Commit Graph

16744 Commits

Author SHA1 Message Date
can1357 ef852af986 feat(computer): implemented modular desktop backend and script workflows
- Replaced monolithic desktop native bindings and action batching with a modular cross-platform backend structure supporting Wayland, X11, macOS, and Win32.
- Updated the computer tool schema and supervisor to execute persistent JavaScript script runs with timeout clamping and asynchronous tool calling.
- Integrated accessibility (AX) tree snapshotting, node querying, and bounds-based hit testing across platform desktop layers.
- Added native clipboard bindings and updated coding-agent prompts, renderers, and tests to validate script-based computer workflows.
2026-08-02 19:46:25 +02:00
can1357 92b50faacc feat(coding-agent/lsp): implemented lsp multiplexer server and shared daemon lifecycle
- Added an LSP multiplexer server, protocol definitions, and daemon lifecycle management to route traffic across sessions.
- Introduced `lsp.shared` settings configuration and SDK session creation support for shared language servers.
- Migrated shared daemon ensure helpers into a central launch module with updated import references.
- Added comprehensive unit tests and fake LSP server fixtures covering muxing, sharing, caching, and restarts.
2026-08-02 18:15:22 +02:00
can1357 4a946e2cfc fix(coding-agent/tools): serialized tab grouping operations in the relay bridge
- Serialized group and ungroup operations to prevent duplicate tab group creation races.
- Queued and serially drained tab grouping requests in the relay bridge to prevent overlapping RPCs.
- Mirrored tab group titles to session storage and healed duplicate groups during background service worker recovery.
- Renamed run-cancellation utility to run-scope and updated corresponding module and test references.
2026-08-02 18:07:07 +02:00
can1357 7c3b24ddf2 feat: implemented cross-platform window discovery and targeting capabilities
- Added window discovery, targeting, and frame validation for macOS, Windows, and Linux platforms.
- Updated computer tool and protocol definitions to support listing and targeting specific application windows.
- Refactored native computer tool exposure to function-only representation across models.
- Updated documentation and test suites to reflect window-scoped computer control capabilities.
2026-08-02 17:35:29 +02:00
can1357 4e65a685ae fix(ai): addressed anthropic stream truncation errors for tool call recovery
- Added `isStreamEnvelopeErrorText` to packages/ai/src/error/flags.ts to recognize stream envelope truncation errors.
- Updated `streamAnthropicOnce` in packages/ai/src/providers/anthropic.ts to throw an envelope error when streams die mid-generation without a terminal frame.
- Updated `recoverTransientErrorToolTurn` in packages/agent/src/agent-loop.ts to recognize Anthropic stream envelope truncation errors for tool call salvage.
2026-08-02 06:14:01 +02:00
can1357 92c79d80c7 feat: introduced OMP Browser Relay extension with CDP RPC execution
- Implement the OMP Browser Relay extension with WebSocket communication and CDP RPC execution.
- Add browser relay server, daemon management, and bridge multiplexing in the coding agent.
- Introduce CLI commands and settings schema options for configuring and installing the relay.
- Add utility functions and test suites supporting environment parsing and relay lifecycle handling.
2026-08-02 05:33:07 +02:00
can1357 06343fef42 fix(bazel): anchored maudio-sys patch hunks with context lines
Bazel's patch parser applies pure-insertion -U0 hunks one line early,
which dropped the lib.rs layout asserts inside 'mod ffi' on linux builds
(E0433). Regenerated the text hunks with -U1 context and moved the C
probe block after the miniaudio include so no hunk touches the crate's
newline-less final line, which the parser also rejects. Verified the
patched lib.rs type-checks for all four linux binding sets and the
darwin natives + maudio_layout_test pass under bazel.
2026-08-02 00:39:53 +02:00
can1357 2c4c3e9102 fix(bazel): rebased maudio-sys patch onto 0.1.5
The 17.2.4 bump moved maudio-sys 0.1.4 -> 0.1.5, which upstreamed the
per-target pregenerated bindings this patch used to add; the old build.rs
hunks no longer applied (CONTENT_DOES_NOT_MATCH_TARGET) and broke every
bazel natives fetch. The rebased patch keeps only what upstream lacks:
- x86_64-unknown-linux-musl pregenerated bindings
- C static asserts + omp_maudio_* ABI probes for maudio_layout_test
- lib.rs compile-time layout asserts pairing with the C side
Hunks are -U0 so bazel's patch parser never sees the no-trailing-newline
marker in miniaudio_version_check.c. Also refreshed MODULE.bazel.lock
for the 17.2.4 Cargo manifest hashes.
2026-08-02 00:33:48 +02:00
can1357 d595332fc6 chore: bump version to 17.2.4 2026-08-02 00:19:30 +02:00
can1357 9ad82cbe6e test(coding-agent): simulated production env in unref worker repro
The CI harness exports PI_TEST_RUNTIME=1, which the wrapper subprocess
inherited; isBunTestRuntime() then suppressed unref in the worker client
and deterministically kept the wrapper alive until the test timed out.
Override PI_TEST_RUNTIME=0 in the wrapper env and restore the 10s bound.
2026-08-01 23:15:11 +02:00
can1357 2d27412022 test(coding-agent): aligned activation tests with write-gated xd mounting
- Updated sdk-tool-activation expectations for 386385f18b: sessions
  without a granted write tool keep extension/SDK tools top-level and
  allocate no xd:// state instead of auto-granting write.
- Raised the unref'd-worker parent-exit repro to a 30s timeout; the 10s
  ceiling SIGTERMed the wrapper (exit 143) on shared-core CI runners.
2026-08-01 23:05:28 +02:00
can1357 23c629be18 test(coding-agent): aligned deferred MCP test with write-gated xd mounting
386385f18b made xd:// mounting require both granted transport halves and
stopped auto-granting write; a read-only session now surfaces deferred
MCP tools top-level. The test still encoded the old auto-grant contract.
2026-08-01 22:55:01 +02:00
can1357 dda859b60f fix(ci): hardened logger probe timeouts and silenced async trait lint
- Raised probe-spawning logger tests to 30s timeouts; bun's 5s default
  SIGTERMed probe children (exit 143) on shared-core CI runners, matching
  the precedent documented in logger-contract.test.ts.
- Allowed clippy::unused_async_trait_impl on KillCommand::execute with an
  unknown_lints guard for the pinned CI nightly that predates the lint.
2026-08-01 22:34:39 +02:00
can1357 d3ca0184de fix(brush-core): exposed windows signal stubs as public re-export
pi-shell calls sys::signal::kill_process on the windows target; the
pub(crate) glob re-export made it invisible outside brush-core, unlike
the unix module where kill_process is pub. Mirrors unix visibility.
2026-08-01 22:24:31 +02:00
can1357 534f43eda6 style(pi-shell): wrapped long allow attributes per rustfmt 2026-08-01 22:12:13 +02:00
can1357 ed7d085708 fix(pi-shell): resolved clippy-strict errors in process builtins
- Made infallible ProcInfo accessors const and annotated Option-returning
  accessors with allow(unnecessary_wraps) since Option is the shared
  cross-platform contract.
- Boxed ParseProcResult::Options to shrink the enum.
- Restructured kill signal resolution to bind signal once instead of
  let-then-reassign sequences.
- Simplified liveness re-check with Option::is_none_or.
2026-08-01 22:08:55 +02:00
can1357 d326af8ed0 feat: implemented process management builtins and cross-platform snapshotting
- Implemented new shell builtins including `top`, `pgrep`, `pkill`, `pidwait`, and `kill`.
- Added a cross-platform process snapshot module supporting Linux, macOS, and Windows.
- Extended job and process handling utilities with process iteration and handle termination methods.
- Replaced test mutex locks with thread-local counters to prevent test races in the minimizer engine.
2026-08-01 21:58:09 +02:00
can1357 30163ed91c fix(ai): closed corruption-latch gaps from cred-latch review
- #readPersistedCredentialBlockReconcileAfter no longer rethrows
  non-corruption errors; transient failures (e.g. SQLITE_BUSY) log at
  debug and fall back to the in-memory probe window, mirroring
  #readPersistedCredentialBlock.
- Constructor's best-effort cleanExpiredCredentialBlocks now routes
  errors through #handlePersistedBlockStoreError so init-time corruption
  latches immediately instead of deferring to the first block read.
- reload() latches and surfaces repair guidance when listAuthCredentials
  throws on a corrupt store, then still rethrows: continuing with zero
  credentials would silently log the user out of every provider.
2026-08-01 21:44:26 +02:00
can1357 5af413d694 Merge PR #7305: fix(ai): latch and surface a corrupt credential-block store (@roboomp) 2026-08-01 21:42:22 +02:00
can1357 3b84fde884 test(ai): replaced busy-handler ordering spy with real lock contention
- The #7298 test asserted PRAGMA-vs-DDL ordering by spying on
  Database.prototype.run SQL strings — implementation plumbing.
- Now a child process creates the db and holds BEGIN EXCLUSIVE for 750ms
  (past open()'s ~700ms retry budget, under the 1000ms headless
  busy_timeout), signaling readiness via a filesystem sentinel; open()
  only survives if the busy handler is installed before the leases DDL.
- Verified the test fails with the ordering fix reverted.
2026-08-01 21:42:05 +02:00
can1357 3e978e95c0 Merge PR #7304: fix(ai): install auth-db busy handler before open()-path leases DDL (@roboomp) 2026-08-01 21:42:05 +02:00
can1357 811fcde05f Merge PR #7306: fix(title): reject overlong auto-generated session titles (@roboomp) 2026-08-01 21:29:46 +02:00
can1357 8fe2b8f9ba Merge PR #7311: fix(catalog): honor openrouter deepseek effort metadata (@roboomp) 2026-08-01 21:29:35 +02:00
can1357 a03bc543de Merge PR #7308: fix(stats): wait for contended usage snapshot reads (@roboomp) 2026-08-01 21:28:27 +02:00
can1357 e154c8ed0b fix(catalog): sourced antigravity claude pricing from google vertex
- Claude ids now alias to google-vertex suffixed entries (claude-opus-4-6@default etc.) so Antigravity follows Google's price if it diverges from Anthropic's list price; plain-id anthropic lookup remains as dangling-alias fallback.
- Regenerated models.json via gen:models.
2026-08-01 21:27:51 +02:00
can1357 d0d15f1a55 fix(catalog): implemented fallback pricing for unpriced antigravity models
- Added `applyAntigravityPricingFallback` to back-fill unpriced `google-antigravity` models using first-party list prices from `google` and `anthropic`.
- Mapped Antigravity model IDs to preview-id aliases (e.g., `gemini-3.1-pro` to `gemini-3.1-pro-preview`) for correct pricing resolution.
- Added test coverage in `packages/catalog/test/generated-policies.test.ts` verifying fallback pricing and preservation of billable costs.
2026-08-01 21:23:17 +02:00
roboomp af11e78796 fix(ai): rejected broker block writes after corruption
Fail broker-facing block mutations on the first corrupt SQLite write and every later latched call instead of returning a false durability acknowledgement. Internal request-path persistence remains an in-memory no-op, preserving local availability.

Verify RemoteAuthCredentialStore keeps its optimistic rate-limit block and does not refresh an empty snapshot when the broker rejects persistence.
2026-08-01 19:13:42 +00:00
roboomp 2cfaeb6116 fix(catalog): honored openrouter deepseek effort metadata
- Parsed OpenRouter reasoning effort ladders and defaults during discovery.

- Preserved explicit thinking metadata from models.yml patches.

- Regenerated the catalog and covered both regression paths.

Fixes #7307
2026-08-01 19:06:44 +00:00
roboomp ae91e7e136 fix(ai): guarded block reconcile reads after corruption
Route credential-block reconcile-after reads through the same corruption latch used by persisted block reads and writes. A latched store now returns an immediate zero probe time without touching SQLite; a first corruption from reconcile-after latches and reports once, while transient errors still propagate.

Add a Codex regression covering a corrupt block write followed by healthy usage reconciliation.
2026-08-01 19:05:57 +00:00
can1357 992963f949 feat(coding-agent): allowed switching to models smaller than session context with compaction
- Make over-context models selectable in the model picker by graying them instead of disabling them.
- Trigger automatic session compaction with the current model prior to switching when an over-context model is chosen.
2026-08-01 20:59:24 +02:00
roboomp 1dc976b8cb fix(ai): guarded broker block operations after corruption
Route the broker-facing list, upsert, and delete methods through the same per-process corruption latch as credential selection. Preserve transient error propagation while returning safe empty/no-op fallbacks for SQLITE_CORRUPT and SQLITE_NOTADB.

Add table-driven coverage proving each public block operation independently reports once and short-circuits every later store call.
2026-08-01 18:56:48 +00:00
roboomp b1ce143a3c fix(stats): added timeout to usage snapshot reads
Installed a five-second SQLite busy timeout before the read-only usage query and covered lock contention with a subprocess-backed regression test.

Fixes #7300
2026-08-01 18:50:54 +00:00
roboomp 294f32d6bc fix(title): reject overlong auto-generated session titles
normalizeGeneratedTitle only guarded emptiness and the none sentinel, so
when the tiny title model ignored the titling task and answered the first
user message, its full one-line reply became the session title verbatim.
Bound accepted titles to 80 chars / 12 words and return null past that,
deferring titling to the next user turn. Both the online and local-worker
paths funnel through this normalizer, so both are covered.

Fixes #7303
2026-08-01 18:50:28 +00:00
roboomp ff557b7a98 fix(ai): latch and surface a corrupt credential-block store
AuthStorage caught unrecoverable SQLite errors (SQLITE_CORRUPT family /
SQLITE_NOTADB) from the persisted credential-block read and write paths
at debug level with no latch. A corrupt agent.db therefore re-queried the
broken store on every credential evaluation while persisted rate-limit
blocks silently stopped applying, failing open in the direction that
hammers rate-limited accounts.

Detect the corruption family via isSqliteCorruptionError, report it once
at error level with the store location and repair guidance, and
short-circuit every later persisted-block read/write for the process
lifetime. Availability is preserved through the in-memory backoff map;
only cross-process persistence is lost.

Fixes #7296
2026-08-01 18:47:19 +00:00
roboomp ce277939ae fix(ai): install auth-db busy handler before open()-path leases DDL
SqliteAuthCredentialStore.open() ran #ensureAuthCredentialRefreshLeasesTable
(CREATE TABLE/INDEX for auth_credential_refresh_leases) with Bun's default
busy_timeout=0, before the constructor's #initializeSchema installed the
handler. Under a concurrent write lock (WAL recovery on parallel omp
startups) the lock-taking DDL failed immediately; the error was not
BUSY-classified, so open()'s bounded retry loop was bypassed.

Install the busy handler on the connection right after it opens, before any
lock-taking statement, via a shared #installBusyTimeout helper reused by
#initializeSchema. Honors the issue-#2421 invariant on every entry path.

Fixes #7298
2026-08-01 18:47:10 +00:00
can1357 72c66c87c1 fix(xdg): adopted legacy secret-placeholder.key and marketplaces.json at XDG paths 2026-08-01 20:46:25 +02:00
can1357 03e54555f9 Merge PR #7065: fix(xdg): fix files and folder for xdg-maintained (@Parsifa1) 2026-08-01 20:39:29 +02:00
can1357 386385f18b fix(coding-agent): skipped xd:// mounting when write tool is not granted
- Prevent xdev state allocation and tool mounting in sessions lacking a write tool.
- Expose discoverable tools top-level instead of auto-granting write transports.
2026-08-01 20:39:08 +02:00
can1357 13a36f7c83 refactor(coding-agent/mcp): changed default MCP request ID format to sequential integers
- Change the default MCP JSON-RPC request ID format from snowflake strings to sequential integers.
- Update server configuration schema, connection equivalence checks, and tests to reflect the new integer default.
2026-08-01 20:33:11 +02:00
can1357 943bbd393e fix(ai): restored cache-retention-aware prompt cache key after codex compaction merge 2026-08-01 20:17:01 +02:00
can1357 9f65d3ae71 chore: applied biome formatting to sweep fix commits 2026-08-01 20:15:15 +02:00
can1357 44c7421462 chore: normalized changelog entries after merging sweep fixes 2026-08-01 20:14:51 +02:00
can1357 51afd5c503 fix(coding-agent): tombstone remote hub kills 2026-08-01 20:14:41 +02:00
can1357 cc884eea9b Merge PR #7252: fix(coding-agent): keep hub-killed subagent from resurrecting as parked (@roboomp) 2026-08-01 20:14:40 +02:00
can1357 b1ba3a8f73 fix(ai): preserve strict tools for detailed OpenRouter errors 2026-08-01 20:14:40 +02:00
can1357 57356552b5 Merge PR #7265: fix(ai): retry opaque OpenRouter strict-tool errors (@roboomp) 2026-08-01 20:14:40 +02:00
can1357 3fd042c38b fix(coding-agent): preserve grouped reads during retraction 2026-08-01 20:14:40 +02:00
can1357 191872990e Merge PR #6881: fix(coding-agent): retract superseded turn's tool cards to stop double render (@roboomp) 2026-08-01 20:14:40 +02:00
can1357 1088ee2127 Merge PR #7203: fix(tui): render mid-turn steering skips as info, not errors (@roboomp) 2026-08-01 20:14:40 +02:00
can1357 61d066bd2a Merge PR #6756: fix(coding-agent): suppress WIP advisor non-blockers (@wolfiesch) 2026-08-01 20:14:39 +02:00