Commit Graph

6138 Commits

Author SHA1 Message Date
can1357 667111575e feat: implemented credential lifecycle tracking and management APIs
- Added `listDisabledCredentials` and `refreshSnapshot` methods to credential stores along with API endpoints and wire schemas.
- Added `authorizedAt` timestamps and Anthropic OAuth grant TTL constants to track credential lifecycles.
- Updated the usage CLI to render auto-disabled credential tombstones and grant expiration warnings.
- Added comprehensive unit and broker integration tests covering the new credential management features.
2026-07-25 18:02:43 +02:00
can1357 bef97a69bb Merge PR #6529: fix(coding-agent): guard retain renderer streaming args (@roboomp) 2026-07-25 00:59:14 +02:00
can1357 8851e93d21 Merge PR #6551: fix(coding-agent): use session settings in file guards (@roboomp) 2026-07-25 00:59:14 +02:00
roboomp 144043ad48 fix(coding-agent): used session settings in file guards
Passed session-scoped settings through Edit and Write generated-file checks and fell back to schema defaults when no global singleton exists.

Guarded inline image sizing against an uninitialized global settings proxy and added isolated-session regression coverage.

Fixes #6549
2026-07-24 22:42:38 +00:00
can1357 f23bc266a8 feat(natives): enabled per-language rewrite rules for mixed-language paths
- Remove uniform language inference requirement, allowing mixed-language paths to rewrite each file in its own language.
- Update `ast_edit_blocking` in `crates/pi-natives/src/ast.rs` to compile rewrite rules per language and skip unsupported languages gracefully.
- Update `ast-edit.md` prompt documentation to reflect mixed-language path support.
- Add test coverage verifying mixed-language tree rewrites.
2026-07-24 21:52:29 +02:00
roboomp d7c7ca033d fix(coding-agent): guarded retain renderer streaming args
- Treated transient non-array retain items as absent during TUI streaming.
- Added regression coverage for malformed partial renderer arguments.
- Documented the fix in the coding-agent changelog.

Fixes #6528
2026-07-24 15:52:01 +00:00
can1357 a38cd95d7d chore: bump version to 17.1.2
- fixed eval preview windowing fixture to use valid identifiers so the display formatter's operator spacing does not rewrite the asserted lines
2026-07-24 17:23:19 +02:00
can1357 c55b28a26d chore(coding-agent): format eval display helpers 2026-07-24 16:49:31 +02:00
can1357 68e76c6243 fix(coding-agent): preserve shared live tools across rebuilds 2026-07-24 16:26:59 +02:00
can1357 b0f1b5c0c5 Merge PR #6496: fix(ai): preserve Anthropic server-tool history (@roboomp) 2026-07-24 16:26:52 +02:00
can1357 457d735475 Merge PR #6509: fix(coding-agent): honor modelRoles.default over cursor/default catalog id (@roboomp) 2026-07-24 16:26:48 +02:00
can1357 2bc26d3d4c Merge PR #6519: fix(coding-agent): avoid duplicate tools in transcript rebuilds (@roboomp) 2026-07-24 16:26:42 +02:00
can1357 ff49b986d5 feat(coding-agent/tools): introduced language-specific code formatters for display rendering
- Added language-specific code formatters for JavaScript, Julia, Python, and Ruby to improve display rendering.
- Integrated display formatting into browser run and eval render tools while preserving verbatim execution.
- Added comprehensive test suites verifying formatting stability, lexical safety, and streaming behavior.
2026-07-24 16:26:03 +02:00
can1357 5acdefc7b3 feat(coding-agent/web): introduced structured web-search query parsing module
- Implemented a structured web-search query parsing module supporting directives, tokenization, date parsing, and syntax serialization.
- Updated search providers to map query directives and date bounds to native provider parameters and filters.
- Added lenient result constraint post-filtering and configuration settings for enhanced engine routing.
- Added comprehensive unit and integration tests covering query parsing, constraint filtering, and provider-specific request mapping.
2026-07-24 16:05:14 +02:00
roboomp 484fa319eb fix(coding-agent): keep running async task handles during rebuild dedup
The rebuild dedup dropped any preserved pendingTools component whose toolCallId
had a persisted toolResult. A background task's initial async.state=="running"
result is persisted while EventController#handleToolExecutionEnd deliberately
keeps its component in pendingTools so a later tool_execution_update/_end can
settle it. Dropping that still-live handle stranded those updates on the running
snapshot. Only terminal results are now owned by the replay; running async
handles stay preserved. Added a regression covering the running-task case.
2026-07-24 13:53:43 +00:00
can1357 db937bd149 feat(coding-agent): added coarse effort parameter to task tool
- Add `effort` (`lo`/`med`/`hi`) parameter to task spawn parameters and prompts.
- Implement `resolveTaskEffortLevel` to map coarse task effort onto model-supported thinking ranges.
- Pass effort configuration through executor options and structured subagent requests.
2026-07-24 15:51:34 +02:00
roboomp 759e551e8c fix(coding-agent): dropped resolved tools from mid-stream rebuild preservation
rebuildChatFromMessages preserves the live pendingTools components across its
clear+replay so streaming keeps routing into them. That preservation assumed
every pending-tool component was still dangling (its result outside
state.messages). Once a tool's result had landed in the session entries while
its component still lingered in pendingTools (a rebuild racing the
tool-completion event, or a background/displaceable snapshot), the replay
reconstructed the completed block from the persisted toolResult AND the
preserved live component was re-appended, so the same tool block rendered twice.

Resolved tool calls are now dropped from the preserved live set and owned by the
replay; only genuinely in-flight (dangling, replay-stripped) calls are preserved.

Fixes #6516
2026-07-24 13:40:57 +00:00
can1357 c6dcfa4137 feat(coding-agent): compacted oversized sse payloads in debug buffer
- Added tool schema and description compaction for oversized data payloads in `packages/coding-agent/src/debug/raw-sse-buffer.ts`.
- Implemented head-tail trimming to preserve leading and trailing event fields when events exceed character budgets.
- Added test coverage verifying SSE debug event truncation, elision markers, and JSON-safe tool compaction behavior.
2026-07-24 15:20:36 +02:00
can1357 9f8aa87dbf feat(task): removed per-call model override from task tool
- Removes `model` field from task item/schema, TaskParams, and TaskItem types.
- Removes model selector validation, formatting, and approval display logic.
- Updates task tool priority docs to reflect that model is no longer per-call overridable.
- Updates eval agent() helper docs and prompt templates to remove model parameter.
- Updates tests to reflect removal of model override capability.
2026-07-24 14:51:48 +02:00
roboomp 8191cf41d3 fix(coding-agent): used authenticated registry models by default
Required CLI model registries to expose getAvailable() and used that authenticated
set whenever callers omit availableModels. Deferred SDK and bench/dry-balance
resolution now lets configured roles beat unauthenticated catalog id collisions.

Updated resolver test registries and made the #6508 regression omit the explicit
availableModels option, covering the deferred-caller path from the review.

Fixes #6508
2026-07-24 11:41:58 +00:00
roboomp df0e77c584 fix(coding-agent): honor modelRoles.default over cursor/default catalog id
`resolveCliModel` ran findExactCliModel's unauthenticated catalog fallback
before configured-role resolution, so the bundled `cursor/default` model (bare
id `default`) shadowed a configured `modelRoles.default`. On machines without
Cursor credentials `--model default` failed with `No API key found for cursor`
instead of resolving the configured, authenticated default role.

Defer the catalog fallback: explicit provider/id references and authenticated
bare ids still win over roles, a configured role now beats an unauthenticated
catalog-only id, and the catalog id is still recovered via the trailing fuzzy
fallback when no role matches.

Fixes #6508
2026-07-24 11:30:51 +00:00
can1357 de00e7f136 feat(tui): renamed large-paste local refs to paste-N.md
- Large-paste menu now saves pastes as local://paste-N.md instead of
  local://attachment-N, giving the artifact a markdown extension and a
  clearer name.
2026-07-24 12:25:40 +02:00
can1357 d4792ed38b fix(tools): leniently inferred missing todo op from unambiguous payloads
- Kept op required in the todo schema; lenientArgValidation now routes raw args to execute(), where resolveTodoParams re-validates and repairs an omitted op (list -> init, phase+items -> append, bare items on empty list -> init).
- Ambiguous op-less calls surface the schema error as a retryable tool error instead of a hard validation failure.
2026-07-24 12:03:06 +02:00
roboomp d868519149 fix(coding-agent): dropped Anthropic server-tool blocks from shares
Redacted assistant anthropicServerTool blocks alongside redactedThinking and providerPayload so /share never uploads raw server_tool_use input or web_search_tool_result encrypted_content.
2026-07-24 09:12:53 +00:00
can1357 6ac5879858 feat(live): rendered visualizer across entire container width
- Removed max width cap of 120 columns in LiveVisualizer.

- Added unit test to verify full width rendering for wider viewports.
2026-07-24 09:28:42 +02:00
can1357 c9c0882724 feat(audio): replaced Chromium browser audio with native audio stack
- Switched from `miniaudio` to `maudio` Rust crate and added `AudioCapture` and `AudioPlayback` native classes.
- Removed browser-side audio infrastructure including Web Audio API, audio worklet processor, and WebRTC runtime.
- Migrated STT recorder and transcriber modules to use native `AudioCapture` with callback-based streaming.
- Replaced streaming audio player with native `AudioPlayback` that writes PCM directly without TypeScript intermediaries.
- Removed ffmpeg, wav, and platform-specific playback commands from the audio toolchain.
2026-07-24 08:54:16 +02:00
can1357 75cc0a054f feat(coding-agent/tools): added default card fallback for tool rendering
- Extracted #formatToolExecution into a standalone formatDefaultToolExecution module.
- Updated xdev renderXdevCall and renderXdevResult to use the default card when no mounted renderer exists.
- Added fallback rendering that shows tool label, args, and output with appropriate theming.
- Added integration test verifying generic card renders for mounted tools without bespoke renderers.
2026-07-24 08:19:13 +02:00
can1357 024f49220e fix(coding-agent): handled xdev execution errors with mounted tool renderer
- Catch execution errors in XdevRegistry and render them using the mounted tool's error handling.
- Preserve xdev dispatch context when device execution fails.
2026-07-24 08:03:17 +02:00
can1357 af9e8546a9 feat: implemented session account selection and pinning via slash command
- Add `pinSessionOAuthAccount` storage method and active account flag to the auth storage API.
- Introduce session account selector component, controller logic, and interactive mode delegation.
- Implement the `/session pin` builtin slash command with text listing and account pinning capabilities.
- Add unit tests covering session account selection, component navigation, and command handling.
2026-07-24 07:57:55 +02:00
can1357 38ad7e71c4 Merge PR #6472: fix(coding-agent): restored legacy keyText export (@roboomp) 2026-07-24 06:51:37 +02:00
can1357 02ad4c3376 Merge PR #6469: fix(tui): prewarmed tiny-title worker off the first-submit hot path (@roboomp) 2026-07-24 06:51:37 +02:00
can1357 4f97aea2db Merge PR #6468: fix(tools): closed spilled output descriptors on error/abort paths (@roboomp) 2026-07-24 06:51:36 +02:00
roboomp fbd8382edb fix(coding-agent): restored legacy keyText export
- Added the upstream keyText helper to the legacy package-root shim.
- Covered active keybinding formatting and documented the compatibility fix.

Fixes #6470
2026-07-24 03:59:10 +00:00
roboomp a39dbc9b44 fix(tools): guarantee spill sink close when tail replay fails
#finalizeFile marked the sink finalized then ran the capped-artifact tail
replay before closing. A write error during that replay threw before
sink.end(), and because #finalized was already set the executor finally
paths calling dispose() could not retry the close, leaking the descriptor
and masking the original tool error.

Moved sink.end() into a finally around the tail replay and swallowed both
the replay and close errors so the descriptor is always released and
dispose() never throws.
2026-07-24 03:53:21 +00:00
roboomp 3cdb93cd01 fix(tui): prewarm tiny-title worker off the first-submit hot path
The first interactive submit fired session.generateTitle() before
startPendingSubmission() painted the optimistic user row, and
tinyTitleClient.generate() spawned the local tiny-title subprocess
synchronously in #ensureWorker() before its first await. With a local
providers.tinyModel configured, subprocess-spawn latency therefore landed
ahead of the first frame, stalling the first prompt.

Paint the pending row before starting titling, and prewarm an idle,
unref'd worker at TUI startup via a no-op ping (no model load) so the
first submit reuses a live subprocess.

Fixes #6462
2026-07-24 03:48:43 +00:00
roboomp 31098f9248 fix(tools): closed spilled output descriptors on error/abort paths
OutputSink.dump() was the only path that closed the spill Bun.FileSink.
The bash and Python executors re-throw on failure and their finally
blocks never closed the sink, so any large-output command that errored
leaked the artifact descriptor until an unrelated read (e.g. a SKILL.md
load) hit EMFILE.

Added an idempotent OutputSink.dispose() that closes the sink exactly
once (awaiting any in-flight sink creation, guarding post-finalize
resurrection) and wired it into every executor's finally block.

Fixes #6463
2026-07-24 03:44:12 +00:00
usr-bin-roygbiv 68ac163e2c fix(computer): harden native desktop execution 2026-07-24 01:40:05 +00:00
can1357 681d7daf65 feat(computer): unified native addon, /computer toggle, function tool
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
  a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
  XTest input with keysym mapping) compiled into the core addon on every
  published target; Linux arm64 and musl are now supported and headless
  hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
  lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
  build dependencies, and the now-unreferenced vendored libspa crate;
  reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
  XTest layouts reject negative origins and coordinates beyond 0..=32767,
  batch coordinates stay bound to the frame last returned to JS with
  intermediate screenshots deferred, coordinate input requires a
  previously returned frame, and failed chord releases still release
  every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
  no input is emitted after expiry and wait-heavy batches are rejected
  upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
  scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
  a regular function tool with a typed GA action schema across OpenAI,
  Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
  session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
2026-07-24 01:40:05 +00:00
usr-bin-roygbiv 57f8acdd18 fix(native): harden desktop input and compatibility 2026-07-24 01:40:05 +00:00
usr-bin-roygbiv b9504f65e7 feat: add native Codex computer use 2026-07-24 01:40:04 +00:00
can1357 4e5cb4d400 test(coding-agent): fixed environment-sensitive and stale-trigger test failures
- Shimmed writable select.value in export-html harness; linkedom's getter-only HTMLSelectElement.value made template.js theme assignment throw under strict mode.
- Bound the oauth-flow port blocker to 127.0.0.1 explicitly; macOS lets a specific-address bind coexist with a wildcard one, so the flow bound the blocked port and never fell back.
- Re-anchored atomic-rewrite race tests on rewriteEntries() after the compaction-supersede rewrite trigger was removed in cb63ebd.
2026-07-24 03:38:15 +02:00
can1357 031d687325 test(coding-agent): aligned transcript compaction test with superseded-summary elision
- Superseded compaction summaries render as elided placeholders in the forward transcript since cb63ebd; only the active compaction keeps its text and frames.
2026-07-24 03:07:17 +02:00
can1357 995814b499 test(coding-agent): stubbed agent.continue in test to isolate queue observation
- Stubbed agent.continue to prevent idle-queue drain from consuming steer before inspection.
2026-07-24 02:48:00 +02:00
can1357 366bd6203e Merge PR #6392: feat(coding-agent): add usage-aware model fallback (@eggpeat) 2026-07-24 02:25:35 +02:00
can1357 77669aed54 Merge PR #6395: feat: configure xdev prompt docs (@joeshull) 2026-07-24 02:25:35 +02:00
can1357 5ded27b0b1 fix(cli): stopped $-pattern expansion when injecting cache prefix 2026-07-24 02:25:25 +02:00
can1357 3f2ef2cea1 Merge PR #6413: feat(cli): benchmark prompt cache reuse (@riverpilot)
# Conflicts:
#	packages/ai/src/providers/pi-native-server.ts
#	packages/ai/src/stream.ts
#	packages/ai/src/types.ts
2026-07-24 02:25:24 +02:00
can1357 b33e705aef Merge PR #6416: feat(ai): add process-scoped OAuth account pools (@atyrode) 2026-07-24 02:24:30 +02:00
can1357 0689092866 Merge PR #6445: feat(extensions): expose session service tiers (@atyrode) 2026-07-24 02:24:29 +02:00
can1357 aff775ecfb Merge PR #6443: fix(coding-agent): make mixed-agent task batches atomic and inspectable (@TechDufus) 2026-07-24 02:24:17 +02:00