login appends sibling keys for every provider (#3265); the stale test still asserted MiniMax replace-on-relogin (#156). Assert append, same-key idempotency, and individual removal via removeCredential (the logout path).
2026-06-22 18:17:46 +02:00
can1357 70dc314277 Merge remote-tracking branch 'origin/farm/caaffa95/filter-brush-incompatible-aliases' 2026-06-22 17:45:32 +02:00
can1357 1082b6316a Merge remote-tracking branch 'origin/farm/5ce2a200/hide-secrets-blocks-advisor' 2026-06-22 17:44:48 +02:00
can1357 3e345a50a1 Merge remote-tracking branch 'origin/farm/8689c858/model-discovery-cache-ttl' 2026-06-22 17:44:39 +02:00
can1357 d025803cb6 Merge remote-tracking branch 'origin/farm/923f93e8/perplexity-isavailable-openrouter-leak' 2026-06-22 17:44:31 +02:00
can1357 75acaa40f1 Merge remote-tracking branch 'origin/farm/4801c6f1/stdio-transport-merge-process-env' 2026-06-22 17:43:52 +02:00
can1357 beb61b1831 Merge remote-tracking branch 'origin/farm/f3af36ee/clear-openai-completions-on-switch' 2026-06-22 17:43:34 +02:00
can1357 0fbcb63539 fix: preserved shells with running background jobs
- Added `Shell.liveBackgroundJobCount` to query active background processes.
- Retained per-call `:async:` shells if background jobs are still running upon turn completion.
- Reaped shells automatically once their last background process exits to prevent lingering processes.
2026-06-22 17:25:19 +02:00
can1357 26c72689c2 feat(coding-agent): added share.store setting for session uploads
- Added a `share.store` configuration option (`blob` | `gist`) that allows users to choose between the default share server or a GitHub gist for storing exported session data.
- Changed the default upload target from secret GitHub gists to the share server to avoid GitHub API rate limits for shared sessions.
- Enabled fallback to the share server when a gist upload fails or the GitHub CLI is unavailable.
2026-06-22 17:25:05 +02:00
Mathews-Tom 6050ddeaf0 fix(secrets): redact a pre-existing placeholder key when no effective secrets
The key-creation fix still built the obfuscator from allEntries when those
entries were all ineffective (e.g. only ignored short plain secrets), so a
pre-existing secret-placeholder.key was left unredacted (hasSecrets() false
disables obfuscation) and a tool read shipped the reusable HMAC key. Gate
the redaction-only obfuscator on hasSecrets() instead of allEntries.length:
whenever a persisted key exists but no configured entry produced an active
secret, build the key-redaction-only obfuscator so the key file is redacted.
2026-06-22 20:43:40 +05:30
Mathews-Tom b735ce76d8 fix(secrets): do not create a placeholder key for ignored short secrets
When the only obfuscate entries were short (<8 char) plain secrets, the
key-creation gate still saw them as obfuscate-mode and wrote/persisted
`secret-placeholder.key`, yet SecretObfuscator tones those entries down so
hasSecrets() is false and provider-output redaction is disabled. The
persisted key was then readable via a tool (leaking it to the model) and
reused for later placeholders. Gate key creation on whether an entry can
actually produce a reversible placeholder via a shared predicate
(secretEntryNeedsPlaceholderKey), single-sourcing the tone-down threshold
as MIN_OBFUSCATE_SECRET_LEN.
2026-06-22 20:29:53 +05:30
Mathews-Tom c67d2bb49d fix(secrets): make default regex replacements distinct from the sentinel
The default replace-mode regex path emitted the raw match verbatim when
its deterministic replacement equalled the `Z`/`ZZ` sentinel (e.g. a
literal regex matching "ZZ"). Route it through a regex-aware distinctness
guard: perturb to a length-preserving distinct value, but only when the
regex does not re-match the perturbed output. For a self-matching short
regex (e.g. `Z+`, `[A-Z]{2}`) any non-sentinel 2-char value is re-matched
and would oscillate, re-leaking on alternate passes, so the sentinel is
kept to preserve the obfuscate() fixed-point invariant. Such configs are
pathological. Plain replace secrets remain unconditionally perturbed.
2026-06-22 20:10:34 +05:30
Mathews-Tom a305af9587 fix(secrets): never emit a plain replace secret equal to the Z/ZZ sentinel
A plain replace-mode secret (or the redacted key) whose entire value is
exactly the deterministic sentinel (`Z`/`ZZ`) was emitted unchanged,
shipping the raw value to the provider. Scope a distinctness guard to
whole configured-secret replacements so the output differs from the input
while staying length-preserving and deterministic; a plain secret only
matches its own literal, so the perturbed output remains a fixed point
under re-obfuscation. Per-chunk remainder redaction keeps the sentinel
fixed-point for cross-restart idempotence.
2026-06-22 19:53:36 +05:30